A Data Broker Fined Over A Data Breach Involving A Third-Party Chatbot
September 22, 2026Read also: Miljödata fined after major data breach; Vodafone España hit with a €400,000 penalty after a ransomware attack; and more.

A data broker fined over a data breach involving a third-party chatbot
TradeZero America, Inc. has been fined $750,000 by the Massachusetts Securities Division following a data breach involving a third-party chatbot service used on the company’s website.
According to a consent order, an unknown hacker gained access in July 2024 to personally identifiable information belonging to thousands of TradeZero customers through the online chat service Tawk.to. Documents that customers uploaded through the chatbot were also compromised.
The investigation found that TradeZero failed to adequately vet the third-party vendor and ensure that appropriate security controls were in place. TradeZero’s parent company later paid the hacker in Bitcoin in exchange for a promise to delete the stolen data, but the company has not received proof that the information was erased.
The investigation also found that TradeZero used an automated system to review customer applications. In the result, some customers were approved for margin accounts or options trading without meeting the appropriate requirements, according to the consent order.
In addition to the $750,000 fine, TradeZero must reimburse Massachusetts investors for trading losses resulting from the improper approvals. The company must also retain an independent compliance consultant and strengthen its cybersecurity and account-approval policies.
Google hit with a €403 million fine over location data
Ireland’s privacy watchdog has fined Google €403 million over the way it collected and stored users’ location data, following a six-year investigation.
The Data Protection Commission (DPC) began its investigation in 2020 after complaints from European consumer groups. It examined Google features, including Web & App Activity, Location History and Location Accuracy.
The DPC found that Google broke several rules under the EU’s GDPR privacy law. Regulators said the company unlawfully processed location data and was not clear enough with users about how their information was handled. Authorities also found that some location data was stored for longer than necessary.
In addition to the fine, the DPC has ordered Google to change its data processing practices to comply with GDPR rules within six months. The regulator said it will publish the full decision at a later date.
Vodafone España to pay €400,000 after a ransomware attack
Spain’s data protection authority (the AEPD) has fined Vodafone España €400,000 after a ransomware attack at one of its service providers exposed the phone numbers of nearly 500,000 customers.
The attack took place on May 27, 2023. The service provider was acting as a processor for Vodafone and stored customer information on its systems. Attackers exploited a critical vulnerability that had been publicly disclosed in January 2023 but had not been patched.
The breach affected 486,768 private customers and 14,571 authorized contacts of business customers. Phone numbers were exposed without encryption. In some cases, other customer information, including names, email addresses and DNI details, was affected. The attack also caused a loss of data availability, requiring the provider to restore files from backups.
The AEPD noted that the breach was the third ransomware infection that the processor suffered within five months. Vodafone reported the incident to the authority on May 30, 2023.
The case initially included alleged breaches of Articles 28, 32, and 5.1(f) of the General Data Protection Regulation (GDPR). The Article 28 charge was later dropped after Vodafone provided the relevant processing agreement.
In its final decision, the AEPD reclassified the remaining infringement from Article 5.1(f), which covers the integrity and confidentiality principle, to Article 32 GDPR, which requires appropriate security measures for processing personal data. As a result, the fine was reduced from the amount proposed during the proceedings to €400,000.
Miljödata fined SEK 1.8 million after a major data breach
Swedish IT provider Miljödata has been fined SEK 1.8 million (approximately €160,000) by the Swedish Data Protection Authority (IMY) after a major data breach in August 2025.
According to Miljödata, a hacker accessed and later published personal data on the Dark Web, affecting about 2.2 million people. The stolen information included social security numbers, contact details and sensitive information about sick leave, rehabilitation and school activities.
Miljödata's customers include many Swedish municipalities, regions, government agencies and private companies. IMY is also investigating two municipalities and one region in connection with the breach.
IMY found that Miljödata did not have strong enough technical and organizational security to protect the personal data it handled. The company also lacked sufficient checks when installing new software and did not have automatic real-time monitoring to detect suspicious activity. IMY concluded that Miljödata had acted negligently and fined the company SEK 1.8 million for violating Article 32 of the EU's General Data Protection Regulation (GDPR).
Ambry Genetics agrees to a $700,000 settlement after a phishing attack exposed health data
The US Department of Health and Human Services’ Office for Civil Rights has reached a $700,000 settlement with Ambry Genetics Corporation over potential violations of the HIPAA Security Rule.
Ambry, a California-based company that provides genetic testing and clinical genomics services, discovered in January 2020 that an employee’s email account had been compromised in a phishing attack. The incident potentially exposed the protected health information of 225,370 people, including names, addresses, dates of birth, some Social Security or driver’s license numbers, financial information, medical diagnoses, lab results, medications and treatment details.
Following an investigation, the Office for Civil Rights found that Ambry may have failed to properly assess security risks, remove access to electronic health information when it was no longer needed, and assign unique user identification in systems containing protected health information.
Under the settlement, Ambry is required to pay $700,000 and follow a corrective action plan monitored by the agency for two years. The company must conduct a new security risk assessment, improve its security policies, strengthen user identification and provide training to employees on HIPAA security requirements.
What’s next:
- Request a free product demo or pricing
- Register for our webinars and product trainings
- Read our Cybercrime Investigations weekly blog
- Follow us on LinkedIn, X, Telegram and WhatsApp
- Subscribe to our Newsletter
- Join our Partner Program