Meitav Trade Suffers Data Breach, Personal Information of Some Clients Compromised
Meitav Trade, an Israeli investment house, experienced an attempted cyberattack last Saturday, during which personal data of a limited number of clients was accessed. While the attackers failed to gain access to clients' trading accounts, they managed to extract personal information including identity card numbers and bank account numbers from a select group of customers. The incident began when clients reported receiving unsolicited one-time password (OTP) SMS messages. Meitav Trade launched an investigation with its external service provider, revealing a vulnerability in an API interface operated by the provider. The company immediately blocked access to the compromised interface, halting further unauthorized activity. Approximately 3,000 OTP SMS messages were sent to clients as part of the attack attempt, and several unsuccessful attempts were made to change the phone number for OTP delivery. The investigation confirmed that a function was exploited by an external party to extract personal details such as full name, ID number, bank account number, and beneficiary information where applicable. Meitav Trade emphasized that no access was gained to client funds or trading accounts, and no passwords, financial data, or identification documents were exposed. The company stated it would notify affected clients and stressed its commitment to protecting customer privacy.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.
Ask About This Article
Duki reads it, and every newsroom on the same story, then answers with sources.