LiMP VPN
← All news

Israel's Largest Broker Leaked Client Data via an API Flaw

Israel's Largest Broker Leaked Client Data via an API Flaw

In short: On September 26, 2026, Meitav Trade — Israel's largest investment house, managing roughly $15 billion across 130,000 accounts — discovered an attack: hackers exploited an API vulnerability at a third-party vendor to extract full names, national ID numbers, and bank account details for about 3,000 clients. In parallel, attackers sent victims fake SMS verification codes and attempted to change the phone numbers linked to their accounts — classic groundwork for intercepting one-time passwords (OTP). The company blocked the vulnerable interface, its shares dropped about 5% on the Tel Aviv exchange, and client trading accounts were not compromised.

What happened

The attack was flagged on September 26, when roughly 3,000 Meitav Trade clients received unsolicited SMS messages asking them to confirm a one-time password (OTP). The investigation found that attackers exploited a vulnerability in an API interface managed by an external vendor, not by Meitav Trade itself. Through that flaw they extracted full names, national identification numbers, and bank account details for a limited set of clients.

Investigators also recorded attempts to change the phone number tied to verification codes — had those succeeded, attackers could have intercepted 2FA codes and logged into accounts as the victims. The company says those attempts failed and that access to trading accounts and money transfers was never compromised.

Why this isn't just one broker's problem

The Meitav Trade case is a textbook supply-chain risk: a service can be properly secured on its own side while a vulnerability at an external API partner still opens a direct path to its customers' data. We've covered how to check whether your data has shown up in a leak and what to do next: the more external integrations — like third-party APIs — a company relies on, the wider its potential attack surface, and the end user usually has no say in which vendors their bank or broker chooses.

The SMS-spoofing and OTP-interception attempt deserves separate attention. It's not exotic — the same tactic shows up in attacks on bank and crypto accounts worldwide: armed with enough personal data from a leak, scammers call or message the victim posing as support staff and talk them into reading out the code from an SMS "to confirm a transaction."

What this means for your data

If you're a customer of any financial service — a bank, a broker, a crypto exchange — a breach like this raises the risk not of a direct account hack, but of follow-up targeted fraud: knowing your real name, ID number, and the fact that you use a specific broker makes it far easier for a scammer to impersonate support staff and talk you specifically out of a verification code. It's worth checking your accounts, rotating sensitive passwords, and switching to hardware-based two-factor authentication (instead of SMS codes, where possible) now, rather than waiting for an official notice from the service.

How to protect yourself

  • Never read a code from an SMS out loud over the phone — not to "support," not to your "bank," not to your "broker." Legitimate organizations never ask for these codes verbally.
  • Switch to hardware security keys or authenticator apps instead of SMS codes wherever a service supports it — SMS can be intercepted through number spoofing or SIM swapping.
  • Turn on alerts for any account changes — a changed phone number, email, or payment details should notify you through a separate channel.
  • Encrypt your connection. LiMP VPN won't fix a vulnerability in someone else's API, but it protects your own traffic to banking and brokerage services from network-level interception on its way there — especially important when connecting over public Wi-Fi.

Plans with a verified no-logs policy: LiMP VPN pricing. More breakdowns of major breaches and incidents on the LiMP VPN blog.

Sources