Wong v. Interactive Brokers Alleges 2FA Failure Cost Investor $4 Million
Unauthorized Access and Liquidation of $4.85 Million Portfolio
Stephanie Lin Foon Wong, a 61-year-old Hong Kong resident, alleges in a FINRA arbitration filing that Interactive Brokers LLC (IB LLC) failed to protect her brokerage account from unauthorized access, resulting in the liquidation of her $4.85 million portfolio and the purchase of hundreds of thousands of shares of HCAI, a microcap stock that collapsed in value. The unauthorized access began on May 29, 2025, from a datacenter IP address (165.154.1.64, owned by UCloud Information Technology (HK)) and a new device (MAC address FE:8B:39:48:91:62), according to the Statement of Claim (Compl. ¶29).
The filing alleges that IB LLC’s two-factor authentication (2FA) system, known as IB Key, failed entirely during the breach. The complaint states that the 2FA system did not send a single push notification, a failure described as a "catastrophic failure of Respondent’s cybersecurity infrastructure" (Compl. ¶2). Ms. Wong contends she never received an authentication prompt, nor did she authorize any login or trade, asserting, "She never approved any login. She never authorized a single trade" (Compl. ¶3).
On May 30, 2025, at 10:33 AM ET (22:33 HKT), the unauthorized party liquidated Ms. Wong’s entire portfolio, valued at $4,855,022.34, which the complaint alleges represented 83% of her life savings (Compl. ¶16). The proceeds from the liquidation, totaling $4,779,622.45 in "Trades (Sales)" credits, were used to purchase 560,000 shares of HCAI at an average price of $8.53 per share (Compl. ¶24). The first purchase of 100,000 HCAI shares cost $849,976.00 (Compl. ¶24). The complaint alleges that these purchases resulted in "Trades (Purchase)" debits from Ms. Wong’s account totaling $4,772,650.83, which it characterizes as unauthorized transfers under the Electronic Fund Transfer Act (EFTA) (Compl. ¶95). By the end of the trading day, HCAI’s price had collapsed to $6.37 per share, resulting in an immediate unrealized loss of $1,208,318.00 and a mark-to-market profit and loss (P/L) of $1,208,270.43 for HCAI on May 30, 2025 (Compl. ¶26). By June 30, 2025, the remaining HCAI shares were valued at $0.809 per share, bringing Ms. Wong’s total losses to $4,073,036.34, or 83% of her life savings (Compl. ¶26). The complaint further details that the total direct losses amounted to $4,074,420.46, with losses locked in by May 30, 2025, at 23:57 HKT totaling $4.07 million (Compl. ¶7, ¶26). By June 30, 2025, Ms. Wong’s post-incident NAV had fallen to $780,601.88, with HCAI shares trading between $0.80 and $6.90 during that period (Compl. ¶26).
Delayed Security Alerts and Failed Anomaly Detection
The complaint alleges that IB LLC’s security systems failed to detect or respond to multiple red flags during the unauthorized access. Despite the use of a new device and IP address, IB LLC’s systems did not trigger real-time alerts or freeze the account. Security notifications were sent only after the unauthorized trades were executed, with significant delays:
- The first trade confirmation email was sent at 22:34 HKT, one minute after trade execution (Compl. ¶7).
- A login notification was sent at 23:04 HKT, 31 minutes after trades began (Compl. ¶7).
- An alert for a new device or IP address was sent at 23:17 HKT, 44 minutes after trades began (Compl. ¶7).
- A password reset notification was sent at 23:57 HKT, 84 minutes after trades began (Compl. ¶7).
The complaint alleges that IB LLC’s trade confirmation system was deployed as a notification after execution rather than a pre-authorization control, rendering it "functionally useless as a security measure" (Compl. ¶28).
Ms. Wong’s trading history over seven years showed no prior microcap transactions (Compl. ¶6). The complaint states that 53 trades were executed in one session, representing a complete liquidation of her portfolio and a single-stock purchase (Compl. ¶29).
Regulatory History and Systemic Failures
The complaint highlights a history of regulatory actions against IB LLC, alleging that these actions demonstrate a pattern of systemic failures in security and supervision. Since 2020, IB LLC has faced over $74 million in regulatory penalties for various violations, including:
- A $38 million settlement with the SEC, FINRA, and CFTC in 2020 for anti-money laundering (AML) failures related to suspicious microcap trading (Compl. ¶44).
- A $20 million penalty from the CFTC in 2023 for supervision and recordkeeping failures (Compl. ¶45).
- An $11,832,136.00 settlement with the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) on July 15, 2025, for sanctions violations stemming from inadequate security auditing and testing (Compl. ¶46). The complaint alleges that this OFAC finding confirmed IB LLC’s systemic failure to audit or test its security systems, directly contributing to the unauthorized access of Ms. Wong’s account.
The complaint also references a 2019 class action lawsuit, Batchelar v. Interactive Brokers, which was preliminarily approved for a $5 million settlement on January 27, 2026 (Compl. ¶47).
Breach of Contract and Additional Causes of Action
The complaint includes multiple causes of action against IB LLC, alleging breaches of contractual and fiduciary duties, as well as violations of federal and state regulations. The counts are as follows:
- Count I: Negligence – The complaint alleges that IB LLC failed to design, maintain, and test adequate security systems, including the IB Key 2FA system, and failed to implement real-time monitoring or anomaly detection protocols (Compl. ¶28, 29, 35, 47, 52).
- Count II: Breach of Contract (against IB LLC and IBHK) – The complaint alleges that IB LLC and its Hong Kong affiliate, Interactive Brokers Hong Kong Limited (IBHK), breached the client agreement governing Ms. Wong’s account by failing to implement effective security controls, as required under Paragraph 5(b) of the agreement. The filing contends that IB LLC’s failure to prevent unauthorized access and trading constitutes a breach of its contractual obligations (Compl. ¶33, 39).
- Count III: Violation of New York Cybersecurity Regulation (23 NYCRR Part 500) (against IB LLC) – The complaint alleges that IB LLC failed to implement effective multi-factor authentication, as required by New York’s cybersecurity regulations, contributing to the unauthorized access of Ms. Wong’s account (Compl. ¶38-39).
- Count IV: Violation of SEC Regulation S-ID (17 C.F.R. § 248.201-202) (against IB LLC) – The complaint alleges that IB LLC failed to detect or prevent identity theft red flags, including the use of a new device and IP address, as required by Regulation S-ID (Compl. ¶41).
- Count V: Failure to Supervise (FINRA Rules 3110, 3120, 4512) (against IB LLC) – The complaint alleges that IB LLC failed to establish, maintain, and enforce a reasonable supervisory system to detect and prevent unauthorized access and trading activity (Compl. ¶44, 52).
- Count VI: Violation of FINRA Rule 2010 (Standards of Commercial Honor and Principles of Just and Equitable Trade) (against IB LLC) – The complaint alleges that IB LLC’s failure to protect Ms. Wong’s account from unauthorized access and its subsequent denial of liability violated FINRA’s standards of commercial honor and principles of just and equitable trade (Compl. ¶72).
- Count VII: Negligent Misrepresentation (against IB LLC) – The complaint alleges that IB LLC negligently misrepresented the security of its brokerage platform and the effectiveness of its 2FA system. The filing states, "IB LLC also represented ... that the IB Key two-factor authentication system would provide an effective security layer" (Compl. ¶84). The complaint contends that Ms. Wong relied on these representations in maintaining her life savings in the account and suffered damages exceeding $4,073,036.34 as a result (Compl. ¶86, 87).
- Count VIII: Violation of SEC Regulation S-P (17 C.F.R. § 248.30) (against IB LLC) – The complaint alleges that IB LLC violated the Safeguards Rule of Regulation S-P by failing to maintain adequate technical safeguards to protect customer information. The filing cites the 2FA bypass and delayed security notifications as evidence of this violation (Compl. ¶67). The complaint further alleges that IB LLC’s failure to comply with Regulation S-P was confirmed by OFAC’s 2025 finding of systemic security failures (Compl. ¶68).
- Count IX: Unjust Enrichment (Ms. Wong v. IB LLC) – The complaint alleges that IB LLC was unjustly enriched by retaining economic benefits, including commissions, fees, and transaction revenue, from the unauthorized trading activity. The filing states, "IB LLC’s retention of these economic benefits is unjust and inequitable" (Compl. ¶90).
- Count X: Violation of the Electronic Fund Transfer Act (15 U.S.C. §§ 1693 et seq. and 12 C.F.R. Part 1005 (Regulation E)) (Ms. Wong v. IB LLC) – The complaint alleges that IB LLC violated the EFTA by failing to comply with error-resolution procedures, including the failure to provisionally recredit Ms. Wong’s account within 10 business days of receiving notice of unauthorized transfers (Compl. ¶93-95, 105). The filing contends that IB LLC’s conduct demonstrates deliberate indifference to its EFTA obligations and willful disregard of Ms. Wong’s statutory rights (Compl. ¶104).
- Count XI: Failure to Provide Provisional Credit (EFTA) (15 U.S.C. § 1693f(c); 12 C.F.R. § 1005.11(c)) (against IB LLC) – The complaint alleges that IB LLC failed to provisionally recredit Ms. Wong’s account within the required 10-business-day period following her report of unauthorized transfers (Compl. ¶105).
- Count XII: Failure to Provide EFTA Disclosures (12 C.F.R. § 1005.7(b)(1), (2), (3)) (against IB LLC) – The complaint alleges that IB LLC failed to provide required disclosures under the EFTA, which bars any liability for Ms. Wong regarding the unauthorized transfers (Compl. ¶108).
- Count XIII: Willful Violation of EFTA (15 U.S.C. § 1693f(e)) (against IB LLC) – The complaint alleges that IB LLC’s violations of the EFTA were willful, entitling Ms. Wong to treble damages in the amount of $12,219,109.02 (Compl. ¶115).
The complaint also alleges that IBHK, Interactive Brokers’ Hong Kong affiliate, sent client messages on May 23 and May 28, 2025, warning of recent SMS scams (Compl. ¶34). Despite this awareness of an active phishing campaign, the complaint alleges that IB LLC’s 2FA and anomaly detection systems failed during the attack on Ms. Wong’s account. The filing further alleges that IBHK’s June 20, 2025 denial letter miscited the client agreement (referencing Paragraph 6 instead of 5(b)) and ignored the failure of the IB Key 2FA system to send a push notification for the unauthorized login (Compl. ¶33). The complaint states that the denial letter contained conclusory assertions without specific evidence or forensic analysis regarding the IB Key failure (Compl. ¶106).
EFTA Violations and Failure to Provide Provisional Credit
The complaint alleges that IB LLC violated the Electronic Fund Transfer Act (EFTA) (15 U.S.C. §§ 1693 et seq.) and its implementing regulation, Regulation E (12 C.F.R. Part 1005), by failing to comply with error-resolution procedures following the unauthorized access. The filing contends that the unauthorized liquidation of Ms. Wong’s portfolio and the purchase of HCAI shares qualify as "electronic fund transfers" under 15 U.S.C. § 1693a(7) (Compl. ¶95). The complaint further alleges that IB LLC directly participated in these unauthorized transfers as a counterparty, as evidenced by trade codes "IA" and "IM" (Compl. ¶97).
Under the EFTA, financial institutions must provisionally recredit a customer’s account within 10 business days of receiving notice of an unauthorized transfer, pending an investigation (15 U.S.C. § 1693f(c); 12 C.F.R. § 1005.11(c)). The complaint alleges that IB LLC failed to meet this deadline, despite Ms. Wong’s prompt reporting of the unauthorized access on June 1, 2025 (Compl. ¶105). Additionally, IB LLC did not deliver its investigation findings within the required three-business-day timeframe (Compl. ¶106).
The complaint further alleges that IB LLC’s investigation was pretextual and ignored key evidence, including the 2FA failure, the use of a new device and IP address, and the anomalous trading pattern. The filing states, "IB LLC’s denial letter blamed Ms. Wong for the compromise of her credentials while ignoring the complete failure of its own 2FA system" (Compl. ¶102). The complaint contends that IB LLC’s conduct demonstrates deliberate indifference to its legal obligations and willful disregard of Ms. Wong’s rights, stating, "IB LLC’s conduct evidences deliberate indifference to its EFTA obligations and willful disregard of Ms. Wong’s statutory rights" (Compl. ¶104).
Under the EFTA, a consumer’s liability for unauthorized transfers is limited to a maximum of $50 if the consumer provides timely notice (15 U.S.C. § 1693g(a)). The complaint alleges that Ms. Wong’s maximum liability should not exceed this amount, as she reported the unauthorized access promptly (Compl. ¶107). The filing further alleges that IB LLC failed to provide required EFTA disclosures under 12 C.F.R. § 1005.7(b)(1), (2), and (3), which bars any liability for Ms. Wong (Compl. ¶108).
The complaint alleges that IB LLC cannot meet its burden of proof under 15 U.S.C. § 1693g(b) to demonstrate that the unauthorized transfers were authorized or that Ms. Wong’s negligence contributed to the unauthorized access. The filing cites the unauthorized access from a new device and IP address, the failure of the IB Key 2FA system, and the inconsistent trading pattern as evidence that the transfers were unauthorized (Compl. ¶109). The complaint also references IB LLC’s Cash Report, which confirms that $4,772,650.83 in purchase debits were processed through an account starting with only $43,058.56 in cash (Compl. ¶109).
The complaint outlines several factors that a reasonable investigation by IB LLC would have revealed, including:
- The unauthorized nature of the transactions (Compl. ¶110(a)).
- Ms. Wong’s prompt reporting of the unauthorized access (Compl. ¶110(b)).
- Ms. Wong’s seven-year trading history, which included no prior microcap transactions (Compl. ¶110(c)).
- Indicators of a pump-and-dump scheme involving HCAI (Compl. ¶110(d)).
- The failure of the IB Key 2FA system to send a push notification during the unauthorized access (Compl. ¶110(e)). The complaint states, "The IB Key two-factor authentication system ... failed entirely. It did not send a single push notification" (Compl. ¶99).
- The insufficient cash balance in Ms. Wong’s account to cover the unauthorized purchases (Compl. ¶110(f)).
- The lack of evidence refuting Ms. Wong’s report of unauthorized access (Compl. ¶110(g)).
The complaint alleges that IB LLC’s failure to comply with EFTA liability limitations and provisional credit requirements directly caused Ms. Wong’s losses, which it quantifies as approximately $4,073,036.34 (Compl. ¶112). The filing further alleges that Ms. Wong’s actual damages equal the full amount of the unauthorized transfers, totaling $4,772,650.83 in debits from her account (Compl. ¶113). The complaint seeks treble damages under 15 U.S.C. § 1693f(e) for willful violations of the EFTA, which would amount to $12,219,109.02 (Compl. ¶115).
Reporting to Hong Kong Police and Financial Dispute Resolution
On June 1, 2025, Ms. Wong filed a formal complaint with IBHK (Support Ticket 966872, IBNR Case 960561) and reported the unauthorized access to the Hong Kong Police via an e-police report (Case No 1:26-cv-06579. ERC2506021049735) (Compl. ¶32). The Hong Kong Police report documented a monetary loss of $1,300,000 (Compl. ¶32). On June 3, 2025, Melvin C, an IBKR Client Services representative, confirmed the unauthorized access from new network addresses and a new device (Compl. ¶32).
The complaint notes that IBHK advised Ms. Wong of the Financial Dispute Resolution Centre (FDRC) in Hong Kong as an escalation option for her complaint (Compl. ¶33). However, the filing contends that IBHK’s June 20, 2025 denial letter asserted that no breach of security controls had occurred, despite the confirmed unauthorized access and the failure of the IB Key 2FA system (Compl. ¶33).
Damages and Emotional Distress
The complaint seeks compensatory damages for the losses suffered as a result of the unauthorized access and liquidation of Ms. Wong’s portfolio. The filing details the calculation of Ms. Wong’s losses, which includes:
- Pre-incident stock value: $3,506,103.50
- Pre-incident bond value: $1,298,116.13
- Pre-incident interest: $7,744.15
- Proceeds from the sale of 383,888 HCAI shares in June 2025: $560,573.51
- Cost basis for the 383,888 HCAI shares sold: $3,270,825.26
- Realized losses from the sale of HCAI shares: $2,710,251.75
- Cost basis for the remaining 176,112 HCAI shares at June 30, 2025: $1,506,643.32
- Closing value of the remaining 176,112 HCAI shares at $0.809 per share: $142,474.61
- Unrealized losses from the remaining HCAI shares: $1,364,168.71
The complaint alleges that the unauthorized liquidation of Ms. Wong’s account and the loss of $4,073,036.34, representing 83% of her life savings, caused her severe emotional distress (Compl. ¶48). The filing notes that Ms. Wong is 61 years old and that the loss of her life savings has had a profound impact on her financial security and well-being. The complaint further alleges that IBHK’s June 20, 2025 denial letter exacerbated her distress by blaming her for the credential compromise while ignoring the failure of IB LLC’s 2FA system (Compl. ¶49).
Client Agreement Provisions and IB LLC’s Discretion
The complaint references several provisions of the IBHK Client Agreement (Form 4144, effective May 10, 2017) that govern Ms. Wong’s account. The agreement outlines IB LLC’s broad discretion in executing trades, including the use of its "Smart Routing" algorithm to seek the best market for orders (Compl. ¶6). The agreement also states that IB LLC may execute orders as agent or principal, use affiliates or brokers, and decline orders or terminate services at its discretion (Compl. ¶8). The complaint highlights the following provisions:
- IB LLC is not liable for actions or decisions of exchanges, markets, dealers, clearing houses, or regulators (Compl. ¶8). The agreement states, "IB IS NOT LIABLE FOR ANY ACTION OR DECISION OF ANY EXCHANGE, MARKET, DEALER, CLEARING HOUSE OR REGULATOR" (Compl. ¶8).
- Clients must monitor orders until IB LLC confirms execution or cancellation and are bound by actual executions if consistent with the order (Compl. ¶9a).
- Clients must notify IB LLC immediately of any inaccurate confirmations, statements, or unplaced orders (Compl. ¶9b).
- IB LLC may adjust a client’s account to correct errors, and clients must return erroneously distributed assets (Compl. ¶9c).
- Clients authorize IB LLC and its affiliates to execute proprietary trades, even with unexecuted client orders at the same price (Compl. ¶10a).
- IB LLC and its affiliates may take opposite positions to a client’s orders for securities, futures, options, or OTC products (Compl. ¶10b).
- Clients warrant that their application information is true and complete and that they have sufficient knowledge and experience to understand the risks of trading (Compl. ¶11a-d).
- Joint account holders authorize each other to trade, receive assets, and modify agreements independently, with joint and several liability for account matters (Compl. ¶12a-c).
- Clients acknowledge the high risk of margin trading and must maintain sufficient equity to meet margin requirements, which IB LLC may modify at any time (Compl. ¶13a-b). The agreement states, "IB MAY MODIFY MARGIN REQUIREMENTS FOR ANY OR ALL CLIENTS FOR ANY OPEN OR NEW POSITIONS AT ANY TIME, IN IB'S SOLE DISCRETION" (Compl. ¶13b).
- IB LLC may liquidate client positions without notice to satisfy margin requirements or for its protection, and clients remain liable for any deficiencies (Compl. ¶13d(i)). The agreement states, "IF AT ANY TIME CLIENT'S ACCOUNT HAS INSUFFICIENT EQUITY TO MEET MARGIN REQUIREMENTS... IB HAS THE RIGHT... TO LIQUIDATE ALL OR ANY PART OF CLIENT'S POSITIONS... WITHOUT PRIOR NOTICE" (Compl. ¶13d(i)).
- Clients are solely responsible for complying with stamp tax rules for Hong Kong short sales, and IB LLC has no liability for ineligible transactions (Compl. ¶14). The agreement states, "Client remains ultimately and solely responsible for complying with IRD stamp tax rules..." (Compl. ¶14).
The complaint alleges that IB LLC’s reliance on these contractual provisions does not absolve it of liability for the unauthorized access and liquidation of Ms. Wong’s account. The filing cites Batchelar v. Interactive Brokers (2019), which held that contractual authorization does not insulate IB LLC from liability for negligent system operation (Compl. ¶73).
Custody and Segregation of Client Assets
The client agreement outlines IB LLC’s role as custodian of client assets and its authority to hold and manage those assets. The agreement states that clients may not deal in securities held by IB LLC without prior written consent (Compl. ¶15a). IB LLC may deposit Hong Kong securities in a segregated trust or client account with an SFC-licensed institution and may redeliver securities of like quantity and type, not identical securities (Compl. ¶15b-c). The agreement further states that securities held by IB LLC are at the client’s sole risk, and IB LLC is liable only for gross negligence or fraud (Compl. ¶15d). Client funds are segregated as trust assets and are not part of IB LLC’s insolvency estate (Compl. ¶15e).
The agreement also authorizes IB LLC to lend, pledge, or re-hypothecate client assets without notice, and clients may lose voting rights as a result (Compl. ¶16). All client assets are pledged to IB LLC as first-priority security interest for obligations under the agreement (Compl. ¶17). The complaint alleges that these provisions do not shield IB LLC from liability for its failure to protect Ms. Wong’s account from unauthorized access.
The complaint seeks the following relief from the FINRA arbitration panel:
- Compensatory damages in the amount of $4,073,036.34, representing the total loss suffered by Ms. Wong (Compl. ¶26).
- Treble damages under the EFTA in the amount of $12,219,109.02 for willful violations of the statute (Compl. ¶115).
The allegations described here are taken from the filing and remain unproven; no responsive pleading is reflected in the source document.
David Brunk is a civil litigation attorney. He can be reached at david@newmanbrunk.com.
From the Complaint Public Court Record
E X H I B I T A Case 1:26-cv-06579 Document 1-1 Filed 07/31/26 Page 1 of 69
FINRA Arbitration No. ________ STATEMENT OF CLAIM AND DEMAND FOR ARBITRATION — Page 1 KRONENBERGER ROSENFELD, LLP Karl S. Kronenberger (CA Bar No. 226112) 548 Market St. #85399 San Francisco, CA 94104 Telephone: (415) 955-1155 Facsimile: (415) 955-1158 karl@kr.law Attorneys for Claimant Stephanie Lin Foon Wong FINANCIAL INDUSTRY REGULATORY AUTHORITY OFFICE OF DISPUTE RESOLUTION STEPHANIE LIN FOON WONG, an individual, Claimant, v. INTERACTIVE BROKERS LLC, a Connecticut limited liability company, Respondent. FINRA Arbitration No. ________ STATEMENT OF CLAIM AND DEMAND FOR ARBITRATION INTRODUCTION 1. Claimant Stephanie Lin Foon Wong (“Ms. Wong” or “Claimant”), by and through the undersigned counsel, hereby files this Statement of Claim and Demand for Arbitration against Respondent Interactive Brokers LLC (“IB LLC” or “Respondent”), and alleges as follows: 2. This case arises from the catastrophic failure of Respondent’s cybersecurity infrastructure, which permitted an unauthorized third party to access Ms. Wong’s brokerage account, liquidate her entire portfolio worth approximately $4.85 million, and use the proceeds to purchase shares of a pump-and-dump microcap security, all without triggering the two-factor authentication (“2FA”) system that Respondent represented would protect her account. Ms. Wong’s total losses exceed $4 million, representing approximately 83% of her life savings. 3. The unauthorized access and trading on Ms. Wong’s account on May 29–30, 2025 was not the result of any failure on Ms. Wong’s part. It was the direct and foreseeable consequence of Respondent’s failure to maintain, test, and audit the IB Key two-factor authentication system that Case 1:26-cv-06579 Document 1-1 Filed 07/31/26 Page 2 of 69
FINRA Arbitration No. ________ STATEMENT OF CLAIM AND DEMAND FOR ARBITRATION — Page 2 Respondent developed, controlled, and de
Questions about this topic: david@newmanbrunk.com