
Meitav Trade says hacker accessed customer data through vendor API vulnerability
About 3,000 customers received unsolicited verification codes, while Meitav said there was no access to funds, trading accounts or passwords.
Meitav Trade reported on Tuesday that an external party accessed personal customer information by exploiting a vulnerability in an API interface operated by one of the company's external vendors. An API is a connection that enables two computer systems to automatically exchange data or commands.
The incident came to light on Saturday, September 26, following reports from customers who received SMS messages containing one-time verification codes for system access that they had not requested. An investigation by Meitav Trade and the external vendor identified a vulnerability in one of the interfaces operated by the vendor. The company said it blocked access to the interface and discontinued its use.
According to the company, approximately 3,000 SMS messages were sent to customers as a result of the incident. There were also attempts to change the phone number to which verification codes were sent, although the company said those attempts were unsuccessful.
The investigation also found that an external party had triggered a function that allowed it to retrieve personal information, including customers' full names, ID numbers, bank account numbers and beneficiary details, where applicable.
Based on the company's investigation to date, there was no access to customer funds or accounts. The trading systems were not compromised, and passwords, financial information and identification documents were not exposed. The company said it would notify customers whose personal information had been accessed.
The incident follows several technical glitches experienced by Meitav Trade customers. Earlier this month, customers logging into the system discovered that their account balances or investment portfolio values were displaying as zero. Meitav Trade said at the time that the problem was a display error caused by a data update and that customers' funds and securities were unaffected.
In March 2025, the trading systems of both Meitav Trade and IBI were down for several hours, preventing customers from executing trades on the local market. The problem originated in the communications system of technology provider FMR, and Meitav Trade directed customers to its trading desk to execute transactions through representatives.
The latest incident comes as Meitav Trade continues to expand rapidly. As of the end of June 2026, the company had approximately 130,000 customer accounts, after adding about 18,900 customers during the first half of the year. Meitav reported that the number of retail brokerage customers had risen from approximately 111,000 at the end of 2025 to approximately 130,000 at the end of June.
The value of customer assets on the platform stood at approximately NIS 46 billion at the end of June, compared with NIS 41 billion at the end of 2025 and NIS 32.9 billion at the end of 2024.














