A just-released report from the Securities and Exchange Commission’s Office of Inspector General confirmed what the American Securities Association has warned for years: The people with access to your most sensitive financial data cannot be trusted to protect it. A former SEC employee improperly accessed and shared nonpublic investigative information, the latest in a long line of insider breaches that make the Consolidated Audit Trail not just a privacy risk, but a ticking time bomb. As the SEC continues to hear from Americans about what to do with the largest collection of their personal financial data ever assembled, the answer is simple: end it. Because it never had the legal right to collect any of it.
The CAT was created in 2012 to replace a fragmented patchwork of trading records with a single, unified audit trail. That was a reasonable goal. What followed was not. The commission built a system that sweeps up every investor’s name, address, date of birth, Social Security number, account numbers, and complete trading history — then stitches it all together with a government-issued tracking identifier called the Customer and Account Identifier, or CCID.
Recommended Stories
The CCID is not a minor technical feature. It is a permanent, government-assigned surveillance tag that follows every American investor across every trade, every account, and every broker — for life. Unlike a Social Security number, which can at least be partially shielded, the CCID is specifically engineered to maximize its surveillance utility. Once created, it follows you forever.
The CAT is not a secure vault. It is a revolving door. The system is designed to support at least 3,000 simultaneous users — Commission staff, SRO employees, plan processor personnel, contractors, and vendors. History shows what that means. In 2016, a trusted CIA employee walked out with 34 terabytes of the agency’s most classified data, undetected. In 2023, an employee at the Consumer Financial Protection Bureau stole the personal and financial data of 256,000 consumers through 65 separate email transfers before a colleague noticed an errant address in a work email. If insiders can compromise the CIA, they can compromise this. The only difference is what gets stolen, and the CAT holds far more.
The external threat is worse. Chinese state-sponsored hackers breached the Office of Personnel Management in 2015, stealing 22 million records. They breached the Treasury Department in late 2024, accessing thousands of files. They compromised nine U.S. telecommunications companies that same year. Foreign adversaries know the government collects this data. They also know the government cannot protect it. The CAT would hand them the most valuable trove ever assembled.
The commission thinks individual identifiers reduce risk. They do not. Dropping a few data fields is meaningless when you simultaneously create a persistent identifier that links everything remaining together. A breach of CAT-linked data is not a breach of a moment in time. It is a breach of an investor’s entire financial life.
The privacy threat is not limited to hackers. A mild application of artificial intelligence to CAT data can derive, with precision, what any investor currently holds — what was bought and never sold is owned. That transforms the CAT from a market surveillance tool into something Congress never authorized: a real-time government inventory of every American investor’s portfolio. A system built to catch insider traders becomes, with minimal additional effort, an instrument for identifying taxable assets, targeting disfavored industries, or suppressing lawful investment that the government disapproves of.
An investor’s portfolio is a window into their conscience. It can reveal religion, politics, and moral conviction — shares bought in a firearms manufacturer, a faith-based divestment, a position taken in support of a cause. It can reveal personal circumstances, because people trade when they marry, lose a job, or prepare to die. The government has no business compiling a permanent record of any of it.
The legal case against this system is equally clear. The Supreme Court has held that aggregating location data over time constitutes a Fourth Amendment search. The CCID aggregates every financial decision an investor has ever made. The First Amendment protects the freedom to invest according to your conscience without Washington watching. And Congress never authorized any of this — not the CAT, not the CCID. The commission built it anyway.
YOUR BANK DATA ARE BEING STOLEN BECAUSE REGULATORS WON’T LET BANKS PROTECT IT
This commission has an immediate opportunity to right this wrong. It should abandon the CCID permanently and destroy the personal data already amassed.
It’s unnecessary. It’s harmful. It’s illegal. End it.
Christopher A. Iacovella is the president & CEO of the American Securities Association.
