Recommended Free Tools
The U.S. Patent and Trademark Office (USPTO) disclosed two separate exposures of trademark filer domicile addresses: one through its Trademark Status and Document Retrieval (TSDR) APIs beginning in February 2020, and another involving a bulk data set from August 2023 to April 2024. A Commerce Department inspector general found that the earlier API exposure also involved attorney information, email addresses and IP addresses. The incidents involved exposure of personal information—not proof that a particular filer suffered fraud or identity theft.
What happened in the trademark data incidents?
The headline covers two distinct incidents affecting trademark information. They involved different systems and time windows, so the May 2024 USPTO notice should not be treated as a complete account of the earlier exposure reviewed by the Commerce Department Office of Inspector General (OIG).
| Incident | System and dates | Information identified | What officials said |
|---|---|---|---|
| Earlier TSDR API exposure | Publicly accessible TSDR APIs; began February 18, 2020, and lasted three years, according to the OIG’s 2024 report. | Domicile addresses, attorney information, email addresses and IP addresses, according to the OIG. | The OIG criticized incident reporting, notification and the handling of the exposure. It said addresses remained publicly accessible after USPTO leadership knew about the issue. |
| Later bulk-data exposure | A bulk data set; August 23, 2023, through April 19, 2024, according to USPTO’s May 7, 2024 notice. | Domicile addresses that should have been hidden. | USPTO said the addresses were not visible in its trademark-record search or trademark documents database. The agency said it blocked access, removed files, applied and tested a patch, then restored access. |
For the later incident, USPTO wrote: “At no point were the impacted domicile addresses visible when users searched trademark records through our search system or our trademark documents database.” That statement describes those search interfaces; it does not negate the separate OIG finding that addresses could be viewed through routine API requests during the earlier incident.
What information was exposed—and how many people were affected?
In the earlier incident, the OIG identified domicile addresses as well as attorney information, email addresses and IP addresses. It said USPTO did not report or notify filers about those additional categories. The agency’s May 2024 notice, by contrast, described domicile addresses retrievable from the bulk data set. Do not assume the two incidents had identical data scopes.
#1 Best Overall
The OIG report noted that USPTO had more than 3 million registered trademarks as of December 2023. That figure is context about the office’s registrations, not a count of exposed records or affected applicants. The official materials cited here do not establish a verified total number of affected trademark filers.
Does exposure mean the information was misused?
No. Exposure means information was accessible through the affected channel; it does not establish that someone used it to commit fraud. Regarding the 2023–2024 bulk-data incident, USPTO said it had no reason to believe domicile data had been misused and that the incident did not result from malicious activity. Those are the agency’s statements about that episode.
The OIG described a possible risk from combining exposed information: bad actors could use it to create convincing USPTO correspondence or impersonate a filer’s attorney. The report identifies a potential fraud pathway, not proof that such fraud occurred to a named trademark applicant.
What did the OIG find about the earlier incident?
In its June 24, 2024 report, the Commerce Department OIG found failures in required incident reporting and filer notification. It also found that addresses stayed publicly accessible after USPTO leadership knew of the exposure, that additional exposed data was not reported or included in notifications, and that the Department Chief Privacy Officer did not assist because of a lapse in the reporting process.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsThe report, OIG-24-029-I, included 10 recommendations. On the Oversight.gov record, two recommendations were listed as open. Recommendation 8 called for a minimum log-retention period of two years and six months. USPTO’s FY2026 Congressional Submission described related implementation as in progress, with a September 30, 2026 target. That is a stated target, not confirmation that implementation has since been completed.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Is the Patent Center incident part of this trademark exposure?
No. A separate USPTO incident involved possible exposure through Patent Center of limited information about certain unpublished patent applications that had recorded assignments during December 2, 2017, through August 1, 2024. The agency’s August 2024 FAQ listed application title and number, owner, filing date and inventor names as potentially exposed. It said application specifications—including claims and drawings—were not exposed. This was a patent incident, not a third trademark data spill.
Quick Recap
Best Value
What should trademark filers take away?
- Check which incident a notice or report describes: the TSDR API exposure beginning in 2020 or the later bulk-data exposure from 2023 to 2024.
- Keep the data scope straight: the OIG identified several information categories in its review of the earlier incident; USPTO’s later notice concerned domicile addresses in a bulk data set.
- Do not equate access with confirmed misuse. USPTO reported no reason to believe the later incident’s data had been misused, while the OIG discussed possible impersonation and fraud risks from the earlier exposure.
- Look to dated agency records for remediation status; a target date or “in progress” status is not proof of completion.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




