October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

USPTO Data Spill Exposed Trademark Applicants’ Personal Information

USPTO disclosed two distinct trademark data exposures: an earlier TSDR API incident and a later bulk-data incident. Here is what each involved and what officials said about potential misuse.
From TheFinanceBase Team4 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The U.S. Patent and Trademark Office (USPTO) disclosed two separate exposures of trademark filer domicile addresses: one through its Trademark Status and Document Retrieval (TSDR) APIs beginning in February 2020, and another involving a bulk data set from August 2023 to April 2024. A Commerce Department inspector general found that the earlier API exposure also involved attorney information, email addresses and IP addresses. The incidents involved exposure of personal information—not proof that a particular filer suffered fraud or identity theft.

What happened in the trademark data incidents?

The headline covers two distinct incidents affecting trademark information. They involved different systems and time windows, so the May 2024 USPTO notice should not be treated as a complete account of the earlier exposure reviewed by the Commerce Department Office of Inspector General (OIG).

Incident System and dates Information identified What officials said
Earlier TSDR API exposure Publicly accessible TSDR APIs; began February 18, 2020, and lasted three years, according to the OIG’s 2024 report. Domicile addresses, attorney information, email addresses and IP addresses, according to the OIG. The OIG criticized incident reporting, notification and the handling of the exposure. It said addresses remained publicly accessible after USPTO leadership knew about the issue.
Later bulk-data exposure A bulk data set; August 23, 2023, through April 19, 2024, according to USPTO’s May 7, 2024 notice. Domicile addresses that should have been hidden. USPTO said the addresses were not visible in its trademark-record search or trademark documents database. The agency said it blocked access, removed files, applied and tested a patch, then restored access.

For the later incident, USPTO wrote: “At no point were the impacted domicile addresses visible when users searched trademark records through our search system or our trademark documents database.” That statement describes those search interfaces; it does not negate the separate OIG finding that addresses could be viewed through routine API requests during the earlier incident.

What information was exposed—and how many people were affected?

In the earlier incident, the OIG identified domicile addresses as well as attorney information, email addresses and IP addresses. It said USPTO did not report or notify filers about those additional categories. The agency’s May 2024 notice, by contrast, described domicile addresses retrievable from the bulk data set. Do not assume the two incidents had identical data scopes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The OIG report noted that USPTO had more than 3 million registered trademarks as of December 2023. That figure is context about the office’s registrations, not a count of exposed records or affected applicants. The official materials cited here do not establish a verified total number of affected trademark filers.

Does exposure mean the information was misused?

No. Exposure means information was accessible through the affected channel; it does not establish that someone used it to commit fraud. Regarding the 2023–2024 bulk-data incident, USPTO said it had no reason to believe domicile data had been misused and that the incident did not result from malicious activity. Those are the agency’s statements about that episode.

The OIG described a possible risk from combining exposed information: bad actors could use it to create convincing USPTO correspondence or impersonate a filer’s attorney. The report identifies a potential fraud pathway, not proof that such fraud occurred to a named trademark applicant.

What did the OIG find about the earlier incident?

In its June 24, 2024 report, the Commerce Department OIG found failures in required incident reporting and filer notification. It also found that addresses stayed publicly accessible after USPTO leadership knew of the exposure, that additional exposed data was not reported or included in notifications, and that the Department Chief Privacy Officer did not assist because of a lapse in the reporting process.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The report, OIG-24-029-I, included 10 recommendations. On the Oversight.gov record, two recommendations were listed as open. Recommendation 8 called for a minimum log-retention period of two years and six months. USPTO’s FY2026 Congressional Submission described related implementation as in progress, with a September 30, 2026 target. That is a stated target, not confirmation that implementation has since been completed.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is the Patent Center incident part of this trademark exposure?

No. A separate USPTO incident involved possible exposure through Patent Center of limited information about certain unpublished patent applications that had recorded assignments during December 2, 2017, through August 1, 2024. The agency’s August 2024 FAQ listed application title and number, owner, filing date and inventor names as potentially exposed. It said application specifications—including claims and drawings—were not exposed. This was a patent incident, not a third trademark data spill.

What should trademark filers take away?

  • Check which incident a notice or report describes: the TSDR API exposure beginning in 2020 or the later bulk-data exposure from 2023 to 2024.
  • Keep the data scope straight: the OIG identified several information categories in its review of the earlier incident; USPTO’s later notice concerned domicile addresses in a bulk data set.
  • Do not equate access with confirmed misuse. USPTO reported no reason to believe the later incident’s data had been misused, while the OIG discussed possible impersonation and fraud risks from the earlier exposure.
  • Look to dated agency records for remediation status; a target date or “in progress” status is not proof of completion.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.