Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The U.S. Patent and Trademark Office (USPTO) disclosed two separate incidents involving trademark filer domicile addresses. An earlier exposure through the Trademark Status and Document Retrieval (TSDR) application programming interfaces lasted about three years beginning February 18, 2020. A later incident made addresses retrievable in a bulk-data set from August 23, 2023, through April 19, 2024. These events involved different systems and response findings, and neither source establishes a verified total number of affected trademark filers.

There were two trademark data exposures, not one

Reports that the “USPTO data spill” exposed trademark applications can combine two episodes. The Commerce Department Office of Inspector General (OIG) examined the older TSDR API exposure in a report dated June 24, 2024. Separately, the USPTO issued a customer notice on May 7, 2024, about a bulk-data exposure during an information-technology transition.

Incident System or channel Time window Information involved What the agencies said about misuse
TSDR API exposure Publicly accessible TSDR APIs Beginning February 18, 2020; approximately three years, according to the OIG Trademark filer domicile addresses; the OIG also identified attorney information, email addresses and IP addresses The OIG described possible impersonation and fraud risks, but did not establish downstream fraud against a named filer
Bulk-data incident A bulk data set during a system transition August 23, 2023–April 19, 2024 Domicile addresses that should have been hidden USPTO said it had no reason to believe the data was misused

What the 2020–2023 TSDR API exposure revealed

In February 2023, USPTO determined that trademark filer domicile addresses had been exposed through publicly accessible APIs for three years. The OIG reported that anyone could view those addresses from anywhere using routine API requests.

The OIG review found that the scope extended beyond addresses. It also listed attorney information, email addresses and IP addresses as exposed during the period. According to the report, USPTO did not report or notify filers about those additional categories.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The report identified failures in required incident reporting and filer notification. It found that addresses remained publicly accessible after USPTO leadership knew about the exposure. A reporting-process lapse also meant the Department of Commerce Chief Privacy Officer did not assist as required.

The OIG warned that combining the exposed information could help bad actors create convincing USPTO correspondence or impersonate a filer’s attorney. That is a risk assessment, not evidence that a particular filer was defrauded because of the exposure.

What the 2023–2024 bulk-data incident involved

In its May 7, 2024 customer notice, USPTO said domicile addresses that should have been hidden were retrievable in a bulk data set from August 23, 2023, to April 19, 2024, while the agency was moving to a new IT system.

USPTO said the addresses were not visible when users searched trademark records or used its trademark documents database: “At no point were the impacted domicile addresses visible when users searched trademark records through our search system or our trademark documents database.” The exposure described in that notice was limited to the bulk-data channel.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

USPTO’s stated response

  • Blocked access to the affected data set.
  • Removed the files.
  • Applied and tested a software patch.
  • Re-enabled access after those steps.

USPTO characterized this episode as not resulting from malicious activity and said it had no reason to believe the domicile data had been misused. Those statements are the agency’s account of the bulk-data incident; they do not erase the separate OIG findings about the earlier API exposure.

What information was not established

  • No reviewed source gives a verified count of affected trademark filers.
  • The OIG’s reference to more than 3 million registered trademarks as of December 2023 is context about USPTO’s registration inventory, not a count of exposed or affected marks.
  • Exposure means information was accessible; it does not by itself prove that unauthorized people used it.

Do not confuse this with the Patent Center incident

USPTO also published an August 14, 2024 FAQ about a separate Patent Center event. That incident concerned limited information from unpublished patent applications with recorded assignments, potentially exposed between December 2, 2017, and August 1, 2024.

The potentially exposed patent fields were an application title and number, owner, filing date and inventor names. Specifications, including claims and drawings, were not exposed. USPTO said it had verified evidence of one unauthorized viewing, by the person who reported the issue. That fact applies only to the patent incident and should not be attributed to trademark filers.

What trademark owners should take from the disclosures

Identify the channel before assessing your risk

An address appearing in a bulk data set is a different event from information obtainable through a TSDR API. The OIG-reviewed episode also had a broader data scope than the bulk-data notice.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Watch for convincing impersonation attempts

The OIG’s warning makes correspondence that appears to come from USPTO or a trademark attorney a practical concern. Independently verify payment requests, deadlines, contact details and changes to representation through trusted channels rather than relying on information in an unexpected message.

Do not infer that every registered mark was affected

The published figures do not support that conclusion. More than 3 million registered trademarks was a December 2023 inventory figure, while the number of affected filers was not stated.

Oversight and remediation status

The OIG report contained 10 recommendations. The Oversight.gov record showed two recommendations still open on the reviewed record. One open recommendation concerns retaining logs for at least two years and six months. USPTO’s FY2026 Congressional Submission described implementation of that item as in progress with a September 30, 2026 target.

That target is a dated status statement, not proof that the recommendation has since been completed. The available records do not establish a later completion date.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Bottom line on the USPTO trademark data spill

The headline describes a real privacy-control failure, but it compresses distinct events. The earlier TSDR API exposure lasted about three years and, according to the OIG, included addresses plus attorney, email and IP information. The later USPTO notice covered domicile addresses in a bulk data set during an 2023–2024 system transition. Neither episode has a verified public count of affected trademark filers, and the records distinguish possible misuse from proven fraud.

Frequently Asked Questions

Were trademark applications themselves publicly visible?

The documented exposures concern filer domicile addresses and, in the OIG review, related attorney, email and IP information. USPTO said the addresses in the 2023–2024 bulk-data incident were not visible through trademark-record search or the trademark documents database.

How many trademark owners were affected?

The reviewed official records do not provide a verified total count of affected trademark filers. The figure of more than 3 million refers to USPTO’s total registered trademarks as of December 2023, not exposed marks.

Is the Patent Center disclosure part of the trademark breach?

No. It was a separate incident involving limited metadata from unpublished patent applications with recorded assignments. Patent specifications, claims and drawings were not exposed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.