Social EngineeringPhishingCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Kestra Financial Services
bd_3f0e180479223a4d · schema v1 · pii pii-v1
Full breach record for Kestra Financial Services →Kestra Financial notified 2 Maryland residents of a phishing incident involving unauthorized access to email accounts in Oct-Nov 2024. The company secured accounts, conducted an investigation, and provided credit monitoring via Experian.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376214.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 6a7c859ffd1685a09ca4e2afe6f5455b71a2d0cc414118f45ba8d376b87de6e3
Reporting entity
- Name
- Kestra Financial Servicesnorm: kestra financial
- Domain
- kestrafinancial.com
Victim entity
- Name
- Kestra Financial Servicesnorm: kestra financial
- Domain
- kestrafinancial.com
Incident
- Discovered
- Dec 18, 2024
- Materiality determined
- —
- Notification sent
- Jan 18, 2025
- Affected individuals
- 2
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 47 weeks(330 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.