HackingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
ASSETMARK, INC.
bd_6ed05ad3f644267a · schema v1 · pii pii-v1
Full breach record for ASSETMARK, INC. →AssetMark, Inc. notified Massachusetts residents of a cybersecurity incident occurring on May 15, 2026, where an unauthorized user accessed customer files using compromised employee credentials. The incident involved the exfiltration of personal information, including names and government identifiers. AssetMark terminated access, reset credentials, engaged forensic investigators, and offered 24 months of credit monitoring via Epiq.
Massachusetts clock✓ MA AG ≤30d17 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_33f04a386aea24d3Washington State AGfiled 2026-06-11(10d gap)Verified
- bd_6886b6cefdfdb7fdOregon State AGfiled 2026-06-11(10d gap)Verified
- bd_6af2c69a79abc5b2Delaware State AGfiled 2026-06-11(10d gap)Verified
- bd_c7f8a628cbde3f8aNew Hampshire State AGfiled 2026-06-11(10d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 25d gap
- bd_d0136116688cfee0Vermont State AGfiled 2026-06-11(10d gap)Verified
- bd_30436bcce4399459Texas State AGfiled 2026-06-18(17d gap)Verified
- bd_b328f99afc4a5251California State AGfiled 2026-06-26(25d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-962-assetmark-inc/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2026
- Raw hash
- f5dbbfa60c63340b43edc785a9ade11f28bf5709e5abdb22e6ef1b8a6888c71d
Reporting entity
- Name
- ASSETMARK, INC.norm: assetmark
Victim entity
- Name
- ASSETMARK, INC.norm: assetmark
Incident
- Discovered
- May 15, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 days(17 days from discovery to filing)
- Compliance flags
- MA AG ≤30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.