HackingStolen CredentialsDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumActive
CETERA FINANCIAL GROUP, INC.
bd_79058398589604ae · schema v1 · pii pii-v1
Full breach record for CETERA FINANCIAL GROUP, INC. →Cetera Financial Group notified Vermont and other state AGs of a data breach involving unauthorized access to a single employee email account between July 7 and August 21, 2025. The incident exposed personal information including names, SSNs, driver's license numbers, and financial account data for at least 96 Vermont residents. CFG engaged federal law enforcement, offered 12-24 months of credit monitoring, and is enhancing security policies.
Vermont clock✗ VT AG >45 bday37 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_a95f62f6f2279f59California State AGfiled 2026-03-25Candidate
- bd_b2cf5e2691400e24Indiana State AGfiled 2026-03-25Verified
- bd_c8e60806383a31eaMaine State AGfiled 2026-03-25Verified
- bd_a989d5443a1c83deNew Hampshire State AGfiled 2026-03-24(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 2d gap
- bd_05000564b48b0cefTexas State AGfiled 2026-03-27(2d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-03-25-cetera-financial-group-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 25, 2026
- Raw hash
- 830f4394352675571b93cc4ccd7fd8e42471f36d7ca6510731d0732acdf66912
Reporting entity
- Name
- CETERA FINANCIAL GROUP, INC.norm: cetera financial
- Domain
- cetera.com
Victim entity
- Name
- CETERA FINANCIAL GROUP, INC.norm: cetera financial
- Domain
- cetera.com
Incident
- Discovered
- Jul 7, 2025
- Materiality determined
- Jan 30, 2026
- Notification sent
- Mar 25, 2026
- Affected individuals
- 96
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Providing notice of the Event to relevant regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 37 weeks(261 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.