HackingStolen CredentialsTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIALMediumContained
THE EDELMAN FINANCIAL ENGINES CENTER, LLC
bd_7ed7d43cfbd3ccbd · schema v1 · pii pii-v1
Full breach record for THE EDELMAN FINANCIAL ENGINES CENTER, LLC →Edelman Financial Engines notified Vermont AG on 2026-02-04 of a Jan 7, 2026 incident where an unauthorized third party accessed personal information including names, DOBs, addresses, SSNs, and financial planning data. EFE terminated access, engaged external experts, and provided 24 months of Kroll credit/identity monitoring. No EFE account access occurred. Rhode Island count explicitly noted as ~9; VT count not specified.
Vermont clock⏱ VT AG >14 bday28 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_1aa0940ef60364b6Maine State AGfiled 2026-02-04Verified
- bd_d0f61c316195a5feNew Hampshire State AGfiled 2026-02-09(5d gap)Verified
- bd_088eccf424942d29Indiana State AGfiled 2026-01-28(7d gap)Verified
- bd_789ad137708c3ca5California State AGfiled 2026-01-07(28d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2026-02-04-edelman-financial-engines-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 4, 2026
- Raw hash
- be3bf7ec5dbc540fde5b27995fa90cd8692d400fe7d2fc48831be19a52d8d904
Reporting entity
- Name
- THE EDELMAN FINANCIAL ENGINES CENTER, LLCnorm: the edelman financial engines center
- Domain
- edelmanfinancialengines.com
Victim entity
- Name
- THE EDELMAN FINANCIAL ENGINES CENTER, LLCnorm: the edelman financial engines center
- Domain
- edelmanfinancialengines.com
Incident
- Discovered
- Jan 7, 2026
- Materiality determined
- Feb 4, 2026
- Notification sent
- Feb 4, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.