LPL FINANCIAL LLC
bd_941f183dd2050015 · schema v1 · pii pii-v1
Full breach record for LPL FINANCIAL LLC →37 incidents on fileLPL Financial LLC reported a cybersecurity incident to the New Hampshire Attorney General on May 20, 2026. A threat actor used social engineering (phishing) to gain unauthorized access to an advisor's LPL portal account on January 8, 2026. The actor initiated an unauthorized ACH transfer from one client account, which was fully reimbursed. The incident resulted in the exposure of one New Hampshire resident's PII, including SSN, account numbers, and contact info. LPL contained the breach by January 23, 2026, and offered two years of credit monitoring to the affected individual.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 8, 2026
Begins
Jan 13, 2026
Discovered
May 20, 2026
Filed
vs. sector median
+10 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- New Hampshire State AGbd_a770fe6ece79659a2026-04-27 · +23dVerified
- Massachusetts State AGbd_a8353a63355898c82026-04-22 · +28dVerified
- Maine State AGbd_df923b8f910900012026-04-22 · +28dVerified
- New Hampshire State AGbd_23641c5817d6e6632026-07-06 · +47dVerified by operator
Filing propagation · 5 filings · 3 states
View merged incident ↗Pattern: first filing Apr 22 (MA), last Jul 6 (NH) — a 75-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.