MalwarePhishingRansomwareData ExfiltratedCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
LPL FINANCIAL LLC
bd_a770fe6ece79659a · schema v1 · pii pii-v1
Full breach record for LPL FINANCIAL LLC →LPL Financial LLC notified the New Hampshire Attorney General of a cybersecurity incident affecting four NH residents. Between Nov 20-25, 2025, phishing messages distributed malware to financial advisors' devices, granting unauthorized third-party access to LPL's encrypted web-based advisor portal. The incident exposed personal information (name, DOB, SSN, account numbers, email, phone) of four individuals. LPL restored accounts, engaged forensic experts, and is offering two years of credit monitoring. No identity theft was identified.
Leak gap clock✗ Leak >180d23 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
A leak claim by cephalus about this victim predates this filing by 243 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_a7104fdbf8649143Leak Sitecephalusfiled 2025-08-26(243d gap)Verified
Regulatory filings (1) · sorted by filing gap
- bd_df923b8f91090001Maine State AGfiled 2026-04-22(5d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/lpl-financial-20260427.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 27, 2026
- Raw hash
- 5b66aba463fd228c798476074e31fb5dc65cb0f357a4abcabf7f9c66b0702028
Reporting entity
- Name
- LPL FINANCIAL LLCnorm: lpl financial
- Domain
- lplfinancial.com
Victim entity
- Name
- LPL FINANCIAL LLCnorm: lpl financial
- Domain
- lplfinancial.com
Incident
- Discovered
- Nov 20, 2025
- Materiality determined
- —
- Notification sent
- Apr 27, 2026
- Affected individuals
- 4
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 23 weeks(158 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.