HackingStolen CredentialsCapture App DataCustomer Data InvolvedDelayed DiscoveryPIILowContained
CETERA FINANCIAL GROUP, INC.
bd_a95f62f6f2279f59 · schema v1 · pii pii-v1
Full breach record for CETERA FINANCIAL GROUP, INC. →Cetera Financial Group reported an unauthorized person accessed a single employee email account between July 7 and August 21, 2025. The compromise was identified through suspicious activity monitoring; personal information of affected individuals was determined to be involved on or around January 30, 2026. Affected individuals were offered IDX credit and identity monitoring services.
California clockConsumers notified Mar 25, 2026 → AG copy submitted Mar 25, 20260d ✓ CA AG copy ≤15d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_79058398589604aeVermont State AGfiled 2026-03-25Verified
- bd_b2cf5e2691400e24Indiana State AGfiled 2026-03-25Verified
- bd_c8e60806383a31eaMaine State AGfiled 2026-03-25Verified
- bd_a989d5443a1c83deNew Hampshire State AGfiled 2026-03-24(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 2d gap
- bd_05000564b48b0cefTexas State AGfiled 2026-03-27(2d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-620788
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 25, 2026
- Raw hash
- cf02b4c25286d7cf69c48d51797e994dde267baa92aba78337d730ac0431251d
Reporting entity
- Name
- CETERA FINANCIAL GROUP, INC.norm: cetera financial
- Domain
- cetera.com
Victim entity
- Name
- CETERA FINANCIAL GROUP, INC.norm: cetera financial
- Domain
- cetera.com
Incident
- Discovered
- —
- Materiality determined
- Jan 30, 2026
- Notification sent
- Mar 25, 2026
- Affected individuals
- Not disclosed
- Data types
- PII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Submitted breach notification to California Office of the Attorney General
Compliance
- Compliance flags
- CA AG copy ≤15d · 0d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status California Consumers notified: Mar 25, 2026→ AG copy submitted: Mar 25, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.