DisclosureLens
HackingFinancial ServicesFinanceStolen CredentialsData ExfiltratedCustomer Data InvolvedIdentity (basic)Financial accountLowContained

TruePoint

bd_ba2f21f703d3869a · schema v1 · pii pii-v1

Severity

Low

Discovered

Mar 26, 2026

Filed

Apr 24, 2026

To disclose

29 days

Affected

1state residents only

Confidence

64%
Full breach record for TruePoint

Truepoint Inc notified clients of a cybersecurity incident on March 26, 2026, where an unauthorized party temporarily accessed company files. Four files were downloaded, containing no actionable information. Other accessed files contained client names, addresses, email addresses, and account numbers. Truepoint engaged forensic experts, contained the access, and is offering to cover passport replacement costs for affected individuals.

Massachusetts clock MA AG ≤30d29 days discovery → filing
occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · 29 days

Mar 26, 2026

Begins

Mar 26, 2026

Discovered

Apr 24, 2026

Filed

vs. sector median

4 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.