Social EngineeringPhishingStolen CredentialsData ExfiltratedCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighContained
ASSETMARK, INC.
bd_c7f8a628cbde3f8a · schema v1 · pii pii-v1
Full breach record for ASSETMARK, INC. →AssetMark, Inc. notified the New Hampshire Attorney General of a data security event on June 11, 2026. On May 15, 2026, an employee's credentials were compromised via a social-engineering event, leading to unauthorized access to customer files. Approximately 3,751 New Hampshire residents were affected. Exposed data included names, Social Security numbers, and account numbers. AssetMark disabled credentials, engaged forensic investigators, notified law enforcement, and provided 24 months of credit monitoring to affected individuals.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_33f04a386aea24d3Washington State AGfiled 2026-06-11Verified
- bd_6886b6cefdfdb7fdOregon State AGfiled 2026-06-11Verified
- bd_6af2c69a79abc5b2Delaware State AGfiled 2026-06-11Verified
- bd_d0136116688cfee0Vermont State AGfiled 2026-06-11Verified
Show 3 more filings ↓Show fewer ↑up to 15d gap
- bd_30436bcce4399459Texas State AGfiled 2026-06-18(7d gap)Verified
- bd_6ed05ad3f644267aMassachusetts State AGfiled 2026-06-01(10d gap)Candidate
- bd_b328f99afc4a5251California State AGfiled 2026-06-26(15d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/assetmark-20260611.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 11, 2026
- Raw hash
- 71fb419e6a207fba16e3a8e88847f43f7cb2be08279c76baea22d38ad6263a7d
Reporting entity
- Name
- Keesal, Young & Logannorm: keesal young logan
- Domain
- kyl.com
Victim entity
- Name
- ASSETMARK, INC.norm: assetmark
Incident
- Discovered
- May 15, 2026
- Materiality determined
- —
- Notification sent
- Jun 11, 2026
- Affected individuals
- 3,751
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Department of Justice Consumer Protection & Antitrust BureauNotified the three major credit reporting agencies: Equifax, Experian, and TransUnion
- Initial access
- phishing_link
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.