Social EngineeringFinancial ServicesFinancePhishingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALSMediumContained
CETERA FINANCIAL GROUP, INC.
bd_c8e60806383a31ea · schema v1 · pii pii-v1
Full breach record for CETERA FINANCIAL GROUP, INC. →Cetera Financial Group (CFG) detected suspicious activity involving a single employee email account. An unauthorized person accessed the account between July 7, 2025 and August 21, 2025. CFG determined on January 30, 2026 that personal information—including names, Social Security numbers, driver's license numbers, and financial account information—may have been compromised. CFG notified 57 Maine residents on March 25, 2026 and offered IDX credit monitoring services.
Maine clockDiscovered Jan 30, 2026 → Filed with AG Mar 25, 202654d ⏱ ME AG >30d8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_79058398589604aeVermont State AGfiled 2026-03-25Verified
- bd_a95f62f6f2279f59California State AGfiled 2026-03-25Candidate
- bd_b2cf5e2691400e24Indiana State AGfiled 2026-03-25Verified
- bd_a989d5443a1c83deNew Hampshire State AGfiled 2026-03-24(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 2d gap
- bd_05000564b48b0cefTexas State AGfiled 2026-03-27(2d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/d0e57260-b175-4aea-8c84-db2a303a1df9.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 25, 2026
- Raw hash
- 8ac567015eea22ec96e16f510ed6705c072423c514bcd7305bcdd6a9fd02a690
Reporting entity
- Name
- CETERA FINANCIAL GROUP, INC.norm: cetera financial
- Domain
- cetera.com
- Industry
- Financial Services
Victim entity
- Name
- CETERA FINANCIAL GROUP, INC.norm: cetera financial
- Domain
- cetera.com
- Industry
- Financial Services
- Industry
- Financial Servicesllm
Incident
- Discovered
- Jan 30, 2026
- Materiality determined
- —
- Notification sent
- Mar 25, 2026
- Affected individuals
- 57
- Data types
- PIIIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcementNotifying relevant regulatorsNotified three major credit reporting agencies
- Initial access
- phishing_link
Compliance
- Time to disclose
- 8 weeks(54 days from discovery to filing)
- Compliance flags
- ME AG >30d · 54d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jan 30, 2026→ Filed with AG: Mar 25, 202654d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.