HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICPIILowContained
CETERA FINANCIAL GROUP, INC.
bd_d72d9cacef1c0c8e · schema v1 · pii pii-v1
Full breach record for CETERA FINANCIAL GROUP, INC. →On April 6, 2020, Cetera Financial Group, Inc. detected unauthorized access to an employee's email account. The account was secured within five minutes, and passwords were reset. An investigation determined that personal information, including names, may have been viewed. Affected individuals were offered one year of complimentary identity protection services.
California clockDiscovered Apr 6, 2020 → Notified Aug 21, 2020137d ✗ CA 60-day late20 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_d28fdbc51402468eWashington State AGfiled 2020-08-21Candidate
- bd_d34b6bcf19629cfaMontana State AGfiled 2020-08-21Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-193366
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 21, 2020
- Raw hash
- 283cc96490e86706ff11543c6f23fe29365d38612622eea4ffcda665b0b8123b
Reporting entity
- Name
- CETERA FINANCIAL GROUP, INC.norm: cetera financial
- Domain
- cetera.com
Victim entity
- Name
- CETERA FINANCIAL GROUP, INC.norm: cetera financial
- Domain
- cetera.com
Incident
- Discovered
- Apr 6, 2020
- Materiality determined
- —
- Notification sent
- Aug 21, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 20 weeks(137 days from discovery to filing)
- Compliance flags
- CA 60-day late · 137d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 6, 2020→ Notified: Aug 21, 2020137d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.