LPL FINANCIAL LLC
bd_e9a1e6956090b735 · schema v1 · pii pii-v1
Full breach record for LPL FINANCIAL LLC →LPL Financial Corporation notified the New Hampshire Attorney General on May 6, 2008, regarding a security breach where hackers compromised the logon passwords of 14 financial advisors and 4 assistants. The attackers used these credentials to access customer accounts to trade penny stocks. The incident affected 10,219 individuals, including 4 New Hampshire residents. Potentially accessible data included names, addresses, Social Security numbers, and dates of birth. LPL engaged Kroll for credit monitoring and identity restoration services and implemented new security policies and personnel.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/lpl-financial-c-20080506.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 6, 2008
- Raw hash
- e0b6833f40625c60e0ae2c796d8b15b2d19502edeaf96ed4be272b9ec551b5ac
Reporting entity
- Name
- LPL FINANCIAL LLCnorm: lpl financial
- Domain
- lplfinancial.com
Victim entity
- Name
- LPL FINANCIAL LLCnorm: lpl financial
- Domain
- lplfinancial.com
Incident
- Discovered
- Jul 16, 2007
- Materiality determined
- —
- Notification sent
- Sep 21, 2007
- Affected individuals
- 10,219
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified our primary regulator, the Financial Industry Regulatory Authority
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 42 weeks(295 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.