LPL FINANCIAL LLC
ent_019dd186a8a4c9a5358425f6d47248bf
Disclosures
20
State AG · Leak Site · 7 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
270,000
as filed · State AG OR
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- LPL FINANCIAL LLC
- Normalized
- lpl financial— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493005NM7F0H1N3EQ39
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- lplfinancial.com
Disclosure history (20)newest first
- ⛰️New Hampshire State AGas victim2026-07-06
LPL Financial LLC notified the New Hampshire Attorney General of a cybersecurity incident affecting 2 NH residents. Unauthorized access to an advisor's portal account occurred starting October 26, 2025, via a malicious script. Personal data exposed included names, SSNs, account numbers, and contact info. LPL contained the breach, worked with law enforcement, and offered 24 months of credit monitoring to affected individuals. Notification was sent June 29, 2026.
- ⛰️New Hampshire State AGas victim2026-05-20
LPL Financial LLC reported a cybersecurity incident to the New Hampshire Attorney General on May 20, 2026. A threat actor used social engineering (phishing) to gain unauthorized access to an advisor's LPL portal account on January 8, 2026. The actor initiated an unauthorized ACH transfer from one client account, which was fully reimbursed. The incident resulted in the exposure of one New Hampshire resident's PII, including SSN, account numbers, and contact info. LPL contained the breach by January 23, 2026, and offered two years of credit monitoring to the affected individual.
- ⛰️New Hampshire State AGas victim2026-04-27
LPL Financial LLC notified the New Hampshire Attorney General of a cybersecurity incident affecting four NH residents. Between Nov 20-25, 2025, phishing messages distributed malware to financial advisors' devices, granting unauthorized third-party access to LPL's encrypted web-based advisor portal. The incident exposed personal information (name, DOB, SSN, account numbers, email, phone) of four individuals. LPL restored accounts, engaged forensic experts, and is offering two years of credit monitoring. No identity theft was identified.
- 🦞Maine State AGas victim2026-04-22
LPL Financial LLC: phishing messages delivered malware to affiliated advisor devices (Nov 10-20, 2025), enabling unauthorized portal access and fraudulent securities transactions/transfers. Law enforcement notified; accounts restored. 1,581 total affected; 2 Maine residents. Experian 24-month credit monitoring offered.
- 🦞Maine State AGas victim2025-12-26
LPL Financial LLC reported a data breach to the Maine Attorney General, indicating that one Maine resident was affected. The breach was discovered on October 10, 2025, and occurred on September 30, 2025. The company is offering 24 months of identity theft protection services through Transunion to those affected. The nature of the breach was listed as "Other".
- GLOBALLeak Siteas victim2025-08-26
LPL Financial DATA LEAK | (I FORGOT THE SIZE,BUT ITS HUGE)
- 🌲Washington State AGas victim2021-09-30
LPL Financial LLC, a finance sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2021-08-05 and filed notice on 2021-09-30. 992 Washington residents were affected. 56 days elapsed between awareness and notification. 10 days to identify the breach. 0 days to contain the breach.
- 🦫Oregon State AGas victim2021-09-30
LPL Financial LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2021-09-30. The breach occurred during 7/26/2021 - 7/28/2021. The breach was discovered on 9/10/2021. 1,605 individuals were affected. Notice was sent on 9/30/2021.
- 🦬Montana State AGas victim2019-01-17
LPL Financial LLC (LPL) reported a data breach to the Montana Attorney General. The breach was reported on 2019-01-17. The breach occurred on 11/1/2018. 756 Montana residents were affected.
- 🦫Oregon State AGas victim2018-11-17
LPL Financial LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2018-11-17. The breach occurred during 11/1/2018. The breach was discovered on 11/1/2018. 270,000 individuals were affected. Notice was sent on 11/17/2018.
- 🐻California State AGas victim2018-11-17
LPL Financial LLC notified clients of a data breach involving its service provider, Capital Forensics, Inc. On November 1, 2018, an unauthorized person accessed a Capital Forensics user account on a third-party file-sharing system. Files containing LPL client information, including names, account numbers, and Social Security Numbers, were potentially accessed. LPL coordinated with Capital Forensics to remove the data and implemented heightened monitoring. Affected individuals are offered two years of complimentary credit monitoring and identity protection services.
- 🌲Washington State AGas victim2018-11-16
LPL Financial LLC, a finance sector entity reported a unclear/unknown incident to the Washington Attorney General. The organization became aware of the incident on 2018-11-01 and filed notice on 2018-11-16. 8,127 Washington residents were affected. 15 days elapsed between awareness and notification. 0 days to identify the breach. 0 days to contain the breach.
- 🦬Montana State AGas victim2018-04-30
LPL Financial LLC reported a data breach to the Montana Attorney General. The breach was reported on 2018-04-30. The breach occurred from 2/20/2018 to 2/28/2018. 3 Montana residents were affected.
- 🐻California State AGas victim2012-02-29
LPL Financial submitted a California SB-44 breach notification to the Office of the Attorney General on February 6, 2012. The filing references redacted client and participant letters but provides no specific details regarding the attack vector, data types, or number of affected individuals.
- ⛰️New Hampshire State AGas victim2010-08-25
LPL Financial Corporation notified the New Hampshire Attorney General on August 25, 2010, regarding a security breach involving the loss of an unencrypted portable drive in the mail on August 18, 2010. The drive contained client personal information, including names, addresses, financial account details, Social Security numbers, and dates of birth. The incident affected a limited number of individuals, including one New Hampshire resident. LPL investigated and notified the affected client.
- ⛰️New Hampshire State AGas victim2010-03-09
LPL Financial Corporation reported the theft of an unencrypted portable hard drive from an advisor's vehicle in New Hampshire on February 24, 2010. The drive contained client PII, including names, addresses, dates of birth, and Social Security numbers. LPL notified the NH Attorney General on March 9, 2010, and subsequently offered solutions to affected individuals.
- ⛰️New Hampshire State AGas victim2009-02-02
LPL Financial Corporation notified the New Hampshire Attorney General of a security breach involving unauthorized access to client personal information. A third-party system error on October 24, 2008, allowed four clients to view the data of 19 individuals, 12 of whom were NH residents. LPL retained Kroll Inc. to provide credit monitoring and identity theft restoration services to affected clients. Notifications were mailed in January 2009. No evidence of fraudulent activity was found.
- ⛰️New Hampshire State AGas victim2008-05-06
LPL Financial Corporation filed a breach notification with the New Hampshire Attorney General on May 6, 2008. The incident involved unauthorized access to customer records, resulting in the exposure of personally identifiable information including names and Social Security numbers. The company provided 12 months of complimentary credit monitoring services to affected individuals.
- ⛰️New Hampshire State AGas victim2008-05-06
LPL Financial Corporation issued a breach notification to New Hampshire residents dated May 6, 2008. The document references a 'Membership Card' and 'Credit Report and Credit Monitoring Service,' indicating potential exposure of PII and financial account data. The specific nature of the breach, affected count, and dates of occurrence/discovery are not detailed in the provided text.
- ⛰️New Hampshire State AGas victim2008-05-06
LPL Financial Corporation notified the New Hampshire Attorney General on May 6, 2008, regarding a security breach where hackers compromised the logon passwords of 14 financial advisors and 4 assistants. The attackers used these credentials to access customer accounts to trade penny stocks. The incident affected 10,219 individuals, including 4 New Hampshire residents. Potentially accessible data included names, addresses, Social Security numbers, and dates of birth. LPL engaged Kroll for credit monitoring and identity restoration services and implemented new security policies and personnel.