LPL FINANCIAL LLC
ent_019dd186a8a4c9a5358425f6d47248bf
Disclosures
25+
State AG · Leak Site · 11 jurisdictions
Multi-filing incidents
5
incidents joining 2+ filings here
Max affected reported
270,000
nationwide · State AG OR
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- LPL FINANCIAL LLC
- Normalized
- lpl financial— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493005NM7F0H1N3EQ39
- SEC EDGAR CIK
- 0001397911
- Domain
- lplfinancial.com
- Corporate parent
- LPL HOLDINGS, INC.— per GLEIF relationship records
Disclosure history (newest 25)newest first
- Vermont State AGas victim2026-09-14
LPL Financial LLC reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-09-14. The reporting organization type is Financial Services. 1 Vermont residents were affected. Categories of data breached: Social Security Numbers, Financial Account Codes, Credit and Debit Account Inf.
- Massachusetts State AGas victim2026-09-01
LPL Financial LLC notified Massachusetts and Maryland residents of a security incident involving an associated financial advisor's device. Unauthorized third-party access via remote access software occurred between September 29, 2025, and June 1, 2026. Affected data includes names, SSNs, account numbers, contact info, and transaction history. LPL contained the incident, rotated credentials, and is offering 24 months of credit monitoring.
- Massachusetts State AGas victim2026-09-01
LPL Financial LLC notified Massachusetts residents of a security incident where an unauthorized third party accessed a financial advisor's device using remote access software between January 14, 2025, and May 29, 2026. The actor may have accessed an LPL portal containing client data, including names, SSNs, account numbers, and transaction history. LPL contained the incident, rotated credentials, and is offering 24 months of credit monitoring.
- New Hampshire State AGas victim2026-07-06
LPL Financial LLC notified the New Hampshire Attorney General of a cybersecurity incident affecting 2 NH residents. Unauthorized access to an advisor's portal account occurred starting October 26, 2025, via a malicious script. Personal data exposed included names, SSNs, account numbers, and contact info. LPL contained the breach, worked with law enforcement, and offered 24 months of credit monitoring to affected individuals. Notification was sent June 29, 2026.
- New Hampshire State AGas victim2026-05-20
LPL Financial LLC reported a cybersecurity incident to the New Hampshire Attorney General on May 20, 2026. A threat actor used social engineering (phishing) to gain unauthorized access to an advisor's LPL portal account on January 8, 2026. The actor initiated an unauthorized ACH transfer from one client account, which was fully reimbursed. The incident resulted in the exposure of one New Hampshire resident's PII, including SSN, account numbers, and contact info. LPL contained the breach by January 23, 2026, and offered two years of credit monitoring to the affected individual.
- New Hampshire State AGas victim2026-04-27
LPL Financial LLC notified the NH Attorney General of a cybersecurity incident where malware distributed via phishing messages affected financial advisors' devices, leading to unauthorized third-party access to client accounts. Between Nov 20-25, 2025, LPL detected unauthorized securities transactions. Investigation confirmed no sensitive PII was accessed, but 4 NH residents were notified as a precaution. LPL restored accounts, secured systems, and offered 2 years of credit monitoring.
- Massachusetts State AGas victim2026-04-22
LPL Financial LLC experienced a cybersecurity incident between November 20-25, 2025, involving malware distributed through phishing messages that affected advisor devices. This led to unauthorized third-party access to advisor accounts on LPL's web-based portal, resulting in unauthorized securities transactions and financial transfers. While no evidence of sensitive personal information access was found, clients were notified out of caution. LPL contacted law enforcement, engaged outside experts, stopped the activity, restored accounts, and implemented new security safeguards. Credit monitoring was offered to affected individuals.
- Maine State AGas victim2026-04-22
LPL Financial LLC reported a cybersecurity incident where malware distributed via phishing messages compromised advisor devices, leading to unauthorized access to client accounts. The breach affected 1,581 individuals, including 2 in Maine. Unauthorized transactions occurred between Nov 10-25, 2025. LPL notified law enforcement, engaged forensic experts, and offered 24 months of credit monitoring. No evidence of ongoing compromise was found.
- Nebraska State AGas victim2025-12-26
LPL Financial LLC reported a cybersecurity incident between September 30 and October 10, 2025, where foreign threat actors gained unauthorized access to affiliated financial advisors' online accounts. The actors executed a 'hack pump-and-dump' trading scheme and may have viewed clients' personal information, including names, addresses, and government IDs. LPL contacted law enforcement, secured accounts, and offered 24 months of credit monitoring via TransUnion. The incident is contained.
- Maine State AGas victim2025-12-26
LPL Financial LLC reported a cybersecurity incident where foreign threat actors accessed affiliated financial advisors' online accounts to execute a "hack pump-and-dump" trading scheme. The breach occurred between September 30 and October 10, 2025, affecting 53 individuals, including 1 Maine resident. Personal information was potentially viewed. LPL contacted law enforcement, secured accounts, and offered 24 months of credit monitoring via TransUnion.
- GLOBALLeak Siteas victim2025-08-26
LPL Financial DATA LEAK | (I FORGOT THE SIZE,BUT ITS HUGE)
- Massachusetts State AGas victim2024-09-24
LPL Financial LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-09-24. 1 Massachusetts residents were affected.
- Massachusetts State AGas victim2022-09-09
LPL Financial LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-09-09. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2021-09-30
LPL Financial LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-09-30. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas victim2021-09-30
LPL Financial LLC reported unauthorized access to an advisor's email account between July 26-28, 2021, discovered on August 5, 2021. The incident affected 992 Washington residents, exposing PII including SSNs, driver's licenses, financial account numbers, and medical information. LPL notified law enforcement, secured the account, and offered 24 months of credit monitoring.
- Oregon State AGas victim2021-09-30
LPL Financial LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2021-09-30. The breach occurred during 7/26/2021 - 7/28/2021. The breach was discovered on 9/10/2021. 1,605 individuals were affected. Notice was sent on 9/30/2021.
- New Hampshire State AGas victim2019-03-12
LPL Financial LLC notified the NH Attorney General of a security incident involving its third-party vendor, Broadridge Financial Solutions. Between July 10, 2018, and January 8, 2019, Broadridge inadvertently transferred AssetMark account data for 14 LPL clients to another broker-dealer. The receiving broker-dealer deleted the data. One New Hampshire resident was affected, with PII including SSN, DOB, and account numbers. LPL notified the individual and offered credit monitoring.
- Massachusetts State AGas victim2019-03-11
LPL Financial LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-03-11. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2019-01-23
Supplemental notice from LPL Financial LLC regarding a data security incident at third-party provider Capital Forensics, Inc. Initial notification covered 2,526 NH residents; this supplemental notice covers 9 additional NH residents. Notifications mailed Jan 17, 2019. Credit monitoring provided.
- Montana State AGas victim2019-01-17
LPL Financial LLC notified the Montana Attorney General of a data breach involving its third-party provider, Capital Forensics, Inc. An unauthorized individual accessed a CFI user account on a file-sharing system on November 1, 2018, potentially exposing client names, LPL account numbers, and Social Security numbers. LPL secured the account, removed data, and began notifying 756 Montana residents starting November 17, 2018, offering two years of credit monitoring.
- New Hampshire State AGas victim2018-11-30
LPL Financial LLC submitted a supplemental notification to the New Hampshire Attorney General regarding a data security incident involving its third-party service provider, Capital Forensics, Inc. (CFI). LPL mailed notification letters to 2,526 NH residents initially, with an additional 110 letters mailed subsequently (total 2,636 NH residents). The incident involved potentially accessed data files on CFI's system. LPL provided credit monitoring and identity protection services for two years.
- New Hampshire State AGas victim2018-11-19
LPL Financial LLC notified the NH Attorney General of a data security incident at its third-party service provider, Capital Forensics, Inc. On November 1, 2018, an unauthorized person accessed a single CFI user's account on a third-party file-sharing system. Files containing LPL client information, including names, account numbers, and Social Security numbers, were potentially accessed. LPL secured the account, removed the data, and notified 2,526 New Hampshire residents. Credit monitoring was offered.
- South Carolina State AGas victim2018-11-19
LPL Financial LLC notified clients of a data security incident involving its service provider, Capital Forensics, Inc. On November 1, 2018, an unauthorized person accessed a Capital Forensics user account on a file-sharing system, potentially exposing client account numbers and Social Security Numbers. LPL launched an investigation, coordinated with Capital Forensics to remove the data, and implemented heightened monitoring. Law enforcement was notified, and affected individuals were offered two years of free credit monitoring and identity protection services.
- Oregon State AGas victim2018-11-17
LPL Financial LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2018-11-17. The breach occurred during 11/1/2018. The breach was discovered on 11/1/2018. 270,000 individuals were affected. Notice was sent on 11/17/2018.
- California State AGas victim2018-11-17
LPL Financial LLC notified clients of a data breach involving its service provider, Capital Forensics, Inc. On November 1, 2018, an unauthorized person accessed a Capital Forensics user account on a third-party file-sharing system. Files containing LPL client information, including names, account numbers, and Social Security Numbers, were potentially accessed. LPL coordinated with Capital Forensics to remove the data and implemented heightened monitoring. Affected individuals are offered two years of complimentary credit monitoring and identity protection services.