Kestra Investment Services, LLC
ent_f29631a7cace1c2c28e00a81
Disclosures
5
State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
432
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Kestra Investment Services, LLC
- Normalized
- kestra investment— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- Montana State AGas reporting2025-09-17
Davis Advisory Group, an affiliate of Kestra, notified customers on September 17, 2025, that on July 24, 2025, a threat actor gained unauthorized access to a computer system using valid credentials. The incident potentially exposed names and financial account information. The company increased security protocols and offered 12 months of Experian identity monitoring.
- Montana State AGas victim2023-11-03
Kestra Investment Services, LLC (via affiliate Maleta Wealth) notified Montana residents of unauthorized access to a computer on Sept 18, 2023. No evidence of PII theft, but notice issued in caution. Kroll identity monitoring offered.
- New Hampshire State AGas victim2018-12-21
Kestra Investment Services, LLC notified the NH Attorney General of a breach involving its third-party vendor, Capital Forensics, Inc. (CFI). On or about Nov 1, 2018, CFI was victimized by a cyberattack where an unauthorized party accessed a CFI employee account on a file-sharing system. Kestra determined on Nov 21, 2018 that client PII (names, SSNs, account numbers) was compromised. 33 NH residents were notified on Dec 20, 2018. CFI engaged forensics and notified law enforcement; credit monitoring was offered.
- Massachusetts State AGas victim2018-12-20
Kestra Investment Services LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-12-20. 432 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2018-12-20
Kestra Investment Services, LLC notified clients of a data breach involving a third-party provider, Capital Forensics, Inc. An unauthorized party accessed data via a CFI employee account on or before Nov 21, 2018. Compromised data included names, SSNs, and account numbers. Kestra engaged forensic investigators and notified law enforcement. Affected individuals received 24 months of identity protection.