LPL Financial LLC reported a cybersecurity incident to the New Hampshire Attorney General on May 20, 2026. A threat actor used social engineering (phishing) to gain unauthorized access to an advisor's LPL portal account on January 8, 2026. The actor initiated an unauthorized ACH transfer from one client account, which was fully reimbursed. The incident resulted in the exposure of one New Hampshire resident's PII, including SSN, account numbers, and contact info. LPL contained the breach by January 23, 2026, and offered two years of credit monitoring to the affected individual.
Affected (this filing): 1