Investmentnews LPL Financial and Ameriprise Report Cybersecurity Breaches Affecting Client Data
Article Content
- •LPL Financial's breach affected 1,581 clients due to a phishing attack involving malware.
- •Ameriprise Financial reported a separate breach affecting 47,876 clients with unauthorized data access.
- •Both firms have been reported to the Maine Attorney General for their cybersecurity incidents.
LPL Financial reported a data breach affecting 1,581 clients due to a phishing attack that occurred on November 10, 2025, and was discovered 10 days later. The breach involved malware that gained unauthorized access to accounts of a small number of affiliated financial advisors. Although LPL stated that there was no evidence of sensitive personal information being accessed, the firm has taken steps to secure affected accounts and offered credit monitoring to clients. Ameriprise Financial also reported a breach affecting 47,876 clients on March 2, 2026, which was discovered on March 18, 2026. This incident involved unauthorized access to stored data and files, though Ameriprise confirmed that no unauthorized transactions occurred. Both firms have been flagged by the Maine Attorney General for these incidents, highlighting ongoing vulnerabilities in the financial sector.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Ameriprise in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…