[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3egwdbl1v9uub":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":29,"seoTitle":30,"seoTitleEn":31,"seoDescription":30,"seoDescriptionEn":32,"logoUrl":33,"isVerified":4,"isSensitive":4,"isSpamList":34,"isMalware":34,"company":35},"6a71ad857197abf2d145dd2e","CeteraFinancialGroup2025","Cetera Financial Group Data Breach","cetera-financial-group-2025","cetera.com","2025-07-07T00:00:00.000Z","2026-08-04T09:14:45.603Z","Cetera filing with the New Hampshire Attorney General","https:\u002F\u002Fmm.nh.gov\u002Ffiles\u002Fuploads\u002Fdoj\u002Fremote-docs\u002Fcetera-financial-group-20260324.pdf",[14,16,17],"https:\u002F\u002Fago.vermont.gov\u002Fdocument\u002F2026-03-25-cetera-financial-group-data-breach-notice-consumers","https:\u002F\u002Foag.my.site.com\u002Fdatasecuritybreachreport\u002Fapex\u002FDataSecurityReportsPage",42947,"known",null,"people","Medium",[24,25,26,27,28],"Names","Physical addresses","Social security numbers","Driver's licenses","Financial information","\u003Cp>\u003Cstrong>The Cetera Financial Group data breach\u003C\u002Fstrong> was a security incident involving unauthorised access to a single employee email account at the financial advice organisation. Cetera's official notice places the account access between 7 July and 21 August 2025.\u003C\u002Fp>\u003Cp>The Texas Attorney General record reports that the incident affected 42,947 people across the United States, including 1,398 Texas residents. New Hampshire and Vermont regulators also published Cetera's consumer notices for the same event.\u003C\u002Fp>\u003Ch2>How was the incident confirmed?\u003C\u002Fh2>\u003Cp>Cetera's filing with the New Hampshire Attorney General confirms that the company investigated suspicious activity in one employee email account and determined that an unauthorised person had accessed it.\u003C\u002Fp>\u003Cp>The Vermont filing identifies the same access period, the 30 January 2026 personal-information review result and the 25 March 2026 notice date. The Texas record identifies the same Cetera Financial Group organisation at its San Diego address and lists the matching event dates.\u003C\u002Fp>\u003Ch2>When did the breach occur?\u003C\u002Fh2>\u003Cp>The known period of unauthorised access was 7 July through 21 August 2025. The catalog event date is the beginning of that period; Cetera did not publicly disclose how the account was initially compromised.\u003C\u002Fp>\u003Cp>Cetera determined around 30 January 2026 that personal information was present in the affected content. Written notification began on 25 March, and the Texas record was published on 27 March 2026.\u003C\u002Fp>\u003Ch2>What information was affected?\u003C\u002Fh2>\u003Cp>Official state records list names, addresses, Social Security numbers, driver's licence details and financial account information. Cetera's New Hampshire and Vermont filings directly confirm the four categories other than addresses.\u003C\u002Fp>\u003Cp>The fields involved varied by person. Cetera's sample consumer letter presents the specific data elements as a recipient-specific field, so the published categories should not be interpreted as applying to all 42,947 people.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>The Texas Attorney General reports a total of 42,947 affected people. The same record separately identifies 1,398 Texas residents within that total.\u003C\u002Fp>\u003Cp>The 110 New Hampshire residents and 96 Vermont residents are state subsets of the nationwide figure. Those counts were not added to the total again.\u003C\u002Fp>\u003Ch2>What risks do these data types create?\u003C\u002Fh2>\u003Cp>A Social Security number combined with driver's licence or financial account information may be used in fraudulent account applications and attempts to bypass identity checks.\u003C\u002Fp>\u003Cp>Targeted messages disguised as financial-adviser or investment-account communications may also appear more convincing. Knowledge of a Cetera relationship or accurate personal details does not prove that the sender is authorised.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Cetera offered eligible notice recipients 12 or 24 months of credit and identity monitoring through IDX. Each recipient should check the service period and enrollment code in their own official notification letter.\u003C\u002Fp>\u003Cp>Recipients can review credit reports, bank and investment accounts, and new-account alerts for unfamiliar activity. Instead of following a link in an unexpected Cetera message, they should use the company's official website or a verified contact channel from the notice letter.\u003C\u002Fp>","","Cetera Financial Group Data Breach (42.9 Thousand People Affected)","Review the verified Cetera Financial Group breach date, the 42,947 people affected, the information involved and practical protective steps.","https:\u002F\u002Fcdn.cookielaw.org\u002Flogos\u002Ff8d16f81-81b4-4a5f-b791-bc27736a619e\u002F8b21dc7e-b2e6-4e22-b133-36ff785da5b0\u002F08c6862a-9000-49fe-85c8-0d9db5233e17\u002Fcetera-logo.png",false,{"name":36,"sector":37,"country":38,"website":10,"websiteArchiveUrl":30,"websiteStatus":39,"websiteCheckedAt":12},"Cetera Financial Group","Financial Services","United States","active"]