[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fLjCggxlM2k6oY5JCBjKxuKKZ0aLCdknt9vEAdLvo5gE":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":17,"pwnCount":18,"totalRecords":19,"dataClasses":20,"description":26,"source":27,"isVerified":4,"isSpamList":28,"isSensitive":4,"severity":29,"processingStatus":30,"logoUrl":31,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a6714002433c16830385c79","WedbushSecurities2025","Wedbush Securities 2025 Data Breach","wedbush-securities-2025","wedbush.com",{"name":12,"sector":13,"country":14,"website":10},"Wedbush Securities Inc.","Financial Services","United States","2025-05-17T00:00:00.000Z","2026-07-27T08:17:04.522Z","2026-07-27T09:30:00.000Z",0,null,[21,22,23,24,25],"Personal information","Names","Financial institution names","Financial account numbers","Social Security numbers","\u003Cp>\u003Cstrong>The Wedbush Securities 2025 data breach\u003C\u002Fstrong> involved possible unauthorized access to a limited set of client data because one of the financial-services firm's web-facing internal applications was misconfigured. According to the official consumer letter, the access period ran from May 17 through July 11, 2025; the company discovered the misconfiguration on July 11 and quickly secured the application.\u003C\u002Fp>\n\u003Cp>A data and address review determined on August 28 that some personal information was affected. Possible fields include names, financial-institution names, account numbers, and Social Security numbers. California and Massachusetts regulatory records confirm the event but do not publish a deduplicated nationwide person total. LeakData keeps pwnCount and totalRecords at zero, and importedRecordCount is also zero.\u003C\u002Fp>\n\u003Ch2>How Was the Wedbush Securities Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary evidence is Wedbush Securities' consumer notice dated November 20, 2025, published in Massachusetts and California regulatory records. On the company's behalf, the letter directly describes the misconfigured web-facing application, access window, review dates, person-specific data fields, environment containment, and identity-protection services.\u003C\u002Fp>\n\u003Cp>The California Attorney General record supplies a second official disclosure route. Claim Depot connects the two state filings and consumer letter and independently summarizes the timeline and data classes. The sources align on the organization, misconfiguration, May 17–July 11 period, and scope involving names, financial-institution names, account numbers, and SSNs.\u003C\u002Fp>\n\u003Ch2>What Happened Between May 17 and July 11, 2025?\u003C\u002Fh2>\n\u003Cp>Around July 11, Wedbush discovered that a web-facing internal application was misconfigured in a way that made unauthorized access possible. The company quickly secured the application and began investigating the nature and scope of potential access. The review found that unauthorized actors may have accessed a limited set of client data in the application from May 17 through July 11.\u003C\u002Fp>\n\u003Cp>The public letter does not say specific files were definitively downloaded or exfiltrated; it uses an assessment that actors “may have had access.” It also does not identify the actor, initial discovery method, authentication mechanism, or technical details of the misconfiguration. LeakData records possible unauthorized access at the confidence stated by the source and does not assume copying.\u003C\u002Fp>\n\u003Ch2>What Client Information May Have Been Affected?\u003C\u002Fh2>\n\u003Cp>Information in the affected files varied by person but could include a client's name, the name of the relevant financial institution, an account number, and a Social Security number. Together, these fields create substantial risk of targeted bank or brokerage impersonation, fraudulent account-verification requests, and identity theft.\u003C\u002Fp>\n\u003Cp>The protection appendix lists birth dates, addresses, and government IDs as general items that may be required to request a credit freeze. That section does not confirm those fields were accessible in the event. LeakData does not add a birth date, address, driver's license, passport, email, telephone number, password, or investment balance merely because it appears in general guidance.\u003C\u002Fp>\n\u003Ch2>Why Do the Financial-Institution Name and Account Number Matter?\u003C\u002Fh2>\n\u003Cp>A financial-institution name may help an attacker target a person through a genuine banking or brokerage relationship. An account number may be abused in fraudulent transfer requests, account-verification schemes, or customer-support impersonation. Risk is greater when combined with an SSN, although an account number alone does not mean a password or login access was compromised.\u003C\u002Fp>\n\u003Cp>The official notice does not disclose an account type, routing number, balance or position, transaction history, payment-card number, PIN, online password, or multifactor-authentication code. LeakData does not present those fields as confirmed. Clients should monitor accounts for unfamiliar transfers, new payees, contact-detail changes, and security-setting updates.\u003C\u002Fp>\n\u003Ch2>How Many People Were Affected and Was Misuse Observed?\u003C\u002Fh2>\n\u003Cp>The public state files do not publish a deduplicated nationwide total. A Massachusetts or California resident count, if available, cannot be treated as the complete national scope. LeakData does not estimate an unknown scale; pwnCount and totalRecords are zero. No client record, account row, or other person-level data was imported, so importedRecordCount is zero.\u003C\u002Fp>\n\u003Cp>Wedbush said it was unaware as of the letter date of attempted or actual misuse of information related to the event. That is a favorable finding through that date, not a guarantee against future fraud. Because SSNs and account numbers are durable or sensitive identifiers, long-term credit and financial-account monitoring remains appropriate for recipients.\u003C\u002Fp>\n\u003Ch2>How Did Wedbush Respond and How Can Clients Protect Themselves?\u003C\u002Fh2>\n\u003Cp>The company secured the application, took immediate steps to protect the environment, notified law enforcement, initiated a scope investigation, and reviewed policies and procedures. Eligible people were offered 12 months of complimentary single-bureau credit monitoring, a credit report, credit score, and proactive fraud assistance through Cyberscout.\u003C\u002Fp>\n\u003Cp>Recipients should enroll only with the code in their letter and review account statements and credit reports for unfamiliar inquiries or transactions. When an SSN was involved, freezes at all three bureaus, a fraud alert, and an IRS Identity Protection PIN may be appropriate. A help line at 833-467-0739 is available from 8:00 a.m. to 8:00 p.m. Eastern on weekdays. LeakData does not host client or account data.\u003C\u002Fp>","Official Wedbush Securities regulatory notice confirming possible unauthorized access to client data through a misconfigured web-facing application",false,"Low","completed","\u002Fuploads\u002Flogo\u002Fwedbush_com.svg"]