Financial Sector Security Intelligence

Tracking breaches, regulatory updates, and threats affecting banks, fintechs, and financial institutions.

Latest Intelligence

View All →

BREACH

Challenge Financial Services, Inc. - Data Breach

Challenge Financial Services, Inc. disclosed a data breach on August 17, 2026. The nature of the breach, the date it occurred or was discovered, the number of records affected, and the specific types of data exposed are not detailed in the provided information.

Breach: Aug 17, 2026California AG

BREACH

Financial Administrative Support Services - Data Breach

Financial Administrative Support Services (FASS) disclosed a data breach on May 26, 2025, after identifying suspicious activity on their network. The investigation revealed that an unknown actor gained access to FASS systems prior to March 26, 2025, and again between June 8, 2025, and June 11, 2025, accessing and/or copying certain information. The compromised data includes the recipient's name and other unspecified data elements. FASS is offering complimentary credit monitoring services and has reported the event to law enforcement.

Breach: May 26, 2025California AG

BREACH

5Star Life Insurance Company - Data Breach

Information regarding a data breach at 5Star Life Insurance Company was disclosed on November 13, 2025. Specific details about the nature of the breach, the date it occurred or was discovered, the number of records affected, and the types of data exposed are not available in the provided information.

Breach: Nov 13, 2025California AG

BREACH

Fairwinds Credit Union - Data Breach

Fairwinds Credit Union experienced a data breach due to a cybersecurity incident at one of its external vendors, Mercadien, P.C. CPAs. The incident occurred within Mercadien's systems between September 7, 2025, and November 7, 2025, potentially exposing personal information of Fairwinds members. Fairwinds was notified by Mercadien on August 13, 2026, and completed its review of impacted members on September 4, 2026. The credit union has terminated its relationship with Mercadien and is offering complimentary credit monitoring and identity restoration services through Experian.

Breach: Sep 7, 2025California AG
BREACH

HILT-Trust 2020-A and its underlying trusts and affiliates ("HILT") - Data Breach

HILT-Trust 2020-A and its underlying trusts and affiliates experienced a data breach that was disclosed on July 23, 2026. The breach resulted in the exposure of personal information including names, addresses, dates of birth, email addresses, and phone numbers. The specific method of attack and the exact date of the incident or discovery are not specified.

Breach: Jul 23, 2026California AG
BREACH

NSE Insurance Agencies - Data Breach

NSE Insurance Agencies disclosed a data breach on November 6, 2025, where unauthorized access to their network was detected around November 28, 2025. An investigation determined that between November 6, 2025, and November 29, 2025, certain files containing personal information, including full name, may have been accessed and acquired. The company is offering a complimentary month of Equifax Credit Watch Gold and advising customers to take precautionary measures such as placing fraud alerts and obtaining credit reports.

Breach: Nov 6, 2025California AG

BREACH

United Underwriters - Data Breach

United Underwriters disclosed a security incident on April 7, 2026, where an unauthorized actor downloaded certain files from their systems on May 1, 2026. The company is offering 24 months of complimentary credit monitoring and identity restoration services through Cyberscout, a TransUnion company, to affected individuals. They have also enhanced their security and monitoring controls.

Breach: Apr 7, 2026California AG

BREACH

Suffolk Federal Credit Union - Data Breach

Suffolk Federal Credit Union is notifying its members of a data security incident that occurred at Mercadien, P.C., CPAs, a former vendor. An unauthorized third party gained access to a portion of Mercadien's computer environment between September 17, 2025, and October 9, 2025. The incident was limited to Mercadien's systems and did not involve Suffolk Credit Union's systems. The investigation determined that personal information, including [Extra 1 (Variable text)], may have been accessed. Suffolk Credit Union is offering a complimentary one-year membership in Experian IdentityWorksSM Credit 3B to affected individuals.

Breach: Sep 17, 2025California AG

BREACH

Apollo Management Holdings, L.P. - Data Breach

Apollo Management Holdings, L.P. experienced a social engineering incident between July 6 and July 10, 2026, resulting in unauthorized access to certain cloud platforms. The compromised information may include names, dates of birth, contact information, home addresses, and Social Security Numbers. The company has notified law enforcement, engaged cybersecurity experts, and is offering complimentary credit monitoring and identity protection services through Cyberscout.

Breach: Jul 6, 2026California AG
BREACH

Integrated Specialty Coverages, LLC (“ISC”) - Data Breach

Integrated Specialty Coverages, LLC (ISC) experienced a security incident involving a third-party cloud platform used for electronic document execution and management. An unauthorized third party accessed a single ISC workspace between June 8, 2026, and June 11, 2026, and downloaded certain files. The affected files contained names in combination with other personal information. ISC's internal systems remain secure, and there is no evidence of misuse of personal information at this time. The company is offering complimentary credit and identity monitoring services through Experian Identity Works.

Breach: Jun 8, 2026California AG
BREACH

Kovack Financial, LLC - Data Breach

Kovack Financial, LLC experienced a data breach where an unknown actor gained access to files on their network between August 8, 2025, and August 27, 2025. The company became aware of suspicious activity on August 28, 2025, and launched an investigation. It was determined on July 16, 2026, that information related to individuals may have been accessed. Kovack is offering 12 months of complimentary credit monitoring and identity restoration services through Cyberscout.

Breach: Aug 8, 2025California AG
BREACH

Langwasser & Company CPAs - Data Breach

Langwasser & Company CPAs disclosed a data breach on May 5, 2026. The notification letter indicates that personal information was compromised, and advises affected individuals on steps to protect themselves, including placing security freezes on credit files with Equifax, Experian, and TransUnion, and obtaining free credit reports. The exact nature of the breach and the specific data compromised beyond what is implied by the protective measures are not detailed.

Breach: May 5, 2026California AG
BREACH

New York City Regional Center, LLC - Data Breach

New York City Regional Center, LLC (NYCRC) disclosed a cybersecurity incident on March 30, 2026. Due to Massachusetts law, specific details about the incident's nature cannot be provided. NYCRC is offering affected individuals two years of complimentary credit monitoring and fraud assistance services through Kroll. These services include single bureau credit monitoring, fraud consultation, and identity theft restoration. The notification also provides general information about consumer rights regarding credit reports and fraud alerts.

Breach: Mar 30, 2026California AG
BREACH

POLAM Federal Credit Union - Data Breach

POLAM Federal Credit Union disclosed a data security incident on May 20, 2025, where a former employee potentially accessed and exfiltrated a limited amount of documents without authorization. The investigation, completed on August 10, 2026, revealed that the affected files contained the full name of individuals. The credit union is offering complimentary single bureau credit monitoring and fraud assistance services through Cyberscout.

Breach: May 20, 2025California AG
BREACH

The Health Trust and its subsidiary, FASS - Data Breach

The Health Trust, a non-profit assisting governmental and non-governmental organizations, disclosed a data breach on May 26, 2025. Suspicious activity was first identified on May 26, 2025, leading to network security measures. Further suspicious activity on June 11, 2025, prompted the company to take its systems offline for investigation. The investigation revealed that an unknown actor gained access to certain Health Trust systems prior to March 26, 2025, and again between June 8, 2025, and June 11, 2025, accessing and/or copying information. The affected data, which was processed by their subsidiary FASS, included the recipient's name and other unspecified information. There is no evidence of actual or attempted fraud or identity theft. The Health Trust is offering complimentary credit monitoring services and has reported the event to law enforcement.

Breach: May 26, 2025California AG

BREACH

Quontic Bank Acquisition Corp. - Data Breach

Quontic Bank Acquisition Corp. disclosed a data breach on March 2, 2026, which occurred on May 28, 2026. The breach involved two former employees retaining certain customer records after their departure. While there is no indication of actual or attempted identity theft or fraud, the exposed information includes customer names and additional data specified as '[Extra1]'. The bank is working with authorities, reviewing its policies, and offering complimentary credit monitoring and identity restoration services through Experian for [Extra3] months.

Breach: Mar 2, 2026California AG

BREACH

Fiesta Insurance Franchise Corporation - Data Breach

Fiesta Insurance Franchise Corporation disclosed a data breach on June 9, 2025. The company is offering complimentary Experian IdentityWorks Credit 3B membership to affected individuals to help protect their identity. The membership includes access to credit reports, credit monitoring, identity restoration support, and identity theft insurance. The notification letter does not specify the exact date of the incident or the number of records affected, but it implies that personal information such as names, addresses, dates of birth, emails, and phone numbers may have been exposed.

Breach: Jun 9, 2025California AG
BREACH

Surplus Line Association of California - Data Breach

On or around April 14, 2026, the Surplus Line Association of California (SLA of California) detected suspicious activity in its network. An investigation, aided by cybersecurity specialists, revealed that unauthorized access and acquisition of certain files occurred on April 4, 2026. A third-party vendor's review on June 15, 2026, confirmed that personal information, potentially including first and last name and Social Security number, was compromised. SLA of California has notified relevant authorities and is offering complimentary identity theft protection services through Cyberscout.

Breach: Apr 4, 2026California AG
BREACH

YouLend US LLC - Data Breach

YouLend US LLC experienced a data privacy breach between June 5, 2026, and June 9, 2026, when unauthorized access to their computer network occurred. The investigation confirmed that certain files containing personal information, including Name, Date of Birth, and Social Security number, were acquired. The company has taken steps to secure its systems, reported the incident to law enforcement, and is offering 12 months of complimentary credit monitoring and identity protection services through Cyberscout.

Breach: Jun 5, 2026California AG

BREACH

Markel Insurance - Data Breach

Markel Insurance experienced a data security incident between March 17-18, 2026, where an unauthorized actor used social engineering to deceive two employees and gain access to a limited portion of Markel's systems. The company detected and blocked the activity, notified law enforcement, and engaged third-party security experts. An investigation determined that the unauthorized actor obtained the victim's name. Markel is offering two years of complimentary credit monitoring and identity restoration services through TransUnion.

Breach: Mar 17, 2026California AG

BREACH

AssetMark, Inc. - Data Breach

AssetMark, Inc., a wealth management platform, experienced a data breach on May 15, 2026, when an unauthorized user gained access to and downloaded files containing customer information using compromised employee login credentials. The company became aware of the incident on the same day and initiated an investigation. By May 18, 2026, it was determined that certain files contained personal information. AssetMark has secured its systems, reset credentials, engaged security professionals, increased monitoring, and implemented additional safeguards. They are offering 24 months of credit monitoring and identity theft prevention services to affected individuals.

Breach: May 15, 2026California AG

BREACH

AssuranceAmerica Managing General Agency, LLC - Data Breach

AssuranceAmerica Managing General Agency, LLC experienced a cybersecurity incident on March 16, 2026, where an unauthorized third party accessed their IT systems and copied data files. The company discovered the suspicious activity on March 17, 2026, and subsequently identified that personal information, including name, contact information, automobile insurance details, driver/vehicle information, claims data, driver's license number, Tax ID, and Social Security number, was compromised. AssuranceAmerica has implemented enhanced security measures, notified law enforcement, and is offering affected individuals 12 months of complimentary credit monitoring services.

Breach: Mar 16, 2026California AG

BREACH

Orrstown Bank - Data Breach

Orrstown Bank disclosed a data breach on June 11, 2026. No further details regarding the date of occurrence, discovery, number of records affected, specific data exposed, or the attack vector were provided in the available information.

Breach: Jun 11, 2026Maine AG
BREACH

the West Series of Lockton Companies, LLC - Data Breach

The West Series of Lockton Companies, LLC, an insurance brokerage firm providing employee benefit services to Dexcom, Inc., inadvertently disclosed an Excel file containing Dexcom employee personal information to three participants of a Request for Proposal (RFP) for family forming benefits. The file contained Social Security numbers, first names, last names, dates of birth, and potentially limited employee benefits election information. Access to the file was promptly revoked, and the RFP participants either did not access it or confirmed its deletion. Lockton is notifying affected individuals out of an abundance of caution and is offering a complimentary two-year membership to Experian IdentityWorks.

Breach: May 13, 2026California AG

BREACH

Caldwell Sutter Capital, Inc. - Data Breach

Caldwell Sutter Capital, Inc. disclosed a data breach on June 11, 2026. The nature of the breach, the date it occurred or was discovered, the number of records affected, and the specific types of data exposed are not detailed in the provided information.

BREACH

McAdam Financial Group - Data Breach

McAdam Financial Group disclosed a data breach on June 10, 2026. No further details regarding the date of occurrence, discovery, number of records affected, specific data exposed, or the attack vector were provided in the available information.

Breach: Jun 10, 2026Maine AG
BREACH

Towerpoint Wealth, LLC - Data Breach

Towerpoint Wealth, LLC experienced a cybersecurity incident on April 27, 2026, where an unauthorized party accessed and copied certain files. The investigation revealed that the affected files contained the minor's name and potentially their Social Security number and/or financial/investment account information. Towerpoint has implemented enhanced security measures, including multi-factor authentication and updated policies, and is offering 12 months of free cyber monitoring services through Cyberscout to affected individuals.

Breach: Apr 24, 2026California AG

BREACH

CNO Services, LLC - Data Breach

CNO Services, LLC disclosed a data breach on June 8, 2026. No further details regarding the date of occurrence, discovery, number of records affected, specific data exposed, or the attack vector were provided in the available information.

Breach: Jun 8, 2026Maine AG

BREACH

Plaza Home Mortgage, Inc. - Data Breach

Plaza Home Mortgage, Inc. experienced a security incident on or around February 17, 2026, when threat actors gained unauthorized access to one employee's computer and information systems. The investigation indicates that personal information, potentially including name, address, social security number, birth date, driver's license or other government identification, and mortgage loan application and servicing information, may have been obtained by an unauthorized party. The company has implemented additional security measures and is offering 12 months of credit monitoring and identity theft services through CyEx.

Breach: Feb 17, 2026California AG

BREACH

Mariner Wealth Advisors, LLC - Data Breach

Mariner Wealth Advisors, LLC disclosed a data breach on June 1, 2026. No further details regarding the date of occurrence, discovery, number of records affected, specific data exposed, or the attack vector were provided in the available information.

Breach: Jun 1, 2026Maine AG