LPL providing credit monitoring, identity protection to investors exposed by data breach

LPL providing credit monitoring, identity protection to investors exposed by data breach
The firm remains tight-lipped about how many investors were affected.
NOV 14, 2018

LPL Financial is taking steps to safeguard financial advisers and their clients whose names, addresses, account numbers and Social Security numbers were exposed in a recent data breach. According to LPL spokesman Jeff Mochal, the broker-dealer is still investigating the matter but is providing affected investors with free credit monitoring and identity protection services. "We have notified our financial advisors of this incident, and will communicate by mail with impacted investors to provide them more information and the steps we are taking — as well as the services we are providing — to protect them," Mr. Mochal said in an emailed statement. He did not indicate how many investors or advisers were affected by the breach. (More: Voice commands, cybersecurity take center stage at T3) In an email to brokers, LPL president and CEO Dan Arnold said the firm has implemented heightened monitoring of the affected accounts for any fraudulent activity. "Protecting your investor is our top priority, and we deeply regret this unfortunate security incident and any potential disruption it may cause to your business," Mr. Arnold said in the email. Capital Forensics Inc., a company that provides data analytics to aid firms in litigation, regulatory, compliance and fraud matters, discovered Nov. 1 that an unauthorized person gained access to a third-party file-sharing system it uses. The person was able to access data files belonging to several of Capital Forensics' clients, including LPL. According to Mr. Arnold's message to brokers, all LPL data were immediately removed upon detecting the breach, and the firm notified regulators. A company spokesperson for Capital Forensics clarified in a statement that thebreach was limited to four hours and was mitigated within six hours of occurrence. The spokesperson added that Capital Forensics is working with outside legal and forensic experts on an ongoing investigation. The company also set up a call center so investors who were affected can get additional information. Without knowing more specifics about the breach, it's tough to determine whether LPL, Capital Forensics or both companies are vulnerable to enforcement actions, said Harley Lippman, CEO of Genesis10, a firm providing internal technology services and staffing for large financial institutions. As with the recent data breach at Voya Financial Advisers, which resulted in a $1 million settlement with the Securities and Exchange Commission, the LPL breach shows how the third parties it deals with can create vulnerabilities for financial institutions. (More: SEC adds cybersecurity bite to its bark) Both the Financial Industry Regulatory Authority Inc. and the Securities and Exchange Commission declined to comment on the matter. Mr. Lippman believes firms like LPL need to do more rigorous penetration testing to identify where data can be accessed on their third-party systems. "A cybersecurity company should try to break into the system, try every which way to hack into it and see where the weaknesses are," he said. "That's basic, but not every cybersecurity company does that."

Latest News

SEC kills 'gag rule' that silenced thousands of settling defendants for over 50 years
SEC kills 'gag rule' that silenced thousands of settling defendants for over 50 years

ASA reacts as regulator drops no-deny policy, freeing firms and individuals to publicly dispute allegations after reaching settlements.

Washington state regulators claim advisor was running Ponzi-like fund
Washington state regulators claim advisor was running Ponzi-like fund

Joel Frank allegedly sold more than $39 million worth of investments in the Equilus Funds to more than 90 investors,

Bipartisan bill aims to take down 401(k) charitable giving hurdle
Bipartisan bill aims to take down 401(k) charitable giving hurdle

The Charity Parity Act would eliminate a costly IRA rollover requirement that blocks direct charitable transfers from workplace retirement plans.

Trump drops $10 billion IRS lawsuit as $1.7B settlement fund takes shape
Trump drops $10 billion IRS lawsuit as $1.7B settlement fund takes shape

A last-minute court filing ends a case against the federal tax-collecting agency that had drawn unprecedented conflict-of-interest questions from Democratic critics.

You Can’t Spell Advisor without AI
You Can’t Spell Advisor without AI

Advisors discuss their use of AI now and how it will change going forward

SPONSORED Beyond wealth management: Why the future of advice is becoming more human

As technical expertise becomes increasingly commoditized, advisors who can integrate strategy, relationships, and specialized expertise into a cohesive client experience will define the next era of wealth management

SPONSORED Durability over scale: What actually defines a great advisory firm

Growth may get the headlines, but in my experience, longevity is earned through structure, culture, and discipline