Skip to main content
Back to overview
Medium

LPL Financial Holdings Data Breach Impacts Over 1,500 Customers

LPL Financial Holdings reported a data breach that occurred on November 10, 2025.

Key points

  • Breach occurred on November 10, 2025.
  • Caused by malware distributed via phishing messages.
  • Compromised devices of affiliated financial advisors.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Phishing Social Engineering

Malware, Social, Hacking activity

03

Potential impact

Potential fraud or account takeover risk

Confidentiality

Published
Nov 10, 2025
Updated
Jun 25, 2026
Confidence
Medium
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Social, Hacking activity

Watch phishing, executive impersonation and account-takeover exposure.

  • Source type: supplier or third-party involvement

Business impact

Potential fraud or account takeover risk
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

LplData DisclosureImpacts OverCustomers LPL Financial HoldingsCausedCompromised

Quick context

Questions about this signal

What happened in this signal?

LPL Financial Holdings reported a data breach that occurred on November 10, 2025. The incident was triggered by malware distributed through phishing messages, compromising a limited number of devices belonging to affiliated financial advisors. This unauthorized access allowed an unidentified third party to perform unauthorized securities transactions and financial transfers involving the accounts of 1,581 individuals.

When was this signal reported?

Shadow Tier lists Nov 10, 2025 as the signal date.

Which organization is connected to this signal?

Lpl is the organization connected to this public signal.

Explore Lpl
Which attack pattern is relevant?

This signal is connected to phishing and social-engineering intelligence based on its reported incident context.

Explore phishing and social-engineering intelligence