Skip to content

Cetera Financial Group

Disclosed Sep 1, 20215 years ago4,388 affectedSettled

Official notice

Email account takeovers exposed 4,388 clients' data; SEC sanctions

The SEC found that cloud email accounts of more than 60 Cetera employees were taken over for over three years, exposing personal information of at least 4,388 clients. Cetera, Cambridge Investment Research and KMS Financial were sanctioned USD 750,000 combined.

What is known

People affected4,388 (as reported by the organization)
DisclosedSep 1, 2021
HappenedNov 29, 2021
AttackPhishing
Data exposedNames, Social Security numbers, Financial
SectorFinance · US
StatusSettled
Lawsuit or fineSEC sanctions, USD 750,000 combined with Cambridge and KMS (Aug 2021)

Sources

Notices filed

WhereFiledPeople
ResearchtotalSep 1, 20214,388
Indiana AGresidents of INJun 9, 20224

Other breaches at Cetera Financial Group

BreachAffected
Disclosed Mar 25, 2026Mar 256 months ago43K
Disclosed Aug 21, 2020Aug 21, 20206 years agoHacking109K
Disclosed Jun 6, 2019Jun 6, 20197 years ago1,662
History of this record
  • 2026-09-25 · source_type: press to official · backfill source
  • 2026-09-25 · source_url: https://techcrunch.com/2021/09/01/sec-fines-brokerage-firms-over-email-hacks-that-exposed-client-data/ to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/2022-DB-Year-to-Date-Report-for-Website.pdf · backfill source
  • 2026-09-25 · verified_by: empty to in-ag · backfill source
  • 2026-09-25 · verified: 0 to 1 · backfill source
  • 2026-09-25 · occurred: empty to 2021-11-29 · backfill source
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about Cetera Financial Group

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.