AssetMark, Inc. Data Breach Exposes Social Security Numbers and Government ID Numbers

Finance data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: June 2026

What Happened in the AssetMark Data Breach?

AssetMark, Inc. recently disclosed a data breach that compromised sensitive personal information belonging to individuals connected to its financial services business. The company filed a formal notification with the Vermont Attorney General’s office in June 2026. This filing confirmed that unauthorized parties gained access to protected personal data.

According to the filing, the exposed information includes Social Security numbers and government ID numbers. These are two of the most sensitive categories of personal data that a financial firm can hold. As a result, this breach carries serious identity theft implications for those affected.

The public notification does not detail the exact method attackers used to gain access. However, regulatory filings of this type typically follow an internal security review or forensic investigation. AssetMark apparently conducted this type of review before determining which data elements were involved and notifying regulators.

Because AssetMark operates as an investment management and technology platform serving financial advisors, any breach touching its systems can ripple across many client relationships. The company’s disclosure to Vermont regulators indicates it has already completed at least a preliminary assessment. Further details may emerge as additional state filings or notices become available.

Who was affected?

The individuals affected by this breach likely include clients whose financial accounts or advisory relationships connect to AssetMark’s platform. Because AssetMark works with independent financial advisors across the country, its systems may hold data belonging to a wide range of investors. This could include retirement account holders, individual investors, and other consumers who work with advisors using AssetMark’s services.

AssetMark has not publicly disclosed the total number of individuals affected by this incident. In addition, the source filing does not specify whether the breach reached employees, contractors, or only clients. Given the nature of the exposed data, however, it appears the incident primarily touched individuals whose financial and identity records AssetMark stores as part of its advisory and custodial functions.

Because Social Security numbers and government ID numbers were involved, minors with custodial investment accounts could also be part of the affected population. This is a common risk in financial services breaches, since account holders sometimes include beneficiaries who are not yet adults. Anyone unsure of their status should reach out directly to AssetMark or their financial advisor for confirmation.

What Information Was Potentially Exposed?

The Vermont Attorney General filing specifically names two categories of exposed data. Both are highly sensitive and commonly targeted by identity thieves. Understanding exactly what was compromised helps affected individuals gauge their personal risk level.

  • Social Security numbers
  • Government-issued identification numbers

Exposure of Social Security numbers creates a significant and lasting risk. Unlike a password, a Social Security number cannot simply be changed after a breach. As a result, criminals can use stolen numbers for years to open fraudulent credit accounts, file false tax returns, or apply for loans in a victim’s name.

Government ID numbers, such as driver’s license or state identification numbers, add another layer of risk. Fraudsters often combine these numbers with a Social Security number to create a more convincing false identity. This means affected individuals face a heightened chance of both financial fraud and broader identity theft schemes, including fraudulent account openings and government benefits fraud.

What is the company doing?

AssetMark responded to the incident by filing an official breach notification with the Vermont Attorney General. This step reflects the company’s legal obligation to report breaches involving residents’ personal information. Filing this notice also signals that AssetMark has identified the specific categories of data involved and is working through its required disclosure process.

Beyond the regulatory filing, companies handling this type of incident typically also notify affected individuals directly, offer credit monitoring or identity protection services, and review internal security controls. The Vermont filing summary reviewed for this article does not specify whether AssetMark is offering these services. Individuals who believe they may be affected should watch for a direct notification letter from AssetMark that will likely include specific remediation offers and instructions.

In many similar cases, financial firms also engage outside cybersecurity firms to strengthen defenses after a breach. Whether AssetMark has taken this step has not been publicly confirmed. Affected individuals should stay alert for updates as the company continues its response.

What Should Affected Individuals Do?

Monitor Your Credit Reports Closely

Anyone who receives a notice from AssetMark should immediately begin checking their credit reports. You can request free reports from all three major credit bureaus and review them for unfamiliar accounts or inquiries. Doing this regularly makes it far easier to catch fraudulent activity early.

In addition, consider spacing out your free reports throughout the year so you have ongoing visibility rather than a single check. Because Social Security numbers do not expire or change, this vigilance should continue well beyond the first few months after the breach notice arrives.

Place a Fraud Alert or Credit Freeze

Given that Social Security numbers and government ID numbers were exposed, placing a credit freeze is one of the strongest protective steps available. A freeze blocks lenders from accessing your credit file, which in turn prevents most attempts to open new accounts in your name. You can request a freeze directly with each of the three credit bureaus at no cost.

Alternatively, a fraud alert offers a lighter-touch option that requires creditors to verify your identity before extending credit. This is a reasonable choice if you expect to apply for credit soon and want to avoid the extra steps involved in lifting a freeze. Either option significantly reduces the risk that stolen data leads to new fraudulent accounts.

Watch for Phishing and Scam Attempts

Following a data breach, criminals often use stolen information to craft convincing phishing emails, texts, or phone calls. Because your name and identifying numbers may now be in the wrong hands, be cautious of any message claiming to be from AssetMark or your financial advisor. Never click links or share information in response to unsolicited requests.

Instead, verify any communication by contacting AssetMark or your advisor directly through a known phone number or official website. This simple habit prevents scammers from tricking you into revealing additional personal or financial details. Staying skeptical of urgent requests for information is one of the best defenses against follow-up scams.

Review Financial and Investment Accounts Regularly

Because this breach touched a financial services provider, it’s especially important to review your investment and bank account statements closely. Look for unauthorized transactions, unexpected withdrawals, or unfamiliar changes to account settings. Report anything suspicious to your financial institution immediately.

Furthermore, consider setting up account alerts that notify you of new logins, password changes, or transactions above a certain threshold. This proactive step gives you a faster way to catch fraud before it escalates. Regular account review, combined with credit monitoring, offers layered protection against the misuse of your stolen data.

Consult a Data Breach Attorney

If you received a notice from AssetMark, it may be worth speaking with an attorney who focuses on data breach cases. An attorney can help you understand whether you qualify for compensation or a potential class action related to this incident. Many offer free consultations, so there is little downside to exploring your options.

Because laws around data breach liability continue to evolve, an experienced attorney can also explain your specific rights under Vermont and federal law. This is particularly useful if you experience actual financial harm connected to the exposed Social Security or government ID numbers. Getting informed early can help you act quickly if you decide to pursue a claim.



More Information

Official data breach notification from Oregon Department of Justice

Official data breach notification from Vermont Attorney General

Related Data Breaches

See the latest data breaches we're tracking →