Ladenburg Thalmann & Co. Inc., a securities broker-dealer and investment banking firm, is notifying clients that an email phishing incident exposed their Social Security numbers, government ID numbers, and financial account information.
Ladenburg Thalmann & Co. Inc., a Miami-based securities broker-dealer and investment banking firm, has begun notifying clients of a data breach stemming from an email phishing incident, according to regulatory filings made with Massachusetts and Vermont. Securities through Ladenburg Thalmann & Co. Inc. and advisory services through its affiliate, Ladenburg Thalmann Asset Management, an SEC-registered investment advisor, may both be implicated. Massachusetts and Vermont regulators were notified the same day, September 24, 2026. Ladenburg’s public filings do not disclose when the phishing incident occurred or when it was discovered.
Source: Massachusetts OCABR annual data breach report, row 2026-1617, filed 09/24/2026 (63 Massachusetts residents); Vermont Attorney General security breach notices, filed 09/24/2026 (5 Vermont residents).
What Information Was Exposed
Ladenburg’s consumer notice letter uses a merge-field template that does not specify the exact information involved in the version reviewed for this post. Its regulatory filings, however, are specific: the Massachusetts filing flags Social Security numbers, financial account information, and driver’s license numbers, while the Vermont filing itemizes Social Security numbers, government ID numbers, financial account codes, and credit or debit card information.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.
A Phishing Incident at a Securities Firm
Ladenburg’s letter describes the incident as “an email phishing incident” and states the firm is “reminding employees to be on the look out for suspicious emails” and implementing additional safeguards. Phishing attacks that succeed against financial services employees are particularly concerning because of the volume and sensitivity of client financial data those employees typically have access to — brokerage account numbers, Social Security numbers, and other data needed to manage securities accounts and investment advisory relationships.
Why This Matters
The combination of Social Security numbers, government ID numbers, financial account information, and payment card data is a serious exposure for any client. For clients of a broker-dealer and investment advisory firm specifically, there’s an added concern: this kind of information could potentially be used not just for identity theft, but to attempt fraudulent transfers or unauthorized transactions within brokerage or investment accounts.
What You Can Do Now
- Enroll in the complimentary 2-year Kroll Identity Monitoring membership offered in Ladenburg’s notice letter, which includes credit monitoring, fraud consultation, and identity theft restoration
- Place a fraud alert or credit freeze with the three major credit bureaus, given that Social Security numbers were confirmed exposed
- Contact Ladenburg Thalmann directly to confirm no unauthorized activity has occurred in your brokerage or advisory account
- Monitor your financial account statements closely for unauthorized activity
- Contact us for a free case review if you received a notice letter from Ladenburg Thalmann
Do You Have Legal Options?
Broker-dealers and investment advisory firms have a legal duty to secure the Social Security numbers and financial account information they hold for clients, including training employees to resist phishing attacks. If you received a notice letter from Ladenburg Thalmann, you may have legal options.
If you received a data breach notice from Ladenburg Thalmann, contact Emery | Reddy today for a free case review.
FAQ
What information was exposed in the Ladenburg Thalmann breach?
Regulatory filings confirm Social Security numbers, government ID numbers, financial account information, and payment card information were involved for at least some affected clients.
How did the breach happen?
Ladenburg’s notice letter describes it as an email phishing incident. The company has not publicly disclosed further details about how the phishing attack succeeded or what systems were accessed as a result.
How many people are affected?
Ladenburg has not released a national total. State filings confirm 63 Massachusetts residents and 5 Vermont residents, which are state subsets of what may be a larger breach given that Ladenburg Thalmann operates as a national broker-dealer.
When did this happen?
Ladenburg’s public filings do not disclose when the phishing incident occurred or when it was discovered.
Do I have a legal claim?
Broker-dealers and investment advisory firms have a legal duty to protect the Social Security numbers and financial account information they hold for clients. If you received a notice letter from Ladenburg Thalmann, contact the Data Breach Attorneys at Emery | Reddy Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.