Skip to content
Back to Blog
critical severity June 12, 2026 · 4 min read

AssetMark, Inc. Data Breach Notice (Massachusetts Attorney General)

If you received a notice from AssetMark, Inc., here’s what the filing says was exposed, and what to do about it.

AssetMark, Inc. notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on June 12, 2026, and the notice lists social security numbers and financial account numbers among the information exposed.

AssetMark, Inc. Data Breach Notice (Massachusetts Attorney General)

The exposure of your Social Security number and financial account numbers in the AssetMark breach means those two pieces of information are now outside the company's control. A Social Security number cannot be replaced the way a credit card or password can. Once it is loose, it remains a permanent key that can be used to open accounts, file fraudulent tax returns, or claim benefits in your name for years to come.

AssetMark, Inc. filed notice with the Massachusetts Attorney General on June 12, 2026, stating that the records of 15,085 people were involved. The filing lists Social Security numbers and financial account numbers as the categories exposed. No other categories appear in the record.

No Passwords or Login Credentials Were Exposed

This is important. The notice does not list passwords, and the record contains no indication that login credentials were taken. You do not need to change your AssetMark password because of this incident. That particular risk does not exist here.

What the Two Exposed Categories Actually Enable

A Social Security number paired with a financial account number gives a criminal the foundation for multiple forms of identity theft. With your SSN, someone can:

  • Apply for new credit in your name
  • File a fraudulent tax return to claim your refund
  • Open bank accounts or brokerage accounts
  • Apply for government benefits

The financial account numbers add concrete details that make these applications more convincing. Because neither piece of information expires, the exposure does not lose its value over time the way stolen passwords often do.

The Letter Is the Only Reliable Way to Know If You Are Affected

AssetMark is required to notify affected Massachusetts residents directly, usually by mail. If you have not received a letter, it is likely your records were not part of the 15,085 included in this filing. However, if you have moved since the incident occurred, the letter may have gone to an old address. In that case, contact AssetMark directly to confirm whether your information was involved.

Social Security Numbers Cannot Be Changed

Unlike a credit card or driver's license, a Social Security number is issued once. The federal government does not provide replacements simply because it has been exposed. This is why regulators treat SSN breaches differently from other types of data loss. The number you were given at birth is the same one you will carry for the rest of your life, and now it is in unknown hands.

Financial Account Numbers Can Be Frozen or Monitored

While the account numbers themselves cannot be "canceled" in the same way as a physical card, you retain several practical controls. You can place a freeze on your credit reports so new accounts cannot be opened without your explicit permission. You can also set up transaction alerts on every bank and brokerage account linked to the exposed numbers so you are notified immediately of any unusual activity.

The Gap Between Incident and Notification

The filing is dated June 12, 2026, but does not state when the incident itself occurred. Without an incident date, it is not possible to calculate how long the information may have been accessible. The record is silent on the initial access method, whether the data was encrypted, and how long any unauthorized party may have had access. These details remain undisclosed.

What This Means for Identity Theft Risk Going Forward

The combination of a permanent identifier and financial details creates a long-term risk rather than a short-term one. Criminals do not need to use the information immediately. They can hold it for months or years and wait for the right opportunity. This is why monitoring and credit freezes are more useful here than one-time password changes.

Placing a Credit Freeze Is the Single Most Effective Step

A credit freeze stops new credit accounts from being opened in your name. It does not affect your existing accounts or your credit score. You can still use your current cards and loans normally. Freezes must be placed separately with each of the three major credit bureaus, and you can lift them temporarily when you need to apply for new credit.

Ongoing Monitoring Beats One-Time Checks

Because the exposed data does not expire, a single credit report pull is not enough. Place your credit on continuous monitoring that alerts you to any new inquiries or accounts. Review your annual tax transcript from the IRS each year to ensure no one has filed returns using your SSN. Check statements from every financial institution tied to the exposed account numbers.

The filing from AssetMark establishes that 15,085 individuals had their Social Security numbers and financial account numbers exposed. It does not establish how the incident occurred or whether the data was protected by encryption. What matters most to you is that two high-value, non-expiring pieces of information are now outside the company's protection.

Focus your effort on the controls you still hold: credit freezes, transaction monitoring, and regular review of tax and financial records. These steps directly address the specific categories named in the June 12, 2026 filing rather than generic breach advice. The letter you may or may not have received remains the clearest signal of whether this particular record set includes you.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on AssetMark, Inc..

  1. Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
  2. Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Report details & sourcing

Severity Critical identifiers that cannot be reissued, alongside documents or accounts that can be misused now
Disclosed June 12, 2026
Last reviewed July 22, 2026
Affected 15085
Data exposed Social Security numbersFinancial account numbers
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email