Skip to content
Back to Blog
high severity June 11, 2026 · 4 min read

AssetMark, Inc. Data Breach Notice (Vermont Attorney General)

If you received a notice from AssetMark, Inc., here’s what the filing says was exposed, and what to do about it.

AssetMark, Inc. notified Vermont residents of a data breach in a filing reported to the Vermont Attorney General on June 11, 2026, and the notice lists social security numbers, government ID numbers among the information exposed.

AssetMark, Inc. Data Breach Notice (Vermont Attorney General)

The exposure of your Social Security number and government ID information cannot be undone. Once these details leave a company's systems, they remain usable for identity theft and fraud for the rest of your life. AssetMark, Inc. has now reported that the records of 1,643 people were included in an incident disclosed to the Vermont Attorney General on June 11, 2026.

This is the core reality of the filing. Social Security numbers do not expire, cannot be reissued on demand like a credit card, and retain their value to criminals indefinitely. Government ID numbers function in much the same way. The filing lists only these two categories of information. No passwords were exposed.

A Number That Cannot Be Changed

When a Social Security number appears in a breach filing, the risk does not fade with time. Criminals can use it to open accounts, file fraudulent tax returns, claim government benefits, or apply for loans in your name. These consequences can appear months or years later, long after the initial news of the breach has passed.

The same permanence applies to government ID numbers. Together, these two pieces of information allow someone to impersonate you across financial, tax, and benefits systems with a level of credibility that is difficult to dispute. The record does not state whether the data was copied and taken or simply viewed. In either case, the exposure has occurred.

What the 1,643 Figure Represents

The filing names exactly 1,643 individuals whose records were affected. This is not an estimate. It is the number AssetMark provided to regulators. The company is required to notify each of these people directly, usually by mail sent to the address it has on file.

If you have not received a letter from AssetMark, it is likely that your information was not part of this group. However, letters can go to outdated addresses. Anyone who has moved since the incident should contact AssetMark directly to confirm whether their records were included. The filing does not provide a separate incident date, so the letter itself remains the clearest indicator available.

Why This Exposure Matters More Than Most

Many data incidents involve information that can be replaced. A compromised password can be changed. A stolen credit card can be canceled. A Social Security number cannot. This single fact changes how you must approach protection. The risk is permanent, which means the defensive steps you take must also be permanent and ongoing.

The absence of passwords in the exposed data is genuine good news. You do not need to change any AssetMark password as a result of this incident. That particular vector is closed. The remaining risk centers entirely on identity theft made possible by the government identifiers now outside the company's control.

How Identity Thieves Use These Numbers Today

A Social Security number paired with a government ID allows a criminal to bypass many automated verification systems. They can attempt to open new bank accounts, credit cards, or utility services. They can file a tax return before you do and direct any refund to themselves. They can apply for government benefits or employment using your identity.

These attacks do not always happen immediately. Some criminals hold stolen identity data for months or years until an opportunity arises. This delayed risk is why monitoring must continue long after the initial notification.

What You Can Still Control

While you cannot change your Social Security number, you retain significant control over how it is used. Placing a freeze on your credit reports prevents new accounts from being opened in your name without your explicit permission. This step is free, reversible, and one of the most effective defenses available after this type of exposure.

Regular review of your tax transcripts, Social Security earnings statement, and Explanation of Benefits statements from any government programs can reveal fraudulent activity before it grows. Early detection remains your strongest ongoing protection.

The Limits of What the Filing Tells Us

The Vermont filing does not disclose how the incident occurred, whether the data was exfiltrated, or how long any unauthorized access lasted. These details are not available to the public. The record focuses solely on what was exposed and how many Vermont residents were named in the company's notification.

This narrow scope is typical of state breach filings. It provides the facts necessary for individuals to protect themselves but does not support conclusions about the company's security practices or response. The only information that matters for your next steps is what the filing actually lists: Social Security numbers and government ID numbers affecting 1,643 people.

Practical Steps That Address This Specific Exposure

  • Place a credit freeze with Equifax, Experian, and TransUnion. This stops new accounts from being opened in your name. It is the single most effective action after a Social Security number exposure.
  • Set up alerts with the IRS and your state tax authority. Notify them that you want to be contacted before any tax return is processed using your Social Security number.
  • Order your annual Social Security earnings statement. Check it for wages reported under your number that do not belong to you.
  • Review your credit reports every four months on a rotating schedule. Space your free weekly reports so you maintain continuous visibility without paying for monitoring.
  • Keep records of the breach notification. If identity theft occurs later, documentation that your number was exposed in this incident can help resolve disputes with creditors and government agencies.

The exposure of these permanent identifiers requires a shift in how you manage your identity. The risk will not disappear, but it can be managed through consistent, deliberate action. The filing has given you the information you need to begin that work now rather than after fraudulent activity appears.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on AssetMark, Inc..

  1. Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Report details & sourcing

Severity High includes at least one identifier that cannot be reissued
Disclosed June 11, 2026
Last reviewed July 22, 2026
Affected 1643
Data exposed Social Security Numbers, Government ID Numbers
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email