AssetMark, Inc. Data Breach Notice (Vermont Attorney General)
If you received a notice from AssetMark, Inc., here’s what the filing says was exposed, and what to do about it.
AssetMark, Inc. notified Vermont residents of a data breach in a filing reported to the Vermont Attorney General on June 11, 2026, and the notice lists social security numbers, government ID numbers among the information exposed.
The exposure of your Social Security number and government ID information cannot be undone. Once these details leave a company's systems, they remain usable for identity theft and fraud for the rest of your life. AssetMark, Inc. has now reported that the records of 1,643 people were included in an incident disclosed to the Vermont Attorney General on June 11, 2026.
This is the core reality of the filing. Social Security numbers do not expire, cannot be reissued on demand like a credit card, and retain their value to criminals indefinitely. Government ID numbers function in much the same way. The filing lists only these two categories of information. No passwords were exposed.
A Number That Cannot Be Changed
When a Social Security number appears in a breach filing, the risk does not fade with time. Criminals can use it to open accounts, file fraudulent tax returns, claim government benefits, or apply for loans in your name. These consequences can appear months or years later, long after the initial news of the breach has passed.
The same permanence applies to government ID numbers. Together, these two pieces of information allow someone to impersonate you across financial, tax, and benefits systems with a level of credibility that is difficult to dispute. The record does not state whether the data was copied and taken or simply viewed. In either case, the exposure has occurred.
What the 1,643 Figure Represents
The filing names exactly 1,643 individuals whose records were affected. This is not an estimate. It is the number AssetMark provided to regulators. The company is required to notify each of these people directly, usually by mail sent to the address it has on file.
If you have not received a letter from AssetMark, it is likely that your information was not part of this group. However, letters can go to outdated addresses. Anyone who has moved since the incident should contact AssetMark directly to confirm whether their records were included. The filing does not provide a separate incident date, so the letter itself remains the clearest indicator available.
Why This Exposure Matters More Than Most
Many data incidents involve information that can be replaced. A compromised password can be changed. A stolen credit card can be canceled. A Social Security number cannot. This single fact changes how you must approach protection. The risk is permanent, which means the defensive steps you take must also be permanent and ongoing.
The absence of passwords in the exposed data is genuine good news. You do not need to change any AssetMark password as a result of this incident. That particular vector is closed. The remaining risk centers entirely on identity theft made possible by the government identifiers now outside the company's control.
How Identity Thieves Use These Numbers Today
A Social Security number paired with a government ID allows a criminal to bypass many automated verification systems. They can attempt to open new bank accounts, credit cards, or utility services. They can file a tax return before you do and direct any refund to themselves. They can apply for government benefits or employment using your identity.
These attacks do not always happen immediately. Some criminals hold stolen identity data for months or years until an opportunity arises. This delayed risk is why monitoring must continue long after the initial notification.
What You Can Still Control
While you cannot change your Social Security number, you retain significant control over how it is used. Placing a freeze on your credit reports prevents new accounts from being opened in your name without your explicit permission. This step is free, reversible, and one of the most effective defenses available after this type of exposure.
Regular review of your tax transcripts, Social Security earnings statement, and Explanation of Benefits statements from any government programs can reveal fraudulent activity before it grows. Early detection remains your strongest ongoing protection.
The Limits of What the Filing Tells Us
The Vermont filing does not disclose how the incident occurred, whether the data was exfiltrated, or how long any unauthorized access lasted. These details are not available to the public. The record focuses solely on what was exposed and how many Vermont residents were named in the company's notification.
This narrow scope is typical of state breach filings. It provides the facts necessary for individuals to protect themselves but does not support conclusions about the company's security practices or response. The only information that matters for your next steps is what the filing actually lists: Social Security numbers and government ID numbers affecting 1,643 people.
Practical Steps That Address This Specific Exposure
- Place a credit freeze with Equifax, Experian, and TransUnion. This stops new accounts from being opened in your name. It is the single most effective action after a Social Security number exposure.
- Set up alerts with the IRS and your state tax authority. Notify them that you want to be contacted before any tax return is processed using your Social Security number.
- Order your annual Social Security earnings statement. Check it for wages reported under your number that do not belong to you.
- Review your credit reports every four months on a rotating schedule. Space your free weekly reports so you maintain continuous visibility without paying for monitoring.
- Keep records of the breach notification. If identity theft occurs later, documentation that your number was exposed in this incident can help resolve disputes with creditors and government agencies.
The exposure of these permanent identifiers requires a shift in how you manage your identity. The risk will not disappear, but it can be managed through consistent, deliberate action. The filing has given you the information you need to begin that work now rather than after fraudulent activity appears.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on AssetMark, Inc..
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
el-group Listed by Inc Ransom Ransomware Group
el-group was listed on the Inc Ransom ransomware leak site. The group claims to have stolen internal…
Victory Personal Care, Inc Listed by Nightspire Ransomware Group
Victory Personal Care, Inc was listed on the Nightspire ransomware leak site. The group claims to ha…
Victory Personal Care, Inc Listed by nightspire Ransomware Group
Data is not available now.…