CSIDB logo
Incident

Kovack Financial, LLC

Incident posture

Attack window
Aug 2025
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-14 13:25

Linked entities

Victim
Kovack Financial, LLC
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2025
Discovered
Aug 2025
Disclosed
Aug 2026
Resolved
Pending

Summary

Kovack Financial, LLC, a Florida-based investment advisor and broker-dealer, discovered suspicious activity on its computer network and later determined that an unauthorized actor had accessed files containing personal information. The accessed data included Social Security numbers, financial account details, and driver's license numbers. After confirming the breach, the company began notifying affected individuals and provided twelve months of complimentary credit monitoring and identity restoration services through a third-party provider. A law firm is investigating the incident to assess whether adequate safeguards were in place and to explore potential legal claims on behalf of those impacted.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

Kovack Financial, LLC became aware of suspicious activity on its computer network on or around August 28 2025, according to a notice of security incident issued by the company. A subsequent investigation determined that an unauthorized actor had gained access to files within the company’s network between August 8 2025 and August 27 2025. On July 16 2026, Kovack Financial concluded that the accessed files contained personal information relating to affected individuals. The company began notifying those individuals by letter dated August 10 2026.

The information that may have been exposed in the breach included Social Security numbers, financial account numbers, and driver’s license numbers. As part of its response, Kovack Financial offered enrolled individuals twelve months of complimentary credit monitoring and identity restoration services through Cyberscout, a TransUnion company. The notification letters informed recipients of the nature of the data involved and the steps the company was taking to address the incident.

Individuals who received the breach notification face an increased risk of identity theft and fraud. Edelson Lechtzin LLP, a national class action law firm, is investigating whether Kovack Financial had adequate safeguards in place to prevent the breach and to protect the affected information. The firm is also examining a potential class action on behalf of those impacted to pursue compensation for harm arising from the breach. These legal considerations represent an additional impact of the incident beyond the immediate exposure of personal data.

Sources

Sources available to members: 1 source.

CSIDB