Tr?id=566623520170033&ev=PageView&noscript=1

Ä¢¹½´«Ã½

Massachusetts Regulators Fine Fidelity $1.25 Million Over Data Breach Allegations

Posted on June 1st, 2026 at 11:49 AM
Massachusetts Regulators Fine Fidelity $1.25 Million Over Data Breach Allegations

From the desk of Jim Eccleston at Ä¢¹½´«Ã½

Massachusetts regulators has fined Fidelity Brokerage Services $1.25 million over allegations that the firm failed to adequately protect customer information and properly notify all affected individuals following a significant data breach.

According to reporting by AdvisorHub, the parties reached a settlement pursuant to a consent order. That consent order reveals that Fidelity's cybersecurity failures allowed an unauthorized third party to access sensitive information belonging to approximately 77,000 customers. At least 2,768 Massachusetts residents were affected by the breach.

Fidelity accepted the consent order without admitting or denying any wrongdoing.

The consent order stated that, over a three-day period in August 2024, an unidentified third party accessed and obtained images containing highly sensitive customer information. The compromised records reportedly included Social Security numbers, financial account information, active credit card numbers, medical information, passports, and driver's license data.

Regulators also alleged that the compromised documents included personal information belonging to beneficiaries, relatives, and minors connected to customer accounts. According to AdvisorHub, although Fidelity notified certain impacted customers, regulators claimed the firm failed to notify all affected individuals whose information appeared in the exposed documents.

According to the consent order, the unauthorized access stemmed from a vulnerability in Fidelity's online access controls. Regulators alleged that the third party manipulated a ten-digit "Image ID" displayed within the browser while viewing customer documents, allowing access to records associated with other users, as reported by AdvisorHub.

The firm declined to comment on whether the breach affected customers affiliated with registered investment advisory firms or whether the incident remained limited to self-directed brokerage accounts.

According to AdvisorHub, this enforcement action is one of several as multiple brokerage firms continue to face scrutiny over cybersecurity incidents and client data breaches.

Ä¢¹½´«Ã½ LLC represents investors and financial advisors nationwide in securities, employment, transition, regulatory, and disciplinary matters.

Tags: eccleston, eccleston law, data breach, financial regulation, cybersecurity law, data privacy, regulatory fines

Return to Archive

TESTIMONIALS

Previous
Next
Quotes Bigger

Fantastic news!!!!  Your professionalism, support and expertise were greatly appreciated.  You made a difficult situation much more bearable.

Marci M.

LATEST NEWS AND ARTICLES

1786636784 Law
August 13, 2026
FINRA Orders Centaurus Financial to Pay $1.1 Million Over Variable Annuity Supervision Failures

The Financial Industry Regulatory Authority (FINRA) has ordered Centaurus Financial Inc.

1786553985 Law
August 12, 2026
Proposed FINRA Enforcement Reforms Draw Mixed Reactions From Industry Participants

A new report recommending changes to the Financial Industry Regulatory Authority's (FINRA) enforcement program has generated mixed reactions from investor advocates, securities attorneys and industry professionals, according to ThinkAdvisor.

1786394861 Law
August 10, 2026
FINRA Fines RBC Capital Markets $275,000 Over Anti-Money Laundering Compliance Deficiencies

The Financial Industry Regulatory Authority (FINRA) has censured and fined RBC Capital Markets $275,000 after determining that the firm failed to establish and implement reasonable anti-money laundering (AML) policies and procedures.