Were you recently affected by a data breach?

M Advisory Group Data Breach

M Advisory Group recently disclosed that an unauthorized third party compromised its email environment, potentially exposing names, health information, and Social Security numbers. Affected individuals are being offered free credit monitoring and should know their legal options.

M Advisory Group
Date of Breach: The unauthorized third-party compromise of the company's email environment was discovered on October 20, 2025.
CAU logo

Who was affected:

Clients of M Advisory Group

Impacted Data:

Names, medical or health information, Social Security numbers/ITINs

M Advisory Group, a financial advisory firm, recently notified individuals that an unauthorized third party compromised its email environment, potentially exposing sensitive personal and health-related information. The company says it has since secured its systems and engaged outside experts to investigate, but the incident nonetheless raises real concerns for anyone whose information was contained in the compromised email account. Financial advisory firms routinely handle highly sensitive client data, including health and financial records, and are expected to take reasonable steps to protect it from unauthorized access.

M Advisory Group’s Data Breach Investigation

According to M Advisory Group’s notification letter, the company discovered an unauthorized third-party compromise of its email environment on October 20, 2025. Upon discovering the intrusion, the company says it secured and remediated the compromise, engaged additional third-party cybersecurity experts, and commenced a digital forensic investigation to determine the scope of the incident. That investigation ultimately determined that an email account contained personal information belonging to certain individuals, and that this personal information could have been compromised as a result of the unauthorized access. The letter does not specify how the unauthorized party first gained access to the email account, whether through a phishing attack, credential compromise, or another method, and does not disclose how long the unauthorized access may have persisted before it was detected in October 2025.

Email-based compromises like this one are among the most common vectors for data breaches across industries, and they are especially consequential for financial advisory firms because client-facing email communications frequently contain highly sensitive information exchanged in the ordinary course of business, including Social Security numbers, account details, and medical or health information related to insurance, estate planning, or benefits matters. Once an attacker gains access to a single email account, they often have visibility into months or years of historical correspondence, meaning the scope of exposed information can be considerably broader than what might be exposed in a single-transaction breach.

The combination of data M Advisory Group says may have been involved, names together with medical or health information and Social Security numbers, is considered particularly sensitive under most state and federal breach notification frameworks. Health information combined with a Social Security number can be exploited not only for conventional identity theft and fraudulent credit applications, but also for medical identity theft and insurance fraud, both of which can be more difficult for victims to detect and unwind than ordinary financial fraud. This is part of why regulatory frameworks, including HIPAA where applicable and state data breach laws generally, treat this type of combined exposure with heightened notification and remediation obligations.

In response to the incident, M Advisory Group is offering affected individuals Single Bureau Credit Monitoring, a Single Bureau Credit Report, and a Single Bureau Credit Score through Cyberscout, a TransUnion company, along with proactive fraud assistance. While the company states it has no evidence at this time that any personal information has actually been misused, it is common for the effects of an email-based data compromise to surface well after the fact, which is why continued vigilance from affected individuals remains important even in the absence of confirmed misuse so far.

When Did This Breach Occur?

M Advisory Group discovered the unauthorized compromise of its email environment on October 20, 2025. The company’s notification letter, dated July 2, 2026, does not specify exactly when the unauthorized access to the email account began, only when it was discovered and remediated.

What Information Was Breached?

According to M Advisory Group’s notification letter, the digital forensic investigation determined that the compromised email account contained personal information that could include an individual’s name, medical or health information, and Social Security number or Individual Taxpayer Identification Number (ITIN). The company states it has no evidence that this information has been misused as a result of the incident.

What You Can Do

If you received a notice from M Advisory Group, consider taking the following steps to help protect yourself:

  • Enroll in the complimentary Single Bureau Credit Monitoring services offered through Cyberscout in your notification letter.
  • Regularly review your credit reports from Equifax, Experian, and TransUnion for unfamiliar accounts or inquiries.
  • Consider placing a security freeze or fraud alert on your credit file with the major credit bureaus.
  • Review any health insurance and medical billing statements for services you did not receive, which can be a sign of medical identity theft.
  • Consider obtaining an Identity Protection PIN from the IRS to help prevent tax-related identity theft.

File a Data Breach Lawsuit Against M Advisory Group

If your personal information was exposed as a result of this incident, you may have legal options available to you. Companies that collect and store sensitive personal, financial, and health-related data have a responsibility to protect it, and when that data is compromised, affected individuals may be entitled to compensation for the risks and burdens they now face.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Not publicly disclosed; reported to the Texas Attorney General on August 22, 2025.
Date of Breach: Not publicly disclosed; reported to the Texas Attorney General on August 22, 2025.
Date of Breach: Not publicly disclosed; reported to the Texas Attorney General on August 22, 2025.
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.