Subscribe To Our Newsletter

This field is for validation purposes and should be left unchanged.

OneDigital Investment Advisors Data Breach

A data breach at OneDigital Investment Advisors LLC, caused by compromised third-party platforms, exposed sensitive personal data including Social Security numbers. Discovered in December 2025, the incident affected over 28,000 people. Impacted individuals may have legal options to seek compensation and protect their identities.

OneDigital Investment Advisors
Date of Breach: August 12 to August 18, 2025
CAU logo

Who was affected:

Clients of OneDigital Investment Advisors

Impacted Data:

Full names

Social Security numbers

OneDigital Investment Advisors LLC disclosed a data breach tied to third-party platforms Salesforce and Drift, exposing sensitive client data. The incident, discovered in December 2025, affected over 28,000 individuals. If your information was involved, you may have legal options to pursue compensation and protect your identity.

OneDigital Investment Advisors LLC’s Data Breach Investigation

OneDigital Investment Advisors LLC, a financial services firm, reported a data breach stemming not from its internal systems, but from third-party vendors used to manage client data. The breach highlights growing cybersecurity risks associated with external service providers, particularly those handling sensitive customer information.

According to the company, the breach occurred between August 12 and August 18, 2025, when unauthorized access was gained to customer data stored within Salesforce systems through a compromised Drift application. Drift, an online chat platform integrated into OneDigital’s customer relationship management (CRM) environment, had previously been managed by Salesloft. This interconnected system created a pathway for attackers to access stored personal data.

OneDigital became aware of the issue on December 22, 2025, after being alerted to suspicious activity. Upon discovery, the company acted quickly, launching an investigation with the assistance of third-party cybersecurity experts. Their forensic analysis confirmed that unauthorized actors accessed and potentially extracted sensitive personal information during the breach window.

While OneDigital stated there was no evidence its own internal systems were directly compromised, the exposure through third-party vendors raises serious concerns about vendor risk management and data protection practices. Companies are still responsible for safeguarding consumer data—even when that data is handled by outside providers.

Following the investigation, OneDigital conducted a detailed review of the impacted data to determine exactly whose information was exposed. The breach ultimately affected 28,414 individuals, including 73 Maine residents.

In response, the company implemented enhanced security protocols and additional employee training to mitigate future risks. It also began notifying affected individuals and offering support services to help protect against identity theft.

This incident underscores a critical issue: even when companies outsource services, consumers still bear the consequences when security fails. If you were notified of this breach, understanding your rights is an important next step.

When Did This Breach Occur?

The OneDigital Investment Advisors LLC data breach occurred between August 12, 2025, and August 18, 2025.

The breach was discovered on December 22, 2025, several months after the unauthorized access took place.

What Information Was Breached?

The data breach involved exposure of the following personal information:

  • Full names
  • Social Security numbers

This type of information is highly sensitive and can be used for identity theft, fraudulent financial activity, and other forms of exploitation.

What You Can Do

If you were impacted by the OneDigital data breach, taking immediate action can help reduce your risk:

  • Monitor your financial accounts: Regularly check bank statements, credit cards, and financial accounts for unauthorized activity.
  • Review your credit reports: Look for unfamiliar accounts or inquiries that could indicate fraud.
  • Place a fraud alert or credit freeze: This can help prevent new accounts from being opened in your name.
  • Enroll in credit monitoring: OneDigital is offering 12 months of free credit monitoring and identity restoration services through Experian—be sure to activate these services.
  • Stay vigilant: Watch for phishing emails or suspicious communications using your personal information.

You don’t have to navigate this situation alone. Many individuals are unaware they may be entitled to compensation after a data breach. Exploring your legal options can help you take back control and hold companies accountable.

File a Data Breach Lawsuit Against OneDigital Investment Advisors LLC

If you received a notification from OneDigital Investment Advisors LLC, you may be eligible to join a class action lawsuit. Data breaches involving Social Security numbers can carry serious long-term risks, and affected individuals may be entitled to financial compensation for damages, time spent addressing the breach, and increased risk of identity theft.

Filing a claim can also help push companies to strengthen their data security practices and prevent future incidents. When many individuals come together, it creates a stronger case for accountability and meaningful change.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Subscribe To Our Newsletter

New cases and investigations, settlement deadlines, and news straight to your inbox.

This field is for validation purposes and should be left unchanged.
Other Data Breaches
Date of Breach: Not Specified
Date of Breach: Not Specified
Date of Breach: March 17, 2026

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.