Mark Leyden and Associates Data Breach Investigation

Written by 
Published on:
March 27, 2026
Updated on:
March 27, 2026

Mark Leyden and Associates disclosed a data breach allegedly involving unauthorized access to a company email account. The company discovered the breach on February 23, 2026, and began notifying affected individuals on March 24, 2026. The unauthorized access occurred over a period of approximately six months, between May and October of 2025. Contact our data breach lawyers to learn more.

What Was Exposed

The compromised information included names, Social Security numbers, driver's license numbers, and financial information. For clients of a wealth management firm, that combination is about as serious as a data breach gets. Social Security numbers open the door to new credit accounts, tax fraud, and identity theft that can take years to untangle. Financial account information can be used to drain accounts or commit wire fraud. Driver's license numbers are used to establish false identities.

The breach, which occurred between January 17, 2025, and October 27, 2025, was the result of external hacking and has raised serious concerns about personal data security and the potential for identity theft among those affected.

Why The Mark Leyden Breach Raises Serious Legal Questions

Financial advisory firms are entrusted with some of the most sensitive personal and financial information people possess. Federal regulations, including those enforced by the Securities and Exchange Commission and the Federal Trade Commission's Safeguards Rule, require financial firms to maintain secure data security programs and to respond quickly when a breach occurs.

When a company's email system is compromised for six months without detection, it raises immediate questions about what security measures were actually in place. Was multi-factor authentication enabled? Were employees trained to recognize phishing attempts? Were systems being monitored for unusual access? The answers to those questions will matter a great deal in any legal proceeding that follows.

A new report from the Identity Theft Resource Center found that data compromises in 2025 reached a record high of 3,322 incidents, a five percent increase from 2024, with analysts noting that bad actors are becoming more sophisticated in targeting organizations that hold sensitive personal data. Financial firms remain a prime target precisely because the data they hold is so valuable.

Why Victims Choose The Lyon Firm

The Lyon Firm represents data breach victims nationwide, handling cases against companies of all sizes that fail to meet their legal obligation to protect client data. Our attorneys understand the federal and state regulations that govern data security at financial firms, and we know how to build a case that gets results. We handle data breach cases on a contingency basis, meaning you pay nothing unless we recover for you. Contact The Lyon Firm today for a free, confidential consultation.

Contact Us

Request a Free Consultation

Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there:

  • It begins with a few simple questions about your situation.
  • From there, a member of our legal team reviews your case.
  • Together, we’ll chart the path forward, helping you take the next step toward resolution.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.