Kovack Financial Data Breach: Is There a Lawsuit? (August 2026 Status)
The Florida broker-dealer confirmed attackers spent nearly three weeks in its network in 2025 — client Social Security numbers and financial account data may be out. Firms are investigating. No settlement exists yet.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What Happened at Kovack Financial
Kovack Financial, LLC — a Florida-based investment advisor and broker-dealer — became aware of suspicious network activity on or around August 28, 2025. The investigation determined an unauthorized actor had access to files between August 8 and August 27, 2025 — nearly three weeks. On July 16, 2026 — almost eleven months later — Kovack determined the accessed files contained personal information. Per the company's notice and its Massachusetts filing, the exposed data may include Social Security numbers, financial account information and driver's license numbers. Notification letters dated August 10, 2026 offer twelve months of Cyberscout credit monitoring.
Case Details
As of August 17, 2026, no class action is confirmed filed. Edelson Lechtzin LLP announced an investigation on August 12, 2026, noting that clients who entrust their most sensitive financial information to a brokerage have every right to expect protection. Financial-firm breaches draw heightened regulatory attention (SEC/FINRA safeguarding rules) — context that tends to strengthen civil claims. This page tracks the docket from the first complaint on.
Current Status — Verified August 17, 2026
Who Is Affected?
Clients (and potentially advisors/employees) of Kovack Financial whose files sat in the accessed systems — the company hasn't published a count. The definitive signal is the letter dated August 10, 2026. If you have accounts through Kovack Securities or Kovack Advisors and receive one, keep it — and enroll in the offered monitoring.
What Could This Pay? (Honest Answer)
Case Timeline
- 1
August 8–27, 2025: The intrusion
An unauthorized actor has access to files in Kovack's network for nearly three weeks.
- 2
On or around August 28, 2025: Detection
Kovack becomes aware of suspicious activity and begins investigating.
- 3
July 16, 2026: Content confirmed
Almost eleven months later, Kovack determines the accessed files contained personal information.
- 4
August 10, 2026: Notification letters
Letters go out with twelve months of complimentary Cyberscout monitoring.
- 5
August 12, 2026: Firms open investigations
Edelson Lechtzin LLP announces its investigation of the breach.
- 6
Expected: first complaints
Financial-sector breaches with year-long notice gaps historically draw filings once letters land.
- 7
What's next
First complaint, then the standard breach-litigation path. We update this page at each milestone.
Kovack Breach Scams
Brokerage clients are premium scam targets — criminals know the accounts are worth raiding.
Fake 'account security' calls from your brokerage
Callers may reference the breach and ask you to 'verify' credentials or move funds to a 'safe account'. Brokerages never do this. Hang up and call your advisor's known number.
Fake 'Kovack settlement claim' sites
No claims portal exists. Any payout form today is a scam. A real claims process would appear in court filings — and on this page.
Monitoring-enrollment phishing
Enroll in Cyberscout only through the code and instructions in your official letter — not through emailed links or callers offering to 'help you enroll'.
Kovack Financial Breach FAQs
Is there a Kovack Financial settlement?
No. As of August 17, 2026 there is no settlement, no administrator, no fund — and no confirmed filed complaint. Edelson Lechtzin is investigating. We update this page when anything changes.
Why did notice take almost a year?
The intrusion ran in August 2025; Kovack confirmed the content on July 16, 2026 and mailed letters on August 10, 2026. Long forensic timelines happen — but an eleven-month gap is exactly what notice-delay claims are built on.
What data was exposed?
Per the notice and Massachusetts filing: Social Security numbers, financial account information and driver's license numbers. Your letter states your specific fields.
Is my investment money at risk?
Account credentials weren't listed as exposed — but SSN + account data enables social-engineering takeover attempts. Strengthen authentication, verify your contact info on file, and treat 'urgent' brokerage calls as hostile until verified.
Should I take the free Cyberscout monitoring?
Yes — it's free and doesn't waive any legal rights. But add credit freezes at all three bureaus; monitoring detects fraud after it happens, freezes prevent it.
How much could a settlement pay?
Unknown — no case exists yet. Financial-firm breaches with SSN exposure historically settle with flat payments plus documented-loss tiers; class size isn't public. Anyone quoting a number today is guessing.
Do I need to sign up with a firm now?
No — a future class settlement would cover you automatically. Individual advice matters only for serious, documented fraud traceable to this breach.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.