We were recently made aware of a data breach at Fidelity Investments that compromised the personal information of about 77,000 Fidelity customers. The breach took place over the course of about two days before Fidelity identified and closed the breach, limiting the number of impacted customers to about 0.15% of their client base. While personal information was accessed, the perpetrators had no direct access to client accounts.
Fidelity has informed us that no Broadview Financial Management clients were impacted by the breach, but we believe this to be a good opportunity to reassure our clients that we are aware of the incident, that we approach data security with the utmost sincerity and vigilance and to explain what would happen in the event they were impacted by such a data breach.
Since most of our clients custody their investments with Fidelity Investments and Charles Schwab, we contacted both institutions to confirm the following information should a data breach impacting our clients occur:
- Fidelity and Schwab would contact Broadview Financial Management to provide a list of impacted clients and the details of the breach. We would take steps to contact impacted clients and coordinate a plan with their investment custodian(s).
- In some cases, Fidelity and Schwab, as custodian, would also contact clients directly to explain the details of the breach, the data that was compromised, and the steps they will take to remedy the situation.
Fidelity and Schwab devote considerable resources to repelling bad actors and ensuring the security of their systems, but it’s clear that criminal hackers are getting more sophisticated and will continue to target large financial institutions and individuals alike.
While we’ve provided our thoughts on this topic numerous times before, the following are a couple quick reminders on how to protect your sensitive personal data from falling into the wrong hands:
- Consider placing a security freeze on your credit files with the major credit reporting bureaus.
- Update your passwords frequently using a combination of uppercase and lowercase letters, numbers and symbols. Don’t use the same password for more than one login.
- Use multifactor authentication (MFA) wherever possible.
- Remember that your bank or financial institution will never ask you for your login credentials, a one-time security code or to confirm any details via email or text.
- Never share personal information such as login credentials, account numbers or Social Security numbers with anyone.
- Never log into accounts through links in emails or text messages.
- Keep your tech and anti-virus software up to date to protect against the latest threats.
For clients whose portfolios we actively manage, let us know right away if you ever have a situation in which you have been hacked or compromised so we can help you coordinate additional security measures with your custodian.
The views expressed are opinions only and should not be relied upon as advice regarding investments, sectors or markets in general.
The above statistics and/or commentary has been obtained from sources we believe are reliable, but we cannot guarantee their accuracy or completeness. Past performance is no guarantee of future results.
This is not a complete analysis of every material fact regarding any company, industry, or economic condition. Due to shifting market conditions, all expressions of opinion are subject to change without notice.
Talk to your financial advisor before acting on information in this document.
Picture from freepik.com.