Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations
    • ‘Warrantless Surveillance’ Debate Resumes in Advance of FISA Hearing Tomorrow
    • 8th Cir.: Consumer’s putative VPPA class action against movie theater operator flickers-out on appeal
    • Bill to Ban Data Brokers From Collecting Kids’ Data Set for Markup Tomorrow
    • Bipartisan Senate Bill Seeks Cyber Assistance for Satellites
    • DoJ Accuses Russian ‘Hacktivist’ of Disrupting Water Systems
    • M Holdings fined, censured, for failing to protect customer information
    • New Complaint Form Released in Denmark
    • Privacy Sweep to Focus on Australian Businesses’ Data Collection
    • Swedish Agency Releases AI Training Guidance
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations

    Cybersecurity Policy Report, M Holdings fined, censured, for failing to protect customer information, (Dec 10, 2025)

    Organizations Mentioned:M Holdings Securities, Inc.

    By Rodney F. Tonkovic, J.D.

    The broker-dealer and adviser had deficient cybersecurity and identity theft prevention programs.

    An Oregon-based firm settled SEC charges that its deficient cybersecurity and identity theft programs led to email account takeovers. The Commission foun ...

    By Rodney F. Tonkovic, J.D.

    The broker-dealer and adviser had deficient cybersecurity and identity theft prevention programs.

    An Oregon-based firm settled SEC charges that its deficient cybersecurity and identity theft programs led to email account takeovers. The Commission found that respondent M Holdings and its member firms lacked sufficient policies and procedures concerning cybersecurity, the protection of customer information, and identity theft prevention. As a result, unauthorized access to email accounts at member firms took place, exposing customers' records and personal information. The Commission found that M Holdings violated safeguard and identity theft protection rules under Regulation S-P and S-ID. In addition to a censure, the firm will pay a $325,000 civil penalty (M Holdings Securities, Inc., Exchange Act Release No. 104255, Investment Advisers Act Release No. 6928 (Nov. 25, 2025)).

    Respondent M Holdings is a registered broker-dealer and investment adviser based in Portland, Oregon. M Holdings provides its services via a network of registered representatives and adviser representatives operating out of 120 branch offices ("member firms").

    Deficient policies. The Commission found that prior to September 2020, M Holdings had no written policies and procedures governing information security across its member firms. The new policy required member firms to adopt their own information security policies and controls. According to the Commission, M Holdings was aware that many member firms did not have the required policies and controls, such as multi-factor authentication, annual security awareness training, and written incident response policies, through March 2024.

    M Holdings also had a deficient identity theft protection program because it did not periodically update the program to reflect changing risks to customers. The program also lacked ways to detect and respond to red flags, even though there were ongoing cybersecurity incidents at member firms.

    Account takeovers. Between July 2019 and March 2024, the email accounts of 17 registered representatives and employees at 13 out of 120 member firms were accessed by unauthorized third parties. The compromised accounts sent credential-harvesting emails to approximately 8,500 individuals, including numerous customers. These incidents also exposed the affected customers’ records and information, including personally identifiable information.

    According to the Commission, the takeovers occurred at the member firms because they had no written information security policies or had policies that were not reasonably designed. Four of the member firms experienced two takeovers during the period at issue.

    Violations. The Commission found that M Holdings violated Rule 30(a) of Regulation S-P and Rule 201 of Regulation S-ID. Rule 30(a) requires every broker-dealer and investment adviser to adopt written policies and procedures for the protection of customer records and information. Rule 201 requires a written identity theft prevention program to prevent, and mitigate identity theft in connection with covered accounts.

    In addition to a cease-and-desist order and censure, M Holdings will pay a civil penalty in the amount of $325,000. In accepting the settlement offer, the Commission took into account the firm's remedial acts undertaken to strengthen its information security and cybersecurity programs.

    The release is No. 34-104255.

    LitigationEnforcement: BrokerDealers CyberPrivacyFeed DataBreach DataSecurity Enforcement GCNNews InvestmentAdvisers DataPrivacy

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use