JPMorgan filed a federal complaint seeking a temporary restraining order and injunctive relief against former advisor Kevin J. Sercia, alleging he stole confidential client information and trade secrets to solicit clients after moving to an affiliate of LPL Financial. The complaint alleges “highly suspicious computer access” shortly before his resignation, including after-hours access to roughly 175 client profiles in JPMorgan’s Advisor Central system, many viewed in rapid succession.
Separately, the FBI alleged that a government contractor employee with elevated access to classified systems, Perez-Lugones, improperly accessed and removed classified information, including taking screenshots of a classified intelligence report, embedding them in a Word document, and printing them under innocuous filenames. Search warrants executed on his home and vehicle reportedly recovered documents marked SECRET, including one found in a lunchbox in his car, and investigators alleged he removed classification markings before leaving his workplace; the case also involved seizure of a Washington Post reporter’s devices as part of a leak investigation.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
JPMorgan filed a federal lawsuit in the Southern District of Florida seeking a temporary restraining order and injunctive relief against former advisor Kevin J. Sercia, alleging he stole confidential information to solicit clients for LPL Financial.
JPMorgan alleges Kevin J. Sercia conducted suspicious after-hours access to internal systems shortly before resigning, including rapidly viewing about 175 client profiles in Advisor Central in the hours before his departure.
Following the investigation, Perez-Lugones was charged under a U.S. law carrying penalties of up to 10 years for allegedly removing and mishandling classified information. A magistrate judge approved release, and the U.S. government sought review of that decision.
On 2026-01-08, search warrants were executed at Perez-Lugones's home in Laurel, Maryland, and his vehicle. Investigators reportedly found documents marked SECRET, including one in a lunchbox in his car and another in his basement.
Investigators allege Perez-Lugones was seen taking handwritten notes from a classified-system workstation, adding to evidence that he was removing sensitive information from secure environments.
The FBI affidavit says Perez-Lugones accessed an additional classified intelligence report on 2026-01-05 as part of the alleged improper removal of classified information from secure systems.
According to an FBI affidavit, Perez-Lugones accessed a classified intelligence report and on 2025-10-28 allegedly took screenshots, inserted them into a Microsoft Word document, and printed the material in a way meant to appear innocuous in print logs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcearstechnica.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.