They Were Already Inside

A 2026 Cybercrime Briefing for Private Wealth

The answer

The 2026 case record shows private-wealth cybercrime moving through trusted identities, adviser devices, third-party platforms and overlooked working copies of sensitive records. Effective defence depends on phishing-resistant authentication, complete session revocation, independent verification for consequential actions, transaction monitoring, disciplined data retention, supplier mapping and rehearsed incident authority before stolen access becomes financial or personal loss.

Hightower’s first compromised account opened the door on Jan 9, 2026.

Somebody had obtained the credentials of a user inside Hightower Holding, the parent company of Hightower Advisors, Hightower Securities and Hightower Trust Company. Files began leaving the wealth-management group’s environment. The activity continued across two days.

Hightower discovered the compromised account and brought in forensic specialists. The network was secured. Investigators began the slow work of identifying what had been touched, what had been taken and whose life existed inside it.

Ten days later, on Jan 19, 2026, another compromised user account appeared.

More files left.

Hightower’s notification described two intrusions, two sets of credentials and two periods of unauthorised downloading. Stolen files contained names, Social Security numbers and driver’s-licence information. State filings placed the affected population at 131,483 people.

Copied credentials gave the intrusion the clean geometry of a burglary carried out with duplicated keys. Nothing had to break. Somebody arrived under a name the system already trusted.

Across the wealth industry, similar scenes were unfolding. A financial adviser’s device carried malware. A criminal reached client accounts and placed trades. A third-party processor exposed debit-card information belonging to a bank. A wealth manager lost files containing passports, tax returns, medical information, passwords and estate plans. A global professional-services firm discovered that tax documents had been sitting inside support tickets while an intruder moved through the platform.

These events form the opening record of private-wealth cybercrime in 2026. They show an industry built around trust encountering criminals who understand exactly how trust moves.

Hightower: Two Compromised Accounts

Hightower’s incident deserves attention because it describes the core problem with identity-based intrusion in very few words.

Someone entered through a compromised user account. Valid credentials carried the intruder through the front door. Permissions, cloud applications and file repositories responded exactly as they would for the employee.

Passwords occupy one layer of that problem. Modern intrusions can also involve stolen browser sessions, approved malicious applications, captured authentication cookies, adversary-in-the-middle phishing and repeated approval prompts designed to exhaust the person holding the device. A successful login can survive a password change when an active session remains valid.

Hightower found a second compromised account ten days after the first. Effective containment requires a complete identity event: revoke sessions, invalidate tokens, remove malicious application grants, inspect mailbox rules, review recent devices, reset recovery methods and hunt for access across every connected service. One repaired credential can leave another route untouched.

Wealth organisations give certain identities extraordinary reach. An adviser may see a client’s holdings, contact information, planning documents and family structure. An assistant may reach calendars, travel and correspondence. An administrator may export whole repositories. The value of an account follows the authority and visibility attached to it.

A criminal inside one of these identities inherits its reputation and its working day. Every normal action becomes available. Search. Download. Forward. Approve. Trade. Invite. Reset.

Security systems see a familiar name.

Criminals see a menu.

Mercer Advisors: A Complete Private-Life Dossier

Mercer Advisors experienced unauthorised access to systems used to store client data on or around Jan 22, 2026. On Mar 25, 2026, investigators confirmed a third party had obtained personal information.

Mercer’s notification lists several possible categories of affected information. Read together, they describe the architecture of a private life.

Names. Postal and email addresses. Telephone numbers. Social Security numbers. Driver’s licences. Passports. Dates of birth. Account numbers. Medical conditions. Tax returns. Usernames and passwords. Estate-planning documents.

A tax return reveals income, assets, entities, dependants and advisers. An estate plan reveals intended beneficiaries, trustees, family tensions and the future movement of wealth. Medical information can create urgency or coercive pressure. A passport supplies a high-grade identity artefact. Credentials create access. Contact details connect every category to a reachable human being.

Put those files in criminal hands and the possible offences multiply. Identity fraud sits at the shallow end. The same material can support account recovery, impersonation, tax fraud, targeted phishing, extortion, synthetic documents, attacks on beneficiaries and approaches to the professionals named throughout the records.

Those records improve a criminal’s language. A forged message becomes convincing when it contains the correct entity, adviser, account reference and family relationship. A call becomes urgent when it touches a real medical condition. A fraudulent instruction gains weight when it arrives with a genuine planning document.

Private wealth firms often function as biographical databases. Their records explain how money connects to people, how people connect to entities and how authority will transfer during death, illness, dispute or succession. That concentration creates enormous service value. It creates equally concentrated criminal value.

Credit monitoring watches identity activity during one part of the aftermath. Passport images held by an extortion crew remain available. Estate plans retain their contents. Relationship maps preserve years of client history.

Effective protection begins earlier: collect fewer copies, shorten retention, isolate highly sensitive documents, restrict bulk export and log every reading or download.

LPL Financial: Malware Reached Client Accounts

LPL Financial shows stolen access becoming financial action.

Phishing compromised adviser devices on Nov 10, 2025. LPL discovered the activity on Nov 20, 2025, and its client notification reached regulators in 2026. Malware opened access to accounts belonging to a small number of affiliated financial advisers on LPL’s web portal.

Then the client accounts moved.

Unauthorised securities transactions and financial transfers appeared. LPL said it stopped the activity, secured the affected accounts and restored impacted accounts to their original financial positions. The filing covered 1,581 people.

A separate incident disclosed earlier involved foreign threat actors using compromised adviser accounts in a pump-and-dump scheme designed to inflate the price of securities.

Criminal logic rewards efficiency. An adviser account carries credibility, access and transactional power. Malware on the adviser’s device can place an intruder inside the same working environment used to serve clients. Clients see activity associated with a trusted financial relationship. Platforms see an authorised user. Markets see orders.

This is the point where cybersecurity becomes asset protection in its most literal form.

Controls must surround the action. A trade from a new device, a transfer to an unfamiliar destination, a sudden cluster of orders in a thinly traded security or a material change in account behaviour should create friction immediately. Historical account behaviour provides the baseline. Deviation supplies the alarm.

FINRA’s 2026 guidance calls for monitoring suspicious logins, unknown browsers, wire requests to new third parties and unusual account activity. It also identifies trading and fund restrictions as possible responses when the evidence warrants them.

Authentication decides who enters. Transaction controls decide what an authenticated identity can do. Private wealth needs both decisions.

Banco Popular: Customer Data Escaped Through Evertec

Banco Popular de Puerto Rico learned about its incident from Evertec, a provider of core financial transaction processing and information-technology services.

Evertec notified Popular on May 15, 2026 that client data had been affected by a cybersecurity incident. Later updates identified additional compromised data. The material included personal information belonging to Banco Popular customers, including debit-card numbers.

Popular’s own systems remained outside the intrusion described in its SEC filing. The data lived with a provider, and the breach lived there too.

This distinction offers limited comfort to the customer whose card number has travelled. People experience the financial relationship as one institution. Their data experiences it as an expanding chain of processors, cloud platforms, analytics services, support providers, identity vendors, document systems and subcontractors.

Every firm in that chain creates another place where access can be gained and information can be copied. The concentration grows when a widely used provider serves several financial institutions. One intrusion can then radiate through a market.

IMF analysis in 2026 focuses on this shared digital foundation. Financial institutions depend on common software, cloud services, payment networks and data infrastructure. AI-enabled tools can find and exploit weaknesses at machine speed. A vulnerability inside a shared provider can expose many institutions during the same window.

For a family office, the dependency chain reaches well beyond banks. It includes wealth managers, law firms, accountants, payroll providers, household systems, aviation companies, medical offices, property managers, schools and specialist software. Several of them hold information that would command severe restrictions inside the family office itself.

A supplier register should therefore answer four questions with precision: what data does the provider hold, which people can reach it, which other companies process it and how quickly will the family learn about an incident?

Contracts allocate liability. Architecture limits exposure. Data minimisation, segregated access, short retention, independent logs and tested exit procedures reduce the amount of trust resting on a promise.

EY: Tax Documents Accumulated in Support Tickets

On Mar 28, 2026, an intruder entered a third-party platform used by EY’s IT teams to support tax-related work. The attacker remained active until Apr 12, 2026, according to client notifications reported in July. EY detected anomalous activity on Apr 23, 2026.

EY used the platform to manage support tickets.

Those tickets sometimes contained documents with client tax information.

Support tickets create overlooked archives inside ordinary work. Someone has a problem. Someone opens a ticket. A screenshot, spreadsheet, return or supporting document becomes useful context. Staff resolve the issue. Attachments stay behind.

Over time, operational systems become accidental archives. Email contains passports. Messaging platforms contain account references. Ticketing systems contain tax documents. Shared drives contain old diligence files. Personal devices contain photographs of signatures and identity cards. Convenience leaves copies everywhere.

Attackers search those quieter repositories because governance often concentrates on the official record. The working copy can carry the same sensitivity with looser permissions, longer retention and weaker monitoring.

EY’s reported response included securing the systems, notifying authorities and affected clients, and offering identity-monitoring services. The incident still leaves a hard question for every firm handling private wealth: how many copies of a client’s life exist outside the system designated to protect it?

Finding the answer requires a data walk. Follow a passport, tax return or estate document through the real work: arrival, review, forwarding, annotation, support, backup, archive and deletion. The path usually crosses far more systems than policy diagrams admit.

FINRA Impersonation: Authority Became the Bait

A message arrives with a time-sensitive regulatory matter. Its sender appears to work for FINRA. A reply leads toward a Microsoft Teams call.

FINRA warned broker-dealers about that active campaign beginning on Mar 26, 2026. The emails used domains designed to resemble the regulator and tried to pull recipients into conversation.

Regulatory contact supplies authority. Time sensitivity creates pressure. A Teams call feels familiar, professional and capable of resolving ambiguity. Recipients may bring colleagues into the room and extend the attacker’s reach.

A meeting invitation can launch a modern financial-services intrusion. Live conversation creates opportunities to steal credentials, deliver malware, gather internal information or persuade staff to take another action. Synthetic voice and video deepen the performance. Real public footage supplies training material. Social platforms supply names, roles and current events.

Recognition has therefore lost much of its value as proof. A familiar face, a familiar voice and a familiar interface can all be manufactured or borrowed. Consequential instructions need verification through a channel selected before the message arrives.

That rule must apply upward. Staff need explicit authority to pause an executive, adviser, regulator, principal or family member when the instruction touches money, credentials, private documents or access. Service culture collapses quickly when saying “wait” feels career-limiting.

Criminals understand hierarchy. Protection requires permission to interrupt it.

FIIG Securities: 385 Gigabytes, 18,000 Clients, $2.5 Million

On Feb 9, 2026, the Australian Securities and Investments Commission announced a $2.5 million civil penalty against FIIG Securities.

FIIG’s breach occurred years earlier. Criminals stole around 385 gigabytes of confidential information. Driver’s licences, passport information, bank-account details and tax-file numbers reached the dark web. Around 18,000 clients received notifications.

ASIC’s 2026 judgment records the long tail of a cyber failure. Attackers may finish their work in hours. Investigation, notification, litigation, regulatory action and client exposure can continue for years.

ASIC identified a catalogue of weaknesses across the period leading to the attack: inadequate resourcing, insufficient multifactor authentication, weak privileged-access controls, security configuration gaps, limited vulnerability management, insufficient monitoring, missing staff training and an incident-response plan that lacked annual testing.

ASIC’s findings cover familiar controls, and familiarity often drains urgency from them. FIIG’s outcome restores the stakes: 385 gigabytes left the organisation, highly sensitive client information reached the criminal underground and a court imposed the first civil penalties of this kind under Australia’s general financial-services licence obligations.

Security programmes often fail through accumulation. One delayed patch meets one overprivileged account. One unmonitored alert meets one untested response plan. One employee faces one persuasive message. The attacker needs a viable sequence. Years of tolerated weakness can supply it.

Budgets expose security spending immediately. Breach costs arrive later, distributed across victims, lawyers, regulators, insurers, executives and years.

What 2026 Has Already Revealed

Seven facts emerge from the case files.

Identity has become the preferred entrance. Compromised accounts and adviser devices let criminals work through permissions that already exist.

Client data has become an operational asset for criminals. Tax records, estate documents, credentials and health information can support several forms of pressure at once.

Financial action can follow immediately. An intruder who reaches an adviser portal can trade, transfer and manipulate.

Third parties expand the event. Data held by a processor can expose customers whose bank maintained secure internal systems.

Forgotten repositories carry premium information. Support tickets, mailboxes, shared folders and cloud applications quietly accumulate documents far beyond their original purpose.

Official authority has become a pretext. Criminals impersonate regulators and use familiar collaboration platforms to pull staff into live interaction.

Weakness accumulates. A breach can emerge from years of underfunding, incomplete controls and unrehearsed response.

INTERPOL’s 2026 assessment describes an industrialising fraud economy. Criminal networks share technology, specialist skills and money-laundering capability across borders. The organisation reported a 54 per cent rise in fraud-related Notices and Diffusions since 2024 and involvement in over 1,500 transnational cases concerning $1.1 billion in lost assets. Its assessment found AI-enhanced fraud 4.5 times as profitable as traditional methods.

IMF analysis places the same acceleration inside the financial system. AI reduces the cost and time required to discover and exploit weaknesses. Shared infrastructure creates the possibility of correlated failures. Attackers can move at machine speed while institutions coordinate through human chains of approval.

For private wealth, the danger is intensely personal. A bank protects payments. An adviser protects portfolios. A family office protects the connections among money, identity, family, property, movement and reputation. Cybercrime can cross all of them through a single trusted account.

How Private Wealth Should Defend Itself

Private wealth environments prize responsiveness. Protection requires deliberate moments of resistance.

Protect identities capable of irreversible action first. Advisers, assistants, finance personnel, trustees, administrators and external providers should use phishing-resistant authentication based on FIDO security keys or equivalent hardware-backed methods wherever systems support it. CISA recommends phishing-resistant MFA, shorter session lifetimes, reauthentication and continuous review of active accounts.

At the first sign of compromise, revoke every active session connected to the identity. Remove unknown devices. Inspect authentication history, mailbox forwarding, delegated access and application grants. Reset recovery channels. Search for the same credentials and devices across connected platforms. Containment should follow the person’s real digital reach.

Then place controls around consequential actions. A new beneficiary, changed payment instruction, large trade, password recovery, bulk download or release of a private document should trigger independent verification. The verification channel must come from a trusted record held before the request. A telephone number inside the requesting email belongs to the request.

Dual approval needs genuine separation. Two approvals inside the same compromised mailbox create one approval wearing two names. Use separate devices, separate channels and clear financial thresholds. Alert the principal or a designated control function when authority, recovery methods or payment destinations change.

Treat adviser and family-office systems as private-intelligence repositories. Restrict exports. Detect abnormal downloads. Flag access from new browsers and locations. Watch for new forwarding rules, unusual OAuth permissions and sudden searches across many clients. Encrypt the most sensitive documents separately. Remove obsolete copies. Keep passports, tax returns and estate plans out of ordinary support tickets and email threads.

Map every external custodian of family information. Include accountants, lawyers, banks, insurers, aviation providers, property managers, schools, medical offices and software vendors. Record the data each one holds, its retention period, its authentication method, its subcontractors and its incident-notification commitment. Bring critical providers into response exercises.

Prepare a single incident room before the crisis. Intelligence, technical security, finance, legal, communications and protective security need one source of truth. A compromised adviser account may create a cyber incident, fraudulent trading, regulatory exposure, identity risk and physical concern during the same hour.

Rehearse the ugly scenarios. An adviser’s device begins placing trades. A regulator invites the compliance team to a Teams call. A principal’s voice requests an urgent transfer. An estate plan appears in a criminal channel. A travel provider reports unauthorised access while the family is in transit.

Exercises should force decisions. Who can freeze activity? Who contacts the bank? Who preserves evidence? Who briefs the family? Who watches for physical escalation? Which channel remains trusted? How does the team operate when email, voice and video all carry doubt?

Teams need those answers before fear enters the room.

Clients Discover the Breach Last

Cyber incidents unfold in an order that favours the attacker.

Criminals learn the credential works. Platforms accept the session. Files leave. Data is sorted. Access is sold or used. A second account is tested. A trade appears. A provider begins investigating. Lawyers and forensic teams arrive. Regulators receive notice.

Clients learn later.

By then, the stolen material may already have crossed systems, borders and criminal groups. A password can be replaced. A trade can sometimes be reversed. The knowledge inside a tax return, estate plan or family dossier will continue to exist wherever it travelled.

That reality changes the standard for private-wealth security. Compliance can document activity. Protection must reduce the amount of life available to steal, constrain what trusted identities can do and detect the first abnormal movement while action remains possible.

Across 2026, every case carries one clear warning.

A future attack may arrive through a person you know, a company you hired, a platform you use every day or an account carrying the correct name.

Your systems will recognise the identity.

Sources

  1. Massachusetts Attorney General — Hightower breach notificationMassachusetts Attorney General

    Primary authority

  2. SecurityWeek — Hightower impact and affected populationSecurityWeek

    Primary authority

  3. California Attorney General — Mercer Advisors breach noticeCalifornia Attorney General

    Primary authority

  4. Maine Attorney General — LPL Financial breach filingMaine Attorney General

    Primary authority

  5. WealthManagement.com — LPL phishing and client-account activityWealthManagement.com

    Industry guidance

  6. SEC — Popular and Evertec cybersecurity disclosureSEC

    Primary authority

  7. TechRadar — EY tax-support platform incidentTechRadar

    Industry guidance

  8. ASIC — FIIG Securities cybersecurity judgmentASIC

    Primary authority

  9. INTERPOL — 2026 Global Financial Fraud Threat AssessmentINTERPOL

    Primary authority

  10. IMF — AI and financial-system cyber riskIMF

    Primary authority

  11. FINRA — 2026 Regulatory Oversight ReportFINRA

    Primary authority

  12. FINRA — March 2026 impersonation campaign alertFINRA

    Primary authority

  13. CISA — Phishing-resistant MFA and session hardeningCISA

    Primary authority

  14. NIST — Incident Response RecommendationsNIST

    Primary authority

Jonathan P. De Collibus

Jonathan co-founded Svperior in 2014 and leads its cyber practice. His work sits where adversarial pressure, technical architecture, and consequential decisions meet, with experience across clinical, financial, public-sector, and private-client systems where confidentiality, continuity, and technical correctness carry material consequences.

Cyber strategy / Adversarial assessment / Security architecture / Private systems

Need to apply this to a specific situation?

Send us the initial context. If the matter fits, we will respond directly.

Send private inquiry