Private Wealth Under Attack: What H2 2026 Numbers Reveal

Cyber incidents are climbing across banks, RIAs, wealth managers and family offices. Fresh data shows where pressure is concentrating—and where defenses are trailing.

The answer

Cyber incidents have become a routine operating condition across private wealth. New data shows where attacks are accelerating, why family capital creates an unusually valuable target, and why identity, money-movement verification, vendor visibility, and rehearsed containment deserve immediate attention from boards and principals.

January had barely started when intruders entered Hightower’s environment and pulled files across two compromised accounts. The wealth-management group later notified 131,483 people.

Mercer Advisors disclosed unauthorised access weeks later. Its notice described the kind of client material wealth firms accumulate through years of legitimate work: identity records, passports, account numbers, tax documents, credentials, health information and estate-planning files.

LPL Financial then reported a different route. Malware reached adviser devices through phishing. Criminals used the access to enter client accounts and initiate securities transactions and transfers. The filing covered 1,581 people.

Three firms. Three attack paths. One commercially obvious target.

Private wealth firms sit close to liquid capital and hold the documents required to impersonate its owners. A criminal who compromises a wealth manager can gain financial coordinates, family relationships, signatures, identity documents, tax history, account details and the trusted communication channel used to move money.

Attackers understand the economics. Fresh numbers from 2025 and 2026 show an industry absorbing attacks at a pace many firms still describe as an IT problem.

93% of private-capital firms reported an incident

Omega Systems surveyed over 300 US financial-services executives in August 2025. Respondents worked at family offices, registered investment advisers, wealth managers, hedge funds, private-equity firms and investment advisers with assets under management ranging from below $1 billion to above $10 billion.

Ninety-three per cent reported at least one known cyber incident during the previous year. Eighteen per cent reported over 25.

Those two figures deserve to sit together. The first shows prevalence. The second shows repetition. A meaningful share of firms face a continuing operating condition, with attackers testing identities, inboxes, endpoints, cloud platforms and vendors again and again.

Preparedness lagged behind the volume:

  • 57% lacked real-time threat monitoring.
  • Over one-third expected breach detection and containment to take at least a week.
  • 6% expected a month or longer.
  • 31% ran cyber assessments quarterly or less frequently.
  • 65% managed security entirely in-house.
  • 17% planned to prioritise security-awareness training during the coming year.

RIAs showed a troubling budget pattern. Seventy-eight per cent of all firms increased cybersecurity spending, while 57% of RIAs did so. Eleven per cent of RIAs cut IT spending significantly.

Family offices reported a distinct confidence gap. Seventy-two per cent believed their concentration of high-net-worth assets attracted additional targeting. Sixty-seven per cent expected legacy systems to obstruct recovery. Only 8% used an outside provider for daily cybersecurity management.

This is survey data, built from executive responses. It measures known incidents and perceived readiness. It still offers a rare direct view into a sector usually hidden inside broad “financial services” statistics.

Attack activity across finance is accelerating

CrowdStrike’s 2026 financial-services threat report recorded a 43% increase in interactive, hands-on-keyboard intrusions over two years. It also counted a 27% year-on-year rise in financial-services victims named on ransomware leak sites during the twelve months ending March 2026.

Akamai’s infrastructure sees another part of the market. Its 2026 financial-services research found:

  • Median duration for network-layer DDoS attacks against financial firms rose 738% from 2024.
  • 96% of surveyed financial-services leaders reported at least one API security incident within twelve months.
  • Banking absorbed 60% of web attacks and 83% of attacks against API endpoints in Akamai’s 2025 financial-services data.
  • Advanced bot activity rose 147% in late 2025.
  • Asia-Pacific received 52% of application-layer DDoS activity aimed at finance.

Each dataset observes a different slice. CrowdStrike measures intrusions and extortion victims within its visibility. Akamai measures traffic flowing through its infrastructure and combines that telemetry with survey results. Omega records executive experience across private-capital firms. Their numbers converge on a useful conclusion: criminals are increasing frequency, duration and automation across the systems used to store information and move capital.

Family wealth creates a dense attack surface

Deloitte surveyed 1,587 family-owned businesses across 35 countries. Every respondent represented a company with at least $100 million in annual revenue. Seventy-four per cent had experienced a cyberattack during the previous two years, and 33% had suffered multiple incidents.

Asia-Pacific respondents reported the highest exposure at 90%.

Malware reached 49% of attacked firms. Phishing or business email compromise reached 48%. Social engineering reached 43%. Only 43% described their cybersecurity strategy as robust and free of known weaknesses. Attack consequences included financial damage for 54%, operational damage for 51% and reputational damage for 51%.

Family businesses and family offices are different populations. The research still matters because family offices frequently share people, devices, email domains, advisers and payment processes with operating companies. A compromise can travel across those relationships. The family principal may approve a transaction from a personal phone, receive board papers through a private address and speak with an adviser over the same messaging account used by relatives.

Corporate security boundaries struggle with lives organised across households, companies, trusts, foundations and advisers.

Fraud is scaling around identity and trust

The FBI’s 2025 Internet Crime Report recorded $8.65 billion in investment-fraud losses and $3.05 billion in business-email-compromise losses.

People aged 60 and above reported 16,926 investment-fraud complaints, up from 9,448 during 2024. That is a 79% increase in a single year. Reported losses in the same group reached $3.52 billion, up 92%.

Business-email-compromise complaints among people aged 60 and above rose 38% to 4,566. Losses rose 48% to $568 million.

These are victim reports, and FBI guidance says reporting remains incomplete. They still map directly onto private wealth. Older investors often control larger pools of capital. Their financial lives involve advisers, accountants, lawyers, family members and assistants. Each trusted relationship supplies language, timing and authority for a convincing request.

INTERPOL’s 2026 global fraud assessment adds an efficiency measure: AI-enhanced fraud generated 4.5 times the profit of traditional methods. INTERPOL also reported a 54% increase in fraud-related Notices and Diffusions since 2024.

Criminals can now prepare a target dossier, imitate a familiar voice, draft messages in a known style and run many conversations simultaneously. Human trust has become programmable.

Australia offers a clear warning

Australia’s Signals Directorate recorded an 11% increase in cyber incidents handled during the 2024–25 financial year. Financial and insurance services became the most frequently reporting non-government sector.

Average reported cybercrime cost for large businesses reached A$202,691, an increase of 219%. ASD cautions readers about the sensitivity of this average to large cases and low reporting volumes. That caveat improves the figure. It tells executives how to read it: loss severity can jump sharply when a small number of successful attacks reach high-value organisations.

The regulator has already moved from warning to penalty. In February 2026, Australia’s Federal Court ordered FIIG Securities to pay A$2.5 million after ASIC’s case over years of cybersecurity failures. A 2023 intrusion removed roughly 385 gigabytes of confidential information and exposed sensitive data connected to about 18,000 clients on the dark web.

ASIC listed familiar deficiencies: weak remote-access controls, incomplete multifactor authentication, weak privileged-account protection, inadequate monitoring, poor patch governance, missing mandatory training and an incident plan that lacked annual testing.

FIIG held roughly A$3 billion in client assets during the period. Attackers needed one viable path. The firm needed every material control to work.

Private wealth offers criminals four returns from one intrusion

The data becomes more useful when viewed through attacker economics.

Immediate money movement

Access to an adviser, assistant or client account can support wire fraud, securities manipulation, payment redirection and account takeover. LPL’s disclosure shows how endpoint malware can become client-account activity.

Identity inventory

Tax files, passports, signatures, dates of birth, account statements and estate records support impersonation, credit fraud and future account recovery attempts. Mercer’s disclosed data categories read like a criminal onboarding package.

Human leverage

Family structures, health information, disputes, trusts and succession plans can support coercion and targeted social engineering. This material holds value after passwords change.

Institutional access

A wealth firm connects to custodians, banks, accountants, law firms, insurers, portfolio systems and client portals. One stolen identity can open a route into several organisations. Verizon’s 2026 breach research found third-party involvement in 48% of breaches, following a 60% year-on-year increase.

This combination explains the attention. A hospital holds sensitive records. A bank moves money. A family office often holds the records, relationships and authority required to reach both people and capital.

Boards should ask ten questions now

Numbers only become valuable when they change behaviour. A board, investment committee or family council can use these ten questions in its next meeting:

  1. How many cyber incidents, account-takeover attempts and high-confidence impersonation attempts reached us during the past twelve months?
  2. Which result counts as an incident internally, and which events disappear into help-desk tickets?
  3. Can we see activity across corporate email, personal email, mobile devices, adviser portals and messaging platforms used for approvals?
  4. Which people can approve money movement, change payment details, reset credentials or release sensitive documents?
  5. Does every high-risk action require verification through a second channel controlled by our organisation?
  6. Which vendors can reach client records, cloud systems, trading tools or identity infrastructure?
  7. Can an attacker reuse one credential across several systems?
  8. How quickly can we revoke sessions, disable integrations, freeze transfers and preserve evidence?
  9. When did we last run a live exercise involving an executive impersonation, compromised adviser device and fraudulent transfer?
  10. Who can make containment decisions at 2 a.m. on a Sunday?

Clear answers should include names, systems, time limits and evidence. “Our provider handles it” describes a dependency. It gives the board zero assurance about response time, authority or outcome.

Spending should follow loss pathways

Many firms respond to higher attack volume by purchasing another security product. The numbers point toward a sharper sequence.

Start with identity. Use phishing-resistant authentication for administrators, advisers and anyone who can approve payments or reset accounts. Bind high-risk actions to fresh authentication. Shut down shared credentials.

Then secure money movement. Require an independently verified callback or trusted in-app confirmation for new payees, changed bank details, large transfers and unusual securities activity. Design the workflow around deepfake-quality impersonation.

Map private and professional exposure. Wealth principals and family-office staff operate across home networks, personal phones, assistants and advisers. Protect those routes with the same seriousness applied to institutional endpoints.

Instrument the vendors. Record which provider stores each data class, which identities can access it, how sessions are revoked and how quickly the provider must report suspicious activity.

Practise containment. Run the exercise during an inconvenient hour. Include the custodian, bank, insurer, legal counsel, communications team and affected family members. Measure minutes.

Private wealth security now protects the machinery of trust: people give instructions, trusted systems recognise them and accumulated records make an imitation credible.

Attackers have already priced that machinery. The numbers show they are buying access aggressively.

Sources

  1. Omega Systems: 2025 Financial Services Cyber Resilience ReportOmega Systems

    Industry guidance

  2. CrowdStrike: 2026 Financial Services Threat Landscape ReportCrowdStrike

    Industry guidance

  3. Akamai: Attack Trends in Financial ServicesAkamai

    Industry guidance

  4. Deloitte Private: Family Business Cybersecurity 2026Deloitte Private

    Industry guidance

  5. FBI: 2025 Internet Crime ReportFBI

    Primary authority

  6. INTERPOL: 2026 Global Financial Fraud Threat AssessmentINTERPOL

    Primary authority

  7. Australian Signals Directorate: Annual Cyber Threat Report 2024–25Australian Signals Directorate

    Primary authority

  8. ASIC: FIIG Securities cyber-security penaltyASIC

    Primary authority

  9. Hightower Holding breach noticeHightower Holding breach notice

    Primary authority

  10. Mercer Advisors breach noticeMercer Advisors breach notice

    Primary authority

  11. LPL Financial breach reportingLPL Financial breach reporting

    Industry guidance

  12. Verizon: 2026 Data Breach Investigations ReportVerizon

    Industry guidance

Adam J. De Collibus

Adam co-founded Svperior and leads systems engineering from requirements through implementation. His work connects architecture, implementation, deployment, and operating discipline across complex environments where failure must be anticipated and technical capability must remain dependable under pressure.

Systems engineering / Technical architecture / Production operations / Operating resilience

Need to apply this to a specific situation?

Send us the initial context. If the matter fits, we will respond directly.

Send private inquiry