Financial Services / Wealth Management (RIA) / Consumer / USA
Large US registered investment advisor and wealth-management firm.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
Around February 16, 2026, ShinyHunters breached Mercer Advisors and threatened to leak roughly 5.7 million internal records; after Mercer declined to pay, the group published data. Mercer notified about 143,000 individuals, with exposed data including names, dates of birth, Social Security numbers, phone numbers and home addresses.
Full threat analysis, exploitation vectors, and principal guidance below.
11 additional sections · verified field analysis · defensive doctrine
499K records analyzed
Mercer Advisors is one of the largest US registered investment advisor (RIA) and wealth-management firms, managing financial planning, investments and related services for individual clients.
A wealth-management firm holds client identity and contact data, dates of birth, Social Security numbers and financial-account and planning information.
ShinyHunters breached Mercer around February 16, 2026, issued a 48-hour ransom ultimatum, and published data after Mercer refused to pay.
Mercer faced multiple class-action lawsuits and regulatory scrutiny as an RIA, with the breach highlighting cybersecurity gaps in wealth management.
• Identity theft and synthetic identity construction using government-issued IDs | • Identity verification bypass using name + date of birth combination | • SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure
A financial-institution breach: account, wealth or payment data supports direct fraud and highly credible financial-impersonation scams. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Financial extortion, data sale
A prolific data theft and extortion group that began as a database theft and resale actor and evolved toward SaaS-focused extortion. Recent activity involves vishing, credential harvesting, SSO compromise, and theft of customer data from cloud and SaaS environments.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation