Pathstone.com 2026 Data Breach

Pathstone Family Office Wealth Management Breach (2026): Ultra-High-Net-Worth Client Contact Records Exposed

Financial institution · Wealth management and advisory services · Investment advisory firm · USA

Pathstone Family Office Wealth Management Breach (2026): Ultra-High-Net-Worth Client Contact Records Exposed

Wealth management and advisory firm.

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach involves high-visibility individuals, so confirming who appears in it could enable targeting. We do not disclose presence publicly or to third parties. Check your own exposure privately below.
Breach Risk Index i
87/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
48KRecords
2026Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
AddressPhysical address
Classification Tags
ShinyHuntersSocial EngineeringFinancial Services2026

Breach Summary

In February 2026, the extortion group ShinyHunters claimed a breach of Pathstone Family Office, LLC, an ultra-high-net-worth wealth manager with about $170 billion in assets, alleging total exfiltration of its Salesforce environment and internal file systems (~15 GB compressed). The actor claimed roughly 641,000 records and detailed profiles of about 91,257 clients including financial intelligence, client contracts, legal paperwork, and estate-planning details, and set a March 2, 2026 ransom deadline. A DataBreach.com parse of circulating data confirmed contact-level identifiers (names, emails, phone numbers, street addresses) for about 48,246 individuals; the richer financial/estate data remains an actor claim not independently confirmed in circulation. Pathstone had not officially confirmed the incident as of the latest reporting.

About Pathstone.com

Pathstone Family Office, LLC is a large U.S. registered investment advisor and multi-family office serving ultra-high-net-worth individuals and families, operating at least 22 offices nationwide and overseeing more than $170 billion in assets. It aggregates highly sensitive financial, estate, tax, beneficiary, and contact information to manage assets and coordinate advisory work. (Not to be confused with the same-named behavioral-health nonprofit Pathstone Corporation.)

Why They Hold Your Data

Wealth-management firms collect highly sensitive investor identity, financial records, account data, beneficiary information, and advisory relationship records across planning and asset-management workflows.

Recent Developments

ShinyHunters listed Pathstone Family Office on its extortion site on February 27, 2026, with a March 2, 2026 ransom deadline, and later advertised a ~15 GB compressed Salesforce database for sale. Pathstone had not officially confirmed the incident as of the latest reporting; class-action investigations were opened. The attack is part of a wave of ShinyHunters Salesforce-targeted breaches of wealth-advisory firms (also naming Mercer Advisors and Beacon Pointe).

Data Points Exposed

4 verified field types
Email Address
Full Name
Phone Number
Physical address High

Breach Impact

Because inclusion in Pathstone’s data identifies someone as an ultra-high-net-worth client, exposure carries outsized risk of targeted spear-phishing, advisor impersonation, extortion, and even physical-security threats to wealthy families, beyond ordinary identity-theft concerns. ShinyHunters claims the stolen Salesforce dataset includes detailed client profiles with financial intelligence and estate-planning details, which if released would sharply amplify these risks.

Exploitation & Downstream Threats

• Highly targeted spear-phishing and advisor/wire-fraud impersonation against ultra-wealthy clients | • Extortion leveraging affluent-client status and (claimed) financial/estate data | • Physical-security and kidnapping-risk targeting of wealthy families via exposed addresses | • Doxxing and property targeting from street-address exposure | • Account takeover and social engineering using client contact and profile data

Principal Risk Advisory

What this means for a principal

A financial-institution breach: account, wealth or payment data supports direct fraud and highly credible financial-impersonation scams. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  2. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  3. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
S
Threat Actor: ShinyHuntersConfidence: High
Data theft / extortion group

Motivation: Financial extortion, data sale
A prolific data theft and extortion group that began as a database theft and resale actor and evolved toward SaaS-focused extortion. Recent activity involves vishing, credential harvesting, SSO compromise, and theft of customer data from cloud and SaaS environments.

Read the full threat-actor profile →
This breach is linked to the ShinyHunters / Scattered Lapsus$ Hunters - Salesforce (2025-26) campaign. See the full campaign analysis →

Protect Yourself

Protect Yourself: Limited Disclosure

Check If You’re Affected: Verification Required

Because this breach involves public-facing or high-profile individuals, confirming anyone’s presence could aid harassment or targeting. We confirm exposure only to the individual concerned. Verify your identity to privately check your own exposure.

We will only confirm whether a specific person appears in this breach to that person.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation