Financial institution · Wealth management and advisory services · Investment advisory firm · USA
Wealth management and advisory firm.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
In February 2026, the extortion group ShinyHunters claimed a breach of Pathstone Family Office, LLC, an ultra-high-net-worth wealth manager with about $170 billion in assets, alleging total exfiltration of its Salesforce environment and internal file systems (~15 GB compressed). The actor claimed roughly 641,000 records and detailed profiles of about 91,257 clients including financial intelligence, client contracts, legal paperwork, and estate-planning details, and set a March 2, 2026 ransom deadline. A DataBreach.com parse of circulating data confirmed contact-level identifiers (names, emails, phone numbers, street addresses) for about 48,246 individuals; the richer financial/estate data remains an actor claim not independently confirmed in circulation. Pathstone had not officially confirmed the incident as of the latest reporting.
Pathstone Family Office, LLC is a large U.S. registered investment advisor and multi-family office serving ultra-high-net-worth individuals and families, operating at least 22 offices nationwide and overseeing more than $170 billion in assets. It aggregates highly sensitive financial, estate, tax, beneficiary, and contact information to manage assets and coordinate advisory work. (Not to be confused with the same-named behavioral-health nonprofit Pathstone Corporation.)
Wealth-management firms collect highly sensitive investor identity, financial records, account data, beneficiary information, and advisory relationship records across planning and asset-management workflows.
ShinyHunters listed Pathstone Family Office on its extortion site on February 27, 2026, with a March 2, 2026 ransom deadline, and later advertised a ~15 GB compressed Salesforce database for sale. Pathstone had not officially confirmed the incident as of the latest reporting; class-action investigations were opened. The attack is part of a wave of ShinyHunters Salesforce-targeted breaches of wealth-advisory firms (also naming Mercer Advisors and Beacon Pointe).
Because inclusion in Pathstone’s data identifies someone as an ultra-high-net-worth client, exposure carries outsized risk of targeted spear-phishing, advisor impersonation, extortion, and even physical-security threats to wealthy families, beyond ordinary identity-theft concerns. ShinyHunters claims the stolen Salesforce dataset includes detailed client profiles with financial intelligence and estate-planning details, which if released would sharply amplify these risks.
• Highly targeted spear-phishing and advisor/wire-fraud impersonation against ultra-wealthy clients | • Extortion leveraging affluent-client status and (claimed) financial/estate data | • Physical-security and kidnapping-risk targeting of wealthy families via exposed addresses | • Doxxing and property targeting from street-address exposure | • Account takeover and social engineering using client contact and profile data
A financial-institution breach: account, wealth or payment data supports direct fraud and highly credible financial-impersonation scams. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Financial extortion, data sale
A prolific data theft and extortion group that began as a database theft and resale actor and evolved toward SaaS-focused extortion. Recent activity involves vishing, credential harvesting, SSO compromise, and theft of customer data from cloud and SaaS environments.
Because this breach involves public-facing or high-profile individuals, confirming anyone’s presence could aid harassment or targeting. We confirm exposure only to the individual concerned. Verify your identity to privately check your own exposure.
We will only confirm whether a specific person appears in this breach to that person.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation