15 Jul Cyber Extortion—An Old Threat Brings New Risks to RIAs
There is one side of Cyber Liability insurance that, for many years, has gone unnoticed by the RIA community: Cyber Extortion. This coverage line provides an insured with counsel and benefits to help address a situation where a cybercriminal has demanded a ransom in exchange for stolen information or access. This was a concern back when RIA firms had their own servers and IT security was mostly internal. For many years now, these situations have not been a serious concern for the average RIA firm.
With information safely stored in the cloud, on third-party email platforms, or in third-party CRMs, most advisors who have experienced a hacking event have not received a ransom demand. Why pay a ransom for stolen information or access when the problem can be resolved by third-party backup systems? Golsan Scruggs currently serves nearly 2,500 financial firms, and on the few occasions when we have seen a ransom demand for one of our clients, counsel has always recommended not paying the ransom and simply recreating the lost data or system. Recently, however, a new type of event has occurred.
This began with some of the Enterprise RIAs like Cetera, Hightower, Pathstone Family Office, Beacon Pointe Advisors, and Mercer Advisors. These data breaches were each reported or occurred sometime between May 2025 and February 2026, and they all seem to have common themes. A cybercriminal organization was able to gain access to secured networks. The criminals then downloaded personal client information—sometimes a few hundred client files, sometimes a few thousand or hundreds of thousands. The reported loss to Mercer is nearly 5.7 million client records.
Rather than trying to use the client data for nefarious purposes, what is new to this kind of data breach is that the cybercriminals are threatening to release the data to the criminal world unless a large sum of ransom money is paid. This is not a new idea, but now the cybercriminals are going one step further—if the ransom is not paid, the criminals will mine the data for client contact information and then contact the clients directly. They will provide proof that they have hacked the RIA, tell the clients about the hacking and ransom demand, and encourage the clients to tell the RIA firm to pay the ransom.
“Reputational harm is the biggest cyber risk to an RIA firm,” says Danny Schwartze, co-founder of Your Cyber Life.
The historic response to an RIA cyber data breach has been to offer credit monitoring to clients, but it is becoming increasingly clear that the RIA’s reputation after a breach is harmed more than its pocketbook.
“Credit monitoring is like a Band-Aid on an open wound,” says Schwartze. “I liken it to someone breaking into your house—would you prefer to be told that they broke in, or would you rather train to prevent the break-in?”
Cybercriminals put a lot of energy into going after these large RIA firms with tens of billions of dollars in assets under management. Those firms are the natural target, but sophisticated crime organizations can easily scale this to target small to mid-sized RIAs. Recently, a smaller, SEC-registered RIA experienced a similar attack. Cybercriminals were able to trick an employee through a phishing scheme, access client data, demand a ransom, and then contact clients to cause reputational harm to the advisory firm and encourage payment of the ransom.
At Golsan Scruggs, we like to say, “We scare because we care.” I quote that as a preface to this question: Imagine all of your clients being told by a criminal that they need to encourage you to pay a ransom or their information will be fully released. What would you do?
The best defense against these claims is to prevent them from happening in the first place. Your Cyber Life and other cybersecurity training businesses provide a number of best practices regarding cybersecurity for RIA firms. Danny Schwartze encourages RIA owners to make some basic considerations for their firms:
- Make cybersecurity part of the culture of your business. Don’t just rely on your IT firm; internally review cybersecurity often. Encourage your employees to ask questions or report anything suspicious.
- Unfortunately, zero trust is the new normal. Never trust; always verify. Develop a couple of different verification methods and stick to them.
- Train regularly to keep cybersecurity top of mind. It is important to recognize that cybercriminals are professional and sophisticated, and that you are their target.
The cybersecurity landscape continues to change; cybercrime organizations are constantly trying to develop the next software to hack your computer or script the next social engineering scheme to fool you or your clients. Golsan Scruggs continues to watch over the RIA risk management landscape and provide updates on the risks for RIA businesses. To review your current situation, please call 503-244-0297.
Resources:
Mercer Advisors (Being Sued)
Beacon Pointe Advisors
https://straussborrelli.com/2026/02/23/beacon-pointe-advisors-data-breach-investigation/
Pathstone Family Office (Being Sued)
https://citywire.com/ria/news/pathstone-sued-by-former-intern-over-data-breach/a2486273
Tufton Capital Management
https://www.financialadvisoriq.com/c/5051734/704194/mercer_discloses_data_breach_recently_acquired
EP Wealth Advisors (Being Sued)
Edelman Financial Engines
https://www.thinkadvisor.com/2026/02/05/edelman-financial-engines-hit-with-data-breach/
https://citywire.com/ria/news/alleged-crypto-scam-victim-sues-edelman-after-liquidating-ira/a2470310
Hightower (Being Sued)
Cetera (Being Sued)
https://citywire.com/ria/news/cetera-suffers-data-breach/a2487110
By Philip Bailey – Golsan Scruggs
Golsan Scruggs is an insurance brokerage firm operating throughout the United States specializing in investment advisor E&O errors & omissions insurance (aka professional liability insurance) for RIA registered investment advisors. As one of the largest insurers of RIA firms in the U.S., we have a dedicated staff that understands the risks of the financial services industry and delivers superior results. We make the underwriting process painless.
At Golsan Scruggs, we believe it is incumbent upon us to earn the right to be appointed as your insurance and risk-management agent. Our RIASURE process exists to serve that purpose.
Our RIASURE Review will analyze your fiduciary exposures, provide rate details and comparisons, and provide a contract comparison. No application required.
To obtain your complimentary RIASURE Review, please provide the following information or contact us at (800)273-5883. Fields marked with * are required.