DataBreachCaseFile.com
MonitoringMaine AG filing · May 20, 2026

The Conrad Capital Management, Inc. Data Breach: Reported Filing Facts

Conrad Capital Management, Inc. operates within the financial services and wealth management sector, serving high-net-worth individuals, institutional clients, and private investors. As an investment management and financial advisory firm, the company is entrusted with extraordinarily sensitive private information. To perform comprehensive financial planning, portfolio management, tax strategizing, and asset administration, Conrad Capital must collect and store vast quantities of non-public personal information. This repository typically includes deep financial histories, banking details, tax identification documents, and comprehensive demographic data necessary to execute fiduciary responsibilities on behalf of its clientele.

State
Maine
Reported
May 20, 2026

What may have been exposed

  • Full Name
  • Social Security Number
  • Date of Birth
  • Financial Account Number
  • Routing Number
  • Tax Return Information
  • Investment Portfolio Details
  • Home Address

In 2026, Conrad Capital Management, Inc. formally reported a significant cybersecurity incident to the Office of the Maine Attorney General. While the precise vectors of the attack continue to be scrutinized, security incidents affecting financial institutions frequently involve sophisticated cyber threats such as targeted ransomware deployments, credential harvesting attacks, unauthorized database access, or vulnerabilities within third-party financial software vendors. In the financial sector, threat actors aggressively target infrastructure knowing that successful breaches yield high-value dossiers capable of facilitating immediate asset liquidation, fraudulent credit applications, and elaborate identity theft schemes.

The breach exposed a wide array of highly sensitive personal and financial data elements, each creating severe, long-term risks for affected individuals. Compromised data fields characteristically include full names, dates of birth, Social Security numbers, bank account and routing numbers, investment portfolio details, and tax identification records. When exposed, this combination of data allows malicious actors to execute account takeovers, siphon funds from investment or checking accounts, file fraudulent tax returns to intercept government refunds, and open unauthorized lines of credit in the victims' names. The financial and emotional toll of remediating these multifaceted identity thefts can persist for years.

As a financial institution handling consumer funds and private wealth, Conrad Capital Management, Inc. was bound by stringent legal obligations to safeguard this sensitive information. Under the Gramm-Leach-Bliley Act (GLBA) and applicable state data protection laws, financial entities are required to maintain robust administrative, technical, and physical safeguards to protect customer records against foreseeable threats and unauthorized access. The occurrence of a data breach of this magnitude strongly suggests potential failures in implementing adequate network segmentation, multi-factor authentication, intrusion detection systems, or vendor risk management protocols, raising serious questions about whether the company met its legal standard of care.

Receiving an official data breach notification letter from Conrad Capital Management, Inc. serves as formal legal acknowledgement that your confidential information was compromised due to corporate security inadequacies. Under modern consumer privacy jurisprudence, the receipt of such a notice establishes legal standing to participate in a class action lawsuit aimed at holding the company accountable for failing to protect your data. You do not need to wait until financial fraud has already occurred to take legal action. Our firm investigates these data security failures on a contingency fee basis, meaning there are never any out-of-pocket costs or fees unless we successfully recover compensation on your behalf.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Guard against tax fraud

    File your tax return as early as possible and consider requesting an IRS Identity Protection PIN so no one can file a fraudulent return in your name.

  • Watch your financial accounts

    Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: Maine Attorney General filing

Related data breach cases