Cresset Capital Management Reports Client Data Exposure Incident
Cresset Capital Management, a wealth management firm, reported a data security incident to the Vermont Attorney General on May 14, 2026. This breach involved the exposure of highly sensitive client data, including Full Names, Social Security Numbers, and financial account information. Individuals affected are advised to take proactive measures to safeguard their personal and financial identity.
- State
- Vermont
- Reported
- May 14, 2026
What may have been exposed
- Full Name
- Social Security Number
- Date of Birth
- Financial Account Number
- Routing Number
- Tax Return Information
- Direct Deposit Account Details
- Investment Portfolio Information
Cresset Capital Management, a prominent wealth management and investment advisory firm, reported a data security incident to the Vermont Attorney General on May 14, 2026. The firm indicated that it is currently monitoring the situation following unauthorized access to its digital network environments.
Due to the nature of Cresset Capital Management's business, the exposed information is highly sensitive and comprehensive. The data types reportedly compromised include Full Name, Social Security Number, Date of Birth, Financial Account Number, Routing Number, Tax Return Information, Direct Deposit Account Details, and Investment Portfolio Information.
The exposure of such detailed personal and financial records presents significant risks for affected clients. Malicious actors could potentially use this information to commit various forms of financial fraud, undertake identity theft, gain unauthorized access to existing accounts, or facilitate other sophisticated scams. The depth of client profiles held by wealth management institutions makes these incidents particularly concerning.
Individuals who receive an official notification regarding this data breach should prioritize protecting their personal and financial identity. It is strongly recommended to regularly review all financial account statements, credit card activity, and credit reports for any signs of suspicious or unauthorized transactions.
Consider placing a fraud alert or a security freeze on your credit files with the three major credit bureaus (Equifax, Experian, and TransUnion). These measures can help prevent new accounts from being opened in your name without your authorization and provide an added layer of security.
What to do if you were affected
Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Guard against tax fraud
File your tax return as early as possible and consider requesting an IRS Identity Protection PIN so no one can file a fraudulent return in your name.
Watch your financial accounts
Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Source: Vermont Attorney General filing
Related data breach cases
- Fun For Less Tours, Inc.
- Wellington at Seven Hills Homeowner's Association, Inc.
- Opportune LLP
- G.I. Medicine Associates, P.C.
- LeMaitre Vascular, Inc.
- Boston Capital Holdings LP
- Lincoln Investment Planning, LLC
- AVL Growth Partners, an Ampleo Company
- Ocracoke Health Center, Inc.
- Kurt J. Lesker Company
- Tessco, LLC
- Powerhouse Retail Services
- Nevada Estate Planning and Probate, LLC
- C2M LLC d/b/a Click2Mail