DataBreachCaseFile.com
MonitoringWashington AG filing · March 23, 2026

The Hightower Holding, LLC (Hightower Advisors, LLC, Hightower Securities, LLC, Hightower Trust Company, N.A.) Data Breach: Reported Filing Facts

Hightower Holding, LLC, operating through its prominent subsidiaries including Hightower Advisors, LLC, Hightower Securities, LLC, and Hightower Trust Company, N.A., represents a major wealth management and financial services enterprise. Serving high-net-worth individuals, families, and institutional clients, the firm manages billions in assets and provides comprehensive financial planning, investment management, fiduciary oversight, and securities brokerage services. Because of the nature of its core business, Hightower acts as a massive repository for highly sensitive personal and financial information. To execute comprehensive wealth management strategies, estate planning, and trust administration, the company routinely collects and maintains extensive personal dossiers containing deep financial, legal, and identity-related data for thousands of clients nationwide.

State
Washington
Reported
March 23, 2026

What may have been exposed

  • Full Name
  • Social Security Number
  • Date of Birth
  • Financial Account Number
  • Routing Number
  • Trust and Estate Documentation
  • Investment and Transaction History
  • Mailing Address

In 2026, Hightower reported a significant security incident to the Washington Attorney General's Office, alerting clients and regulatory authorities to an unauthorized compromise of its network infrastructure. In the wealth management and financial sector, breaches of this magnitude typically involve sophisticated cyberattacks, unauthorized network intrusion, or vulnerabilities within third-party vendor systems used for financial reporting and client management. Threat actors aggressively target financial institutions to intercept high-value data feeds, exploit legacy software systems, or deploy ransomware capable of locking internal networks. When an enterprise managing complex financial portfolios experiences a security failure, it points to systemic vulnerabilities in access controls, inadequate network segmentation, or delays in patching known security flaws.

The data compromised in this incident likely encompasses a devastating combination of personally identifiable information and core financial credentials. Victims face the exposure of full names, dates of birth, Social Security numbers, financial account numbers, banking routing numbers, trust documents, and detailed investment transaction histories. Unlike standard retail breaches where credit cards can be quickly canceled, the exposure of core financial and identity infrastructure creates long-term, multi-layered risks. Cybercriminals armed with Social Security numbers, exact account details, and asset holdings can execute sophisticated account takeovers, orchestrate targeted wire fraud, initiate fraudulent tax filings, and apply for unauthorized loans. The exposure of trust and estate documentation further opens high-net-worth individuals to bespoke social engineering and identity theft schemes designed to drain generational wealth.

As a regulated financial institution handling consumer wealth and fiduciary assets, Hightower operated under stringent legal obligations to secure and protect client data. Under the Gramm-Leach-Bliley Act (GLBA), federal regulations mandate that financial institutions establish comprehensive administrative, technical, and physical safeguards to protect customer nonpublic personal information. Additionally, state-level consumer protection statutes, including the Washington Data Breach Notification Act, impose strict duties to maintain reasonable security practices. The occurrence of a data breach of this scale strongly indicates a failure to satisfy these statutory duties, raising serious questions regarding whether the firm implemented adequate intrusion detection, multi-factor authentication, and continuous network monitoring.

Receiving a data breach notification letter from Hightower is a formal acknowledgment that your private financial and personal information was compromised due to corporate security failures. Legally, the receipt of this letter establishes the foundational standing necessary to participate in a class action lawsuit and seek financial accountability. You do not need to wait until you experience actual financial loss, identity theft, or fraudulent transactions to assert your rights. Our firm investigates and litigates data breach cases on a contingency fee basis, meaning you pay nothing out of pocket and owe no legal fees unless we successfully recover compensation on your behalf.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Watch your financial accounts

    Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: Washington Attorney General filing

Related data breach cases