DataBreachLegalCenter.com
Investigation OpenMassachusetts AG filing · May 14, 2026

The Cresset Capital Management (“Cresset”) Data Breach: Incident Facts and Free Case Review

Cresset Capital Management ("Cresset") operates as a prominent wealth management and investment advisory firm, catering to high-net-worth individuals, family offices, and institutional clients. Because of the sophisticated financial services it provides, Cresset routinely collects, processes, and maintains an extraordinary volume of highly sensitive personal and financial data. This includes comprehensive client portfolios, estate planning documents, tax identification records, banking details, and intimate details regarding personal wealth and asset distribution. The preservation of this data is central to the fiduciary duty Cresset owes to its clientele, making the security and confidentiality of these digital assets an absolute operational necessity. In 2026, Cresset reported a significant data security incident to the Office of the Attorney General of Massachusetts, alerting regulators and affected individuals that its network infrastructure had been compromised. While the exact vectors of the attack are still being scrutinized, security incidents affecting premier financial institutions typically involve sophisticated cyberattacks, such as unauthorized intrusions into centralized databases, deployment of targeted ransomware, or vulnerabilities within third-party vendor ecosystems. In the wealth management sector, threat actors actively target systems containing high-value financial records and personally identifiable information, seeking to exploit institutional blind spots and circumvent perimeter security controls. The data compromised in the Cresset breach reportedly exposes a wealth of sensitive categories, each carrying severe implications for affected account holders. The exposed information typically includes full legal names, Social Security numbers, dates of birth, home addresses, financial account and routing numbers, investment portfolio details, and tax-related documents. The exposure of this information creates immediate and long-term risks, including unauthorized financial account takeover, fraudulent tax filings, and sophisticated spear-phishing campaigns designed to trick clients into wiring funds or disclosing additional credentials. Because wealth management clients are prime targets for high-ticket financial fraud, the exposure of these dossiers significantly elevates their risk profile for severe identity theft. As a financial institution entrusted with nonpublic personal information, Cresset is subject to strict regulatory standards, including the safeguards and privacy provisions of the Gramm-Leach-Bliley Act (GLBA) and applicable state data protection statutes. These legal frameworks mandate that financial entities implement rigorous administrative, technical, and physical safeguards to protect sensitive client data from unauthorized access or disclosure. The occurrence of a data breach of this magnitude strongly suggests a failure to maintain adequate cybersecurity defenses, pointing toward potential systemic negligence in monitoring network activity, encrypting sensitive repositories, or vetting third-party access points. Receiving a data breach notification letter from Cresset serves as formal legal notice that your private financial and personal information has been compromised through no fault of your own. Under modern legal standards, the receipt of such a notice often establishes the legal standing necessary to participate in a data action lawsuit, without requiring you to demonstrate that financial theft has already occurred. Our firm is currently investigating potential class action claims against Cresset on a contingency fee basis, meaning you pay nothing out of pocket and owe no attorney fees unless a financial recovery is successfully secured on your behalf.

State
Massachusetts
Reported
May 14, 2026

What to do if you were affected

These general steps can help limit the risk of identity theft and fraud after any data breach.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Related data breach cases