The JM Forbes and Co. Data Breach: Incident Facts and Free Case Review
JM Forbes and Co. operates as a prominent private wealth management, investment advisory, and fiduciary institution, entrusted with managing the substantial financial portfolios, generational wealth, and complex estates of high-net-worth clients, family offices, and institutional accounts. Because of the sophisticated nature of their services, the firm routinely gathers, processes, and stores an extensive volume of highly sensitive personal and financial data. This includes detailed asset valuations, estate planning documents, tax identification records, trust agreements, and granular banking details required to execute high-value financial transactions and administer long-term asset management strategies. In 2026, JM Forbes and Co. reported a significant cybersecurity incident to the New Hampshire Attorney General, alerting clients and regulatory authorities to a breach of its digital network infrastructure. While specific technical forensics remain under evaluation, incidents affecting financial institutions and wealth management firms typically involve sophisticated cyberattacks such as unauthorized access to legacy databases, credential harvesting targeting administrative personnel, or third-party vendor compromises that bypass perimeter security controls. Financial sector entities remain prime targets for sophisticated threat actors seeking to exploit vulnerabilities in proprietary client portals and internal financial reporting systems. The exposure resulting from this security incident compromises a catastrophic array of sensitive information, directly threatening the financial security and privacy of affected individuals. Unauthorized access to core financial account numbers, routing details, Social Security numbers, dates of birth, and comprehensive asset portfolios creates an immediate and severe risk of identity theft, financial account takeover, and fraudulent wire transfers. Furthermore, the compromise of tax documents and estate planning files exposes clients to sophisticated tax fraud and targeted social engineering schemes designed to intercept future financial distributions and compromise auxiliary business accounts. As a fiduciary and financial institution, JM Forbes and Co. was bound by stringent federal and state regulatory frameworks, including the Gramm-Leach-Bliley Act (GLBA) and applicable New Hampshire state data protection statutes, to implement robust administrative, physical, and technical safeguards. These legal obligations mandate continuous risk assessments, multi-factor authentication, encryption of nonpublic personal information, and rigorous vendor oversight. The occurrence of a data breach of this magnitude serves as a strong indication of potential systemic failures in maintaining adequate cybersecurity measures, raising serious questions regarding the firm's compliance with its statutory duties to protect sensitive client data. For individuals who have received an official data breach notification letter from JM Forbes and Co., this correspondence serves as a formal acknowledgment that your private financial and personal information was compromised due to inadequate data security practices. Legally, the receipt of this notice establishes standing to participate in a class action lawsuit aimed at holding the institution accountable for failing to safeguard your sensitive records. Our firm evaluates these cases on a contingency fee basis, meaning you pay nothing out of pocket and owe no legal fees unless we successfully recover compensation on your behalf.
- State
- New Hampshire
- Reported
- July 6, 2026
What to do if you were affected
These general steps can help limit the risk of identity theft and fraud after any data breach.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Related data breach cases
- Janome America, Inc.
- Sullivan Environmental Services
- City of New Britain, Inc.
- New Hampshire Housing Yardi’s RentCafe
- Pocket FM
- Werth Wealth Management, LLC
- Wei Wei & Company
- Ameriprise Financial
- Joyal Financial Management Group
- Quantum Health
- HCA Healthcare, Inc.
- Alabama Symphonic Association Inc.
- Tombigbee Healthcare Authority dba Whitfield Regional Hospital
- Foster & Eldridge LLP