DataBreachPayment.com
MonitoringCalifornia AG filing · May 14, 2026

The Cresset Capital Management Data Breach: Incident Facts and Free Case Review

Cresset Capital Management operates as a prominent, high-net-worth wealth management and investment advisory firm, catering to affluent individuals, family offices, and institutional investors. Because of the nature of private wealth management, the firm routinely collects, manages, and retains vast quantities of highly sensitive financial, legal, and personal information. Clients entrust Cresset with comprehensive portfolio data, detailed estate planning documents, tax returns, and core identification records necessary to execute complex financial strategies. Consequently, the firm holds a treasure trove of private data that represents an exceptionally lucrative target for cybercriminals seeking to exploit high-value targets.

Received a Cresset Capital Management notification letter? Find out in minutes if you qualify for compensation.

Free case review
State
California
Breach date
April 6, 2026
Reported
May 14, 2026

What may have been exposed

  • Full Name
  • Social Security Number
  • Financial Account Number
  • Date of Birth
  • Routing Number
  • Tax Return Information
  • Direct Deposit Account Details
  • Mailing Address
  • Investment and Portfolio History

In 2026, Cresset Capital Management formally reported a significant security incident to the California Attorney General, signaling a breakdown in the digital defenses protecting its sensitive network architecture. While the exact vector of the breach continues to be evaluated, incidents affecting sophisticated financial institutions typically involve unauthorized external intrusions, compromised employee credentials, or vulnerabilities within third-party vendor ecosystems. In the wealth management sector, attackers frequently target legacy databases, cloud storage repositories, or client portals designed to facilitate seamless communication and document sharing, bypassing perimeter controls to quietly exfiltrate confidential files.

The data compromised in the Cresset Capital Management breach exposes victims to severe, multi-faceted risks that extend far beyond simple annoyance. Because financial institutions maintain extensive client profiles, exposed records routinely include full names, Social Security numbers, dates of birth, banking and brokerage account numbers, routing details, and comprehensive tax or estate planning documentation. Armed with Social Security numbers and financial account details, malicious actors can execute seamless account takeovers, drain investment portfolios, intercept wire transfers, and open fraudulent lines of credit. Furthermore, the inclusion of tax returns and asset inventories allows identity thieves to perpetrate sophisticated tax refund fraud and targeted phishing campaigns designed to extract even deeper financial concessions.

As a financial institution handling sensitive consumer data, Cresset Capital Management was bound by stringent legal obligations to maintain robust, multi-layered cybersecurity protocols. Under the Gramm-Leach-Bliley Act (GLBA) and applicable California data protection statutes, wealth management firms are legally required to implement administrative, technical, and physical safeguards to protect nonpublic personal information from unauthorized access and disclosure. The occurrence of a data breach of this magnitude strongly suggests potential failures in upholding these statutory duties, whether through inadequate network monitoring, delayed patching, or insufficient employee security training, leaving the firm vulnerable to legal scrutiny.

Receiving a data breach notification letter from Cresset Capital Management is a formal acknowledgement that your private financial information was compromised due to corporate security failures. Legally, the receipt of this letter establishes the necessary standing to participate in a class action lawsuit aimed at holding the institution accountable for failing to safeguard your data. Crucially, affected individuals do not need to prove that financial fraud has already occurred to seek legal redress; the increased risk of future identity theft and the loss of privacy are actionable injuries under the law. Our firm evaluates these cases on a contingency fee basis, meaning you pay nothing out of pocket and owe no legal fees unless we successfully recover compensation on your behalf.

Received the Cresset Capital Management notification letter? The Cresset Capital Management case file tracks this filing.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Guard against tax fraud

    File your tax return as early as possible and consider requesting an IRS Identity Protection PIN so no one can file a fraudulent return in your name.

  • Watch your financial accounts

    Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: California Attorney General filing

Related data breach cases