Hackers Are Attacking Wealth Management Firms Including Mercer, Beacon Pointe. What's at Risk. -- Barrons.com

Dow Jones
Mar 03

By Kenneth Corbin

"ShinyHunters" might sound reminiscent of the title of smash-hit animation film KPop Demon Hunters, but it is neither fiction nor entertaining. Instead, it is the name of a hacking group known for infiltrating corporate systems and attempting to extort victims by threatening to expose sensitive information about clients and internal operations. Wealth management firms Mercer Global Advisors and Beacon Pointe appear to be among its latest targets.

A report last week said the group has released millions of records from the two firms to the dark Web. Mercer and Beacon Pointe also recently appeared on other websites listing companies targeted by ShinyHunters.

The cases underscore the persistent threat that bad actors pose to financial services firms and their client data.

Denver-based Mercer acknowledges being the target of a recent attack but wouldn't identify the perpetrators. It says the damage was "contained" and acknowledged the breach targeted client information, although it wouldn't say how many clients were affected or what sort of information was compromised.

"We recently became aware of an issue involving unauthorized access to some of our systems used to store client data," Mercer says. "We are actively investigating the matter with the assistance of leading cybersecurity experts, and we have also notified law enforcement."

Beacon Pointe declined to comment. But in a notification letter filed with Massachusetts authorities, the Newport Beach, Calif.-based firm confirmed a recent data breach and offered to enroll affected clients in an Experian identity-monitoring service. Beacon Pointe could face a class-action lawsuit, as lawyers working with ClassAction.org are asking to hear from clients whose information may have been compromised in the attack.

ShinyHunters has been linked to multiple high-profile hacking incidents, and it is known to U.S. and foreign authorities. The group is believed to be associated with the cybercrime outfits Lapsus$ and Scattered Spider, which loosely operate under the collective Scattered Lapsus$ Hunters that made waves following its alleged involvement with recent breaches of Salesforce and Salesloft systems through social-engineering attacks that affected large companies including Google and Cisco.

In a blog post last June, Google described the breach as the product of a voice phishing attack, in which the hackers impersonate IT support personnel over the phone to gain access to a company's systems. "In all observed cases, attackers relied on manipulating end users, not exploiting any vulnerability inherent to Salesforce," Google wrote.

That style of attack, which uses stolen credentials rather than evading or disabling a firm's cyber defense system, can be especially dangerous given that the target might not become aware of the breach until weeks or months after the intrusion.

"They have gone undetected," says Ryan Quirk, founder and CEO of the cybersecurity firm Sparrow Risk Group. "They have had time to figure out who is who in the organization, where the data is kept, determined how to commandeer the data and exfiltrate it out. For the malevolent actor, this becomes an easy ransom demand."

A different kind of ransomware ring. ShinyHunters operates slightly differently from traditional ransomware rings. Instead of encrypting and locking organizations out of their own files, the group and its affiliates threaten to leak sensitive information and call public attention to the organizations. Some of the messages it sends to its targets, including those purportedly sent to Mercer and Beacon Pointe, offer a short window to engage with the hackers before they say they will leak data and inflict "several annoying (digital) problems" on the organization. "Make the right decision, don't be the next headline," said the messages, which were posted on leak sites.

It can be difficult to take the real measure of a group such as ShinyHunters. Allison Nixon, a researcher at the cybersecurity group Unit 221B, says those types of ransomware groups often make outlandish claims and that their style of emotional intimidation takes its cues from sextortion campaigns targeting teenagers, which were marked by threats to leak embarrassing content such as nude photos. "This is highly effective on young children but it should not have the same level of success with a corporation," she writes in a blog post urging companies not to pay any ransom demands.

Nixon describes the individuals who engage in attacks under the banner of ShinyHunters or a similar outfit as generally young, socially isolated males prone to infighting, drug abuse, and erratic behavior. Posts on leak sites and ransomware-tracking sites claim that the attack on Mercer compromised more than five million records and that the BeaconPointe breach covered more than 100,000 records, figures the companies won't confirm or deny.

Posts have also claimed an attack on robo-advisor Betterment and, more recently, wealth manager Pathstone Family Office. Betterment has been providing regular updates on a breach that occurred in January, but a spokeswoman says that incident wasn't a ransomware operation. A spokeswoman for Pathstone declined to comment, citing the firm's policy not to address "matters that pertain to our clients' privacy and security."

What to do. Nixon of Unit 221B argues that "breached data is breached, and no ransom payment or promises by criminals will un-breach it," and that ShinyHunters and similar groups can't be trusted to keep their word to delete the information they have stolen even if their demands are met. Instead, she suggests that companies are best served by ignoring the emotional component of the threat and focusing their efforts on notifying clients and working with law-enforcement and outside experts to mitigate the damage.

"Once the situation has been properly assessed...move as quickly as possible to demonstrate noncompliance to the ransom request," Nixon advises. "Politely acknowledge the ransom request was received, and tell the threat group that you will be declining to pay the ransom."

Write to advisor.editors@barrons.com

This content was created by Barron's, which is operated by Dow Jones & Co. Barron's is published independently from Dow Jones Newswires and The Wall Street Journal.

 

(END) Dow Jones Newswires

March 02, 2026 15:12 ET (20:12 GMT)

Copyright (c) 2026 Dow Jones & Company, Inc.

At the request of the copyright holder, you need to log in to view this content

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10