KerberRose Wealth Management Breach Post Mortem: One Inbox, 27,000 People

A single compromised email account at a wealth management firm reached a backup platform holding clients’ Social Security numbers and bank details. Here is how it happened — and what amended Regulation S-P now expects from you.

Bottom line up front: An attacker took over one employee mailbox at KerberRose Wealth Management — itself an SEC-registered investment adviser. That single mailbox compromise resulted in limited access to part of a backup platform that held bulk client data. Public breach reporting puts the count at roughly 27,076 people, exposing names, addresses, Social Security numbers, financial account numbers, bank account information, and dates of birth. The firm found out two days later and notified within 28 days. For an SEC-registered RIA, this is not an analogy — it is the exact scenario amended Regulation S-P now governs. The lessons are about identity, segmentation, and backup access — not exotic malware.

The rest of this article is free to read with a BrainTrust membership — joining takes about a minute, and no credit card is required.

Join the BrainTrust   Already a member? Sign in

Done For You

Need it handled for you? Remote CISO and cyber compliance engagements for RIAs →