Hightower Holding LLC, parent of Hightower Advisors and related U.S. advisory businesses, disclosed a cybersecurity incident in which an unauthorized party used compromised user credentials to access its network. Public regulatory summaries described activity around 8–9 January 2026 and further file access via a separate compromised account around 19–20 January 2026. Stolen files included names, Social Security numbers, and driver’s license numbers; Maine filings listed 131,483 affected individuals, with consumer notices summarized around late March 2026.
Why credential theft still matters at RIA scale
Wealth and advisory firms hold high-value identity data. Even without a public ransomware brand, credential-based intrusion can yield bulk PII suitable for fraud and targeted attacks.
Canonical record: Hightower Holding 2026 on BreachHistory.
Source: SecurityWeek