2026 Hightower Holding — ~131K individuals (credential compromise; names, SSNs, DLs)
Data compromised
Names, Social Security numbers, driver’s license numbers
Technical writeup
Hightower Holding LLC, parent of Hightower Advisors and related U.S. wealth-management businesses, disclosed a data security incident in which an unauthorized actor accessed its network using compromised user credentials. Public regulatory-style summaries described activity around January 8–9, 2026 and additional unauthorized file access via a different compromised account around January 19–20, 2026. Stolen files contained names, Social Security numbers, and driver’s license numbers. Maine Attorney General filings cited 131,483 affected individuals; consumer notices referenced outreach around late March 2026. The company attributed the event to compromised credentials rather than a stated environmental deficiency and offered identity monitoring.
Root cause
Compromised user credentials; unauthorized network access