← Mercer Advisors

2026 Mercer Advisors — Jan intrusion; ShinyHunters claim; multi-state AG notices from March 31

2026 17.7K records affected Share on X

Data compromised

Names, addresses, phones, emails, DOB, driver’s license/government ID, financial account numbers (varies by individual)

Technical writeup

Mercer Advisors Inc., a national wealth RIA (Denver headquarters), disclosed unauthorized access to systems storing client data with activity summarized around January 22–25, 2026. The firm’s investigation concluded March 25, 2026 that an unauthorized third party obtained certain personal information. Multi-state attorney general breach filings and mail notifications began March 31, 2026 (e.g., California, Massachusetts, Texas); early public counts included on the order of 15,486 Texas residents and 2,178 Massachusetts residents in regulatory summaries, with additional states listed in secondary trackers—total affected population may grow as filings update. In February 2026, ShinyHunters claimed a larger dark-web dump (millions of records alleged); treat actor claims as unverified versus official notices. Exposed categories described in summaries included names, contact data, driver’s license and other government ID numbers, dates of birth, and financial account numbers for some individuals. Mercer offered Experian IdentityWorks and custodial-account guidance per disclosure materials.

Root cause

Unauthorized network access; extortion group claims (ShinyHunters)

References