Quarterly breach intelligence filtered for law firms, CPA practices & wealth managers
A single compromised email account exposed 27,000+ wealth management clients in Wisconsin. A boutique Houston CPA firm proved size buys no immunity. And a bank spent eight months learning its own customers were caught in an accounting vendor's breach. June 3 also brought amended SEC Regulation S-P fully into force for smaller RIAs — with documented vendor oversight now the standard examiners test for.
AI-generated spear phishing crossed the human-detection threshold, and the SEC issued its first enforcement actions under amended cybersecurity rules — targeting RIAs for missing documentation, not breaches.
Third-party vendor compromise doubled as a share of all breaches. Wealth managers targeted by name. A CPA firm paid $60K for an 18-month notification delay. The subprocessor problem reached enforcement stage.
OAuth tokens, SaaS integrations, and trusted vendor relationships replaced direct network attacks as the dominant breach vector. Professional services attacks up 39% YoY and 162% over five years.
BEC and credential-stuffing campaigns reached record levels. Law firm and CPA email infrastructure targeted disproportionately relative to firm size. MFA fatigue and session token theft emerged as primary entry vectors.
