S&P 500 5,248.49 ▲ +0.42%
NASDAQ 16,402.18 ▲ +0.66%
DOW 39,127.84 ▼ −0.11%
US 10Y 4.21% ▼ −2bp
BTC $67,420 ▲ +1.28%
GOLD $2,341 ▲ +0.18%
USD/EUR 1.0824 ▼ −0.06%
VIX 13.42 ▼ −2.4%
OIL $82.16 ▲ +1.04%
DXY 104.21 ▲ +0.08%
S&P 500 5,248.49 ▲ +0.42%
NASDAQ 16,402.18 ▲ +0.66%
DOW 39,127.84 ▼ −0.11%
US 10Y 4.21% ▼ −2bp
BTC $67,420 ▲ +1.28%
GOLD $2,341 ▲ +0.18%
USD/EUR 1.0824 ▼ −0.06%
VIX 13.42 ▼ −2.4%
OIL $82.16 ▲ +1.04%
DXY 104.21 ▲ +0.08%
Latest› Regulation› Story
Regulation · June 2, 2026

Mariner Wealth Advisors Breach Exposes Data of Nearly 9,000 Clients via Cloud Apps

A November 2025 hacking incident involving three employee cloud accounts leaked names, Social Security numbers, and account details; a separate 2024 breach at an affiliate affected over 9,300 individuals.

Mariner Wealth Advisors Breach Exposes Data of Nearly 9,000 Clients via Cloud Apps Photo · James O'Connell for InvestLin

Mariner Wealth Advisors, the Overland Park, Kansas-based mega-RIA, disclosed a data breach that compromised the personal information of nearly 9,000 individuals after a criminal third party accessed cloud application accounts belonging to three employees. The firm notified Maine's Attorney General this week, detailing that the incident was detected on November 4, 2025, when suspicious activity was first observed. The affected accounts were immediately isolated, and Mariner launched an investigation with third-party forensic experts while coordinating with federal law enforcement and regulators.

According to a sample client notice filed with Maine authorities, the breach involved the download of files containing personally identifiable information. The compromised data included names, account numbers, dates of birth, and Social Security numbers or other government identification numbers. Of the 8,995 individuals impacted, 17 were residents of Maine. Mariner emphasized that client financial accounts, investment portfolios, and other assets are held on entirely separate systems at separate entities and were not affected by the incident.

The firm stated that it has engaged external researchers to monitor websites, forums, and other online sources for signs that the downloaded data has been misused, but no such malicious activity has been detected to date. Mariner reiterated its commitment to protecting client information and noted that it will continue to emphasize cybersecurity awareness in employee training and work with external advisors to fortify its defenses.

This breach is distinct from an earlier incident involving Newport Advisory, which was operating as a Mariner-affiliated entity and now does business as Mariner Wealth Advisors. In a separate filing with the Maine Attorney General, Mariner disclosed that unauthorized actors accessed and copied files from Newport's network in late December 2024, several weeks after news of Mariner's acquisition of Newport. The unauthorized activity, detected on January 12, 2025, affected 9,323 individuals.

By the numbers
8,995
individuals affected in Mariner breach
9,323
individuals affected in Newport Advisory breach
17
Maine residents among those impacted
Nov 4, 2025
date suspicious activity first detected

The incidents come amid heightened regulatory scrutiny. Under the Securities and Exchange Commission's amended Regulation S-P, which took effect for firms managing at least $1.5 billion in December 2024, registered investment advisors must notify affected clients of a data breach within 30 days of detection. Smaller firms are expected to comply starting this week. Mariner's disclosures appear to align with these requirements.

Mariner has publicly documented its investment in cybersecurity infrastructure. In a case study published by email security firm Material Security, Thomas Brittain, senior vice president of information technology at Mariner Wealth Advisors, described the firm's shift to a zero-trust approach for email security. The case study noted that Mariner, like many financial services organizations, faces frequent spear-phishing attempts. Brittain highlighted that the firm's digital environment spans multiple tenants using both Google Workspace and Microsoft 365, a complexity driven by years of acquisitions and mergers.

“Taking a Zero Trust approach to email security is critical because malicious content is always going to get through,” Brittain said in the case study. “Blockers might catch 98% of attacks, but the answer is not to get from 98% to 99% – because that's still not bulletproof.” The case study described how Mariner compressed what used to be an hours-long process to respond to phishing incidents down to minutes.

The breach underscores ongoing cybersecurity challenges for wealth management firms, which hold sensitive client data. As the industry grapples with evolving threats, advisors may want to review their own security protocols and client communication plans. For context, the broader financial advisory landscape is seeing shifts in client demographics and asset growth, such as the rise in HSA assets hitting $174 billion and the trend of nearly half of U.S. parents housing adult children, which may influence planning needs.

JO
About the author

James O'Connell

Regulation & Compliance Editor · Washington, D.C.

Covers the SEC, FINRA, DOL and state regulators from Washington, D.C.

Next story · Don't miss

Inspired Healthcare asset sale yields $713M, 59% of $1.2B raised from investors

Bankruptcy court approves sale of 30 properties, but investor recoveries remain uncertain amid fee disputes and arbitration hurdles.

Read the story →
Inspired Healthcare asset sale yields $713M, 59% of $1.2B raised from investors