Mariner Wealth Advisors, the Overland Park, Kansas-based mega-RIA, disclosed a data breach that compromised the personal information of nearly 9,000 individuals after a criminal third party accessed cloud application accounts belonging to three employees. The firm notified Maine's Attorney General this week, detailing that the incident was detected on November 4, 2025, when suspicious activity was first observed. The affected accounts were immediately isolated, and Mariner launched an investigation with third-party forensic experts while coordinating with federal law enforcement and regulators.
According to a sample client notice filed with Maine authorities, the breach involved the download of files containing personally identifiable information. The compromised data included names, account numbers, dates of birth, and Social Security numbers or other government identification numbers. Of the 8,995 individuals impacted, 17 were residents of Maine. Mariner emphasized that client financial accounts, investment portfolios, and other assets are held on entirely separate systems at separate entities and were not affected by the incident.
The firm stated that it has engaged external researchers to monitor websites, forums, and other online sources for signs that the downloaded data has been misused, but no such malicious activity has been detected to date. Mariner reiterated its commitment to protecting client information and noted that it will continue to emphasize cybersecurity awareness in employee training and work with external advisors to fortify its defenses.
This breach is distinct from an earlier incident involving Newport Advisory, which was operating as a Mariner-affiliated entity and now does business as Mariner Wealth Advisors. In a separate filing with the Maine Attorney General, Mariner disclosed that unauthorized actors accessed and copied files from Newport's network in late December 2024, several weeks after news of Mariner's acquisition of Newport. The unauthorized activity, detected on January 12, 2025, affected 9,323 individuals.
The incidents come amid heightened regulatory scrutiny. Under the Securities and Exchange Commission's amended Regulation S-P, which took effect for firms managing at least $1.5 billion in December 2024, registered investment advisors must notify affected clients of a data breach within 30 days of detection. Smaller firms are expected to comply starting this week. Mariner's disclosures appear to align with these requirements.
Mariner has publicly documented its investment in cybersecurity infrastructure. In a case study published by email security firm Material Security, Thomas Brittain, senior vice president of information technology at Mariner Wealth Advisors, described the firm's shift to a zero-trust approach for email security. The case study noted that Mariner, like many financial services organizations, faces frequent spear-phishing attempts. Brittain highlighted that the firm's digital environment spans multiple tenants using both Google Workspace and Microsoft 365, a complexity driven by years of acquisitions and mergers.
“Taking a Zero Trust approach to email security is critical because malicious content is always going to get through,” Brittain said in the case study. “Blockers might catch 98% of attacks, but the answer is not to get from 98% to 99% – because that's still not bulletproof.” The case study described how Mariner compressed what used to be an hours-long process to respond to phishing incidents down to minutes.
The breach underscores ongoing cybersecurity challenges for wealth management firms, which hold sensitive client data. As the industry grapples with evolving threats, advisors may want to review their own security protocols and client communication plans. For context, the broader financial advisory landscape is seeing shifts in client demographics and asset growth, such as the rise in HSA assets hitting $174 billion and the trend of nearly half of U.S. parents housing adult children, which may influence planning needs.


