S&P 500 5,248.49 ▲ +0.42%
NASDAQ 16,402.18 ▲ +0.66%
DOW 39,127.84 ▼ −0.11%
US 10Y 4.21% ▼ −2bp
BTC $67,420 ▲ +1.28%
GOLD $2,341 ▲ +0.18%
USD/EUR 1.0824 ▼ −0.06%
VIX 13.42 ▼ −2.4%
OIL $82.16 ▲ +1.04%
DXY 104.21 ▲ +0.08%
S&P 500 5,248.49 ▲ +0.42%
NASDAQ 16,402.18 ▲ +0.66%
DOW 39,127.84 ▼ −0.11%
US 10Y 4.21% ▼ −2bp
BTC $67,420 ▲ +1.28%
GOLD $2,341 ▲ +0.18%
USD/EUR 1.0824 ▼ −0.06%
VIX 13.42 ▼ −2.4%
OIL $82.16 ▲ +1.04%
DXY 104.21 ▲ +0.08%
Latest› Practice› Story
Practice · September 17, 2026

VanEck CEO reveals cyberattack hit firm months ago; client assets untouched

Jan van Eck said attackers were 'many layers away' from client funds, underscoring persistent cybersecurity threats facing asset managers.

VanEck CEO reveals cyberattack hit firm months ago; client assets untouched Photo · Margaret Holloway for InvestLin

VanEck, the New York-based asset manager known for its exchange-traded funds and digital-asset strategies, fell victim to a cyber intrusion earlier this year, Chief Executive Jan van Eck disclosed Wednesday during a panel at the Future Proof festival in Huntington Beach, California. The attack, which van Eck described as a product of pervasive social engineering, did not compromise client funds, he said.

“We got hacked several months ago,” van Eck said. “Basically social engineering is happening every day at almost every company you've ever heard of.” His comments add VanEck to a growing roster of wealth-management firms that have disclosed security breaches in recent months, underscoring the sector's vulnerability to increasingly sophisticated threats.

Van Eck emphasized that safeguarding client assets remains the firm's top priority, and in this instance, the intruders “were many layers away from that.” He also stressed that VanEck does not retain clients' personal data, a design choice that may have limited the breach's impact. The CEO did not specify the nature of the attack, the data accessed, or the number of individuals affected, and VanEck has not filed a public disclosure with regulators.

The incident aligns with a broader pattern of cyberattacks across the financial-advisory industry. In January, the Maine attorney general's office reported that 1,581 clients of LPL Financial were affected by a phishing scam that occurred on Nov. 10, 2025. Separately, a March data breach at Ameriprise Financial impacted 47,876 clients, according to the same state regulator. These cases highlight the persistent threat of credential theft and unauthorized access.

By the numbers
1,581
LPL clients affected in phishing scam
47,876
Ameriprise clients affected in data breach
$1.25M
Fine against Fidelity for 2024 breach
9,000
People affected by Mariner cloud breach

Earlier this year, Mariner Wealth Advisors disclosed a cloud-based breach affecting nearly 9,000 individuals, while Massachusetts regulators fined Fidelity Brokerage Services $1.25 million over a client-information data breach dating back to 2024. The incidents have prompted advisors and asset managers to reassess their cybersecurity protocols, particularly as artificial intelligence tools lower the barrier for attackers.

During the Future Proof panel, van Eck offered practical advice for firms navigating this environment. “Just be super clear about who has what data,” he said, urging companies to map data flows and limit access. He also cautioned against viewing AI as a panacea for security, noting that the same technology can be weaponized by bad actors. His warning echoes a broader industry concern: as firms adopt AI for efficiency, they must also defend against AI-driven attacks.

Kate Burke, CEO of Allspring Global Investments, who shared the panel, echoed those concerns. “The cost of protecting yourself from a cybersecurity attack is increasing, from an AI attack, is increasing all of the time,” she said. “And so we work with partners to ensure we're safe, we work with our vendors to understand what their protocols are.” Burke's remarks underscore the financial and operational burden that cybersecurity now places on asset managers, a theme that resonates across the industry.

The VanEck breach comes as the firm continues to expand its product lineup, including digital-asset ETFs, which have drawn regulatory scrutiny and investor interest. While the attack did not affect client assets, it serves as a reminder that even well-capitalized firms are not immune. For advisors, the incident reinforces the need to vet third-party vendors and maintain robust internal controls, as asset managers increasingly outsource critical functions.

Industry observers note that cybersecurity has become a board-level issue, with firms allocating more resources to threat detection and response. A recent AssetMark survey found that 85% of advisors now use AI tools, but many struggle to integrate them securely. The VanEck incident, though not catastrophic, highlights the importance of proactive measures.

As the wealth-management industry grapples with these challenges, van Eck's disclosure serves as a cautionary tale. “Just be super clear about who has what data,” he reiterated, a mantra that may become increasingly central to operational resilience. For now, VanEck appears to have avoided the worst, but the episode underscores that no firm is beyond reach.

MH
About the author

Margaret Holloway

Senior Editor, Wealth Management · New York

Twenty years covering the wealth industry from New York. Former managing editor at a national wealth trade weekly.

Next story · Don't miss

Inspired Healthcare asset sale yields $713M, 59% of $1.2B raised from investors

Bankruptcy court approves sale of 30 properties, but investor recoveries remain uncertain amid fee disputes and arbitration hurdles.

Read the story →
Inspired Healthcare asset sale yields $713M, 59% of $1.2B raised from investors