DataBreachLegalTeam.com
MonitoringCalifornia AG filing · May 14, 2026

Cresset Capital Management Discloses 2026 Data Breach

Cresset Capital Management, a high-net-worth wealth advisory firm, reported a data security incident in May 2026 that compromised sensitive client information. This breach may expose affected individuals to substantial risks, including potential financial fraud and identity theft, due to the nature of the exposed data.

Received a Cresset Capital Management notification letter? Find out in minutes if you qualify for compensation.

Free case review
State
California
Breach date
April 6, 2026
Reported
May 14, 2026

What may have been exposed

  • Full Name
  • Social Security Number
  • Financial Account Number
  • Date of Birth
  • Routing Number
  • Tax Return Information
  • Direct Deposit Account Details
  • Mailing Address
  • Investment and Portfolio History

Cresset Capital Management recently notified clients about a data breach that occurred on April 6, 2026, with the incident officially reported to the California Attorney General on May 14, 2026. While the specific cause is under investigation, the event signifies a failure in the firm's systems designed to protect highly confidential client data.

As a prominent wealth management firm, Cresset Capital handles an extensive array of personal and financial details essential for managing complex client portfolios. This includes sensitive records such as estate planning documents, tax information, and detailed investment histories, making such data an attractive target for cybercriminals.

The compromised data categories reportedly include Full Name, Social Security Number, Financial Account Number, Date of Birth, Routing Number, Tax Return Information, Direct Deposit Account Details, Mailing Address, and Investment and Portfolio History. Exposure of these specific data types significantly elevates the risk of sophisticated identity theft, account takeover, and financial fraud.

Firms like Cresset Capital Management are legally obligated by both federal and state laws, including the Gramm-Leach-Bliley Act, to implement robust security measures to protect nonpublic personal information. A breach of this magnitude suggests potential shortcomings in these required safeguards, whether in technical defenses, administrative oversight, or employee training protocols.

If you have received a data breach notification letter from Cresset Capital Management, it confirms that your sensitive information was exposed due to this incident. Receiving such a letter provides you with legal standing to explore your options, even if you haven't yet experienced financial harm. The mere exposure of your data and the increased risk of future identity theft can constitute a compensable injury under the law.

Our dedicated team of attorneys is currently monitoring this breach and evaluating potential claims on behalf of affected individuals. We offer free case reviews to help you understand your rights and determine the best course of action. We operate on a contingency fee basis, meaning you will not pay any upfront costs and only owe legal fees if we successfully recover compensation for you.

Received the Cresset Capital Management notification letter? The Cresset Capital Management case file tracks this filing.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Guard against tax fraud

    File your tax return as early as possible and consider requesting an IRS Identity Protection PIN so no one can file a fraudulent return in your name.

  • Watch your financial accounts

    Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: California Attorney General filing

Related data breach cases