Cresset Capital Management (“Cresset”) Data Breach Notice (Massachusetts Attorney General): What Was Exposed & What To Do
Cresset Capital Management (“Cresset”) has notified the Massachusetts Attorney General of a data breach that came to light on May 14, 2026, exposing the Social Security numbers, financial account numbers, and driver’s license numbers of 131 individuals. Anyone who received notice or believes their information may have been involved should review the notice, place a fraud alert or credit freeze, and monitor their accounts for unauthorized activity.
Cresset Capital Management (“Cresset”) notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on May 14, 2026. According to that notice, the incident involved the exposure of Social Security numbers, financial account numbers, and driver’s license numbers, and it affected 131 people.
Public detail beyond the regulator filing is limited. What is known so far is the organization involved, the date the notice was reported, the number of people listed as affected, and the categories of information named as exposed. Those facts matter because the data types are the kind commonly used in identity theft and account fraud.
Inside the incident
The available record is a data-breach notice from Cresset Capital Management (“Cresset”) associated with a Massachusetts Attorney General / Office of Consumer Affairs filing reported on May 14, 2026. The notice states that Social Security numbers, financial account numbers, and driver’s license numbers were among the information exposed. It lists 131 people as affected.
The filing does not publicly describe how the incident occurred, when unauthorized access began or ended, whether systems were encrypted or ransomed, or whether a specific intrusion method was confirmed. Scale beyond the stated figure of 131 people, the full geographic scope outside Massachusetts residents who were notified, and any forensic timeline are not detailed in the facts provided. No threat group is attributed in the disclosure.
In short, the confirmed core is regulatory notification of a breach affecting a defined number of people and naming three sensitive data categories. Other operational particulars remain undisclosed in the material at hand.
How a breach like this happens
Incidents that lead to notices naming Social Security numbers, financial account numbers, and government ID numbers often follow familiar patterns in the wider industry, though none of these patterns is confirmed for this specific case. Attackers may obtain credentials through phishing or reused passwords, exploit unpatched remote-access software, or abuse a compromised vendor account that already has legitimate access to client files. Once inside, they may copy databases, document stores, or backup sets that contain identity and account fields.
In other cases, a misconfigured cloud storage bucket, an exposed file-transfer system, or malware on a workstation used for wealth-management work can lead to the same result: bulk export of records that were never meant to leave the firm’s control. Ransomware groups sometimes exfiltrate data before encryption and later claim they hold it; other actors simply sell or dump the files. Because no method or actor is named in the Cresset notice facts, these remain general background illustrations only, not a description of what happened here.
Organizations that hold high-value personal and financial data are frequent targets precisely because the information can be reused for tax fraud, new-account opening, and social-engineering attacks against banks. Defensive practice typically includes multi-factor authentication, least-privilege access, monitoring for unusual data transfers, and rapid containment when anomalies appear—but the presence or absence of any particular control in this incident is not stated in the public notice summary.
Who is Cresset Capital Management (“Cresset”)?
Cresset Capital Management (“Cresset”) is a firm operating in the wealth- and investment-management sector. Firms of this type typically advise high-net-worth individuals and families, manage investment portfolios, and coordinate banking, trust, or estate-related services. In the ordinary course of that work they collect and retain identity documents, tax identifiers, account numbers, and related personal details needed to open accounts, meet regulatory know-your-customer rules, and execute transactions.
A breach at such an organization is consequential because the data set is both concentrated and durable. Social Security numbers and driver’s license numbers do not expire quickly; financial account numbers can be used to attempt unauthorized transfers or to craft convincing fraud against the account holder’s other institutions. Even when the number of people listed is relatively modest—as here, 131—the sensitivity of each record can be high. Clients and prospects of wealth managers often assume confidentiality as a core part of the relationship; any confirmed exposure therefore carries reputational and practical weight for both the firm and the individuals named in the notice.
What was likely exposed
The Massachusetts notice names the following categories as among the information exposed: Social Security numbers, financial account numbers, and driver’s license numbers. Those are the only data types confirmed in the facts provided. The notice does not itemize every field in every file, nor does it state whether names, addresses, dates of birth, email addresses, or other contact details were also included. Exact file contents beyond the named categories remain unconfirmed.
Organizations in this sector commonly hold additional records—tax forms, beneficiary designations, wire instructions, and correspondence—but it would be inaccurate to treat those as established elements of this breach. Readers should rely only on the categories the firm reported: government identity numbers and financial account numbers for the 131 people referenced in the filing.
Why it matters
For affected individuals, exposure of a Social Security number combined with a driver’s license number and financial account data raises concrete risks. Criminals can attempt to open new credit lines, file fraudulent tax returns, take over existing brokerage or bank accounts, or impersonate the person when calling institutions. Recovery can require placing fraud alerts, monitoring credit, and working with banks to replace account numbers—steps that take time even when no money is ultimately lost.
For the organization, the incident creates notification obligations, potential regulatory scrutiny, and the need to support clients who may face secondary fraud. The reported count of 131 people is limited in absolute terms, yet each case involves highly sensitive identifiers. Because the disclosure does not describe root cause or containment measures, outside observers cannot independently assess residual risk from the same vector; that assessment rests with the firm and its investigators.
There is no public attribution in the facts to a named criminal group, and no dollar loss figure is provided. The practical significance rests on the data types and the confirmed affected population rather than on unverified claims of scale or motive.
If your data was in this breach
If you believe you are among the people Cresset notified, or if you are a client who received a letter referencing this incident, consider the following practical steps:
- Read the notice carefully for any reference number, the exact data categories listed for you, and any offer of credit monitoring or identity-protection services, and enroll within the stated deadline if you choose to use them.
- Place a free fraud alert with one of the major credit bureaus and consider a credit freeze if you want to block new-account opening in your name.
- Monitor bank, brokerage, and credit-card statements for unfamiliar activity; report suspicious transactions promptly to the institution.
- Be alert to phishing or phone calls that reference the breach and ask for passwords, one-time codes, or remote access—legitimate firms and bureaus will not demand those details unsolicited.
- If a driver’s license number was involved, check your state’s guidance on whether a replacement license or heightened DMV fraud watch is advisable.
- Retain the notice and any related correspondence; they can help when disputing fraudulent accounts later.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in other known breach data sets. That check does not replace official notice from Cresset, but it can help you see whether the same address appears in unrelated incidents and decide how broadly to tighten account security.
Public detail on this event remains anchored to the May 14, 2026 Massachusetts filing: 131 people affected, and Social Security numbers, financial account numbers, and driver’s license numbers among the information exposed. Further operational facts have not been provided in the material summarized here.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Healthfirst Bluegrass, Inc. Data Breach Notice (Massachusetts Attorney General)Murfreesboro Medical Clinic Data Breach Notice (Massachusetts Attorney General)Spectrum Laboratory Products, Inc. Data Breach Notice (Massachusetts Attorney General)Alan Gordon, CPA Data Breach Notice (Massachusetts Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.