Cresset Capital Management Data Breach Notice (Vermont Attorney General): What Was Exposed & What To Do
Cresset Capital Management disclosed a data breach on May 14, 2026, affecting 19 individuals whose Social Security numbers, government ID numbers, financial account codes, and credit and debit account information were exposed. Vermont Attorney General records indicate the exposure; affected individuals should check their statements and consider placing fraud alerts or credit freezes.
Cresset Capital Management notified Vermont residents of a data breach in a filing reported to the Vermont Attorney General on May 14, 2026. According to that notice, the incident affected 19 people and involved exposure of Social Security numbers, government ID numbers, financial account codes, and credit and debit account information. For a wealth-management firm that routinely handles sensitive personal and financial records, even a relatively small confirmed count of affected individuals carries lasting practical consequences for those named in the notice.
Public detail beyond the Vermont filing remains limited. What is known so far comes directly from the regulator-reported notice: the organization, the reporting date, the number of people affected, and the categories of data listed as exposed. No further technical timeline, intrusion method, or broader geographic scope has been supplied in the available record.
What happened
On May 14, 2026, Cresset Capital Management’s data-breach notice was reported to the Vermont Attorney General. The filing states that 19 individuals were affected. The notice explicitly lists Social Security numbers, government ID numbers, financial account codes, and credit and debit account information among the data elements exposed.
The public record does not describe how the incident was discovered, whether systems were accessed remotely or through another vector, how long any unauthorized access lasted, or whether data was exfiltrated in bulk or viewed in place. Timing details prior to the May 14, 2026 reporting date, the precise number of systems involved, and any containment steps taken by the firm are undisclosed in the materials available. The notice is limited to the fact of notification, the headcount of 19, and the named data categories.
How a breach like this happens
Incidents that result in exposure of Social Security numbers, government identifiers, and financial account details typically follow a small number of well-understood patterns, none of which can be confirmed as the cause in this specific case. Attackers often obtain initial access through stolen or guessed credentials, phishing messages that harvest login information, or unpatched remote-access services. Once inside a network, they may move laterally to file shares, customer-relationship systems, or backup repositories where concentrated personal and financial records are stored.
In other common scenarios, a misconfigured cloud storage bucket, an unsecured database, or a third-party vendor with overly broad access can expose the same classes of data without a dramatic “break-in.” Ransomware groups sometimes exfiltrate data before encryption as leverage; in other cases, opportunistic thieves simply copy what they find. Because no threat actor or technical method is attributed in the Cresset notice, these remain general background descriptions of how breaches of this data type usually unfold, not statements about the firm’s incident.
Organizations that hold high-value identity and financial data are attractive targets precisely because the information can be reused for fraud long after the initial compromise. Defensive measures such as multi-factor authentication, network segmentation, encryption at rest, and continuous monitoring reduce but never eliminate the possibility of exposure.
Cresset Capital Management and its sector
Cresset Capital Management operates in the wealth-management and investment-advisory sector. Firms of this type typically maintain detailed client files that include identity documents, tax identifiers, bank and brokerage account numbers, transaction histories, and sometimes copies of government-issued IDs. They also hold contact information, beneficiary designations, and records needed for regulatory compliance and tax reporting.
Because the business model depends on trust and on the secure handling of precisely the data types named in the Vermont notice, a breach notification carries reputational and operational weight even when the confirmed number of affected individuals is modest. Clients expect that Social Security numbers and account credentials will remain confidential; any confirmed exposure therefore raises immediate questions about ongoing account security and long-term identity risk. The sector is heavily regulated, and state attorney-general notifications such as the one filed on May 14, 2026, form part of the mandatory transparency framework that applies when personal information of residents is involved.
What was likely exposed
The Vermont notice names four categories as exposed: Social Security numbers, government ID numbers, financial account codes, and credit and debit account information. These are the only data types confirmed in the public record. No additional fields—such as dates of birth, home addresses, email addresses, or full transaction histories—are listed, so their presence or absence cannot be asserted.
Organizations in wealth management routinely store exactly these high-sensitivity elements because they are required for account opening, tax reporting, wire transfers, and identity verification. When a notice lists them, the practical assumption for affected individuals is that the core identifiers needed for financial fraud and identity theft may now be in unauthorized hands. Exact file names, record counts beyond the 19 people, or the format in which the data existed remain unconfirmed.
The real-world impact
For the 19 people named in the notice, the concrete risks center on identity theft and financial fraud. A Social Security number combined with a government ID number and credit or debit account details can be used to open new lines of credit, file fraudulent tax returns, drain or redirect existing accounts, or impersonate the victim in dealings with other financial institutions. Because these identifiers do not expire easily, the exposure window can last years rather than weeks.
Affected individuals may face time-consuming credit freezes, extended fraud alerts, manual review of account statements, and the possibility of disputed transactions. The firm itself faces notification costs, potential regulatory inquiries, and the need to support clients through remediation. Even a small confirmed population of 19 does not reduce the severity of harm for each person whose full set of listed identifiers was involved; it simply limits the total number of people who must take protective steps.
No dollar losses, confirmed fraud cases, or secondary victim counts are stated in the available notice, so those outcomes remain outside the established facts.
Were you affected?
If you are or have been a client of Cresset Capital Management, review any direct correspondence the firm may have sent regarding the May 14, 2026 notice. Place a fraud alert or credit freeze with the major credit bureaus, monitor bank and credit-card statements for unfamiliar activity, and consider requesting a free annual credit report. Change passwords on related financial accounts and enable multi-factor authentication wherever it is offered. Because only 19 people are listed in the Vermont filing, most clients will not be among those affected; the notice itself is the authoritative source for individual status.
As an additional check, readers can run a free exposure scan of their email address to see whether that address has appeared in other known breach data sets. That step does not confirm or deny inclusion in the Cresset incident, but it can surface unrelated exposures that warrant the same protective measures.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Arthur J. Jerry Data Breach Notice (Vermont Attorney General)Access Residential Management Data Breach Notice (Vermont Attorney General)Covercraft Industries, LLC Data Breach Notice (Vermont Attorney General)Advantest America, Inc. Data Breach Notice (Vermont Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.