Ferguson Wellman Listed by losttrust Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Ferguson Wellman Listed by losttrust Ransomware Group (reported September 26, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On September 26, 2023, the investment advisory firm Ferguson Wellman was listed by the ransomware group losttrust, which claimed to have carried out an attack involving the exfiltration of internal files. Public detail remains limited: the number of people affected is unknown, and no independent confirmation of the full scope has been widely established beyond the group’s listing itself.
For clients and others connected to an investment advisory firm that manages substantial assets, any claim of internal-file theft raises practical questions about confidentiality and follow-on risk. What is known so far is confined to the reported listing and the description of internal files taken in a ransomware incident; further specifics have not been disclosed in the available record.
Inside the incident
According to the reported information, Ferguson Wellman appeared on a losttrust leak-site listing dated September 26, 2023. The group’s claim centers on a ransomware attack in which internal files were exfiltrated. No public figure has been given for the volume of data, the precise systems involved, or the number of individuals whose information may have been included. Timing details beyond the reporting date, the initial access method, and any negotiation or recovery steps remain undisclosed.
In the absence of a detailed official disclosure in the source record, the incident is best understood as an asserted ransomware event with data theft, attributed by the group to itself via its listing. Whether the listing was later removed, whether a ransom was paid, or whether the firm has issued a fuller accounting are not stated in the facts provided. Readers should treat the group’s assertion as a claim pending corroboration from the organization or regulators.
Inside losttrust
Losttrust is a ransomware operation that became publicly visible in 2023 and has followed the double-extortion model common among contemporary groups: encrypting systems while also copying data and threatening to publish it if demands are not met. Like many such actors, it has used dedicated leak sites to name alleged victims and, in some cases, to stage sample or bulk data releases as pressure. Public reporting on the group has generally described opportunistic targeting across sectors rather than a narrow industry focus, with listings serving both as proof-of-compromise claims and as leverage.
Nothing in the available facts attributes to losttrust any unique technical detail or specific statement about Ferguson Wellman beyond the listing and the assertion that internal files were exfiltrated. Claims made on criminal leak sites are not independently verified by default; they function as allegations intended to force engagement. Prior activity by the group, as documented in open sources, has included naming organizations of varying sizes and threatening data dumps, but those patterns do not prove the contents or completeness of any single claimed haul.
About Ferguson Wellman
Ferguson Wellman is a privately owned investment advisory firm that, by its own description in the reported material, serves individuals, families, and institutions. For more than four decades it has designed and managed customized investment portfolios for clients’ IRAs, trusts, foundations, endowments, and corporate retirement and pension plans. Together with its division West Bearing Investments, the firm reported managing $8.2 billion for 913 clients as of January 1, 2022 (figures updated annually). It offers entry points into strategies developed by its own analysts, with a stated minimum of $4 million for Ferguson Wellman client portfolios.
Firms of this type sit at the intersection of personal wealth, institutional capital, and long-term financial planning. They typically maintain detailed records of client identities, account structures, beneficiary arrangements, and investment holdings. A breach claim against such an organization is consequential because the data environment is inherently sensitive: it can link real people and entities to substantial assets and to confidential planning documents. That does not establish negligence or confirm what was taken; it explains why listings of advisory firms attract attention from clients, counterparties, and, where applicable, regulators.
What data was at risk
The facts name the exposed material only as “internal files exfiltrated in [a] ransomware attack.” No inventory of file types, no count of records, and no confirmation of whether client personal data, account numbers, tax identifiers, or internal communications were included has been provided in the source record. Exact contents therefore remain unconfirmed.
Organizations in the investment-advisory sector commonly hold, in the ordinary course of business, client names and contact details, government identifiers, account and portfolio data, trust and estate documents, correspondence, and internal research or operational files. Any of those categories could in principle appear among “internal files,” but stating that they were present in this incident would be speculation. Until the firm or a formal notification process specifies what was involved, the prudent position is that internal material was claimed stolen and that the precise mix is unknown.
The real-world impact
For individuals and institutions associated with the firm, the primary risks are secondary misuse of any personal or financial details that may have been among the taken files—phishing that references real account relationships, social-engineering attempts aimed at wealth-transfer or identity fraud, and longer-term exposure if documents surface in criminal markets. Because the number of people affected is unknown and the data types are not itemized, it is not possible to quantify how many clients or employees face elevated risk, only to note that the category of data typically held by such firms makes those outcomes plausible if the claim is accurate.
For the organization, a public ransomware listing can affect client trust, trigger contractual or regulatory notification duties, and impose costs related to investigation, system recovery, and monitoring. Those operational and reputational effects do not depend on sensational framing; they follow from the ordinary consequences of an asserted compromise of internal systems at a firm managing billions in client assets. No dollar loss, downtime figure, or confirmed client-harm count is given in the facts.
Were you affected?
If you are a client, employee, or counterparty of Ferguson Wellman, monitor account statements and communications for unexpected activity, and treat unsolicited requests for credentials, wire instructions, or personal details with heightened caution—especially messages that reference the firm or your portfolio. Consider placing fraud alerts with major credit bureaus if you believe sensitive identifiers could have been involved, and follow any official guidance the firm issues. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets, which may help you decide whether additional monitoring is warranted.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Brown and Streza Listed by losttrust Ransomware GroupParadise Custom Kitchens Listed by losttrust Ransomware GroupSpecialty Process Equipment Listed by losttrust Ransomware GroupThe WorkPlace Listed by losttrust Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Ferguson Wellman Listed by losttrust Ransomware Group →
Publicly posted by losttrust — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.