LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Ferguson Wellman Listed by losttrust Ransomware Group

HIGH severityUnverified claimHow we verify

Ferguson Wellman Listed by losttrust Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 26, 2023
Ferguson Wellman Listed by losttrust Ransomware Group

Reported September 26, 2023.

HIGH
Severity
September 26, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Ferguson Wellman Listed by losttrust Ransomware Group (reported September 26, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On September 26, 2023, the investment advisory firm Ferguson Wellman was listed by the ransomware group losttrust, which claimed to have carried out an attack involving the exfiltration of internal files. Public detail remains limited: the number of people affected is unknown, and no independent confirmation of the full scope has been widely established beyond the group’s listing itself.

For clients and others connected to an investment advisory firm that manages substantial assets, any claim of internal-file theft raises practical questions about confidentiality and follow-on risk. What is known so far is confined to the reported listing and the description of internal files taken in a ransomware incident; further specifics have not been disclosed in the available record.

Inside the incident

According to the reported information, Ferguson Wellman appeared on a losttrust leak-site listing dated September 26, 2023. The group’s claim centers on a ransomware attack in which internal files were exfiltrated. No public figure has been given for the volume of data, the precise systems involved, or the number of individuals whose information may have been included. Timing details beyond the reporting date, the initial access method, and any negotiation or recovery steps remain undisclosed.

In the absence of a detailed official disclosure in the source record, the incident is best understood as an asserted ransomware event with data theft, attributed by the group to itself via its listing. Whether the listing was later removed, whether a ransom was paid, or whether the firm has issued a fuller accounting are not stated in the facts provided. Readers should treat the group’s assertion as a claim pending corroboration from the organization or regulators.

Inside losttrust

Losttrust is a ransomware operation that became publicly visible in 2023 and has followed the double-extortion model common among contemporary groups: encrypting systems while also copying data and threatening to publish it if demands are not met. Like many such actors, it has used dedicated leak sites to name alleged victims and, in some cases, to stage sample or bulk data releases as pressure. Public reporting on the group has generally described opportunistic targeting across sectors rather than a narrow industry focus, with listings serving both as proof-of-compromise claims and as leverage.

Nothing in the available facts attributes to losttrust any unique technical detail or specific statement about Ferguson Wellman beyond the listing and the assertion that internal files were exfiltrated. Claims made on criminal leak sites are not independently verified by default; they function as allegations intended to force engagement. Prior activity by the group, as documented in open sources, has included naming organizations of varying sizes and threatening data dumps, but those patterns do not prove the contents or completeness of any single claimed haul.

About Ferguson Wellman

Ferguson Wellman is a privately owned investment advisory firm that, by its own description in the reported material, serves individuals, families, and institutions. For more than four decades it has designed and managed customized investment portfolios for clients’ IRAs, trusts, foundations, endowments, and corporate retirement and pension plans. Together with its division West Bearing Investments, the firm reported managing $8.2 billion for 913 clients as of January 1, 2022 (figures updated annually). It offers entry points into strategies developed by its own analysts, with a stated minimum of $4 million for Ferguson Wellman client portfolios.

Firms of this type sit at the intersection of personal wealth, institutional capital, and long-term financial planning. They typically maintain detailed records of client identities, account structures, beneficiary arrangements, and investment holdings. A breach claim against such an organization is consequential because the data environment is inherently sensitive: it can link real people and entities to substantial assets and to confidential planning documents. That does not establish negligence or confirm what was taken; it explains why listings of advisory firms attract attention from clients, counterparties, and, where applicable, regulators.

What data was at risk

The facts name the exposed material only as “internal files exfiltrated in [a] ransomware attack.” No inventory of file types, no count of records, and no confirmation of whether client personal data, account numbers, tax identifiers, or internal communications were included has been provided in the source record. Exact contents therefore remain unconfirmed.

Organizations in the investment-advisory sector commonly hold, in the ordinary course of business, client names and contact details, government identifiers, account and portfolio data, trust and estate documents, correspondence, and internal research or operational files. Any of those categories could in principle appear among “internal files,” but stating that they were present in this incident would be speculation. Until the firm or a formal notification process specifies what was involved, the prudent position is that internal material was claimed stolen and that the precise mix is unknown.

The real-world impact

For individuals and institutions associated with the firm, the primary risks are secondary misuse of any personal or financial details that may have been among the taken files—phishing that references real account relationships, social-engineering attempts aimed at wealth-transfer or identity fraud, and longer-term exposure if documents surface in criminal markets. Because the number of people affected is unknown and the data types are not itemized, it is not possible to quantify how many clients or employees face elevated risk, only to note that the category of data typically held by such firms makes those outcomes plausible if the claim is accurate.

For the organization, a public ransomware listing can affect client trust, trigger contractual or regulatory notification duties, and impose costs related to investigation, system recovery, and monitoring. Those operational and reputational effects do not depend on sensational framing; they follow from the ordinary consequences of an asserted compromise of internal systems at a firm managing billions in client assets. No dollar loss, downtime figure, or confirmed client-harm count is given in the facts.

Were you affected?

If you are a client, employee, or counterparty of Ferguson Wellman, monitor account statements and communications for unexpected activity, and treat unsolicited requests for credentials, wire instructions, or personal details with heightened caution—especially messages that reference the firm or your portfolio. Consider placing fraud alerts with major credit bureaus if you believe sensitive identifiers could have been involved, and follow any official guidance the firm issues. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets, which may help you decide whether additional monitoring is warranted.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyFerguson Wellman security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Ferguson Wellman’s full breach history →

More recent breaches

Brown and Streza Listed by losttrust Ransomware GroupSeptember 26, 2023Paradise Custom Kitchens Listed by losttrust Ransomware GroupSeptember 26, 2023Specialty Process Equipment Listed by losttrust Ransomware GroupSeptember 26, 2023The WorkPlace Listed by losttrust Ransomware GroupSeptember 26, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Ferguson Wellman Listed by losttrust Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by losttrust — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram