A second lawsuit has been brought against Mercer Advisors in the aftermath of last month’s cyberattacks from criminal hacking group ShinyHunters targeting several large RIAs.
John Amick filed the second class action complaint on March 6 against Mercer, which allegedly had 5.7 million individual internal records exposed in a cyber breach that occurred in mid-February. Amick’s lawsuit follows a similar class action complaint filed March 2 by Paul Berger, both of which allege Mercer refused to pay a ransom to ShinyHunters who then leaked client information to the dark web after their demands were not met.
Mercer is alleged to have sent an email notice to the plaintiff on February 25 saying the firm recently identified unauthorized access to some of its systems used to store client data. The exposed customer information allegedly included names, contact information, full or partial social security numbers, emergency contacts, legal documents, and other personal info.
A spokesperson for Mercer declined to comment for this story. The lawsuits claim that Mercer “failed to comply with FTC guidelines and industry best practices” to protect client’s personal information—including failure to implement or maintain multi-factor authentication, credential protection measures, regular security audits and risk assessments.
“Despite the sensitivity of the PII and the heightened risk profile of wealth-management clients, Mercer’s data-security measures were insufficient to prevent or promptly detect the ShinyHunters attack,” reads Amick’s complaint.
The plaintiffs are seeking “damages, including compensatory, punitive, and/or nominal damages, in an amount to be proven at trial” against Mercer, which manages over $96 billion in client assets. Other wealth management firms to have their systems attacked last month by ShinyHunters included Pathstone Family Office and Beacon Pointe Advisors. Industry publication Cybernews posting screenshots of extortion threats from ShinyHunters against the RIAs.
Pathstone, which manages roughly $170 billion in assets, did not respond to a request for comment by press time. ShinyHunters has previously carried out cyber attacks against Google, Adidas, Allianz Life, Cisco, Farmers Insurance Group and Workday, among other companies.
A spokesperson for Beacon Pointe, which manages about $60 billion in client assets, sent the below statement saying the recent data breach impacted less than 0.5% of its clients.
“Beacon Pointe was targeted by an unauthorized bad actor, but our security systems worked as designed to contain the scope of the incident. The incident affected an extremely small percentage of our client base – less than 0.5%. Those clients were notified weeks ago, and we deployed proactive measures to protect their accounts.”
Salespeople at the firm often went beyond the matching algorithm to recommend network advisors on its Zoe Wealth platform, according to the regulator.
The Protect College Sports Act would cap school payments and codify NIL rights, with implications for advisors guiding young athletes.
"I know the number that I want to be able to retire on, and now I just want out," says Wilmington Trust's Marguerite Weese, describing a common refrain among business-owner clients.
Bessemer and Brown Brothers Harriman veteran Robert Ludricks III and private markets specialist Olof Akesson join the ultra-high-net-worth push on the East Coast.
765 investors were promised 260% annual returns on truck leases
As AI makes financial information more accessible than ever, Lana Hock explains why human judgment, trust, and empathy remain the qualities clients value most in a financial advisor
Northern Trust’s Ken Lassner shows advisors how to convert volatility into after-tax portfolio gains