[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3ho0u8bq2lcjz":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":4,"isSpamList":33,"isMalware":33,"company":34},"6a7026d1b3130fabede46a4c","HightowerHolding2026","Hightower Advisors 2026 Data Breach","hightower-advisors-2026","hightoweradvisors.com","2026-01-08T00:00:00.000Z","2026-08-03T05:27:45.887Z","Hightower Holding, LLC","https:\u002F\u002Fwww.in.gov\u002Fattorneygeneral\u002Fconsumer-protection-division\u002Fid-theft-prevention\u002Ffiles\u002FDB-Year-to-Date-Report-7_2026.pdf",[14,16,17],"https:\u002F\u002Foag.my.site.com\u002Fdatasecuritybreachreport\u002Fapex\u002FDataSecurityReportsPage","https:\u002F\u002Fwww.mass.gov\u002Fdoc\u002F2026-447-hightower-holding-llc\u002Fdownload",131483,"known",null,"people","High",[24,25,26,27],"Names","Social security numbers","Driver's licenses","Financial account information","\u003Cp>\u003Cstrong>The 2026 Hightower Advisors data breach\u003C\u002Fstrong> covers two related unauthorized-access events involving compromised user accounts in systems operated by Hightower Holding, LLC and its subsidiaries, affecting 131,483 people.\u003C\u002Fp>\u003Cp>The official notice published in Massachusetts places the first event on January 8-9, 2026 and the second on January 19-20, 2026. Hightower issued its combined notification letter on March 23, 2026.\u003C\u002Fp>\u003Ch2>How did the events occur?\u003C\u002Fh2>\u003Cp>Hightower discovered the first compromised user account on January 9. Its investigation determined that certain files were downloaded without authorization from the company environment between January 8 and January 9.\u003C\u002Fp>\u003Cp>During the continuing review, the company identified a second compromised account on January 19; additional files were downloaded between January 19 and January 20. Public documents do not explain how the credentials were compromised or identify the person responsible.\u003C\u002Fp>\u003Ch2>What information may have been involved?\u003C\u002Fh2>\u003Cp>The Texas Attorney General record lists names, Social Security numbers, driver's license numbers, and financial information such as account or payment-card details among the possible data types.\u003C\u002Fp>\u003Cp>The fields involved may have varied by person. The four classes should not be assumed to apply to every notice recipient or to have appeared together in the same file.\u003C\u002Fp>\u003Ch2>What does the 131,483 figure represent?\u003C\u002Fh2>\u003Cp>The Indiana Attorney General's 2026 report records 131,483 affected people nationwide for the combined notification. This is the reportable population associated with the two access events.\u003C\u002Fp>\u003Cp>The 1,204 Indiana residents in that report and the 563 people in the Texas record are state subsets. They should not be added to the nationwide total of 131,483.\u003C\u002Fp>\u003Ch2>Why do these data types matter?\u003C\u002Fh2>\u003Cp>A Social Security number, driver's license, or financial account detail combined with a name can support identity theft, fraudulent credit applications, and account-fraud attempts.\u003C\u002Fp>\u003Cp>An attacker may cite a real advisory relationship, account type, or identity detail to appear credible. An accurate detail in a message does not prove that the sender represents Hightower or a financial adviser.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients should regularly review credit reports and financial account activity and report applications, accounts, or transactions they do not recognize.\u003C\u002Fp>\u003Cp>The official notice offers eligible recipients 12 months of single-bureau credit monitoring and fraud assistance through Cyberscout. Use only the enrollment code and deadline in the letter sent directly to you.\u003C\u002Fp>\u003Cp>Do not provide a Social Security number, account detail, password, or verification code during an unsolicited call or message. Verify contact details and account links by opening hightoweradvisors.com independently.\u003C\u002Fp>\u003Ch2>Confirmed scope\u003C\u002Fh2>\u003Cp>The confirmed scope consists of the January 8-9 and January 19-20, 2026 access windows, two compromised user accounts, unauthorized file downloads, and 131,483 affected people. The notice says there was no indication at the time that information had been used for identity theft or fraud, but that finding is time-bound; the credential-compromise method and responsible actor were not publicly disclosed.\u003C\u002Fp>","","Hightower Advisors Data Breach: 131,483 People Affected","Two unauthorized-access events in the Hightower Advisors data breach affected 131,483 people. Review the disclosed data types and safety steps.","\u002Fuploads\u002Flogo\u002Fhightower-advisors-official.svg",false,{"name":13,"sector":35,"country":36,"website":10,"websiteArchiveUrl":29,"websiteStatus":37,"websiteCheckedAt":12},"Finance","United States","active"]