[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fb81sox1lpgi4":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":35,"seoTitle":36,"seoTitleEn":37,"seoDescription":36,"seoDescriptionEn":38,"logoUrl":39,"isVerified":4,"isSensitive":4,"isSpamList":40,"isMalware":40,"company":41},"6a6fffcc39a984008898ea0a","MercerAdvisors2026","Mercer Advisors 2026 Data Breach","mercer-advisors-2026","merceradvisors.com","2026-01-22T00:00:00.000Z","2026-08-03T02:41:16.539Z","2026-08-03T02:44:06.897Z","Mercer Advisors","https:\u002F\u002Foag.ca.gov\u002Fecrime\u002Fdatabreach\u002Freports\u002Fsb24-621099",[15,17,18,19],"https:\u002F\u002Fwww.mass.gov\u002Fdoc\u002F2026-491-mercer-advisors-inc\u002Fdownload","https:\u002F\u002Fwww.thinkadvisor.com\u002F2026\u002F04\u002F17\u002Fmercer-faces-data-breach-lawsuits\u002F","https:\u002F\u002Fxposedornot.com\u002Fbreach\u002FMercer",320684,"known",null,"email_identifiers","High",[26,27,28,29,30,31,32,33,34],"Email addresses","Names","Phone numbers","Physical addresses","Dates of birth","Social security numbers","Driver's licenses","Government issued IDs","Financial account information","\u003Cp>\u003Cstrong>The 2026 Mercer Advisors data breach\u003C\u002Fstrong> involved unauthorized access to certain systems used to store client data. The subsequently published dataset contained 320,684 verified unique email addresses.\u003C\u002Fp>\u003Cp>Mercer Advisors is a US registered investment adviser providing wealth management, financial planning and family-office services. The disclosed incident concerned systems holding client information.\u003C\u002Fp>\u003Ch2>How was the incident confirmed?\u003C\u002Fh2>\u003Cp>The California Attorney General entry publishes the Mercer Advisors filing, organization identity and known breach dates. The company letter preserved by Massachusetts authorities separately confirms that an unauthorized party obtained certain personal information.\u003C\u002Fp>\u003Cp>An independent news organization reported the official filings and a Mercer spokesperson’s statement, while separately covering claims that linked the later data publication to the same event. A verified dataset entry supports the domain, period, unique-email count and core contact fields.\u003C\u002Fp>\u003Ch2>When did the breach occur?\u003C\u002Fh2>\u003Cp>The California entry lists January 22 and January 25, 2026 as the known breach dates. Mercer described the incident as occurring on or around January 22 and said the access was blocked and the event contained.\u003C\u002Fp>\u003Cp>The company determined on March 25, 2026 that the unauthorized party had obtained personal information and sent notification letters on March 31. The data publication reported in February was treated as a later stage of this event, not a separate breach.\u003C\u002Fp>\u003Ch2>What information was affected?\u003C\u002Fh2>\u003Cp>Depending on the person, the scope could include names, postal and email addresses, phone numbers, dates of birth, Social Security numbers, driver’s license or other government-issued ID numbers, and financial account numbers.\u003C\u002Fp>\u003Cp>The sample notice variants make clear that not every field applied to every person; some recipients did not have a Social Security number involved. Passwords and account-login credentials were not confirmed as exposed.\u003C\u002Fp>\u003Ch2>How many records were affected?\u003C\u002Fh2>\u003Cp>The verified figure is 320,684 unique email addresses in the published dataset. It is a count of confirmed email identities, not an exact number of affected people announced by the company.\u003C\u002Fp>\u003Cp>The company’s public sample notice does not provide a nationwide affected-person total. Raw-record claims reported elsewhere use a different measurement and were not added to the 320,684 figure.\u003C\u002Fp>\u003Ch2>What are the potential risks?\u003C\u002Fh2>\u003Cp>Identity numbers, dates of birth and financial account information combined with contact fields can support identity theft, account takeover, fraudulent transfers and targeted phishing.\u003C\u002Fp>\u003Cp>Mercer said it had no evidence at the time of notice of identity theft, fraud or other harm connected with the event. That does not rule out later misuse, so financial activity and credit records still deserve monitoring.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients should review custodial-account activity, changes to contact information and new transfer requests through a known direct channel. Unrecognized activity should be reported promptly to the relevant financial institution.\u003C\u002Fp>\u003Cp>Review credit reports regularly and consider a credit freeze or fraud alert where appropriate. Unexpected email or phone requests claiming to come from Mercer should be verified independently before following links or providing information.\u003C\u002Fp>","","Mercer Advisors Data Breach: 320.7K Email Identifiers","The Mercer Advisors data breach exposed 320,684 unique email addresses. Review the timeline, verified data types and practical safety steps.","\u002Fuploads\u002Flogo\u002Fmercer-advisors-official.webp",false,{"name":14,"sector":42,"country":43,"website":10,"websiteArchiveUrl":36,"websiteStatus":44,"websiteCheckedAt":12},"Finance","United States","active"]