Did Hightower Holding, LLC (Hightower Advisors, LLC, Hightower Securities, LLC, Hightower Trust Company, N.A.) have a data breach?
Answer
Yes. Hightower Holding, LLC (Hightower Advisors, LLC, Hightower Securities, LLC, Hightower Trust Company, N.A.) reported a data breach to the Washington Attorney General on March 23, 2026.
View the official filingWhat the filing says
- Reported to
- Washington Attorney General
- Filing date
- March 23, 2026
- Breach date
- Not stated in the filing
- People affected
- Not stated in the filing
Information involved
- Full Name
- Social Security Number
- Date of Birth
- Financial Account Number
- Routing Number
- Trust and Estate Documentation
- Investment and Transaction History
- Mailing Address
In plain terms
Hightower Holding, LLC, operating through its prominent subsidiaries including Hightower Advisors, LLC, Hightower Securities, LLC, and Hightower Trust Company, N.A., represents a major wealth management and financial services enterprise. Serving high-net-worth individuals, families, and institutional clients, the firm manages billions in assets and provides comprehensive financial planning, investment management, fiduciary oversight, and securities brokerage services. Because of the nature of its core business, Hightower acts as a massive repository for highly sensitive personal and financial information. To execute comprehensive wealth management strategies, estate planning, and trust administration, the company routinely collects and maintains extensive personal dossiers containing deep financial, legal, and identity-related data for thousands of clients nationwide.
In 2026, Hightower reported a significant security incident to the Washington Attorney General's Office, alerting clients and regulatory authorities to an unauthorized compromise of its network infrastructure. In the wealth management and financial sector, breaches of this magnitude typically involve sophisticated cyberattacks, unauthorized network intrusion, or vulnerabilities within third-party vendor systems used for financial reporting and client management. Threat actors aggressively target financial institutions to intercept high-value data feeds, exploit legacy software systems, or deploy ransomware capable of locking internal networks. When an enterprise managing complex financial portfolios experiences a security failure, it points to systemic vulnerabilities in access controls, inadequate network segmentation, or delays in patching known security flaws.
The data compromised in this incident likely encompasses a devastating combination of personally identifiable information and core financial credentials. Victims face the exposure of full names, dates of birth, Social Security numbers, financial account numbers, banking routing numbers, trust documents, and detailed investment transaction histories. Unlike standard retail breaches where credit cards can be quickly canceled, the exposure of core financial and identity infrastructure creates long-term, multi-layered risks. Cybercriminals armed with Social Security numbers, exact account details, and asset holdings can execute sophisticated account takeovers, orchestrate targeted wire fraud, initiate fraudulent tax filings, and apply for unauthorized loans. The exposure of trust and estate documentation further opens high-net-worth individuals to bespoke social engineering and identity theft schemes designed to drain generational wealth.
As a regulated financial institution handling consumer wealth and fiduciary assets, Hightower operated under stringent legal obligations to secure and protect client data. Under the Gramm-Leach-Bliley Act (GLBA), federal regulations mandate that financial institutions establish comprehensive administrative, technical, and physical safeguards to protect customer nonpublic personal information. Additionally, state-level consumer protection statutes, including the Washington Data Breach Notification Act, impose strict duties to maintain reasonable security practices. The occurrence of a data breach of this scale strongly indicates a failure to satisfy these statutory duties, raising serious questions regarding whether the firm implemented adequate intrusion detection, multi-factor authentication, and continuous network monitoring.
Receiving a data breach notification letter from Hightower is a formal acknowledgment that your private financial and personal information was compromised due to corporate security failures. Legally, the receipt of this letter establishes the foundational standing necessary to participate in a class action lawsuit and seek financial accountability. You do not need to wait until you experience actual financial loss, identity theft, or fraudulent transactions to assert your rights. Our firm investigates and litigates data breach cases on a contingency fee basis, meaning you pay nothing out of pocket and owe no legal fees unless we successfully recover compensation on your behalf.
Other filings by Hightower Holding, LLC (Hightower Advisors, LLC, Hightower Securities, LLC, Hightower Trust Company, N.A.)
Companies often file the same breach in several states. Each filing is listed separately.
Commonly recommended next steps
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Watch your financial accounts
Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Look up another company
Other breaches reported in Washington
- zHealth, Inc.Yes — reportedWashington · September 11, 2026
- Cornerstone Staffing Solutions, Inc.Yes — reportedWashington · September 11, 2026
- Quatrro Business Support Services, Inc.Yes — reportedWashington · September 9, 2026
- Hibbett Retail, Inc.Yes — reportedWashington · September 8, 2026
- Catalyst Brands LLCYes — reportedWashington · September 4, 2026
- LHC Group, Inc.Yes — reportedWashington · September 4, 2026
- Bimbo Bakeries USA (Oracle)Yes — reportedWashington · September 4, 2026
- Virta Health Corp. and Virta Medical, PC (Department of Health And Human Services)Yes — reportedWashington · September 3, 2026
- Mogren, Glessner & Ahrens, P.S.Yes — reportedWashington · September 3, 2026
- The Lighthouse for the Blind, Inc.Yes — reportedWashington · September 3, 2026
DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with Hightower Holding, LLC (Hightower Advisors, LLC, Hightower Securities, LLC, Hightower Trust Company, N.A.).