DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Aperio Group client account data breached by successful phishing attack

Posted on February 12, 2018 by Dissent

On January 30, Aperio informed advisors of a data breach that occurred when two employees’ email accounts were compromised by successful phishing attacks that resulted in auto-forwarding email from those accounts to two external accounts.

Aperio discovered the problem on January 11, 2018, and their investigation determined that all emails sent to those two accounts between August 21, 2017 and January 11, 2018 had been blind copied/forwarded to the two external addresses.

The compromised data included account names, account numbers, email addresses, and account balances.  Social security numbers and clients’ login credentials were reportedly not compromised.

Actual phishing email that was sent to numerous employees; two of whom fell for it. Aperio provided this to advisors and intermediaries. 

An FAQ on the incident, a copy of which was obtained by DataBreaches.net, indicates that Aperio did not disclose the number of affected end-clients, but indicated that it would be notifying advisors/intermediaries with lists of compromised accounts. At another point, in response to a query about how much data was compromised, the firm noted that three emails, out of the several thousand emails or so that had been copied/forwarded, had attached spreadsheets that were not password-protected. Those three emails and attached spreadsheets accounted for the vast majority of compromised data, Aperio claims.

Aperio did not immediately respond to an inquiry from this site asking how many clients had their account information compromised.

Significantly, Aperio noted that it was not aware of any indication of misuse of customer information by the time of the notification.  Aperio’s presentation to advisors  – a copy of which was also obtained by DataBreaches.net – seems to minimize the risks of adverse consequences to investors because no SSN were involved and no login credentials were compromised.

It’s almost as if Aperio never heard of credential stuffing or brute force attacks.

In any event, Aperio states that it is not aware of any misuse of the compromised data, and it does not instruct its advisors to necessarily notify investors of the breach:

Notify clients?

— Our understanding is no federal requirement

— Most states don’t require notification for the information compromised

— Five states do:  MA, NC, WI, KS, IL

— Two states require notifying state: AG, MA, NC

And in case advisors were wondering, Aperio makes clear that in most cases, they will not notify the advisor’s investors, and that they will only notify end-clients if three specific conditions are met. Aperio is a regulated entity, but not a FINRA-regulated entity. And they are probably quite relieved that so far, there has been no misuse of the data, because they claim that although they carry cyber-insurance for breaches, it would not cover this incident.

I think the bottom line may be that if you are an investor who does not live in MA, NC, WI, KS, IL , do not expect any notification from Aperio, and even if you live in one of those states, they may not notify you.  Whether your advisor will notify you, well, your guess is as good as mine at this point and will presumably depend on what the intermediaries’ legal counsel advise them about their obligations under state laws.

Aperio has notified the FBI, and working with their IT vendor, have taken steps to reduce the amount of sensitive information in internal emails. They have also strengthened employee training and restricted the ability of information to be transmitted by email, while strengthening the security of documents.

Category: Business SectorCommentaries and AnalysesPhishingU.S.

Post navigation

← One Plugin, Over 4,200 Victims – When Thousands of Government Websites Were Hijacked to Mine Monero
NC: Coastal Cape Fear Eye Associates notifies patients after ransomware attack →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes
  • Cocospy stalkerware apps go offline after data breach
  • Ex-NSA bad-guy hunter listened to Scattered Spider’s fake help-desk calls: ‘Those guys are good’
  • Former Sussex Police officer facing trial for rape charged with 18 further offences relating to computer misuse
  • Beach mansion, Benz and Bitcoin worth $4.5m seized from League of Legends hacker Shane Stephen Duffy
  • Fresno County fell victim to $1.6M phishing scam in 2020. One suspected has been arrested, another has been indicted.
  • Ransomware Attack on ADP Partner Exposes Broadcom Employee Data
  • Anne Arundel ransomware attack compromised confidential health data, county says
  • Australian national known as “DR32” sentenced in U.S. federal court
  • Alabama Man Sentenced to 14 Months in Connection with Securities and Exchange Commission X Hack that Spiked Bitcoin Prices

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Police secretly monitored New Orleans with facial recognition cameras
  • Cocospy stalkerware apps go offline after data breach
  • Drugmaker Regeneron to acquire 23andMe out of bankruptcy
  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law
  • Montana Becomes First State to Close the Law Enforcement Data Broker Loophole
  • Privacy enforcement under Andrew Ferguson’s FTC
  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.