HackingFinancial ServicesFinanceData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALSPIIMediumContained
Mercer Advisors Inc.
bd_41c52380b4cba0f8 · schema v1 · pii pii-v1
Full breach record for Mercer Advisors Inc. →Mercer Advisors Inc., a wealth management firm, experienced a cybersecurity incident on or around January 22–25, 2026, involving unauthorized access to systems storing client data. An unauthorized third party obtained personal information including names, contact details, government-issued IDs, dates of birth, account numbers, SSNs (for some), health information, tax information, and credentials. The incident was contained and notification letters were sent March 31, 2026.
California clockConsumers notified Mar 31, 2026 → AG copy submitted Mar 31, 20260d ✓ CA AG copy ≤15d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_74d6e3e7644e603dLeak Siteshinyhuntersfiled 2026-02-21(38d gap)Verified
Regulatory filings (5) · sorted by filing gap
- bd_c9cf67fb541b2750Washington State AGfiled 2026-03-31Verified
- bd_cf90fb475588f316Indiana State AGfiled 2026-03-31Verified
- bd_7434b0177f07c09aTexas State AGfiled 2026-04-02(2d gap)Verified
- bd_4c2c111384c82779Oregon State AGfiled 2026-04-17(17d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 106d gap
- bd_d07d326962bb13dfMaine State AGfiled 2025-12-15(106d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-621099
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 31, 2026
- Raw hash
- ea9b776048ffbd405698222cd1d6699daab0a62bb0c7945a3059148e02f7f8c8
Reporting entity
- Name
- Mercer Advisors Inc.norm: mercer advisors
- Domain
- merceradvisors.com
Victim entity
- Name
- Mercer Advisors Inc.norm: mercer advisors
- Domain
- merceradvisors.com
- Industry
- Financial Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Mar 31, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALSPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1530 Data from Cloud Storage Object
- Threat actor
- External
Compliance
- Compliance flags
- CA AG copy ≤15d · 0d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status California Consumers notified: Mar 31, 2026→ AG copy submitted: Mar 31, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.