DisclosureLens
HackingFinancial ServicesFinanceCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDFinancial accountMediumContained

Cresset

bd_6b53a0819e2ea55e · schema v1 · pii pii-v1

Severity

Medium

Discovered

Apr 6, 2026

Filed

May 14, 2026

To disclose

5 weeks

Affected

Not disclosed

Linked

7 filings

Confidence

65%
Full breach record for Cresset

Cresset Capital Management, LLC reported a data breach discovered on April 6, 2026, involving unauthorized access to personal information including names, contact details, dates of birth, Social Security numbers, driver's license numbers, passport numbers, and financial account information. The company contained the incident and engaged third-party cybersecurity professionals. No evidence of misuse or public release was found. Affected individuals were offered credit monitoring and identity protection services.

Incident timeline

discovery → filing · 5 weeks / 38 days

Apr 6, 2026

Begins

Apr 6, 2026

Discovered

May 14, 2026

Filed

vs. sector median

3 wks faster

This filing is one of 7 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (6) · sorted by filing gap

Show 2 more filingsup to 88d gap

Filing propagation · 7 filings · 6 states

View merged incident ↗
Illinois State AGMay 1 · first
California State AG+13d · this page

Pattern: first filing May 1 (IL), last Aug 10 (TX) — a 101-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.