Cresset Capital Management (“Cresset”) Data Breach Notice (Massachusetts Attorney General)
If you received a notice from Cresset Capital Management (“Cresset”), here’s what the filing says was exposed, and what to do about it.
Cresset Capital Management (“Cresset”) notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on May 14, 2026, and the notice lists social security numbers, financial account numbers and driver's license numbers among the information exposed.
The filing from Cresset Capital Management has placed your Social Security number, a financial account number, and a driver’s license number into the hands of an unknown party. With 131 Massachusetts residents named in the notice filed on May 14, 2026, this is a small but high-impact breach: the exact combination of identifiers that identity thieves prize most.
These Three Numbers Do Not Expire
A Social Security number cannot be replaced the way a compromised credit card can. Once it is exposed, it remains permanently valuable for opening accounts, filing fraudulent tax returns, or building synthetic identities. The same permanence applies to a driver’s license number when paired with an SSN. Financial account numbers can be changed, but the other two pieces cannot. That combination is what matters here.
No passwords were exposed. This means the breach does not put your Cresset login at direct risk, and you do not need to change any password because of this incident. That is genuine good news amid otherwise serious exposure.
What Thieves Can Do With This Specific Combination
With your name, Social Security number, and driver’s license number, a criminal can attempt to:
- Apply for new credit or loans in your name
- File a fraudulent tax return before you do
- Impersonate you when dealing with government agencies
- Build a synthetic identity by mixing your real documents with fabricated ones
The financial account numbers add another vector: anyone who obtains them alongside enough personal detail can attempt unauthorized transfers or open new accounts at institutions that already hold related records. Because the record lists these categories without saying which individuals received every item, your own notification letter is the only document that confirms precisely what applied to you.
The Letter Is the Only Reliable Check
Cresset is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your information was not included in the 131 records. However, letters go to the last known address. Anyone who has moved since the incident should contact Cresset directly to confirm whether their records were involved. The filing does not state when the incident occurred, so the letter itself remains the only practical way to know.
Why This Exposure Matters Long After the Headlines Fade
Unlike a stolen password that can be rotated or a credit card that can be canceled, a Social Security number travels with you for life. Its value does not decay quickly. The same is true for a driver’s license number when it can be used to verify identity across multiple systems. Financial account numbers can trigger immediate fraud, but the SSN and license combination creates risk that lasts for years.
This is why the Massachusetts filing, though modest in scale, carries outsized weight. The 131 people named received the precise set of identifiers that enable persistent identity theft rather than one-time card fraud.
What Remains Under Your Control
You cannot change your Social Security number, but you can make it harder for thieves to use it. Monitoring is the realistic response. Place a freeze with the three major credit bureaus so new credit cannot be opened without your explicit permission. Monitor your tax filings each year and respond immediately to any IRS notice that does not match your own records. Review explanations of benefits and account statements for unfamiliar activity even if the accounts themselves were not listed in the filing.
Because financial account numbers were exposed, review every statement from institutions linked to those accounts. Even small test charges can signal that a thief is validating stolen data. Set up alerts for any transaction, no matter how small.
The Gap Between Exposure and Notification
The record reached the Massachusetts Office of Consumer Affairs on May 14, 2026. The filing does not disclose when the incident itself took place. Without that date, it is impossible to know how long the information may have been available before notification. The only fact provided is the filing date and the number of people affected.
This leaves the people whose records were included in a familiar position: the breach has already happened, the identifiers are already out, and the remaining work is defensive. The exposure of Social Security numbers, driver’s license numbers, and financial account numbers means the risk is now permanent for the 131 individuals named. The practical response is targeted monitoring, credit freezes, and treating any future unsolicited contact that references these details as suspect until verified.
The letter from Cresset is the definitive answer for whether you were among those 131. Its absence is usually meaningful, but anyone uncertain because of an address change should reach out to the firm directly. The record supports no broader conclusions about how the incident occurred. It simply states what was exposed and to how many Massachusetts residents.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Cresset Capital Management (“Cresset”).
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.
- Report the licence number to your state DMV. Most states will note the number as compromised, and some will issue a new one. It is the field that turns a stolen identity into a usable one in person.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…