On January 21, 2024, investment firm Smith Affiliated Capital appeared on the leak site of the monti Ransomware Group. The listing states that internal files were exfiltrated during a ransomware attack. The firm, founded in 1982, provides discretionary and advisory investment management services. The leak-site posting does not quantify how many client records were affected or list the specific data types beyond “internal files.”
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Smith Affiliated Capital
Get alerted the next time Smith Affiliated Capital files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Smith Affiliated Capital’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The monti leak site entry, accessible via the onion address indexed by ransomware.live, claims that Smith Affiliated Capital suffered a ransomware intrusion and that attackers successfully removed internal files. No sample data is shown in the public posting, and the disclosure does not state the volume of records involved or name the exact systems accessed. The notification simply confirms that exfiltration occurred and that the firm has been listed as a victim. Public reporting on monti indicates the group follows a double-extortion model: encrypt systems where possible and threaten to publish stolen data if ransom is not paid.
Why This Matters for You and Your Family
If you or your family are clients of Smith Affiliated Capital, your financial profiles, account statements, tax documents, or correspondence may now sit in an attacker’s archive. Even when exact record counts remain unknown, the exposure of internal files from an investment advisor often includes names, addresses, Social Security numbers, dates of birth, and detailed portfolio information. That combination gives criminals everything needed to file fraudulent tax returns, open accounts in your name, or impersonate you to brokers and banks. High-net-worth families are frequent targets precisely because their data commands higher prices on underground markets.
The Doxxing and Identity-Chain Risk
Stolen investment-advisory files rarely stay isolated. A single leaked email or phone number can be chained with gaming usernames, social-media handles, and family-member details to build a complete identity map. Once attackers link your brokerage login to a child’s Roblox or Fortnite account that reuses the same password, they can pivot from financial fraud to full account takeover and public doxxing. Credential leaks of this nature routinely cascade into harassment, SIM-swapping, and extortion attempts against the entire household.