Ransomware victim disclosure
← All victimsTOWERPOINT WEALTH, LLC
Claimed by shinyhunters · listed 20 days ago
Status timeline
- Listed
Apr 30, 2026
- Data leaked
At a glance
- Group
- shinyhunters
- Status
- Data leaked
- Country
- US
- Sector
- Financial Services
- Listed on leak site
- Apr 30, 2026
About the victim
AI dossier — public-source company profileTowerPoint Wealth, LLC is a US-based wealth management and financial advisory firm operating under the domain towerpointwealth.com. The company appears to serve individual and institutional clients with investment and financial planning services. No additional public site content was available to confirm scale or headquarters address.
- Industry
- Wealth Management & Financial Advisory
Attack summary
Severity: critical — The victim is a financial services firm and the claimed exfiltration includes PII at scale from a Salesforce CRM system, which in a wealth management context almost certainly contains regulated financial data (client account details, SSNs, financial records). Exfiltration of regulated financial PII from an advisory firm meets the critical threshold.ShinyHunters claims to have exfiltrated Salesforce CRM records containing personally identifiable information (PII) and internal corporate data, issuing a final warning with a deadline of 4 May 2026 before publishing the data and threatening additional unspecified 'digital problems.'
Data the group says was taken
AI dossier — extracted from the leak post- Salesforce CRM records
- Personally identifiable information (PII)
- Internal corporate data
What the group claims
Salesforce records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 4 May 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 1 May 2026 | Warning: FINAL WARNING
Sources
- Victim sitetowerpointwealth.com
Source
Indexed 20 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
