Ransomware victim disclosure
← All victimsPathstone
listed as Pathstone.com · Claimed by Shinyhunters · listed 3 months ago
Status timeline
- ListedMar 6, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Mar 6, 2026
- Data size
- 15 GB
About the victim
AI dossier — public-source company profilePathstone is a U.S.-based wealth advisory and multi-family office firm serving individuals, families, family offices, and institutional clients such as foundations and endowments. As of December 31, 2025, the firm has 775+ team members and oversees $185B+ in aggregate assets under management, advisory, and administration. It provides comprehensive services including investment management, tax strategy, estate planning, philanthropy, and personal financial operations.
- Industry
- Wealth Management & Multi-Family Office Advisory
- Employees
- 775+
Attack summary
Severity: critical — Pathstone manages $185B+ in assets for high-net-worth families and institutions; a confirmed 15 GB exfiltration of Salesforce records likely contains significant regulated financial PII (client identities, account details, investment data) at scale, constituting a critical breach of sensitive financial and personal data.ShinyHunters claims to have exfiltrated 15 GB (compressed) of Salesforce records and other internal corporate data from Pathstone, stating the company failed to reach a ransom agreement. The data has been published, indicating confirmed exfiltration with no encryption explicitly mentioned.
Data the group says was taken
AI dossier — extracted from the leak post- Salesforce CRM records
- Internal corporate data
- Potentially client and investor information
What the group claims
Salesforce records were compromised and other internal corporate data have been compromised. The company failed to reach an agreement with us despite all the chances and offers we made. They don't care about their clients nor investors. | Size: 15GB (compressed) | Updated: 06 Mar 2026 | SHA256: 6377f58fe8229bc376bbcf6acc32d00cdfb0ac415b8660106f29ca14fa6d0561
Sources
- Victim sitePathstone.com
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

