Digital executive protection

Latest articles

Articles about identifying, reducing, and fixing cybersecurity and online privacy risks in the personal lives of high-net-worth executives and their families.

Woman shopping at a high-end shop

What the IDScan.net breach means for high-net-worth individuals, executives and their family members who have a Canadian driver's licence

Over 153 million driver's licences, including those from over 1 million Canadian were recently exposed on the dark web. Canada's privacy commissioner is now investigating IDScan.net as part of this breach. For high-net-worth individuals, executives and their families, the risk goes beyond fraud, since a leaked identity card can enable impersonation and targeted scams with heightened consequences.

On September 1, 2026, cybersecurity journalist Brian Krebs found a listing on the dark web called Nexus selling scans of more than 153 million driver's licences from Canada and the U.S.A. The images appeared to come from an identity verification company most people have never heard of: IDScan.net.

Have you ever handed your driver's licence to a retail store cashier, nightclub manager, hotel front desk clerk or car rental agent? If yes, this breach may impact you.

If matters even more if you run a company, sit on an advisory board or manage family wealth.

Here is what we know, why it hits harder at the high-net-worth level, and what a smart response looks like.

What we know so far

The information that follows comes from Krebs on Security, Global News, Yahoo Finance Canada and IDScan.net itself.

These identity files claimed 153 million driver's licences, 10 million ID cards, 3 million travel documents and 579,000 medical cards. About 1.1 million records were Canadian, and Ontario had the most, at 473,673.

Krebs said a record could include front and back images, plus infrared and ultraviolet scans. He checked nine people's records. Each had travelled on or near the date stamp, including at a car rental counter and a cannabis dispensary.

IDScan.net sells ID scanning software to businesses such as bars, casinos, car rental firms and cannabis shops. The company's September 4th notice said an unauthorized party may have accessed or copied customer data, including names and ID numbers. IDScan.net said full access required payment, and it offered free credit monitoring.

Officials then stepped in:

- The FBI said on September 2 that it was looking into the incident. The RCMP also said it was monitoring the situation.

- On September 21, Privacy Commissioner Philippe Dufresne opened a formal investigation. The investigation will examine IDScan.net's security safeguards and whether it properly told affected people, under PIPEDA, Canada's federal private-sector privacy law. CBC and The Spec also covered the announcement.

One caution: the big numbers come from the seller and from Krebs. Global News reported that neither the RCMP nor the Canadian Centre for Cyber Security has confirmed them.

IDScan.net has not said how many Canadians are affected. Krebs reported that Nexus went offline soon after his story ran. A site going dark does not mean copied data disappears.

Why your Canadian driver's licence is more than just an identity card

A driver's licence holds your full name, home address, birth date and ID number, plus your photo. Yahoo Finance reports that modern scanners capture both sides of the card and often send the image to cloud servers.

Criminals can use those details to open credit in your name. They can also write scams that sound real, because they know things about you.

Experts told Global News that phishing emails and texts are the likely next step. They also said that once data is out, there is little you can do to pull it back. And you can't reset your face like a password.

Researchers have warned that AI photo-matching tools make stolen photo scans a real concern.

Why this breach in particular matters for high-net-worth individuals, executives and their family members

You have increased visibility

Security researcher Zach Edwards said, "There's never been a breach of driver's licences at this scale." He added that the ongoing nature of the breach created national security risks for high-profile people.

Krebs found licences of senior U.S. officials for sale. Cybernews reported that analysts see celebrities, politicians, lawyers and wealthy people as especially exposed.

For a prominent family, a name, address and face are a strong starting kit for a targeted scam, or something worse. A driver's licence scan is also easy to pair with public facts about you, like your company, your donations and your advisory board seats.

You have heightened responsibility

If you lead a business, a family office or an estate, your identity is a key that opens other people's money. A criminal posing as you can call a bank, email an advisor or pressure an assistant. The damage can be financial, and it can hurt your reputation too.

You deal with added complexity

Wealth means more properties, vehicles, trips, accounts and people acting on your behalf. Your adult children get scanned at clubs. An assistant rents a car. A house manager registers a guest. Each one is another vendor holding another copy.

There is a bright side: Wealth buys excellent lawyers, accountants and security advisors. The problem is that each sees only their own slice. No one often sees the whole picture.

You can't audit every vendor

The privacy commissioner's investigation matters. Under PIPEDA, businesses must protect the data they collect. Unfortunately investigations come after the breach, and your driver's licence was sitting with a company you never chose, after a scan you didn't think twice about.

A modern approach: Assume you are exposed, but limit the damage

Good security today does not depend on keeping every secret. It assumes some of your data is already out there, then makes it hard to use. Five habits help:

1. Ask for a visual check

Yahoo Finance notes you can usually ask staff to look at your card instead of scanning it. You can also ask where scans are stored.

2. Watch your credit

Pull your reports from TransUnion or Equifax, and consider a fraud alert. The RCMP also urges people to monitor financial and government accounts and to report fraud to police and the Canadian Anti-Fraud Centre.

TransUnion is included with your Richter Guardian subscription.

3. Lock down your accounts, including email addresses and social media

Use strong, unique passwords and multi-factor-authentication (MFA) everywhere, as the Canadian Centre for Cyber Security advises. Start with your email addresses and social media accounts, for everyone in your family.

4. Set a family "verify first" rule

Any urgent request for money, access or documents has to be confirmed through a second channel, like a call to a known number. This should cover assistants, advisors and adult children.

5. Get a single, comprehensive and ongoing view of your digital risk level

Someone should watch the whole household, not each account on its own.

You can start making these first four changes today.

The fifth is difficult and time-consuming to do alone, and where Richter Guardian delivers as a modern personal cybersecurity program for high-net-worth individuals, executives and their families.

Where Richter Guardian fits

Richter Guardian can't pull a licence out of a dark web vendor's database. No one can. What we can do is watch the doors criminals try next.

After a government ID leaks, attackers still need to act like you. That often means taking over an email account or social account, or building a fake profile.

Richter Guardian's reputation and identity protection is built for that moment. It works in four steps:

Understand

We begin by understanding your personal digital environment, including the devices and accounts you rely on, your social media presence, and where exposure is most likely to exist.

Monitor

24 hours a day, 7 days a week, our monitoring and prevention runs quietly in the background. Richter Guardian helps identify meaningful risk signals tied to your personal digital life.

Surface

When something matters, our team of cybersecurity experts will review it. We share with you the context and priority, so you know why it's important. This can be done via the Richter Guardian mobile app, telephone, email, online video or in-person.

Guide

If action is needed, Richter Guardian's human-led team, known as the Cyber Defence Desk help you decide next steps, discreetly.

Instead of a flood of alerts, you get what matters: Summary and guidance explained in plain language, and a human to talk to and lead you through the situation.

Our team can also coordinate with your existing advisors or IT service provider, so your family office, lawyer and bank aren't left guessing. Richter Guardian fits into a busy life instead of interrupting it.

Take the next step: Request a private consultation or complete a brief assessment

A breach like this is a good opportunity to look at you and your family's digital risk level, before someone else does.

Request a private consultation. Discuss the identities and accounts you want protected, and ask us any questions. It's confidential and no-obligation.

Not yet ready to talk? Try our What's my risk? assessment. It takes a few minutes, needs no sensitive details, and your summary arrives by email.

Sailing on vacation with father and son

A $4.5-Million Account Raid: What Every Investor Should Learn About Protecting Their Wealth While on Vacation

A Calgary investor is suing TD Waterhouse Canada Inc. after fraudsters allegedly broke into his TD Direct Investing accounts while he vacationed in Hawaii. Nothing has been proven in court, but the case shows how fast wealth can vanish once login credentials fall into the wrong hands.

What happened

A Calgary investor is suing TD Waterhouse Canada Inc. after fraudsters allegedly broke into his TD Direct Investing accounts while he vacationed in Hawaii.

According to The Globe and Mail, the intruders sold his holdings and poured more than $5 million into a thinly traded Hong Kong stock.

When it collapsed, he lost roughly $4.5 million in retirement savings.

TD says he either made the trades himself or failed to secure his account. Nothing has been proven in court, but the case shows how fast wealth can vanish once login credentials fall into the wrong hands.

Why this keeps happening

This isn't an isolated incident.

TD Bank has faced other serious regulatory scrutiny in recent years, and securities fraud attorneys continue to field claims from investors who say controls failed them.

Banks guard their own core systems closely, but the real weak points are often somewhere else: the client's personal devices, account passwords, and email accounts, all sitting outside the bank's  oversight and controls.

Why travel makes you a target

It's worth pausing on the timing here: the alleged fraud happened while the investor was away in Hawaii. That's not a coincidence worth overlooking.

Vacations pull people out of their normal routines on purpose, and that's exactly what makes them good for rest, and terrible for security.

At home, most people have habits without even thinking about them: checking accounts over morning coffee, noticing a strange email between meetings, recognizing when something on a statement looks off.

Travel disrupts every one of those habits at once:

- You're on hotel or airport Wi-Fi, which is rarely as secure as your home network.
- You're checking email and banking apps quickly, often on borrowed time between activities, so a suspicious login alert can get skimmed past instead of read carefully.
- Time zone changes mean notifications may arrive at 3 am and get dismissed unread.

Many people intentionally "unplug" from their finances while traveling, treating vacation as a break from monitoring entirely.

Fraudsters understand this pattern well. Account takeovers cluster around known absences: holidays, long trips and/or business travel.

A window of even a few days without anyone watching an account closely is often all it takes to sell off holdings and move funds into a single volatile position, which is exactly what allegedly happened in this case.

None of this means people shouldn't travel or unplug — they should. It means the monitoring can't rely on the account owner remembering to check in from a beach in Hawaii.

Steps you can take right now

Basic habits, especially before and during travel, meaningfully reduce your own risk:

- Turn on multi-factor authentication for every brokerage, banking, and email account.
- Use a unique, strong password for each financial account — never reuse them.
- Avoid logging into financial accounts on public or hotel Wi-Fi while traveling.
- Set up account alerts for trades, withdrawals, and login attempts before you leave.
- Designate someone you trust to glance at statements while you're away.
- Review account activity closely in the days right after returning.
- Ask your brokerage about limiting or freezing margin trading if you rarely use it.

Where personal habits aren't enough

Even careful people get targeted, especially the moment they step away from their routine.

This is a gap Richter Guardian is built to close.

Corporate and bank-side security stops at the workplace door — it doesn't watch the personal phone, laptop, or email account a fraudster actually needs.

Richter Guardian's monitoring and prevention service watches continuously, including while clients travel, for compromised credentials and suspicious activity. If something looks wrong, clients aren't left to figure it out alone.

Our incident response team, the Cyber Defence Desk, is reachable via phone, email, video or a mobile app to explain what's happening and guide next steps.

The bottom line

Vacations should mean rest, not vigilance. For high-net-worth individuals and families with complex accounts and multiple devices, someone still needs to be watching while you're not. Protection shouldn't stop where your routine does.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Executive sitting in chair, legs crossed

Understanding Business Email Compromise: Why Trusted Emails Still Need Verification

Business email compromise, or BEC, is a targeted scam in which a criminal impersonates someone you trust. The message may come from a lookalike email address or a real account that has been compromised. Executives, high-net-worth individuals and their families, and anyone able to move money or release sensitive information are valuable criminal targets.

Business Email Compromise, or BEC, is a targeted scam in which a criminal impersonates someone you trust. They may pose as an executive, lawyer, vendor, advisor, employee, or family member and ask you to send money, change banking details, or share sensitive information.

The message may come from a lookalike email address or a real account that has been compromised. This can make the request appear normal and include details that only a trusted person would seem to know.

Executives, high-net-worth individuals and their families, and anyone able to move money or release sensitive information are valuable criminal targets. AI-written emails and voice cloning can make these scams even more convincing.

How it works

An attacker sends a message that appears to come from someone you know. It is designed to seem routine or urgent so that you act before confirming the request another way.

If a real email account has been compromised, the attacker may review conversations, invoices, contacts, and travel details. They can use this information to create a convincing request at the right time.

The risk works both ways. You may receive a fraudulent message, or your own account may be taken over and used to contact others in your name.

Why BEC is a major threat

According to the FBI Internet Crime Complaint Center’s 2025 Annual Report, BEC led to 24,768 reported complaints and more than $3 billion in reported losses in 2025. Only investment fraud caused greater reported losses that year.

BEC is also becoming harder to identify. AI can create professional messages without the spelling mistakes or awkward wording often linked to scams. Voice cloning may also make a call or voice message sound like someone you know.

Warning signs of business email compromise

Watch for:

  • Urgency combined with secrecy
  • New or changed payment or banking details
  • A reply-to address that differs from the sender’s address
  • A request that skips the normal approval process
  • Pressure to move the conversation to text or WhatsApp
  • An unusual request for sensitive information

A message from a compromised account may not show any of these signs. Verifying the request is more reliable than deciding whether the email looks suspicious.

How to protect yourself

Confirm every new payment instruction, banking change, or urgent transfer by calling the person directly. Use a number saved in your contacts, shown on a previous statement, or obtained from another trusted source.

Never use a number provided in the same email as the request.

During the call, confirm the payment amount, recipient, bank, account details, and reason for the transaction. Be especially careful if any information has changed.

Require approval from a second trusted person for payments above a set amount. Everyone involved should be expected to pause and verify a request, even if this causes a short delay.

Protect every email account including personal accounts, with a strong, unique password and multi-factor authentication. Keep recovery information current and check for unfamiliar forwarding rules, filters, connected applications, or signed-in devices. Do not reuse your email password on other services.

If you have been targeted

If you sent money or shared banking information, contact your financial institution immediately. Ask whether the payment can be stopped, recalled, or frozen. Keep the original emails, messages, and payment records.

If you believe your email account was compromised:

  1. Change the password from a trusted device.
  2. Sign out of other active sessions.
  3. Review the account’s security and recovery settings.
  4. Remove unfamiliar rules or connected applications.
  5. Notify anyone who may have received a fraudulent message from your account.

How Richter Guardian can help you

Richter Guardian can help reduce BEC risk by monitoring for exposed credentials and identifying impersonation attempts, including lookalike domains, websites, or accounts created in your name.

We can also help secure your accounts, review suspicious requests, and provide guidance if you believe an account has been compromised.

If you receive a suspicious email, payment request, banking change, or request for sensitive information, contact us before taking action.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Older man holding eyeglasses while looking at a tablet

Why Richter Guardian's Digital Executive Protection Works Like a Home Security System

A monitored home security system watches the doors, the windows, and the driveway, and it alerts a real person the moment something looks wrong. Richter Guardian is built around the same underlying idea as a home security system, just applied to a high-net-worth family's digital footprint.

Most families already understand physical home security. A monitored home security system watches the doors, the windows, and the driveway, and it alerts a real person the moment something looks wrong.

Few high-net-worth families would consider their primary residence unprotected in this way.

Yet the equivalent protection is often missing for the digital side of an executive's family life, where far more of their exposure now lives: within personal email accounts, mobile phones, computers, social media profiles, and financial credentials.

Richter Guardian is built around the same underlying idea as a home security system, just applied to a family's digital footprint.

It is worth walking through the comparison directly, because it makes clear what "protection" should include.

Sensors on every door and window, not just the front entrance

A home security system is only as strong as the size of its coverage. A system that only watches the front door leaves every other entry point open. This is why home security systems place sensors on every window, every door, and often the garage too.

Richter Guardian applies this same principle to an executive's digital life on the home and family front. Personal digital protection means every meaningful entry point is covered, not just the obvious one. This includes:

- Personal laptops, tablets and phones, which are frequently the least protected devices in a household.
- Personal and family email accounts, often the single most valuable target since they often double as the recovery method for banking and investment accounts.
- Social media accounts, which can be cloned or impersonated to reach family members, friends, or staff.

Just as an unmonitored side window undermines a home security system's front-door sensor, one unprotected personal device or account can undermine protection everywhere else.

24/7 monitoring, not a sign in the yard

A home security sign discourages some opportunistic activity, but it does not stop a determined intruder, and it certainly does not respond to one.

The value of a real home security system comes from continuous monitoring: sensors that are always active and a monitoring center that is always watching.

The digital equivalent is continuous monitoring for leaked credentials, impersonation, and malware:

- A stolen password sitting on the dark web is like a duplicated house key sitting in a stranger's pocket. It does nothing on its own, but it becomes dangerous the moment someone decides to use it.
- Ongoing dark web and credential monitoring means that exposure is caught before it turns into a break-in, rather than being discovered only after money or data is already gone.

Monitoring that connects you with a real person, not just an app that pings you

When a home alarm is triggered, the value isn't only the alert. It's what happens next.

A monitoring centre verifies the situation and, if needed, contacts emergency services on the homeowner's behalf. Compare that to a security system that simply sends a phone notification and leaves the resident to figure out what to do.

With Richter Guardian, when an issue arises or clarification is required, our concierge support team contacts you in a secure, private and discreet manner. You can also contact us at any time. Either way, communication takes place through the Guardian mobile app, a phone call, or another agreed-upon channel.

Our Guardian professionals, also known as the Cyber Defence Desk, explain what’s happening in clear language and guide next steps in a way that fits into your broader wealth and risk strategies.

This matters most in the moment it's needed: when there's a convincing call, a strange pop-up, or an unexpected wire request.

When you know exactly who to speak with, and have those questions be answered by a real person, is the difference between a contained incident and a costly one.

Motion sensors around the perimeter, not just the locks

Good home security doesn't rely on locks alone. It adds motion sensors, cameras, and perimeter alerts, so that suspicious activity is noticed even if no door has actually been breached yet.

The digital version of this is reputation and identity protection. A cloned social media profile or an impersonation attempt is a form of activity around the perimeter of a family's digital life, well before any account can be compromised.

Monitoring for that activity, and acting on it early, is what keeps a small warning sign from becoming a full-blown incident involving fraud or reputational harm.

Covering every household under one family's roof, not just one address

Here is where the comparison becomes especially important for high-net-worth families with more than one residence, or with members living in different homes altogether.

A homeowner with a vacation property, or an adult child in a separate residence, would not consider that second home "covered" by the security system installed at the primary address. Each home needs its own protection.

The same is true digitally, and it is often overlooked.

A family's digital exposure does not stop at one address. It follows every family member:

- the adult child at university;
- the parent living independently; and
- the staff working across more than one property.

Each of these people and their accounts and devices represents a separate point of exposure, and each needs to be covered on its own, not assumed to be safe because "the family" has security somewhere.

This is why Richter Guardian's approach extends coverage across the full footprint of a family, not just one principal or one property.

Extended visibility across multiple households means that a family member living somewhere else entirely is not left outside the perimeter simply because they aren't under the same roof.

The value of thinking about digital executive protection this way

None of this is meant to suggest that digital executive protection and home security are the same thing, because they aren't.

The underlying logic that makes a home security system worth having is exactly the logic that should apply to a family's digital exposure: full coverage, continuous monitoring, a real response when something goes wrong, and protection that follows every member of the family, not just one address.

Families who wouldn't leave a single window unmonitored at home are, in many cases, leaving several digital windows wide open without realizing it.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Have questions after reading?

If something you’ve read raises a concern, our team can help you understand how it applies to you. Richter Guardian provides ongoing monitoring and expert support for individuals, families, and leadership teams.

  • Clear visibility into personal digital risk
  • Guidance from experienced cybersecurity professionals
  • Support designed for both private clients and enterprise leadership
Have questions after reading?