The challenge

In our modern digital landscape, cybersecurity threats are an equal-opportunity challenge that can impact anyone, anywhere. As our world becomes more interconnected through technology, it’s crucial to recognize that cybersecurity isn’t just a concern for tech experts; it’s a shared responsibility that affects us all.

In one such case, a client found herself facing a daunting cybersecurity challenge. While browsing the internet, she received a pop-up message claiming that her computer was compromised by a virus. The message instructed her to call a specific number, which were impersonating Apple Support. Unfortunately, she fell victim to this scam, leading to a compromise of her computer.

The root cause analysis suggests that her computer might have been compromised during the installation of browser filters to block ads, where cybercriminals took possession of her computer system for 45 minutes. The client was distressed upon receiving a fraudulent invoice, wondering how this happened to her. This case study highlights the importance of cybersecurity and how Richter Guardian can offer a solution.

The solution

Richter Guardian, a comprehensive cybersecurity service offered by Richter, was instrumental in addressing this client’s situation. When the client reached out to Richter, our team quickly assessed the situation and took immediate action.

First, we onboarded the client to the Richter Guardian service, which includes social media protection, endpoint protection for devices (laptops, desktops, and mobile devices), and monitoring for compromised credentials on the dark web. This multi-layered approach ensured comprehensive protection for the client.

In addition to onboarding the client to Richter Guardian, we conducted a thorough analysis of her compromised computer. We also extended the protection to her mobile devices, ensuring her entire digital presence was safeguarded.

Furthermore, we educated the client on cybersecurity best practices, including the importance of strong, unique passwords and the use of two-factor authentication. We worked closely with her to ensure that her online accounts and data remained secure.

The result

The results of our intervention were significant. The client experienced several benefits from our Richter Guardian service:

Peace of Mind: The client no longer felt vulnerable to cyber threats. She gained confidence in her ability to navigate the digital landscape safely.

Device and Data Protection: All her devices, including her compromised computer, were fortified against potential threats. Her sensitive data was secure, and she no longer worried about cyberattacks.

Reputation Protection: Richter Guardian helped protect her online reputation by proactively monitoring for impersonation attempts and taking swift action to remove any fraudulent accounts.

Educational Insights: The client received valuable insights and recommendations to enhance her cybersecurity awareness. She learned how to recognize potential threats and avoid falling victim to scams in the future.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Case studies
Subscribe to newsletter

Subscribe to receive our latest news and insights in your inbox each week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Protect your digital life by detecting risks before they escalate

Richter Guardian gives you enterprise-level cybersecurity tailored for individuals, families, and executives.

24/7 monitoring & threat intelligence
Identity theft & impersonation detection
Fast incident recovery & expert guidance
Have questions after reading?
Blog

Related posts

Woman shopping at a high-end shop

What the IDScan.net breach means for high-net-worth individuals, executives and their family members who have a Canadian driver's licence

Over 153 million driver's licences, including those from over 1 million Canadian were recently exposed on the dark web. Canada's privacy commissioner is now investigating IDScan.net as part of this breach. For high-net-worth individuals, executives and their families, the risk goes beyond fraud, since a leaked identity card can enable impersonation and targeted scams with heightened consequences.

On September 1, 2026, cybersecurity journalist Brian Krebs found a listing on the dark web called Nexus selling scans of more than 153 million driver's licences from Canada and the U.S.A. The images appeared to come from an identity verification company most people have never heard of: IDScan.net.

Have you ever handed your driver's licence to a retail store cashier, nightclub manager, hotel front desk clerk or car rental agent? If yes, this breach may impact you.

If matters even more if you run a company, sit on an advisory board or manage family wealth.

Here is what we know, why it hits harder at the high-net-worth level, and what a smart response looks like.

What we know so far

The information that follows comes from Krebs on Security, Global News, Yahoo Finance Canada and IDScan.net itself.

These identity files claimed 153 million driver's licences, 10 million ID cards, 3 million travel documents and 579,000 medical cards. About 1.1 million records were Canadian, and Ontario had the most, at 473,673.

Krebs said a record could include front and back images, plus infrared and ultraviolet scans. He checked nine people's records. Each had travelled on or near the date stamp, including at a car rental counter and a cannabis dispensary.

IDScan.net sells ID scanning software to businesses such as bars, casinos, car rental firms and cannabis shops. The company's September 4th notice said an unauthorized party may have accessed or copied customer data, including names and ID numbers. IDScan.net said full access required payment, and it offered free credit monitoring.

Officials then stepped in:

- The FBI said on September 2 that it was looking into the incident. The RCMP also said it was monitoring the situation.

- On September 21, Privacy Commissioner Philippe Dufresne opened a formal investigation. The investigation will examine IDScan.net's security safeguards and whether it properly told affected people, under PIPEDA, Canada's federal private-sector privacy law. CBC and The Spec also covered the announcement.

One caution: the big numbers come from the seller and from Krebs. Global News reported that neither the RCMP nor the Canadian Centre for Cyber Security has confirmed them.

IDScan.net has not said how many Canadians are affected. Krebs reported that Nexus went offline soon after his story ran. A site going dark does not mean copied data disappears.

Why your Canadian driver's licence is more than just an identity card

A driver's licence holds your full name, home address, birth date and ID number, plus your photo. Yahoo Finance reports that modern scanners capture both sides of the card and often send the image to cloud servers.

Criminals can use those details to open credit in your name. They can also write scams that sound real, because they know things about you.

Experts told Global News that phishing emails and texts are the likely next step. They also said that once data is out, there is little you can do to pull it back. And you can't reset your face like a password.

Researchers have warned that AI photo-matching tools make stolen photo scans a real concern.

Why this breach in particular matters for high-net-worth individuals, executives and their family members

You have increased visibility

Security researcher Zach Edwards said, "There's never been a breach of driver's licences at this scale." He added that the ongoing nature of the breach created national security risks for high-profile people.

Krebs found licences of senior U.S. officials for sale. Cybernews reported that analysts see celebrities, politicians, lawyers and wealthy people as especially exposed.

For a prominent family, a name, address and face are a strong starting kit for a targeted scam, or something worse. A driver's licence scan is also easy to pair with public facts about you, like your company, your donations and your advisory board seats.

You have heightened responsibility

If you lead a business, a family office or an estate, your identity is a key that opens other people's money. A criminal posing as you can call a bank, email an advisor or pressure an assistant. The damage can be financial, and it can hurt your reputation too.

You deal with added complexity

Wealth means more properties, vehicles, trips, accounts and people acting on your behalf. Your adult children get scanned at clubs. An assistant rents a car. A house manager registers a guest. Each one is another vendor holding another copy.

There is a bright side: Wealth buys excellent lawyers, accountants and security advisors. The problem is that each sees only their own slice. No one often sees the whole picture.

You can't audit every vendor

The privacy commissioner's investigation matters. Under PIPEDA, businesses must protect the data they collect. Unfortunately investigations come after the breach, and your driver's licence was sitting with a company you never chose, after a scan you didn't think twice about.

A modern approach: Assume you are exposed, but limit the damage

Good security today does not depend on keeping every secret. It assumes some of your data is already out there, then makes it hard to use. Five habits help:

1. Ask for a visual check

Yahoo Finance notes you can usually ask staff to look at your card instead of scanning it. You can also ask where scans are stored.

2. Watch your credit

Pull your reports from TransUnion or Equifax, and consider a fraud alert. The RCMP also urges people to monitor financial and government accounts and to report fraud to police and the Canadian Anti-Fraud Centre.

TransUnion is included with your Richter Guardian subscription.

3. Lock down your accounts, including email addresses and social media

Use strong, unique passwords and multi-factor-authentication (MFA) everywhere, as the Canadian Centre for Cyber Security advises. Start with your email addresses and social media accounts, for everyone in your family.

4. Set a family "verify first" rule

Any urgent request for money, access or documents has to be confirmed through a second channel, like a call to a known number. This should cover assistants, advisors and adult children.

5. Get a single, comprehensive and ongoing view of your digital risk level

Someone should watch the whole household, not each account on its own.

You can start making these first four changes today.

The fifth is difficult and time-consuming to do alone, and where Richter Guardian delivers as a modern personal cybersecurity program for high-net-worth individuals, executives and their families.

Where Richter Guardian fits

Richter Guardian can't pull a licence out of a dark web vendor's database. No one can. What we can do is watch the doors criminals try next.

After a government ID leaks, attackers still need to act like you. That often means taking over an email account or social account, or building a fake profile.

Richter Guardian's reputation and identity protection is built for that moment. It works in four steps:

Understand

We begin by understanding your personal digital environment, including the devices and accounts you rely on, your social media presence, and where exposure is most likely to exist.

Monitor

24 hours a day, 7 days a week, our monitoring and prevention runs quietly in the background. Richter Guardian helps identify meaningful risk signals tied to your personal digital life.

Surface

When something matters, our team of cybersecurity experts will review it. We share with you the context and priority, so you know why it's important. This can be done via the Richter Guardian mobile app, telephone, email, online video or in-person.

Guide

If action is needed, Richter Guardian's human-led team, known as the Cyber Defence Desk help you decide next steps, discreetly.

Instead of a flood of alerts, you get what matters: Summary and guidance explained in plain language, and a human to talk to and lead you through the situation.

Our team can also coordinate with your existing advisors or IT service provider, so your family office, lawyer and bank aren't left guessing. Richter Guardian fits into a busy life instead of interrupting it.

Take the next step: Request a private consultation or complete a brief assessment

A breach like this is a good opportunity to look at you and your family's digital risk level, before someone else does.

Request a private consultation. Discuss the identities and accounts you want protected, and ask us any questions. It's confidential and no-obligation.

Not yet ready to talk? Try our What's my risk? assessment. It takes a few minutes, needs no sensitive details, and your summary arrives by email.

People meeting in a luxury office setting

Why Family Offices Need to Improve Security Beyond Their Corporate Perimeter

Recent government breaches and rising cyber attacks illustrate why family offices must protect ownership, trust, and personal information beyond the corporate perimeter. While outsourced services to family offices are increasingly necessary, family office executives and managers must emphasize vendor oversight, coordinated accountability, household coverage, and human behaviours into their security plan.

In August 2026, the Liechtenstein government disclosed that hackers had broken into a register holding beneficial ownership data for 31,000 legal entities. The incident is part of a pattern that keeps privacy compromises high on the private banking and wealth management agenda, and it wasn't an isolated event.

Around the same time, government systems in the UK, the Netherlands, Sweden, and Spain were also targeted, and researchers tracked 187 ransomware attacks on government agencies worldwide in just the first half of the year, a 13 percent rise from the second half of 2025.

Why does a European government breach matter to a family office in Canada or the USA?

The data stolen in attacks like this often includes the same information that family offices work hard to protect: ownership structures, trust details, and personal information tied to wealthy families.

When a government registry gets hit, the fallout can reach private clients who never even knew their data lived there.

This is the backdrop for a bigger shift happening across the family office world right now: more offices are hiring outside specialists to handle essential services, and that shift brings real benefits along with new risks that need careful management.

Family offices are easy targets, and criminals know it

Family offices sit on enormous wealth but often run lean, and that combination makes them attractive to criminals.

- A cybersecurity consultant who previously worked at Google and served as deputy chief information security officer for New York City has said family offices have not kept pace with cybersecurity strategy, so it isn't surprising that so many have already been attacked.

- A 2020 report from law firm Dentons found that about one in four family offices had suffered a cyberattack, with nearly two-thirds of those attacks happening in just the prior 12 months. A separate EY survey found the number closer to three in four.

- More recent US research tells a similar story: one 2025 study found 37 percent of family offices had experienced an attack in the previous two years, with average losses per incident reaching $1.2 million, and 62 percent of family offices still had no formal cybersecurity plan in place. The problem has caught regulators' attention too, with cybersecurity now a named priority area for SEC examinations.

Closer to home, Canadian advisors are sounding the same alarm.

Looking ahead to 2026, family office advisors flagged shoring up cybersecurity as one of the most pressing issues on their radar, alongside geopolitical volatility and cross-border risk.

Business email compromise, deepfake voice cloning, and social engineering scams are getting harder to catch because generative AI makes fraud attempts look and sound convincingly real, as Richter's own commentary on the “human firewall” has noted.

The rise of the outside specialist

Faced with all of this, many family offices have concluded they can't do everything in-house.

A recent Ocorian survey of family offices managing a combined $119.37 billion found that 77 percent expect to increase their use of outsourced specialists over the next three years, and only 21 percent expect no change at all.

Cybersecurity is one of the top three services families are already sending outside, cited by 49 percent of respondents, just behind illiquid investment advice. The main reasons families gave for outsourcing were the need for more sophisticated services, a lack of in-house expertise as the office grows, and the simple cost-effectiveness of hiring a specialist rather than building a full internal team.

This trend isn't limited to cybersecurity.

Family offices across Hong Kong, Singapore, and other hubs are bringing in outside experts for governance, succession planning, and legacy work as the sector matures and families realize that no single in-house team can master every discipline at once.

The logic is sound. Cyber threats evolve daily. Keeping a specialist current on the latest phishing tactics, deepfake tools, and vendor exploits is a full-time job, and most family offices don't have room on staff for a full-time cybersecurity expert.

What gets more complicated when you bring in outside help

Hiring a specialist solves one problem and creates a new one: you now must manage a relationship with someone outside your walls who has access to some of your most sensitive information. That adds real complexity.

Vendor risks

First, there's the vendor risk itself. Every external specialist, contractor, or platform you connect to your systems becomes a potential entry point for an attacker. Criminals increasingly go after the weakest link in a chain of vendors rather than attacking a well-defended target directly.

If your outside technology provider, IT consultant, or even a bookkeeper has an overly relaxed password policy, that weakness becomes yours too.

Coordination challenges

Second, there's the coordination problem. When a family office builds a “lean” model with just one to three internal staff and outsources nearly everything else, someone still needs to own the big picture.

Without a person or team tracking how all the outside pieces fit together, families can end up with the exact fragmentation they were trying to avoid: one firm handles the network, another handles computers and phones, a third handles monitoring, and nobody owns the whole picture when something goes wrong.

Personal and household gaps

Third, there's the personal and household gap.

Corporate-style information and IT security, even when outsourced well, tends to stop at the office door.

This type of security protects the family office's servers and accounts, but personal devices, family members' social media, household staff, and private communications often fall outside that coverage entirely.

Criminals know this and increasingly go after the people rather than the institution, calling family members directly and posing as a security expert who needs remote access, or targeting an assistant's inbox instead of the principal's.

Human factors

Finally, there's the human factor, which no amount of outsourcing removes.

Most cybersecurity breaches trace back to human error, not a firewall failure. Training family members, executive staff, and household contacts to recognize scams matters just as much as any technology contract you sign.

What family offices need to know before signing a contract

Given all this, hiring external specialists is smart, but it needs to be done carefully. A few considerations matter most.

Check credentials and scope, not just reputation

Ask exactly what the specialist covers. Does it include personal devices and family members, or only office infrastructure? Many families assume broader coverage than they're actually getting.

Require a real incident response plan, in writing

A written plan should spell out who gets called first, how a breach gets contained, and who communicates with the family. Too many family offices only think about this after something has already gone wrong.

Keep one person accountable for the whole picture

Even with several outside vendors involved, someone inside the family office needs to own coordination between them, so no risk quietly falls through the cracks.

Ask about multi-jurisdiction experience

Wealthy families increasingly cross physical borders, and the ability to operate across multiple jurisdictions was the single most important factor families cited when choosing a specialist in the Ocorian survey.

Build in ongoing verification, not a one-time check

Vendor risk changes over time. A specialist that was solid two years ago may have grown, been acquired, or changed staff since then. Periodic reviews catch changes before they become a problem.

Don't skip the human side

No contract replaces training family members and staff to spot phishing attempts. Be sure to verify wire transfer requests by phone, and question unusual requests, even urgent-sounding ones.

Where Richter Guardian fits in: Closing the personal gap

The clearest lesson from recent breaches, whether it's a government registry in Europe or a Canadian family office's own systems, is that modern cybersecurity can't stop at the corporate perimeter.

Cybersecurity has to extend to the people: principals, family members, executives, and trusted household staff, wherever they are and whatever device they're using.

This is exactly the gap Richter Guardian was built to close.

Family office managers are already responsible for keeping operations running while protecting privacy and sensitive communication, but personal devices, private accounts, and household exposure often sit in a space where ownership is unclear and support is inconsistent.

Richter Guardian extends structured, human-led protection into that space, working alongside your existing corporate security team and outside specialists rather than replacing them.

- That means continuous threat and vulnerability monitoring that give a clear view of personal digital exposure across devices, accounts, and identities.

- It means ongoing, proactive monitoring designed to surface meaningful risk signals without burying families in constant alerts.

- It means reputation and identity protection that helps catch impersonation and credential exposure early.

- When something does go wrong, it means concierge, human-led incident response with a clear next step, so a compromised account or suspicious message doesn't spiral into operational chaos.

Bringing in outside cybersecurity expertise is one of the smartest moves a family office can make right now. Just make sure the coverage reaches all the people who need it, not just at the office.

If you support principals or families with elevated exposure and want a clearer approach to personal digital protection, Richter Guardian starts with a confidential conversation to understand your priorities.

Ready to stay protected from digital threats, with experienced professionals overseeing your family office security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Sailing on vacation with father and son

A $4.5-Million Account Raid: What Every Investor Should Learn About Protecting Their Wealth While on Vacation

A Calgary investor is suing TD Waterhouse Canada Inc. after fraudsters allegedly broke into his TD Direct Investing accounts while he vacationed in Hawaii. Nothing has been proven in court, but the case shows how fast wealth can vanish once login credentials fall into the wrong hands.

What happened

A Calgary investor is suing TD Waterhouse Canada Inc. after fraudsters allegedly broke into his TD Direct Investing accounts while he vacationed in Hawaii.

According to The Globe and Mail, the intruders sold his holdings and poured more than $5 million into a thinly traded Hong Kong stock.

When it collapsed, he lost roughly $4.5 million in retirement savings.

TD says he either made the trades himself or failed to secure his account. Nothing has been proven in court, but the case shows how fast wealth can vanish once login credentials fall into the wrong hands.

Why this keeps happening

This isn't an isolated incident.

TD Bank has faced other serious regulatory scrutiny in recent years, and securities fraud attorneys continue to field claims from investors who say controls failed them.

Banks guard their own core systems closely, but the real weak points are often somewhere else: the client's personal devices, account passwords, and email accounts, all sitting outside the bank's  oversight and controls.

Why travel makes you a target

It's worth pausing on the timing here: the alleged fraud happened while the investor was away in Hawaii. That's not a coincidence worth overlooking.

Vacations pull people out of their normal routines on purpose, and that's exactly what makes them good for rest, and terrible for security.

At home, most people have habits without even thinking about them: checking accounts over morning coffee, noticing a strange email between meetings, recognizing when something on a statement looks off.

Travel disrupts every one of those habits at once:

- You're on hotel or airport Wi-Fi, which is rarely as secure as your home network.
- You're checking email and banking apps quickly, often on borrowed time between activities, so a suspicious login alert can get skimmed past instead of read carefully.
- Time zone changes mean notifications may arrive at 3 am and get dismissed unread.

Many people intentionally "unplug" from their finances while traveling, treating vacation as a break from monitoring entirely.

Fraudsters understand this pattern well. Account takeovers cluster around known absences: holidays, long trips and/or business travel.

A window of even a few days without anyone watching an account closely is often all it takes to sell off holdings and move funds into a single volatile position, which is exactly what allegedly happened in this case.

None of this means people shouldn't travel or unplug — they should. It means the monitoring can't rely on the account owner remembering to check in from a beach in Hawaii.

Steps you can take right now

Basic habits, especially before and during travel, meaningfully reduce your own risk:

- Turn on multi-factor authentication for every brokerage, banking, and email account.
- Use a unique, strong password for each financial account — never reuse them.
- Avoid logging into financial accounts on public or hotel Wi-Fi while traveling.
- Set up account alerts for trades, withdrawals, and login attempts before you leave.
- Designate someone you trust to glance at statements while you're away.
- Review account activity closely in the days right after returning.
- Ask your brokerage about limiting or freezing margin trading if you rarely use it.

Where personal habits aren't enough

Even careful people get targeted, especially the moment they step away from their routine.

This is a gap Richter Guardian is built to close.

Corporate and bank-side security stops at the workplace door — it doesn't watch the personal phone, laptop, or email account a fraudster actually needs.

Richter Guardian's monitoring and prevention service watches continuously, including while clients travel, for compromised credentials and suspicious activity. If something looks wrong, clients aren't left to figure it out alone.

Our incident response team, the Cyber Defence Desk, is reachable via phone, email, video or a mobile app to explain what's happening and guide next steps.

The bottom line

Vacations should mean rest, not vigilance. For high-net-worth individuals and families with complex accounts and multiple devices, someone still needs to be watching while you're not. Protection shouldn't stop where your routine does.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.