A family office exists to protect the family's wealth. Yet, the assets criminals are increasingly targeting with AI aren't corporate accounts or portfolios.

The targets are now personal phones, computers, social media profiles, and email addresses that belong to the people in the family themselves, as well as their trusted managers and executives.

Family office security must also extend there, because every one of those personal touchpoints is a potential doorway into everything else.

One compromised account is rarely the end goal

Criminals rarely stop at a hacked email inbox or a cloned social media profile. They use it as a foothold; a way to keep the cracked door open, ready for further entry.

  • A compromised personal email account becomes the launch point for a wire transfer request that looks like it came from a family member.
  • A cloned social media account becomes a tool for approaching family members, friends, or staff with a fabricated emergency.
  • A malware-infected laptop becomes a quiet way to sit inside a household's financial life for months before anyone notices.

This is what makes personal digital exposure so dangerous for family offices specifically: the assets being protected are already concentrated, and the family members connected to them are the easiest way in. Close one gap and criminals will look for the next unmonitored device, account, or email inbox.

Where increased personal exposure risk lives

Ultra-high-net-worth family office security solutions need to cover the full footprint of a wealthy family, not just the office itself.

Each of these, left unmonitored, becomes a route toward impersonation, extortion, or fraud aimed at the family and, by extension, the office itself.

Personal devices

Phones, tablets, and laptops used by principals, spouses, adult children, teenagers, grandparents and management staff are frequently the least protected devices in the entire family enterprise, even though they often hold access to email, banking apps, and shared documents.

Social media accounts

Profiles tied to philanthropy, business involvement, or simply a family's public visibility are prime material for impersonation. A convincing fake account, built from real photos and real details, can be used to solicit money, extract information, or damage a family's reputation.

Personal computers

Home computers used for both family life and financial oversight are common malware entry points, particularly when shared across a household or used for both work and personal browsing.

Email addresses

A compromised personal or family email account is often the single most valuable asset to a criminal, since it's frequently the recovery method for banking, investment, and other financial accounts.

AI is drastically reducing the time between exposure and attack

What has changed recently isn't just the number of points of exposure — it's how quickly and convincingly they can now be exploited:

  • RBC's 2026 Fraud Prevention Month research found that among businesses that experienced fraud in the past year, 81% said the incident involved AI tools, with AI-generated phishing messages the single most common attack type, followed by deepfake documents and voice-clone impersonation calls.
  • BMO Wealth Management separately flagged that a two-to-three-second voice clip lifted from a public video, interview, or social post is now enough to generate a convincing cloned voice, often used to fabricate a family-emergency call requesting money or urgent account access.

That combination — minimal source material, minutes of setup, and near-flawless output — is what lets a single exposed asset be turned into an attack far faster, and against a far wider set of family members, than was possible even a few years ago.

Coverage in Canadian Family Offices has pointed to research from the law firm Dentons showing that many family offices have been slow to modernize their security practices, leaving them more exposed just as attacks are becoming easier to launch.

What happens when separate personal exposures are strung together with AI

The greater danger isn't any one compromised account on its own — it's how several small exposures can be chained into a single, coordinated attack using AI.

  • A compromised personal email account becomes the launch point for a wire transfer request that looks like it came from a family member.
  • A cloned social media account becomes a tool for approaching family members, friends, or staff with a fabricated emergency.
  • A malware-infected laptop becomes a quiet way to sit inside a household's financial life for months before anyone notices.

A voice cloned from a public speech or interview can be combined with travel details or family updates pulled from a social media account to build a believable, time-pressured story. That story can then be delivered through a spoofed or already-compromised email address, adding a layer of apparent legitimacy that a bank, advisor, or household staff member may not question in the moment.

Recent reporting on Canadian fraud trends has described scammers using AI chatbots to sustain a fabricated interaction across multiple calls, emails, and messages, keeping a target engaged until money moves or information is disclosed.

The Canadian Anti-Fraud Centre has flagged impersonation and synthetic identity fraud, which similarly stitches together small pieces of real personal information into a convincing fake identity, among the fastest-growing fraud categories in Canada.

This is why closing every individual gap matters.

In an AI-assisted attack, an unmonitored device, an unclaimed and impersonated social media profile, and a leaked email password aren't isolated weaknesses — they're raw material an attacker can combine into one faster, more convincing, and more damaging campaign.

Covering the family, not just the family office

Closing these gaps means tightening the everyday habits around how a family uses its devices and accounts, alongside ongoing monitoring for signs of compromise:

  • Unique credentials and multi-factor authentication on every personal account tied to the family, not only the ones the office manages directly.
  • Continuous monitoring for leaked credentials and impersonation, so a stolen password or a cloned profile is caught before it's used, not after.
  • Verification habits for financial requests, including a standing rule that no transfer or account change is actioned from an email or message alone, regardless of how convincing it looks.
  • Awareness across the whole household, including staff, extended family, and anyone with access to shared devices or networks, since a single unprotected entry point undermines protection everywhere else.

Where Richter Guardian fits

Security for ultra-high-net-worth family offices means treating every family member's devices, accounts, and inboxes as part of the perimeter that needs protecting — not an afterthought outside it.

Richter Guardian monitors those personal assets on a 24/7 basis, watching for impersonation, malware, and leaked credentials before they turn into extortion or fraud, and helps families build the habits that keep new gaps from opening.

Ready for your family office to stay protected from digital threats, with experienced professionals overseeing personal cybersecurity?

For family office executives and managers looking to close the gap between institutional protections and personal exposure, request a private consultation to learn about where that exposure lives.

Family and personal risk
Subscribe to newsletter

Subscribe to receive our latest news and insights in your inbox each week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Protect your digital life by detecting risks before they escalate

Richter Guardian gives you enterprise-level cybersecurity tailored for individuals, families, and executives.

24/7 monitoring & threat intelligence
Identity theft & impersonation detection
Fast incident recovery & expert guidance
Have questions after reading?
Blog

Related posts

Two people at a table having a business meeting

Cheaper Cyber Insurance, Costlier Risk: The Family Office Coverage Gap

The cyber insurance market is softening just as the threats driving demand for it accelerate. Premiums are falling, yet more than 40% of cyber claims are now denied — most often because controls attested to on the application were never actually in place. For family offices, with their informal governance and concentrated wealth, a cheaper policy is increasingly a policy that will not pay.

The cyber insurance market is softening just as the threats driving demand for it accelerate.

Premiums are falling, yet more than 40% of cyber claims are now denied — most often because controls attested to on the application were never actually in place.

For family offices, with their informal governance and concentrated wealth, a cheaper policy is increasingly a policy that will not pay.

The defensible position for family offices is verifiable security controls, not a lower premium.

The market contradiction

Reporting from the Family Office Cybersecurity Forum in New York describes a market where competition is outpacing risk. New entrants including major carriers have pushed prices down, and average premiums were projected to fall a further 11% in 2026.

Buyers are being advised to shop around — but price is now the least important variable.

The frequency and severity of losses continue to climb even as rates drop, and the early signs suggest the rate of decline is starting to slow.

By the numbers

- ~50% of US family offices were hit by a cyberattack in 2025.

- 40%+ of cyber insurance claims are currently being denied — driven by missing controls, late notification and absent policy provisions, not exclusions.

- ~75% of carriers now run external attack surface scans during underwriting, replacing self-attestation.

- $713K average global ransomware claim in 2025 — nearly double the $374K recorded in 2024.

- 60% of family offices are confident their staff can detect and prevent AI-powered attacks.

- 2,137% rise in deepfake-driven fraud attacks since 2022; now 6.5% of all fraud.

Why family offices are uniquely exposed

Forum specialists characterized family offices as structurally vulnerable in ways that standard commercial cyber exposure does not capture.

The same traits that make a family office efficient make it exploitable:

- Cultures of informal approval and trust-based authorization.

- Heavy reliance on personal assistants and a small circle of staff.

- A bias toward speed over documented process.

- Multi-generational structures that widen the attack surface and blur accountability.

Layered on top is an AI-driven threat surface: deepfake voice impersonation of principals, AI-generated phishing, and business email compromise.

The FBI logged a 37% rise in AI-assisted BEC incidents using cloned executive voices, and attackers can now sit undetected inside a compromised environment for 100 days or more.

The regulatory squeeze

Family offices and their advisers face a tightening regulatory environment that mirrors what insurers already demand.

Amendments to the SEC's Regulation S-P took effect for smaller registered investment advisers on June 3, 2026, introducing a written incident response program, a 30-day customer breach notification obligation, and expanded vendor oversight.

The SEC's examiners have named S-P compliance a 2026 priority.

The critical point for prospects: the controls the regulator now mandates are, in most cases, the same controls cyber insurers require for a claim to be honored. One program satisfies both.

How Richter Guardian can help family offices

- Controls verification and attestation readiness — ensuring what you tell underwriters is true and evidenced.

- External attack surface assessment aligned to carrier underwriting scans.

- Regulation S-P alignment: written incident response program, breach notification readiness, vendor risk oversight.

- Human-layer defence against deepfake and AI-enabled social engineering, including principal and staff awareness.

- Ongoing managed monitoring so that controls stay in place between renewals.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Executive sitting in chair, legs crossed

Understanding Business Email Compromise: Why Trusted Emails Still Need Verification

Business email compromise, or BEC, is a targeted scam in which a criminal impersonates someone you trust. The message may come from a lookalike email address or a real account that has been compromised. Executives, high-net-worth individuals and their families, and anyone able to move money or release sensitive information are valuable criminal targets.

Business Email Compromise, or BEC, is a targeted scam in which a criminal impersonates someone you trust. They may pose as an executive, lawyer, vendor, advisor, employee, or family member and ask you to send money, change banking details, or share sensitive information.

The message may come from a lookalike email address or a real account that has been compromised. This can make the request appear normal and include details that only a trusted person would seem to know.

Executives, high-net-worth individuals and their families, and anyone able to move money or release sensitive information are valuable criminal targets. AI-written emails and voice cloning can make these scams even more convincing.

How it works

An attacker sends a message that appears to come from someone you know. It is designed to seem routine or urgent so that you act before confirming the request another way.

If a real email account has been compromised, the attacker may review conversations, invoices, contacts, and travel details. They can use this information to create a convincing request at the right time.

The risk works both ways. You may receive a fraudulent message, or your own account may be taken over and used to contact others in your name.

Why BEC is a major threat

According to the FBI Internet Crime Complaint Center’s 2025 Annual Report, BEC led to 24,768 reported complaints and more than $3 billion in reported losses in 2025. Only investment fraud caused greater reported losses that year.

BEC is also becoming harder to identify. AI can create professional messages without the spelling mistakes or awkward wording often linked to scams. Voice cloning may also make a call or voice message sound like someone you know.

Warning signs of business email compromise

Watch for:

  • Urgency combined with secrecy
  • New or changed payment or banking details
  • A reply-to address that differs from the sender’s address
  • A request that skips the normal approval process
  • Pressure to move the conversation to text or WhatsApp
  • An unusual request for sensitive information

A message from a compromised account may not show any of these signs. Verifying the request is more reliable than deciding whether the email looks suspicious.

How to protect yourself

Confirm every new payment instruction, banking change, or urgent transfer by calling the person directly. Use a number saved in your contacts, shown on a previous statement, or obtained from another trusted source.

Never use a number provided in the same email as the request.

During the call, confirm the payment amount, recipient, bank, account details, and reason for the transaction. Be especially careful if any information has changed.

Require approval from a second trusted person for payments above a set amount. Everyone involved should be expected to pause and verify a request, even if this causes a short delay.

Protect every email account including personal accounts, with a strong, unique password and multi-factor authentication. Keep recovery information current and check for unfamiliar forwarding rules, filters, connected applications, or signed-in devices. Do not reuse your email password on other services.

If you have been targeted

If you sent money or shared banking information, contact your financial institution immediately. Ask whether the payment can be stopped, recalled, or frozen. Keep the original emails, messages, and payment records.

If you believe your email account was compromised:

  1. Change the password from a trusted device.
  2. Sign out of other active sessions.
  3. Review the account’s security and recovery settings.
  4. Remove unfamiliar rules or connected applications.
  5. Notify anyone who may have received a fraudulent message from your account.

How Richter Guardian can help you

Richter Guardian can help reduce BEC risk by monitoring for exposed credentials and identifying impersonation attempts, including lookalike domains, websites, or accounts created in your name.

We can also help secure your accounts, review suspicious requests, and provide guidance if you believe an account has been compromised.

If you receive a suspicious email, payment request, banking change, or request for sensitive information, contact us before taking action.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Hands typing on a laptop keyboard

Fraud Alert — CRA Data Breach Settlement Scams

A legitimate $8.7 million settlement claims process opened August 4, 2026, for victims of a 2020 Government of Canada data breach—but its publicity gives fraudsters cover to build fake portals, send phishing schemes, create impersonations and harvest personal credentials. Expect fake eligibility checks, fake claims portals and claims administrator scams involving KPMG, CRA, and class counsel through the February 2027 deadline.

On August 4, 2026, the claims process opened for a $8.7 million settlement of a class action against the Government of Canada.

This covered people whose personal or financial information in a Government of Canada online account, including the Canada Revenue Agency portal, was accessed without authorization in 2020.

KPMG is the court appointed administrator, and eligible class members can submit claims online or by mail until February 3, 2027.

The settlement is legitimate, but the publicity around it is exactly the conditions fraudsters look for:

  • A national news story
  • A real government linked payout
  • A real deadline
  • A real administrator asking people to enter a last name and the last three digits of a Social Insurance Number on a website

That combination gives criminals a credible pretext to build convincing fake eligibility checkers and claim portals, and to harvest identity data and account credentials at scale.

Our expectation

A wave of phishing email, SMS, social media advertising, sponsored search results, and voice calls impersonating KPMG, the CRA, the Federal Court, and class counsel, beginning within days of the news coverage and continuing through the February 2027 claim deadline.

The only legitimate channels and what to watch for

Official settlement website

https://www.breachsettlementcanada.kpmg.ca (English and French). This is the court appointed administrator's website.

Official email address

breachsettlementcanada@kpmg.ca

What the real eligibility check asks for

  • Last name
  • Last three digits of the SIN
  • An email address
  • Nothing more at the eligibility stage

What the real process NEVER asks for

  • Full SIN
  • Date of birth
  • Banking credentials
  • CRA My Account user ID or password
  • A multi factor authentication code
  • A credit card number
  • A copy of a government ID uploaded to a chat window
  • Any payment or fee. There is no fee to file a claim

Anything arriving by unsolicited text, direct message, or phone call that pushes you toward a different address, a shortened link, or an app download should be treated as fraudulent until proven otherwise.

What the fakes will look like

The following mock ups were produced by Richter Guardian for training purposes.

These are not real messages and the addresses and links shown are illustrative only.

Share them with your household, your office staff, and anyone who manages correspondence on your behalf.

Example 1: Phishing email impersonating the claims administrator

What to watch for

  • Look-alike sender domain rather than https://www.breachsettlementcanada.kpmg.ca
  • A pre-approved dollar figure the real administrator would never quote up front
  • A 48 hour forfeiture threat against a deadline that is actually February 3, 2027
  • A  request for the full SIN
  • CRA sign-in details
  • Banking information

Example 2: Smishing text message

What to watch for

  • The administrator does not solicit claims by text message
  • The domain is not kpmg.ca
  • The amount is presented as guaranteed
  • Urgency is manufactured

Legitimate class action notice arrives by mail or from the administrator's own address.

Example 3: Fake eligibility and claim portal

What to watch for

  • An unencrypted look-alike domain
  • A full SIN and CRA credentials requested where the real site asks only for a last name
  • Three SIN digits
  • An email address
  • An ID upload
  • A processing fee where the real claim is free
  • False scarcity counters

Criminals also buy sponsored search advertisements so these pages appear above the real one.

Example 4: Voice call and voicemail pre-text

What to watch for

  • An inbound unsolicited call
  • Identity verification demanded by the caller rather than by you
  • Above all, a request to read back a code sent to your phone. That code is a multi factor authentication (MFA) prompt for an account the caller is trying to take over at that moment. No legitimate organization will ever ask for it

Example 5: Social media and search advertising

What to watch for

  • An invented average payout
  • A fabricated deadline
  • A paid placement above the genuine result

Reach the administrator by typing the address directly - https://www.breachsettlementcanada.kpmg.ca - rather than by clicking any advertisement or search result.

Red flags to brief your household and staff on

Unsolicited contact

The administrator contacts class members by mail or from its own domain. It will not cold call, text, or direct message you.

A guaranteed amount up front

Real compensation is up to $80 or up to $200 for time spent, plus up to $5,000 in documented out of pocket costs, and amounts may be reduced depending on how many claims are approved. Nobody can promise you $5,000.

Artificial urgency

The real deadline is February 3, 2027. Any message giving you 24 hours, 48 hours, or "this week" is manufacturing pressure.

Over collection of identity data

The genuine eligibility check asks for a last name, the last three digits of your SIN, and an email address. A request for the full SIN, date of birth, ID scans, or CRA credentials is a data harvest.

Any request for a fee

Filing a claim is free. A processing, verification, or expedite fee means fraud.

Any request for a code

A one time passcode read aloud, forwarded, or typed into a third party site hands over your account.

Look-alike domains

Check the address carefully. The genuine site is https://www.breachsettlementcanada.kpmg.ca.

Anything ending in .info, .net, .co, .ca-claims, or a hyphenated variant of the KPMG name is not it.

Payment by unusual method

Requests to move funds, buy gift cards, or receive a payout through e-transfer to a new recipient are not part of any settlement.

What we recommend you do

For principals and family members

Type the address, never click

Reach the eligibility check only by typing https://www.breachsettlementcanada.kpmg.ca into the web browser. Do not use links from email, text, social media, or search advertisements.

Verify by calling back

If someone claims to be the administrator, hang up and contact breachsettlementcanada@kpmg.ca from the details on the official site.

Treat the SIN as a credential

Never provide a full Social Insurance Number to an inbound contact.

Check your CRA account directly

Sign in to CRA My Account by typing the address, confirm your direct deposit details and mailing address have not been changed, and enable multi factor authentication if it is not already on.

Consider a credit file alert

If you believe your information was exposed, place a fraud alert with Equifax Canada and TransUnion Canada.

For family offices and business staff

Brief your team this week

Forward or print this email to anyone who handles correspondence, banking, or tax filings on a principal's behalf.

Add a verification step

Any instruction arising from a settlement, refund, or government notice must be verified by an out of band call to a known number before any data or funds move.

Watch for lookalike domains

Ask your IT provider to monitor for newly registered domains that combine your family or firm name with settlement, claim, refund, or CRA terms.

Tune your email filtering

Quarantine newly registered sender domains and flag external mail referencing CRA settlements or class action payouts.

Report and preserve

Report suspected scams to the Canadian Anti-Fraud Centre at 1-888-495-8501 and preserve the original message headers rather than deleting them.

If you think you've already been caught

Move quickly

Change the password on any account whose credentials were entered, starting with CRA My Account and your email, and revoke active sessions.

Call the CRA

If CRA credentials were disclosed, contact the CRA immediately and ask that the account be locked and reviewed for changes to direct deposit or address.

Notify your bank

Report the exposure and ask for enhanced verification on outbound payments.

File a credit alert

Contact Equifax Canada and TransUnion Canada.

Contact Richter Guardian

Speak to your Richter Guardian team. We can help contain the incident, assess what was exposed, and coordinate monitoring.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.