A Canadian wealth advisory firm engaged LeakTrace after its institutional custodian introduced enhanced cyber due diligence requirements at the individual advisor level. The firm's compliance officer requested a forensic audit covering the firm and its senior advisors as evidence for the custodian file. The engagement produced material findings that changed the firm's authentication baseline and its advisor onboarding process.
Engagement origin
The firm's compliance officer had received a written communication from the institutional custodian outlining enhanced cyber posture expectations for firms in the firm's asset-under-management tier. The requirements referenced the Canadian Investment Regulatory Organization's published guidance on cyber controls and asked for firm-level and advisor-level evidence within a sixty-day window. The firm's compliance officer contacted LeakTrace on the recommendation of a peer at a similarly sized firm.
Discovery scope
The engagement covered the firm's registered domains, the senior advisors' individual exposure patterns, the firm's client-facing portal, and public-record aggregation on the advisors' personal addresses. Advisor coverage was scoped to the six senior advisors identified by the compliance officer as handling household relationships above a stated threshold.
Findings summary
The audit produced findings in three categories.
- Advisor authentication baseline. Four of the six senior advisors' primary email addresses were present in breach databases actively monitored by threat actors. Three had passwords recovered. Two of those three reused the recovered password across the firm's authentication baseline, meaning the enhanced due diligence request was not hypothetical.
- Client portal reconnaissance surface. The firm's client-facing portal disclosed advisor names and household relationship patterns through link metadata visible to unauthenticated users. This exposure allowed a targeting attacker to reconstruct which advisor served which household without authenticated access.
- Public-record aggregation on senior advisors. Public records aggregated the advisors' personal addresses, corporate directorships, philanthropic contributions, and political disclosures into a picture rich enough to enable pretexting against advisor-to-client wire flows. Two of the six advisors' addresses were listed alongside their households' addresses in the same aggregated view.
Client actions
The firm rotated credentials for all four exposed advisors, enforced hardware-token multi-factor authentication across the partnership, and reconfigured the client portal to require authenticated access to advisor and household metadata. The firm engaged LeakTrace for continuous monitoring of the senior advisors and added the finding to its custodian filing. The compliance officer used the finding as the anchor for a firm-wide advisor cyber policy update that referenced the Canadian Investment Regulatory Organization guidance directly.
Outcome
The custodian accepted the firm's evidence file. The firm was not asked to increase the reserve requirement discussed in the enhanced due diligence intake. The compliance officer later described the finding as the reason the firm now runs advisor exposure audits during the initial onboarding process for every senior advisor, not only during periodic reviews.
Findings were drawn from monitored breach databases, DNS and certificate transparency logs, corporate registry filings, and public-record aggregation across Canadian data brokers. No client data was accessed. No system-level access was requested from the firm or the custodian. The findings were formatted specifically for regulatory filing use in coordination with the firm's counsel.