An American multi-family office engaged LeakTrace to establish household-level exposure baselines for each of the principal families the office serves. The findings surfaced patterns the office's existing security posture had been sized against a corporate-cyber threat model rather than a household-cyber threat model, and the office restructured its standing security program in response.

Engagement origin

The office serves a modest number of ultra-high net worth principal families through a dedicated staff that manages investment operations, tax planning, philanthropic affairs, and administrative concierge functions. The office's Chief Executive had inherited a security program calibrated to corporate perimeter concerns: firewall posture, endpoint protection on office-issued devices, and email hygiene. A recent industry incident in which a peer family office had absorbed a wire-fraud loss traced to household-level pretext construction prompted the Chief Executive to commission a household-level review. LeakTrace was referred by a wealth advisory partner the office had been working with for several years.

Discovery scope

LeakTrace conducted household-level external attack surface audits against each principal family's public footprint. The scope included the principals' personal email exposure across monitored breach databases, family member social media exposure and cross-reference potential, residential property record aggregation, professional affiliations and philanthropic disclosures, and the vendor and household staff relationships visible through public records. The engagement did not touch the office's internal systems or any principal's personal devices; it evaluated only what a targeting attacker would find through public and monitored sources.

Findings summary

  • Personal email exposure across all families. Every principal family had at least one member with personal email addresses in breach databases with recoverable password fragments. Password reuse patterns were identifiable in cases where family members had personal social accounts breached, extending the blast radius into other personal services the family used.
  • Property record cross-reference exposure. Real estate records disclosed principal residences at a level of detail that permitted physical mapping, and referenced trust entities that were themselves searchable in public corporate filings. A targeting attacker could construct the family's residential footprint from public records without accessing any private data.
  • Household staff social media exposure. Personal social media of household staff, including drivers, security personnel, and property managers, disclosed principal family travel patterns, residence occupancy, and family member movement. This is the most common vector we observe for physical-presence signal exposure and had not been part of the office's staff onboarding.
  • Philanthropic and professional affiliation exposure. Board memberships, philanthropic sponsorships, and professional advisory roles held by the principal families were publicly aggregated in ways that provided a targeting attacker with multiple context-anchored pretexts for impersonation against the office's own staff.
  • Wealth advisor cross-contamination signal. Public records referenced the office's engagement with several external investment managers and specialty service providers. Combined with the family exposure surface, the vendor cross-contamination created a plausible pretext for advisor-to-office wire fraud attempts.

Office actions

The Chief Executive commissioned a phased restructure of the office's security program. Personal email exposure was addressed at the individual principal level through data-broker opt-out programs and passphrase manager rollouts across all family members. Property record exposure was addressed through the office's counsel with revised trust entity structures where feasible. Household staff onboarding was revised to include a social media protocol restricting personal disclosure of principal family movement, and existing staff were audited against the new protocol. Vendor and philanthropic exposure was reviewed by the office's operations team for pretext risk and communicated to the principal families' outside advisors. The office engaged LeakTrace for a standing quarterly household baseline refresh.

Outcome

Within the following year the office recorded a documented reduction in inbound pretext attempts against its administrative staff, measured against the baseline from the audit period. Two identified pretext attempts targeting principal family members were intercepted through the revised household staff protocol before the pretext could reach the office's wire authorization workflow. The Chief Executive referenced the LeakTrace audit in the office's annual client family communication as evidence of standing security attention.

Methodology transparency

All findings were derived from public and monitored sources only. No portion of this engagement required access to any principal family's personal devices, financial accounts, or private communications. Findings were reviewed with the office's counsel prior to any principal-facing action. This case file documents the pattern of household-level exposure baselines LeakTrace conducts with American multi-family offices, and is not attributed to the specific office or any principal family referenced.