A Canadian mid-market financial advisory firm engaged LeakTrace to complete a custodian-required enhanced due diligence review with a documented exposure baseline. The audit produced the client-side reference material the custodian had requested and satisfied the enhanced due diligence requirement without further follow-up.

Engagement origin

The firm operates a Portfolio Manager practice registered with the Canadian Investment Regulatory Organization, with approximately thirty investment advisor representatives across several offices in one province. The firm's institutional custodian had introduced an enhanced due diligence requirement at the individual advisor level, referencing evolving expectations under the Canadian Investment Regulatory Organization guidance and comparable regulatory frameworks. The firm's Chief Compliance Officer identified that the firm's existing information-security program was documented at the firm level but did not extend to the advisor-level exposure surface the custodian's enhanced due diligence requirement referenced. LeakTrace was engaged through the firm's wealth advisor referral network.

Discovery scope

LeakTrace conducted an external attack surface audit against each investment advisor representative's business email pattern, professional registration records, and the household correlation surface that a targeting attacker would use to construct a pretext against advisor-to-client communication. The engagement was scoped as pre-advisor education material rather than as a firm-wide penetration engagement. Findings were formatted for regulatory filing use in coordination with the firm's compliance officer and outside counsel.

Findings summary

  • Advisor personal email exposure. A meaningful fraction of the advisor representatives had personal email addresses appearing in monitored breach databases, with a subset having recoverable password fragments. Reuse patterns extended into professional accounts holding client correspondence in a subset of cases.
  • Client-side pretext exposure. Public affiliations and personal disclosures across advisor representatives permitted a targeting attacker to construct plausible pretexts against the firm's advisor-to-client communication, particularly in the context of quarter-end trade authorization and rebalancing communication cycles.
  • Custodian platform authentication. The firm had multi-factor authentication configured on the custodian platform, but a subset of advisors had backup authentication methods enrolled that reduced the strength of the multi-factor posture below the current industry baseline referenced in the custodian's enhanced due diligence framework.
  • Vendor mapping. DNS records disclosed the firm's outsourced information-technology provider and its trading platform vendor. Both had current business relationships documented in the firm's compliance records; the disclosure created a targeting vector rather than an operational exposure.
  • Household correlation exposure. Public-record aggregation on advisor representatives identified household composition and family relationship signals consistent with the exposure the Canadian Investment Regulatory Organization enhanced due diligence framework anticipates in advisor-to-client wire fraud scenarios.

Firm actions

The firm implemented a phased remediation program under compliance officer and counsel supervision. Advisor credentials appearing in the breach index were rotated across affected personal accounts, and multi-factor authentication was enforced on the custodian platform with backup authentication methods restricted to hardware tokens for advisors above a defined client book size. Household correlation exposure was addressed at the individual advisor level through data-broker opt-out processes documented by the compliance officer. Vendor documentation was updated to reference the current security posture and to formalize the annual vendor risk review cycle. The custodian's enhanced due diligence submission referenced the LeakTrace baseline and the remediation program as documented evidence of client-side attention.

Outcome

The custodian accepted the firm's enhanced due diligence submission on the strength of the documented baseline. The submission did not require further follow-up beyond the standing annual review cycle. The firm's Chief Compliance Officer engaged LeakTrace as a standing partner for annual baseline refreshes and for new-advisor onboarding audits, and referred the pattern to two peer firms served by the same custodian.

Methodology transparency

All findings were derived from public and monitored sources only. No portion of this engagement required access to the firm's internal systems, purchased breach data, or coordination with any threat actor. Enhanced due diligence submission was executed by the firm's compliance officer under counsel coordination with the LeakTrace baseline as reference material. This case file documents the pattern of custodian enhanced due diligence engagements LeakTrace conducts with Canadian financial advisory firms, and is not attributed to the specific firm, custodian, or advisor representatives referenced.