Business
Business Security · Overview Scope · Domain Audit Shadow · Mailbox Forensics Monitoring · Continuous Coverage Fix Session · Implementation
Individual
Personal Protection · Overview Scope · Personal Credential Scan
Solutions
Dark Web Monitoring Domain Impersonation Protection Credential Breach Detection Compliance Monitoring
Intelligence
Threat Intelligence Global Breach Map Breach Feed
Company
Partners How It Works About Press & Media
Sign In
For Family Offices · Chiefs of Staff · Heads of Security

The principal is not the attack surface. The household and the advisor tenants are.

Wire-fraud interception on the CPA's inbox and the attorney's paralegal is where family-office losses actually originate. LeakTrace audits the advisor network, household, and principal under mutual NDA in seven business days.

Same institutional rigor Kroll and K2 quote at $75,000 to $250,000 per family. Rebuilt for single-family and multi-family offices that need it inside a week, not eight.
Research methodology anchored in:
FBI IC3 HHS OCR FTC Safeguards Rule SEC Reg S-P IRS Circular 230 FERPA ABA Model Rule 1.6 CISA FINRA GLBA HIPAA CCPA / CPRA IBM NIST PCI-DSS Verizon DBIR CIS Controls
Household up to 8 members Advisor tenant DMARC audit BEC precursor lookalike-domain sweep NDA-first intake Encrypted delivery, un-branded on request

Three surfaces the principal doesn't see. All three carry the family's exposure.

Family-office losses don't happen on the principal's own account. They happen on the CPA's inbox, the estate attorney's paralegal, the wealth manager's tenant. FBI IC3 has business email compromise as the highest-loss cybercrime category, and most victims had MFA enrolled at time of compromise.

Surface 1
The advisor network
CPA, attorney, wealth manager, insurance broker: each holds wire instructions, tax filings, and estate documents. Each is the actual target of a business-email-compromise operator building a spoofed-invoice attack.
Surface 2
The household
Spouse, adult children, extended family, household staff. Every registered email, broker-site listing, credential in a public breach. These accounts are how the operator gets legitimate contact with the principal.
Surface 3
The principal's public footprint
Property records, corporate filings, philanthropic disclosures, press mentions. All legal, all indexed. Combined with the household surface they produce the correlation graph an operator uses to construct a plausible pretext.
Surface 4
Wire-fraud precursor detection
Lookalike domains registered against advisor sending domains, MX records configured, silence for two to six weeks, then a routine-looking wire instruction. Our advisor-tenant scanner catches the pattern before the wire message arrives.

Not theoretical. Documented public record.

The advisor-tenant vector is the documented pattern. Every incident cited below is a real, publicly disclosed breach affecting family-office-adjacent capital flows.

Feb 2024
Change Healthcare / UnitedHealth ransomware
ALPHV / BlackCat ransomware exfiltrated the health and financial records of an estimated 100 million Americans through a single credential-compromise on the Change Healthcare tenant. Family offices with medical or estate records touching UnitedHealth's payment pipeline were directly affected. Documented in SEC 8-K filings and Congressional testimony.
Nov 2023
Fidelity National Financial ransomware
The largest US title insurer disclosed a cybersecurity incident that disrupted an estimated ~1,300 pending real-estate closings, including wire transfers tied to high-net-worth transactions. Documented in SEC 8-K filings and industry breach registries. One advisor-side tenant compromise cascading into hundreds of families' capital flows.
2023-2024
Silent Ransom Group law-firm campaigns
Multiple US and Canadian law firms holding family and estate files targeted by an organized ransomware operator. Client files (estate plans, trust documents, wire instructions) exfiltrated and either leaked or held for ransom. Documented across FBI advisories, Halcyon tracking, and firm disclosures.
May 2020
Grubman Shire Meiselas & Sacks
Entertainment / high-net-worth law firm holding contracts and personal correspondence for Lady Gaga, Madonna, LeBron James and others. ~756GB exfiltrated and publicly leaked when ransom refused. Illustrates the reputational blast radius of a single advisor-tenant compromise.

Fortune 500 rigor. Priced for the single-family office, not the enterprise board.

Kroll, K2, Booz Allen, and the private-banking-attached intelligence firms quote $75,000 to $250,000 per family for this class of engagement. Their delivery is four to eight weeks and structured for institutional risk committees, not office chiefs of staff. We deliver the same institutional rigor (analyst-grade briefing, defensible sourcing, senior review) scoped and priced for the single-family or multi-family office that needs it inside a week.

Fixed pricing per engagement. Discussed on the intro call under mutual NDA so we can scope to the specific principal, household size, and advisor network. No hourly billing, no scope-creep line items, no surprise invoicing mid-audit.

Two engagement structures. Point-in-time audit or twelve-month coverage.

Point-in-time

Household + Advisor Network Audit

The signature deliverable. Everything an operator would map before an attack, mapped by us first, with the remediation plan attached.

  • Principal identity monitoring across breach databases + broker footprint
  • Household coverage up to eight members
  • Advisor tenant audit + wire-fraud posture review (up to 4 tenants: CPA, attorney, wealth manager, insurance broker)
  • Property and public-holdings correlation review
  • Executive briefing + technical evidence pack + remediation plan (mutual NDA, encrypted delivery, un-branded on request)
Twelve-month coverage

Ongoing Monitoring Engagement

Everything in the Household + Advisor Audit, plus twelve months of continuous monitoring with priority analyst access.

  • Includes the full Household + Advisor Network Audit at kickoff
  • Twelve months of continuous monitoring + wire-fraud precursor surveillance (DMARC + lookalike-domain) on advisor tenants
  • Quarterly re-baseline briefings (four delivered over twelve months)
  • Priority 24-hour analyst line + incident-response coordination
  • Discretion tier: no branding on outputs, mutual NDA on every deliverable
Start the conversation
Twenty minutes. NDA signed before we go concrete.

If you carry responsibility for a principal's exposure, wire-fraud posture, or advisor-network risk, this is a conversation worth having. Mutual NDA available on request before the first call.

Book the intro call  →