Were you recently affected by a data breach?

J. Michael May Data Breach

J. Michael May, an independent financial advisor affiliated with Osaic Wealth, disclosed in August 2026 that a June 2026 iCloud account compromise let an unauthorized actor view one client’s name and financial account number. Learn what happened and how to protect yourself.

J. Michael May
Date of Breach: June 15, 2026 to June 23, 2026 (identified June 22, 2026)
CAU logo

Who was affected:

Clients of J. Michael May

Impacted Data:

Names, financial account numbers

J. Michael May, an independent financial advisor based in Haymarket, Virginia, recently notified New Hampshire regulators and at least one client that a cybersecurity incident had exposed sensitive account information. Financial professionals who store client data are expected to safeguard it with the same diligence as any regulated institution, and any lapse in that protection can leave clients vulnerable to fraud.

J. Michael May’s Data Breach Investigation

On June 22, 2026, J. Michael May identified unusual activity within several customer accounts that he manages as a financial advisor. Mr. May is not affiliated with Osaic Wealth, Inc. as an employee, but offers securities and financial advice through Osaic as an independent financial professional. Upon discovering the suspicious activity, Mr. May promptly began working to secure the affected accounts and launched an investigation with the assistance of third-party cybersecurity firms.

The investigation determined that an unauthorized actor gained access to Mr. May’s personal iCloud account on June 15, 2026. Through that access, the unauthorized actor was able to obtain a backup of Mr. May’s iPhone, which contained stored credentials for the financial institutions Mr. May uses to provide products and services to his clients. Using those stolen credentials, the unauthorized actor then accessed customer accounts at various times between June 15, 2026, and June 23, 2026.

After reviewing what information was accessible to the unauthorized actor within the affected accounts, Mr. May determined on July 27, 2026, that the actor may have viewed the name and financial account number belonging to one New Hampshire resident. On August 10, 2026, Mr. May notified the New Hampshire Attorney General’s office of the incident and began mailing individual notification letters to the affected resident by first-class mail. Mr. May has also established a dedicated call center to answer questions from anyone who received a notification letter, and is offering twelve months of complimentary credit monitoring and identity theft protection through Cyberscout, a TransUnion company.

Incidents that begin with a compromised personal cloud account are becoming an increasingly common entry point for identity thieves and cybercriminals targeting professionals who handle sensitive client data. Smartphones today routinely back up far more than photos and messages; stored passwords, saved login sessions, and even cached credentials for financial platforms can end up preserved in a cloud backup without the device owner fully realizing how much sensitive information has accumulated there. When a cloud account itself is compromised, whether through a phishing attempt, a reused or weak password, or a successful social-engineering attack against the provider, an intruder can potentially unlock access to every account whose credentials happen to be stored on that device. This makes cloud-account security a critical, if often overlooked, link in the chain of protections that financial professionals rely on to keep client information safe.

Financial advisors and independent wealth-management professionals are attractive targets for cybercriminals precisely because a single compromised advisor can provide a pathway into the accounts of many different clients at once. Unlike a large financial institution, which typically maintains dedicated security teams, multi-factor authentication requirements, and continuous monitoring across its own systems, an individual advisor’s cybersecurity often depends heavily on the personal devices and habits of that one professional. A single weak point, such as an unsecured cloud backup, can therefore expose an outsized amount of sensitive financial data relative to the size of the practice. This dynamic has made phishing campaigns, credential-stuffing attacks, and device-compromise schemes increasingly common against solo practitioners and small advisory firms, not just large custodians and broker-dealers.

Even a narrow combination of exposed data, such as a name paired with a financial account number, can be enough for a bad actor to attempt fraud. Account numbers can be used to attempt unauthorized transfers, to impersonate the account holder when contacting a financial institution, or to combine with other publicly available information to build a more complete profile for identity theft. Notification letters like the one described above typically arrive well after the underlying intrusion has already been contained, which is why financial professionals are urged to enhance security measures such as multi-factor authentication and encrypted device backups even after an incident has been resolved, both to prevent recurrence and to reduce the value of any data that may have already been exposed.

The timeline in this matter, unauthorized access identified in June 2026, a determination of exactly what data was viewed made in late July 2026, and notification letters mailed in mid-August 2026, reflects the multi-step process that most data breach investigations follow: containment first, forensic review of exactly what was accessed second, and individual notification only once the scope of the exposure is reasonably well understood. New Hampshire law requires that businesses and professionals handling personal information promptly determine whether a security breach has resulted in the misuse, or likely misuse, of that information, and notify both affected individuals and the state Attorney General’s office once that determination is made. Reporting the incident to New Hampshire regulators, as Mr. May did, is a standard part of complying with the state’s data breach notification statute.

When Did This Breach Occur?

The unauthorized access to J. Michael May’s iCloud account occurred on June 15, 2026, and the unauthorized actor is believed to have accessed affected customer accounts intermittently between June 15, 2026, and June 23, 2026. Mr. May identified the unusual account activity on June 22, 2026, and immediately began working to secure the accounts while launching a forensic investigation with third-party cybersecurity firms. That investigation concluded on July 27, 2026, when Mr. May determined which specific information had been accessible to the unauthorized actor. Notification letters were then mailed to the affected individual, and the New Hampshire Attorney General’s office was notified, on August 10, 2026, roughly seven weeks after the initial intrusion was discovered.

What Information Was Breached?

According to the notification, the unauthorized actor may have accessed the name and financial account number belonging to one New Hampshire resident whose account was managed by J. Michael May. The exposure occurred because credentials for the financial institutions used to service client accounts were stored on Mr. May’s iPhone and backed up to his iCloud account, which the unauthorized actor was able to compromise. Mr. May has not publicly disclosed whether any additional data types, such as Social Security numbers or dates of birth, were involved in this particular incident.

What You Can Do

If you received a notification letter from J. Michael May, you are being offered twelve months of complimentary credit monitoring and identity theft protection services through Cyberscout, a TransUnion company, and are encouraged to enroll within 90 days of the letter’s date. You should also closely review your financial account statements for any unauthorized transactions and consider placing a fraud alert or a security freeze on your credit files with Equifax, Experian, and TransUnion. Reviewing your accounts regularly over the next 12 to 24 months, and reporting any suspicious activity to your financial institution and to law enforcement promptly, can help limit the damage from any potential misuse of your information.

File a Data Breach Lawsuit Against J. Michael May

If you received a data breach notification letter from J. Michael May and are concerned about how the exposure of your name and financial account information may affect you, you may have legal options available.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: June 15, 2026 to June 23, 2026 (identified June 22, 2026)
Date of Breach: March 27, 2026 - April 5, 2026 (discovered April 5, 2026; notifications sent July 9, 2026)
Date of Breach: Not publicly disclosed
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.