Subscribe To Our Newsletter

This field is for validation purposes and should be left unchanged.

Marble Harbor Investment Counsel Data Breach

Marble Harbor Investment Counsel, LLC disclosed a cybersecurity incident involving unauthorized access to a brokerage platform used for client securities transactions between April 13 and April 23, 2026. The breach potentially exposed sensitive client information connected to investment accounts. The company has since worked with its broker-dealer to secure affected systems, notified law enforcement, and offered affected individuals complimentary credit monitoring and fraud assistance services while consumers evaluate potential legal options related to the incident.

Marble Harbor Investment Counsel
Date of Breach: April 23, 2026
CAU logo

Who was affected:

Clients of Marble Harbor Investment Counsel

Impacted Data:

Full names

Personal identifiers

Financial or brokerage-related account information

Additional sensitive information depending on the individual affected

Marble Harbor Investment Counsel, LLC (“MHIC”) disclosed a data breach after an unauthorized actor gained access to a brokerage platform used to manage client securities transactions. The incident potentially exposed sensitive personal information belonging to affected individuals.

Marble Harbor Investment Counsel, LLC’s Data Breach Investigation

Marble Harbor Investment Counsel, LLC recently disclosed a cybersecurity incident involving unauthorized access to a brokerage platform used to conduct securities transactions for client accounts. According to the company’s breach notification letter, MHIC became aware of suspicious activity affecting the platform on April 23, 2026.

After discovering the incident, the investment advisory firm reportedly worked closely with the broker-dealer associated with the platform to investigate the nature and scope of the unauthorized activity. MHIC stated that the investigation determined an unauthorized actor had access to the brokerage platform between approximately April 13, 2026, and April 23, 2026.

The organization reviewed all information that may have been accessible during the incident window in an effort to identify affected individuals and determine what information may have been compromised. MHIC also notified law enforcement authorities regarding the cybersecurity event.

Although the company did not publicly disclose the total number of affected individuals in the notification letter itself, the breach involved sensitive client information connected to brokerage and investment accounts. Financial services organizations are frequently targeted by cybercriminals because they maintain valuable personal and financial information that can potentially be used for fraud, identity theft, account takeovers, or phishing schemes.

According to the notice, the compromised information included affected individuals’ names in combination with additional sensitive data elements identified during the investigation. The specific categories of information exposed varied depending on the individual involved.

Cybersecurity incidents involving brokerage platforms and investment accounts can be particularly concerning because unauthorized access to financial information may expose individuals to risks involving fraudulent account activity, identity theft, unauthorized transactions, and financial scams. Even when accounts themselves remain secure, exposed personal information can later be used in targeted phishing attempts or other fraudulent schemes.

MHIC stated that protecting personal information remains among its highest priorities and that it worked with the broker-dealer to secure all client accounts following discovery of the incident. The organization also reported that it continues to monitor account activity and maintain safeguards designed to protect sensitive information.

As part of its response efforts, Marble Harbor Investment Counsel is offering affected individuals twenty-four months of Triple Bureau Credit Monitoring services through IDX. The services include fraud assistance and remediation support to help individuals monitor and respond to potential misuse of their information.

The notification letter encouraged affected individuals to remain vigilant by monitoring custodial account statements and reviewing credit reports for suspicious activity. Consumers were also advised to consider fraud alerts, credit freezes, and other protective measures to help reduce the risk of identity theft or unauthorized financial activity.

Cyberattacks targeting financial services firms continue to increase nationwide as threat actors seek access to valuable consumer and account information. Organizations entrusted with sensitive financial information may face legal scrutiny regarding whether appropriate cybersecurity safeguards were implemented to protect client data from unauthorized access.

Individuals affected by the Marble Harbor Investment Counsel breach may wish to better understand their legal rights and determine whether compensation may be available for damages associated with the exposure of their personal information.

When Did This Breach Occur?

According to the notification letter, the unauthorized access to the brokerage platform occurred between approximately April 13, 2026, and April 23, 2026. Marble Harbor Investment Counsel, LLC discovered the incident on April 23, 2026.

The organization subsequently launched an investigation, reviewed potentially affected information, and notified law enforcement authorities.

What Information Was Breached?

According to the breach notification letter, the compromised information may have included:

  • Full names
  • Personal identifiers
  • Financial or brokerage-related account information
  • Additional sensitive information depending on the individual affected

What You Can Do

If you received a notification from Marble Harbor Investment Counsel, LLC regarding this incident, there are several important steps you may consider taking to help protect your information from fraud or misuse.

First, carefully monitor your brokerage accounts, bank accounts, custodial account statements, and credit reports for unusual activity or unauthorized transactions. Promptly report suspicious activity to your financial institution or account provider.

You may also wish to place a fraud alert or security freeze with Equifax, Experian, and TransUnion. Fraud alerts encourage lenders to verify your identity before extending credit, while security freezes can help restrict unauthorized access to your credit file.

Affected individuals are encouraged to enroll in the complimentary twenty-four months of Triple Bureau Credit Monitoring services offered through IDX. The enrollment deadline listed in the notice is August 21, 2026.

Consumers should also remain cautious of phishing emails, suspicious phone calls, or fraudulent communications referencing the breach. Cybercriminals sometimes use publicly disclosed incidents to trick victims into providing additional account credentials or financial information.

Many individuals impacted by financial data breaches may not realize they have legal rights. Exploring your legal options may help you understand whether compensation could be available for identity theft risks, financial harm, privacy violations, or time spent responding to the breach.

File a Data Breach Lawsuit Against Marble Harbor Investment Counsel, LLC

If you received a data breach notification from Marble Harbor Investment Counsel, LLC, you may be eligible to pursue compensation through a data breach lawsuit.

Financial services firms and investment advisory companies that collect and maintain sensitive personal information may have a responsibility to implement reasonable cybersecurity safeguards to help protect client data from unauthorized access. When hackers gain access to financial systems or brokerage platforms, affected individuals can face serious risks involving fraud, identity theft, and unauthorized account activity.

A data breach lawsuit may help impacted individuals recover compensation for damages such as out-of-pocket expenses, identity protection costs, lost time spent monitoring accounts, emotional distress, and other harms associated with the breach. Legal action may also encourage organizations to strengthen cybersecurity protections and improve data security practices moving forward.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Subscribe To Our Newsletter

New cases and investigations, settlement deadlines, and news straight to your inbox.

This field is for validation purposes and should be left unchanged.
Other Data Breaches
Date of Breach: April 23, 2026
Date of Breach: January 14, 2026
Date of Breach: April 19, 2026

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.