The Mercer Advisors data breach lawsuit is actually a set of at least three proposed class actions, now consolidated in Colorado federal court as In re Mercer Advisors Data Security Litigation, brought on behalf of the more than 143,000 clients whose personal information was exposed in a January 2026 cyberattack by the hacking group ShinyHunters.1PACER Monitor. Berger v. Mercer Advisors, Inc. et al The suits allege Mercer failed to put basic cybersecurity protections in place and waited too long to warn the people whose data was taken.
What the Lawsuits Allege
Three complaints have been filed against Mercer Advisors Inc. and its SEC-registered subsidiary Mercer Global Advisors Inc.
The first, Berger v. Mercer Advisors (Case No. 1:26-cv-00842), was filed March 2, 2026 by plaintiff Paul Berger. It brings claims of negligence, negligence per se, unjust enrichment, and breach of implied contract, and asks for money damages plus a court order forcing Mercer to strengthen its data security.2ClassAction.org. Berger v. Mercer Advisors Complaint
A second complaint, Amick v. Mercer Advisors, was filed four days later by plaintiff John Amick and makes essentially the same allegations, singling out the absence of multi-factor authentication, credential protection, and regular security audits.3InvestmentNews. Mercer Faces Second Class Action Lawsuit After ShinyHunters Cyberattack
A third suit was filed April 15, 2026 in the U.S. District Court for the Southern District of California. It seeks damages, restitution, and injunctive relief on theories of negligence, invasion of privacy, and related claims.4ThinkAdvisor. Mercer Faces Data Breach Lawsuits
All three complaints tell a similar story. Mercer, they say, assured clients it kept their information secure but did not implement protections that FTC guidance and industry standards call for at wealth management firms, including:
- Multi-factor authentication for system access
- Encryption of personally identifiable information
- Intrusion detection and real-time access logging
- Regular security audits and risk assessments
- Timely disposal of data no longer needed
The plaintiffs also allege Mercer unreasonably delayed telling affected people, leaving them exposed to identity theft for weeks while the data was already circulating on the dark web.5ClassAction.org. Data Breach Lawsuit Alleges Mercer Advisors Failed to Protect Confidential Info From Cyberattack
What Information Was Exposed
Mercer completed its own investigation on March 25, 2026 and confirmed that an unauthorized party obtained personal information belonging to 143,104 individuals. The notice Mercer filed with the California attorney general’s office on March 31, 2026 identified the compromised categories as:
- Names, postal addresses, email addresses, and phone numbers
- Social Security numbers, driver’s license numbers, and passport numbers
- Dates of birth, financial account numbers, and emergency contact information
- Contracts between Mercer and its clients, employee training materials, and other legal documents
ShinyHunters has publicly claimed it took over five million records, and Cybernews reported that the leaked dataset was roughly five gigabytes and contained about 5.7 million records, though with duplicates. Mercer has not confirmed that figure; its 143,104 number reflects individuals it verified as affected through its internal review.6ClaimDepot. Mercer Advisors 2026 Data Breach
One point of dispute matters for anyone weighing their risk. Cybernews reported finding full or partial Social Security numbers in the leaked dataset, while some Mercer notification letters stated the company believed SSNs were not included.4ThinkAdvisor. Mercer Faces Data Breach Lawsuits
The Timeline Behind the Delay Claim
The intrusion began on or around January 22, 2026, with a second incident reported to California authorities on January 25.4ThinkAdvisor. Mercer Faces Data Breach Lawsuits According to one of the lawsuits, ShinyHunters obtained single sign-on credentials through voice phishing.7Lunar Cyber. Mercer Advisors Breach Catalog On February 6, the group claimed responsibility, gave Mercer a 48-hour ransom deadline, and after Mercer refused to pay, dumped the stolen data on a dark web site.8Financial Advisor Magazine. Cyber Gang Targeted Beacon Pointe, Mercer in Alleged Data Extortion
Mercer emailed some clients about “unauthorized access” on February 25. Formal notification letters did not go out until March 31, more than two months after the initial intrusion and nearly a month after the data appeared publicly online.9California Attorney General’s Office. Mercer Advisors Sample Individual Notice That gap is central to the plaintiffs’ delayed-notification claim.
Where the Case Stands
The consolidated Colorado case is currently stayed under a court order issued June 8, 2026. The parties must file a joint status report by August 28, 2026, and a scheduling conference is set for October 6, 2026. Interim co-lead counsel for the plaintiffs are attorneys from Milberg PLLC, Hausfeld LLP, and Nussbaum Law Group PC.1PACER Monitor. Berger v. Mercer Advisors, Inc. et al
No motions to dismiss, settlement talks, or substantive rulings have been publicly reported, and no SEC, FINRA, or state regulatory enforcement action against Mercer tied to this breach has been announced. Mercer has reported the incident to law enforcement and to the California attorney general’s office.4ThinkAdvisor. Mercer Faces Data Breach Lawsuits
What Affected Clients Can Do Now
Mercer is offering affected individuals a two-year membership in Experian’s IdentityWorks Credit Plus at no cost. The service covers credit monitoring, dark web monitoring, up to one million dollars in identity theft insurance, and identity restoration assistance. Enrollment closes July 31, 2026. Mercer also set up a dedicated call center for questions.9California Attorney General’s Office. Mercer Advisors Sample Individual Notice
Enrolling in the monitoring does not require you to release any legal claims and does not opt you out of the class actions. If the consolidated case moves toward a settlement or a certified class, notice would typically go to affected individuals at that point through the addresses Mercer already has on file. Because the litigation is stayed, no claim form or settlement fund exists yet.
Regulatory Backdrop
Mercer Global Advisors is an SEC-registered investment adviser managing roughly $84 billion in assets, which subjects it to Regulation S-P. That rule requires firms to adopt written policies to protect customer information, guard against anticipated threats, and prevent unauthorized access.10SEC EDGAR. Mercer Global Advisors Inc. Adviser Summary Amendments to Regulation S-P took effect for larger advisers on December 3, 2025, about seven weeks before the Mercer intrusion, adding requirements for a formal incident response program, client breach notifications, and enhanced oversight of third-party service providers.11Lowenstein Sandler. SEC Brings Cybersecurity and Identity Theft Controls Case Against RIA and Broker-Dealer Whether regulators will open a separate action against Mercer over the breach has not been publicly disclosed.