Chicago Partners Wealth Advisors Data Breach

Alleged

Ransomware claim involving Chicago Partners Wealth Advisors.

Published: Sep 3, 2026 Storm
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Chicago Partners Wealth Advisors
Industry
Financial Services
Threat Actor
Storm
Date of Incident
Sep 3, 2026

Executive Summary

On September 3, 2026, the Storm ransomware group added Chicago Partners Wealth Advisors to its dark web extortion portal. Chicago Partners Wealth Advisors operates as an independent wealth management and investment advisory firm, with its primary online presence at chicagopartners[.]com. As a firm that manages concentrated client financial data, it represents a prime target for ransomware actors seeking leverage. This listing was identified via SOCRadar’s Dark Web Monitoring service. The company has not independently confirmed the claim. The Storm group has demonstrated a pattern of targeting financial advisory firms, leveraging the sensitive client data these entities hold for extortion. In the 60 days preceding this listing, Storm claimed 41 victims, with the majority based in the United States, followed by Australia and Canada. The financial services sector is consistently among the most frequently targeted industries, alongside manufacturing and healthcare. Recent U.S. financial services victims within this timeframe include The Cecilian Bank, American Contractors Insurance Group, and Phoenix Group of Companies, indicating that Chicago Partners Wealth Advisors aligns with the group’s established targeting profile.

Technical Analysis

A check of stealer-log telemetry for the domain chicagopartners[.]com returned no records within the queried dataset. It is important to note that this query was paginated, and thus, potential credential exposure under a sibling domain or through personal email aliases used by staff is not ruled out. The absence of direct correlation in the queried dataset does not serve as a definitive confirmation that the organization is unaffected by compromise or that no malicious activity has occurred. The potential for infostealer-harvested credentials to support ransomware operations remains a significant concern. Such credentials can be leveraged for initial access to corporate networks, bypassing traditional perimeter defenses. While no direct evidence of compromised credentials for Chicago Partners Wealth Advisors was found in the initial check, this null result does not exclude the possibility of their existence in other data feeds, under alternate domains, or through credentials that may have been used and rotated prior to indexing. Continued monitoring of dark web and stealer-log feeds is advised.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.