7.6 Fraud, Cybersecurity & Digital Asset Management

Key Takeaways

  • Business email compromise is the dominant wire fraud vector against wealthy families, and the only reliable control is an out-of-band verbal callback to a phone number already on file — never a number supplied in the request itself.
  • Wealthy families are disproportionately targeted because their identities, transactions, and relationships are publicly discoverable through property records, entity filings, philanthropic donor lists, and social media posts by family members and household staff.
  • SEC Regulation S-P requires registered advisers to maintain written policies for safeguarding customer records and, under the 2024 amendments, to provide notice of a data breach involving sensitive customer information within 30 days of becoming aware of it.
  • Self-custodied cryptocurrency is uniquely fragile in estate planning because a lost private key is unrecoverable by any court order, so key custody, multi-signature arrangements, and fiduciary instructions must be planned separately from the will.
  • The Revised Uniform Fiduciary Access to Digital Assets Act gives a fiduciary access to digital accounts only where an online tool designation or a document grants it — a will that is silent, combined with a platform terms-of-service agreement, can leave a fiduciary locked out entirely.
Last updated: August 2026

7.6 Fraud, Cybersecurity & Digital Asset Management

The official content outline lists "fraud and cyber security (e.g., identity protection and digital asset management)" as a knowledge statement under Risk Management and Asset Protection. It is there because the modern threat to a $30,000,000 family balance sheet is less often a plaintiff's attorney than a well-researched social engineer who spends three weeks reading the family's email before sending a single wire request.


1. Why Wealthy Families Are Structurally Exposed

Affluence generates a public data trail that ordinary households do not have:

  • Property records disclose addresses, purchase prices, and mortgage lenders.
  • Secretary of state filings disclose entity names, registered agents, and managers.
  • Philanthropic donor lists, gala programs, and board rosters confirm capacity and relationships.
  • SEC Forms 3, 4, and 5 disclose exact holdings for corporate insiders.
  • Social media — often posted by children, not principals — reveals travel schedules, household staff, school names, and the answers to security questions.
  • Household staff and vendors hold credentials, schedules, and physical access.

Add a family office that transacts by email, wires that are large enough not to look unusual, and the fact that the principal is frequently traveling and hard to reach, and the attack surface is complete.


2. The Attack Patterns That Actually Succeed

Business Email Compromise (BEC)

The dominant financial threat. The attacker compromises or spoofs an email account — often the family office bookkeeper, the estate attorney, or the principal — then observes silently for weeks, learning tone, timing, counterparties, and typical amounts. When a plausible transaction appears (a closing, a capital call, a philanthropic pledge), the attacker inserts fraudulent wire instructions that match the family's normal patterns.

Common refinements: lookalike domains (for example "smithfamily0ffice.com" with a zero in place of the letter o), auto-forwarding rules installed in the compromised mailbox so the victim never sees the reply, and urgency plus confidentiality framing — "the seller is threatening to walk; do not discuss with anyone until it closes."

Other Vectors

  • Spear phishing and pretexting: targeted messages using real names and real transactions.
  • SIM swapping: the attacker ports the victim's mobile number to defeat SMS-based two-factor authentication, then resets passwords. This is why SMS is the weakest second factor.
  • Ransomware: encrypts family office systems and exfiltrates data for double extortion.
  • Account takeover at the custodian, using credentials reused from an unrelated breach.
  • Identity theft and synthetic identity fraud: credit opened in the client's name or in a child's dormant Social Security number.
  • Insider risk: household staff, a disgruntled former employee, or a family member with a gambling or substance problem.
  • Physical convergence: a social media post revealing travel enables a home burglary, and the family's own publicity does the reconnaissance.

3. Controls That Work

The Wire Verification Protocol — the Single Highest-Value Control

For every wire above a defined threshold, and for every change to previously provided instructions:

  1. Out-of-band verbal callback to a phone number already on file, never a number appearing in the request email or attachment.
  2. Dual authorization — a second named individual approves independently.
  3. Mandatory callback for any instruction change, however plausible the explanation.
  4. A defined delay window for first-time payees.
  5. A no-exceptions rule, including for the principal. The urgency-plus-authority combination is precisely the attacker's tool, so an exception granted for the principal is the exception the attacker will engineer.

Technical Baseline

  • Phishing-resistant multi-factor authentication — hardware security keys or authenticator apps, never SMS.
  • A password manager with unique credentials per site, eliminating credential reuse.
  • A carrier port-freeze / account PIN on every family mobile line to blunt SIM swapping.
  • Credit freezes at all three bureaus for every family member, including minors, whose unused Social Security numbers are the most valuable and least monitored.
  • Encrypted, tested, offline backups — a backup that has never been restored is a hypothesis, not a control.
  • A segregated network for family office financial systems.
  • Annual penetration testing and phishing simulation for family and staff.

Governance and Transfer

  • Written incident response plan with named roles, counsel, and forensics contacts pre-engaged.
  • Cyber liability insurance covering social engineering fraud specifically — note that standard crime policies frequently exclude voluntary transfers induced by fraud, which is exactly the BEC loss. Read the social engineering endorsement and its sublimit.
  • Vendor diligence on the custodian, family office software, and any cloud provider.
  • Onboarding and offboarding checklists for household staff, including immediate credential revocation.

The Adviser's Own Obligations

  • SEC Regulation S-P requires written policies and procedures to safeguard customer records and information. The 2024 amendments add an incident response program and require notification to affected individuals as soon as practicable, and not later than 30 days after becoming aware that sensitive customer information was or was likely accessed without authorization.
  • Regulation S-ID (the Identity Theft Red Flags Rule) requires a written identity theft prevention program.
  • FinCEN rules require suspicious activity reporting by covered institutions and, for many entities, beneficial ownership reporting.
  • State breach notification statutes apply in parallel and are often stricter than federal rules.

4. Digital Assets: Custody, Access, and Transfer

The Custody Problem for Cryptocurrency

Self-custodied digital assets are controlled entirely by a private key. There is no institution to appeal to, no fraud department, and no court order that can reconstruct a lost key. Substantial estates have simply evaporated because the only person who knew the seed phrase died.

Custody ModelControlEstate Planning Implication
Exchange / qualified custodianThird party holds the keysRecoverable through normal fiduciary channels; carries platform counterparty risk
Self-custody hardware walletClient holds the keyZero counterparty risk, total key-loss risk; requires an explicit succession plan
Multi-signature (e.g., 2-of-3)Split among client, fiduciary, and a serviceBalances control and recoverability; the standard recommendation for meaningful balances

Practical protocol: store the seed phrase on durable media (steel plate, not paper) in a bank safe deposit box or a fireproof safe; split the phrase across two locations under a documented scheme; give the executor instructions on where and how to find it without ever disclosing the key itself; and — critically — never put a private key or seed phrase in a will, because a probated will is a public document.

RUFADAA and Fiduciary Access

The Revised Uniform Fiduciary Access to Digital Assets Act, adopted in nearly every state, establishes a three-tier priority:

  1. An online tool provided by the platform — Google's Inactive Account Manager, Facebook's Legacy Contact — controls if used, and overrides the will.
  2. If no online tool, the will, trust, or power of attorney controls, provided it expressly grants access to digital assets.
  3. If neither, the platform's terms of service control, which usually means the fiduciary gets nothing beyond a catalogue of communications and no content.

The gap this creates is why every modern estate plan must include express digital asset authority in the will, trust, and power of attorney — and why the client should still complete the online tool designations, since they take priority.

Valuation and Transfer of Intangibles

Cryptocurrency is property, not currency, for federal tax purposes. It receives a §1014 basis step-up at death like other property, and it is not subject to the wash sale rule under the current statute because §1091 applies to stock and securities. Other intangible digital assets — domain names, monetized social accounts, photograph libraries, digital royalty streams — require appraisal, and many carry non-transferable license terms that make the "asset" an unassignable personal right. Confirm transferability before assuming an item is even part of the estate.

Loading diagram...
Wire Fraud Interception: The Verification Control Chain
Test Your Knowledge

A family office bookkeeper receives an email from the principal’s genuine, compromised email account instructing an urgent $2,400,000 wire to close on a property, with new banking instructions and a request for confidentiality. The email includes a phone number "in case you need to confirm." What is the correct control response?

A
B
C
D
Test Your Knowledge

A client dies holding $4,000,000 of Bitcoin in a self-custodied hardware wallet. His will is silent on digital assets, he never completed any platform legacy designations, and no one in the family knows the seed phrase. What is the realistic outcome?

A
B
C
D
Test Your Knowledge

Under the 2024 amendments to SEC Regulation S-P, what is a registered investment adviser required to do when it becomes aware that sensitive customer information was, or was likely, accessed without authorization?

A
B
C
D