J. Michael May Data Breach Exposes Names and Financial Account Numbers

Finance data breach illustration
Breach Discovery: June 2026Breach Notification: August 2026

What Happened in the J. Michael May Data Breach?

J. Michael May works as an independent financial advisor in Haymarket, Virginia. He offers securities and financial planning services through Osaic Wealth, though he is not an Osaic employee. In August 2026, he disclosed a cybersecurity incident that touched at least one client’s financial account information.

The trouble started with something surprisingly ordinary: a compromised personal iCloud account. An unauthorized actor broke into that account and pulled a backup of Mr. May’s iPhone. Because that backup held stored login credentials for the financial institutions he uses to manage client accounts, the intruder suddenly had a path into those systems too.

Using the stolen credentials, the attacker accessed customer accounts intermittently over roughly a week. Mr. May noticed unusual activity and moved quickly to lock things down. He then brought in outside cybersecurity specialists to figure out exactly what had happened and who was affected.

The forensic review took several weeks to complete. As a result, the exact scope of the exposure was not confirmed right away. Once the investigation wrapped up, Mr. May determined that the intruder may have viewed a client’s name and financial account number. He then notified New Hampshire regulators and began the process of mailing formal notice to the individual whose data was involved.

Who was affected?

This incident appears narrow in scope. Based on the available information, it involves one New Hampshire resident whose account Mr. May managed as an advisor. The notification does not indicate that a broader pool of clients had their data viewed.

However, the fact that only one confirmed victim has been named does not mean the exposure risk was small in nature. Because the intrusion started at the credential level, the attacker theoretically had access to any account tied to those stored logins. The investigation determined that only one person’s data was actually viewed, which is a distinct question from what could have been accessed.

It has not been publicly disclosed whether any other clients were affected in ways that fell short of viewed data, or whether additional states may see similar notifications. Individuals who worked with Mr. May as clients, particularly in New Hampshire, should treat this as directly relevant to them.

What Information Was Potentially Exposed?

The notification identifies a limited but sensitive set of data tied to this incident. Because the exposure involves financial account numbers, affected individuals should still take it seriously despite the narrow scope.

  • Full name
  • Financial account number

Mr. May has not publicly disclosed whether other data types, such as Social Security numbers or dates of birth, were part of this incident. For now, the confirmed exposure centers on identity and account-level financial information.

Even this narrower combination of data carries real risk. A name paired with an account number can let a bad actor attempt unauthorized transfers or impersonate the account holder when contacting a bank or brokerage. Fraudsters often combine stolen account details with other publicly available information to build a more convincing profile for social engineering attacks.

In addition, account-level fraud can be harder to detect quickly because it may not trigger the same alerts as a stolen credit card. Consequently, ongoing account monitoring becomes especially important. Financial fraud stemming from a stolen account number can take weeks to surface, which is part of why extended monitoring periods matter so much after an incident like this one.

What is the company doing?

Once Mr. May identified the suspicious activity, he acted to secure the affected accounts immediately. He then engaged third-party cybersecurity firms to investigate the intrusion and determine what data had actually been viewed. This forensic work concluded in late July 2026.

Following that determination, Mr. May notified the New Hampshire Attorney General’s office, as required under the state’s breach notification law. He also began mailing individual notification letters to the affected resident by first-class mail in August 2026.

As part of his response, Mr. May set up a dedicated call center so affected individuals can ask questions about the incident. He is also offering twelve months of complimentary credit monitoring and identity theft protection through Cyberscout, a TransUnion company, to the impacted client.

What Should Affected Individuals Do?

Enroll in the Offered Credit Monitoring

If you received a notification letter, take advantage of the twelve months of free credit monitoring and identity theft protection through Cyberscout. This service can flag suspicious activity on your credit file before it spirals into a larger problem.

Because enrollment typically requires action within a set window, don’t wait to sign up. Check the letter for the specific enrollment deadline and mark it on your calendar right away.

Consider a Fraud Alert or Credit Freeze

Since a financial account number was exposed, placing a fraud alert or full credit freeze with Equifax, Experian, and TransUnion adds another layer of protection. A freeze restricts new accounts from being opened in your name without your explicit approval.

This step is especially useful when account-level data has already been viewed by someone outside your control. As a result, even if your account number alone can’t open new lines of credit, a freeze helps guard against related identity theft attempts using your name and other details.

Watch Your Financial Statements Closely

Review your bank and brokerage statements regularly for any transactions you don’t recognize. Because the exposed account number could be used to attempt unauthorized transfers, early detection matters.

If you spot anything suspicious, report it to your financial institution immediately. In addition, file a report with local law enforcement so there’s an official record if further fraud develops.

Stay Alert for Phishing Attempts

Scammers often follow a breach announcement with phishing emails or calls designed to look like they’re from your bank or advisor. Be cautious of any message asking you to confirm account details or click a link.

Instead, contact your financial institution directly using a phone number you already know is legitimate. This simple habit can prevent a second wave of fraud from compounding the original exposure.



Related Data Breaches

Check other recent data breach notifications →