Asset managers hold the maps that connect principals, family offices, advisers, entities, and capital movements. That placement puts them inside private-client networks where one compromised set of relationship records lets an attacker move from impersonation to wire instructions or document access without ever touching the principal's own systems.

Ransomware.live and FalconFeeds.io recorded the INC Ransom listing of belpointeasset.com and belpointe.com on 22 June 2026. BreachSense logged the same item with a claimed 400 GB data size. Incident type: ransomware/extortion listing.

The records that matter are not portfolio holdings. They are the names of advisers, fund interests tied to specific entities, recent document requests, capital-call schedules, entity ownership chains, and the email addresses and phone numbers used for day-to-day coordination. An attacker with those facts can draft a request that references an actual upcoming call amount, the correct entity name, and the last document packet sent, then route it to the exact staff member who handled the prior exchange.

Immediate exposure points

Every client that routes wires, signature packets, or liquidity updates through Belpointe now sits on an open reference list. The attacker knows which portals accept instructions, which staff members clear capital calls, and which email threads contain prior approvals. Instructions that previously moved on email alone can be replayed with matching context. Entity structures listed in the data show which accounts sit behind which advisers, so forged requests can target the right approval chain instead of guessing.

Staff accounts left active on shared portals after role changes give direct entry. Historical folders that still contain tax documents or prior correspondence supply templates for future fakes. Any message that names a fund, cites a recent transaction date, or references an internal entity identifier can be made to look routine because the attacker already holds the surrounding facts.

Secvred control layer

Secvred would map every capital-call notice, wire instruction template, and document-portal request that touches Belpointe or any connected adviser. It would remove all stale adviser and staff accounts from shared portals. It would lock payment authority behind a pre-approved callback number or secondary channel that email alone cannot change. It would verify any message that names a specific fund, recent transaction, or internal entity by forcing an independent check outside the original thread. It would empty or access-restrict old shared folders holding historical correspondence or tax documents. It would monitor every new request that references Belpointe-linked entities and make any email-only instruction that moves funds or unlocks records unusable until the secondary channel confirms.

Operational follow-through

List the exact email addresses and portal logins that exchange wires or signature packets with Belpointe. Mark which instructions currently require only email content and which facts from the claimed data set would validate a forged version. Trace every entity that appears in Belpointe correspondence and confirm whether its approval chain still relies on the same contacts listed in the records. Remove any shared folder that contains prior capital-call notices or entity diagrams. Separate fund-interest data from the email identities that normally reference it so that context alone cannot trigger movement of capital or release of documents.

Repeat the same mapping for every other asset manager that holds similar relationship records for the same principals. The pattern repeats across firms that sit between family offices and their underlying entities. One listing supplies the template; the next listing supplies the next set of live references.