Sector study · scan of 26 September 2026
How UK Wealth and Investment Managers Look to an External Scan
A September 2026 baseline of 193 firm websites drawn from the UK’s largest wealth managers and investment managers, scanned from the outside using only what anyone on the internet can see.
35 of 184
firms have staff passwords on criminal lists (953 records)
53
cannot tell mail systems to refuse email forged in their name
6
named on ransomware leak sites
71.2
average exact score out of 100
What we found
Stolen staff passwords for 35 of the 184 firms reported, about one in five, appear in criminal credential collections: 953 records, an average of 27 per affected firm. Most were harvested by malware on individuals’ own devices or come from breaches of other websites. We cannot see whether any still works, and we did not try, but each firm can reset those logins today.
Fifty-three firms do not instruct receiving mail systems to refuse or spam-file email forged in their name. In this sector that matters more than the number suggests. A message that appears to come from a client’s adviser, about their own portfolio, is the opening move in a payment-redirection fraud, and the setting costs nothing to publish.
Six firms appear on ransomware leak sites. A listing is a criminal group’s own claim and needs matching to the right entity and date before anyone draws a conclusion. Two firms report a software version matching a flaw on the public list of those being exploited. Both are the same flaw, which can take a website offline but gives no access to data.
Six firms have a risky port answering on an address used only by that firm, among them one identified database server and one file-transfer server. A further 14 cases sit on shared provider addresses and are reported separately, because only the provider can confirm or close them.
There is good news too. No firm carries a known-breach record or a browser safety warning, and 131 of 184 firms, 71%, refuse forged email or send it to spam.
How to read the scores
150 firms have an exact score, averaging 71.2. 34 have a floor score, because their website turned an automated visitor away, which is a security control working rather than a fault. Counting those at their floor, the average across all 184 is 69.0. Wealth managers average 70.4 and investment managers 72.2 on exact scores. The two lists share 21 firms, so that gap is not a ranking. Nine websites produced no usable score and are excluded.
What this is, and what it is not
We looked at each firm’s website from the outside, the way any client could. We did not log in anywhere, try any password or exploit anything. Nothing here means a firm has been broken into, nothing here is a compliance judgement, and the report names no firm. The 75,696 client records linked to 102 firms belong to members of the public whose own devices were infected. They are not a leak from any firm.
Where to start
Reset and protect any staff logins found in criminal collections, with multi-factor authentication. Publish an email policy set to refuse or spam-file forged mail. Close or restrict any database or file-transfer port answering the internet, and patch against HTTP/2 Rapid Reset.
Read the full report
Download the full report (PDF, 27 pages)See how a domain looks to an external scanThis analysis was produced with MyDomainRisk, a product of Huro Data Technologies Ltd, which has a commercial interest in it. It is not independent certification, an audit, or legal or regulatory advice.