Hacked! Is Your Retirement Plan at Risk for a Cyber Attack?

April 15, 2024

Cyber-crime is on the rise worldwide. As a result, growing numbers of organizations are taking critical steps to protect their valuable electronic data from hackers and other cyber criminals — a process known as cybersecurity. It’s serious business, and a trend retirement plan sponsors and committees should pay attention to.

“Cyber-crime is the greatest threat to every company in the world,” said IBM’s chair, president and CEO Ginni Rometty. Billionaire investor and businessman Warren Buffett echoed that sentiment, claiming that “cyber-attacks are a bigger threat to humanity than nuclear weapons.” In short, cyber-crime is extremely dangerous, and many businesses are vulnerable to cyber-attacks — some without even knowing it. 


Why Is Cybersecurity Important?

Thanks largely to the proliferation of high-profile cyber-attacks and data breaches that have hit organizations over the years, Gartner Group calculated an estimated worldwide cybersecurity spending of $150.4 billion in 2021. Moreover, information security research firm and publisher Cybersecurity Ventures predicts that, by 2025, cybercrime will cost the world $10.5 trillion annually. A single successful cyber-attack can cost an organization millions of dollars. Clearly, the costs related to cybersecurity threats are significant. 

Cybersecurity and Your 401(k) Plan 


Beyond the expenses related to a potential cyber-attack, there are a number of reasons why retirement plan sponsors and committees should focus on specific cybersecurity efforts to protect their plan assets and information. For starters, if you think your plan isn’t a target, think again. It’s not a matter of if, but when your plan gets hacked.


Here’s why: Recently, cyber attackers have begun to set their sights on plan sponsors themselves rather than their recordkeepers and custodians because they know that the former typically lack the sophisticated cybersecurity defenses of their vendors. 


Cyber criminals also know that defined contribution (DC) plan sponsors and their vendors manage large amounts of money, and in so doing, collect highly sensitive personal data from plan participants and their beneficiaries. This includes names, address, birthdates and Social Security numbers. This information is extremely valuable to hackers because most of it is permanently associated with an individual and can’t be changed or cancelled like a credit card or bank account information. 


Enrollment data such as account balance, direct deposit and compensation/payroll information is also at risk, and therefore, potentially vulnerable to a cyber-attack if not properly handled and protected by plan sponsors and their third-party vendors. Therefore, it’s critical for sponsors to address cybersecurity within their own organizations, as well with vendors such as recordkeepers, trustees, TPAs and investment advice providers, which receive personal data from the plan.


Some examples of cyber threats to retirement plans might include fraudulent distribution or loan requests, or ransomware attacks and phishing techniques where a hacker might obtain log-in credentials (i.e., through a stolen laptop or mobile device storing personal data and passwords) to access participants’ account information online. 


What Is My Responsibility?

While retirement plan information is protected under specific regulations, there are no comprehensive laws that protect plan sponsors and service providers against cyber threats, like there are for group health plans (i.e., the Health Insurance Portability and Accountability Act, or HIPAA). Nonetheless, plan sponsors must act in a fiduciary capacity under the best interest clauses of the Employee Retirement Security Income Act (ERISA), the law that governs retirement plans. In addition, sponsors must adhere to the data privacy requirements for electronic notices. The following graphic breaks down the regulatory guidelines for plan sponsors’ fiduciary duties related to cybersecurity and electronic distribution of plan information:


Regulations and Cybersecurity*


Fiduciary Obligations

  • The selection and monitoring of service providers is a fiduciary act
  • The decision makers must act prudently and solely in the interest of the plan participants and beneficiaries
  • Plan fiduciaries are liable for failing to prudently select and monitor service providers 
  • This may include prudence in selecting and monitoring service providers to ensure they maintain adequate cybersecurity practices and protocols


ERISA and electronic distribution of plan information

  • If plan notices are disseminated electronically, the plan sponsor (and not the service provider) is required to protect the confidentiality of personal data
  • Similarly, plan sponsors are required to take measures to ensure websites with plan information are secured to protect the confidentiality of personal information


*Source: Callan


Several states also have laws governing the protection of employees’ social security numbers and employers’ responsibilities to notify employees in the event of a security breach. However, these laws are designed to regulate the employer rather than the plan sponsor, so ERISA would likely take precedence in a retirement plan-related cyber-attack.


What Can I Do to Protect Plan Assets and Information?


Most organizations take a reactive approach to cyber-attacks, addressing them only after an incident has occurred. However, that can be expensive, complicated and mostly ineffective. 


Plan sponsors have an opportunity to proactively address and manage cybersecurity risks using a variety of tactics to improve their ability to prevent, detect and respond to cyber-attacks.


First off, assume that your company’s retirement plan will be attacked. When setting up defenses against cyber threats, consider addressing the following questions:

  • What is our internal risk?
  • Where does our data go and how is it transmitted and stored (e.g., to third parties, or maintained on a server or in the cloud)?
  • Have we done appropriate due diligence on our vendors, and any partners with whom they may share data? 
  • What is our organization’s definition of a “breach”? 
  • What is our vendors’ definition of a “breach,” and what would prompt them to disclose that to us? 
  • How do we monitor our internal processes and procedures, and that of our external partners, on an ongoing basis? 
  • Do contracts and agreements cover indemnification, notification procedures (i.e., does the vendor have to notify us when it discovers a breach, or only after the breach has been contained) and remediation? 
  • What is our process for when we experience a breach?


In addition, plan sponsors should: 

  • Implement a specific process for addressing and fixing cybersecurity concerns, which would include, for example, identifying potential security gaps in how they share information with third party vendors. 
  • Make sure they have appropriate cyber liability insurance coverage to help mitigate damages from potential attacks, and that they understand what the policy covers. Ideally, the coverage should be as broad as possible.
  • Consider hiring an outside cybersecurity firm with retirement plan experience to conduct periodic audits and ensure participants’ data is secure.
  • Thoroughly vet external service providers and negotiate to put responsibility on the vendor for correcting damages from a cyber-attack on a plan.
  • Put processes and stop gaps in place to restrict access to plan systems, applications, data and other sensitive information.
  • Develop a cybersecurity risk management strategy specific to their retirement plan, which addresses the sponsor’s response to a breach (including appropriate notices and remediation methods). 


Moreover, sponsors should also encourage plan participants to:

  • Regularly check accounts for unauthorized activity.
  • Protect passwords and login information. Participants should choose strong passwords, change them regularly and avoid accessing retirement savings accounts using shared computers or open Wi-Fi networks.
  • Protect laptops and other devices with encryption.
  • Participants should be instructed to read plan-issued materials and keep their contact information up to date. Accurate contact information ensures they can be contacted as soon as possible in the event of a data breach so they can take immediate action. 
  • Consider consolidating retirement savings when changing jobs. Fewer open retirement saving accounts means reduced odds of exposure to a data breach.


Cyber threats are evolving and becoming more sophisticated every year. As such, plan sponsors must do their best to try to stay one step ahead of hackers by heightening their cybersecurity defenses to protect the personal information of participants and their beneficiaries. 


Retirement plan fiduciaries can take proactive steps to help secure sensitive retirement plan data. The challenge for many is knowing where to start. We hope this article provided several key steps plan sponsors and retirement committees can take to boost their cybersecurity protections and fortify their plans against insidious cyber-attacks.


 [1]Morgan, Steve. “Top 5 Cybersecurity Facts, Figures and Statistics for 2018.” Jan. 2018.

 [2]Oyedele, Akin. “BUFFETT: This is the number one problem with mankind.” May 2017. 

 [3]STAMFORD, Conn. “Gartner Forecasts Worldwide Security and Risk Management Spending to Exceed $150 Billion in 2021.” May 2021. 

 [Morgan, Steve. “Cybercrime To Cost The World $10.5 Trillion Annually By 2025.” 13, Nov. 2020.

September 15, 2026
The Challenge Sometimes the most expensive retirement plan mistakes aren't dramatic. They're quiet. A former client of ours changed retirement plan providers following an acquisition several years prior. On the surface, everything appeared to be operating normally after moving to the new provider: employees continued making contributions to the plan, the plan’s investments remained in place, and the business continued its normal operations. Then another merger opportunity came along. As part of their due diligence process, the buyers reviewed the retirement plan. What they found immediately raised concerns. The annual Form 5500 filings required by ERISA law had not been submitted for several years. That also meant that none of the required compliance testing had been completed, and routine administrative responsibilities had also gone undone. What had started as a routine review quickly became a significant obstacle to completing the business sale. The Hidden Risk Many employers assume that once a retirement plan provider is hired, responsibility for the plan’s ongoing administration has effectively been transferred to that provider. But a plan sponsor is never completely relieved of its responsibility to oversee the plan. Even when outside providers are hired to handle filings, testing, recordkeeping, or other administrative functions, the employer still needs to make sure those responsibilities are being fulfilled. At the same time, there is an important difference between a provider that simply waits for the employer to supply information and one that actively works with the employer to make sure the plan stays on track. In this case, some of the missing work may have resulted from information requested by the provider that was never supplied by the employer. Technically, the employer still had a responsibility to provide that information and ensure the work was completed. But years of required administration should not quietly disappear into a communication gap. A proactive administrator follows up. If the usual contact isn’t responding, they escalate the issue. They make sure the appropriate people understand what is outstanding, why it matters, and what could happen if it isn’t addressed. Retirement plans require ongoing attention every year, including government filings, compliance testing, participant administration, documentation, and, when necessary, operational corrections. When those responsibilities are neglected, the consequences may not become obvious immediately. Instead, problems can accumulate quietly in the background until an IRS inquiry, Department of Labor investigation, audit, or—as in this case—a business transaction suddenly exposes years of unresolved issues. The prospective buyer made it clear that the retirement plan issues needed to be addressed before the transaction could move forward. The Rescue Knowing we had previously administered their plan, the current company leadership contacted us. Our first step was to determine the full scope of the problem. The timing made the situation particularly challenging. This wasn’t simply a retirement plan cleanup project. A business transaction was underway, and the company needed answers quickly. We assembled a team to determine the full scope of the problem and begin developing a path forward. Because we have deep experience with taking over neglected plans, we were able to separate perceived problems from actual compliance issues and reconstruct the plan's history. In reviewing the prior documentation, we identified exactly which administrative functions had been completed and which had been missed. We gathered historical payroll and participant data and developed a comprehensive correction strategy. Having access to historical plan records was especially important. Retirement plan problems may not surface until years after the underlying event, making good record retention critical. If you’re curious about how long to hold onto plan documentation, please see our blog post here . The final correction effort proved to be far more manageable than originally feared. Instead of allowing uncertainty around the retirement plan to continue hanging over the transaction, the employer now understood what had actually gone wrong, what needed to be corrected, and what steps were required to move forward. The Outcome With the correction efforts clarified and a clear roadmap in place, the employer was able to begin correcting the plan and continue moving toward its business transaction. More importantly, the company avoided entering the acquisition process with unresolved retirement plan liabilities hanging over or ruining the deal. The experience also reinforced an important lesson: Changing retirement plan providers doesn't eliminate administrative responsibilities. But it also demonstrated why the quality of the administrator matters. A good retirement plan administrator doesn’t simply process the information that arrives. They help make sure the information arrives in the first place. The Lesson: Oversight Is a Shared Process Employers ultimately have a responsibility to oversee their retirement plans, even when they hire professionals to handle much of the day-to-day work. That doesn’t mean the employer should have to become a retirement plan expert or personally track every filing deadline and compliance requirement. That’s one of the reasons experienced administration matters. A proactive provider should help keep the employer informed, identify missing information, follow up when something is outstanding, and escalate issues before a missed request becomes a missed filing—or several years of missed filings. The cost of failing to do so can extend well beyond an annual administration fee: Missed filings and potential penalties Incomplete compliance testing Corrective work Additional professional fees Delayed business transactions Uncertainty during mergers and acquisitions  By the time those costs appear, they can far exceed whatever might have been saved by choosing a lower-cost service model. That’s why retirement plan administration shouldn’t simply be viewed as paperwork. It should be viewed as an ongoing partnership in managing risk.
August 18, 2026
The Challenge A business owner came to us after receiving confusing news from their retirement plan actuary. Their Defined Benefit (Cash Balance) Plan had performed exceptionally well over several years; strong investment returns seemed to have created what’s called an overfunded Plan. While it seems like a positive name, an overfunded plan can create excessive and unexpected tax liabilities. So, their actuary recommended terminating the Plan by transferring the excess assets into the company's other Plan, a 401(k)/Profit Sharing Plan, before eventually closing both Plans, a lengthy and complicated process.
July 15, 2026
As we wrap up the second quarter of 2026, one trend continues to stand out: retirement plans are becoming increasingly specialized. Whether driven by changing regulations, unique workforce structures, or evolving business goals, employers are finding that a one-size-fits-all approach simply doesn't work. This quarter, we explored the unique retirement plan challenges facing several industries—including medical and dental practices, construction companies, architecture and design firms, wineries, and California employers navigating CalSavers requirements. We also continued our series on the hidden risks of low-quality retirement plan services, highlighting how operational complexity, fragmented accountability, and misaligned incentives can create costs that extend far beyond administrative fees. For employers still evaluating their retirement plan options, we also discussed opportunities that many business owners overlook, including the ability to establish retirement plans after filing a tax extension and potentially generate meaningful tax savings. Below is a recap of the articles we published this quarter. We hope they provide practical insights to help you reduce risk, improve plan performance, and make more informed retirement plan decisions.
More Posts