Cyber & Resilience - 6 min read - 23 July 2026

Your bank didn't lose your data. Its accountant did, ten months before anyone told you.

An unauthorised party sat inside Mercadien P.C.'s network for over three weeks in autumn 2025. Mercadien is an accounting firm. One of its advisory clients was Pinnacle Financial Partners, a US bank. Pinnacle only confirmed in June that its own clients' Social Security numbers and account details were in the stolen data, and notifications are only landing now. The gap between intrusion and notice is the real story.

Mercadien, P.C., a certified public accounting firm that provides advisory services to a range of business clients, detected unauthorised access to its network in November 2025, tracing the intrusion itself back to a window between 17 September and 9 October 2025, according to the firm's own breach notice as summarised by ClassAction.org's coverage. The exposed data, per that notice, includes names, addresses, dates of birth, government ID numbers, Social Security numbers and financial account details, with some individuals' usernames, passwords, IRS PINs and payment card information also affected. The firm reported the incident to the Maine and Massachusetts Attorneys General in late December 2025 and began notifying individuals directly.

That would already be a bad quarter for Mercadien. It became a worse one for Pinnacle Financial Partners, a Tennessee-based bank, when Pinnacle determined on 16 June 2026 that data belonging to some of its own clients was part of what Mercadien had lost. Morgan & Morgan's Data Breach Brief, published this week, lists Pinnacle among the notable disclosures of the past seven days, alongside a note that affected individuals are being offered twenty-four months of complimentary credit monitoring and identity protection through Experian IdentityWorks. Nine months, in other words, separate the intrusion from the moment Pinnacle's own clients found out their Social Security numbers had been sitting in a compromised third-party system.

Nobody in this chain lied. The timeline is the problem.

There's no evidence here of a cover-up. Mercadien found the intrusion, reported it to regulators within the expected window, and began notifying its own directly affected clients. Pinnacle, once it learned its clients' data was implicated, disclosed that too. Every individual link in the chain behaved roughly as a breach notification framework expects. The problem is what happens when you add the links together: discovery, forensic investigation, determining which of your clients' clients were actually affected, and finally notifying the people at the end of that chain is a process that, done properly and honestly, still took the better part of a year here. For someone whose Social Security number was exposed in September 2025, "properly and honestly" is cold comfort against "ten months of exposure before you knew to watch for it."

This is the structural cost of subcontracted trust. Pinnacle's clients never chose Mercadien, never signed anything with Mercadien, and in most cases had likely never heard of Mercadien before this notice arrived. Their data ended up there anyway, because Pinnacle's advisory relationship with an accounting firm required sharing it, and the accounting firm's own security posture became, without any of those clients agreeing to it, a determining factor in whether their identity stayed safe.

Third-party breach notification chains are getting longer, not shorter

We've covered this pattern before with Nintendo's breach through an HR survey vendor, where the exposed data belonged to employees who had no direct relationship with the compromised platform at all. The Mercadien-Pinnacle chain adds a further link: it isn't the primary vendor's own customers who are exposed, it's the customers of the company that hired the vendor for a supporting function. Every additional hop in a vendor relationship is an additional hop in the notification chain when something goes wrong, and each hop tends to add weeks or months, not days, to the time before an affected individual actually learns their data was involved.

For enterprise risk teams, the uncomfortable implication is that your own vendor risk register probably stops one layer too early. Most programmes assess the vendors you contract with directly. Far fewer ask those vendors which of their own subcontractors and professional service providers - the accounting firm, the outside counsel, the benefits administrator - hold copies of data that originated with your customers. That's exactly the layer where this incident happened, and it's the layer that formal pre-contract technology due diligence most often skips, because the fourth-party relationship isn't visible in the contract you're actually reviewing.

  • Ask direct vendors and professional services providers (accountants, auditors, outside counsel, benefits administrators) which of their own subcontractors receive copies of data that originated with your organisation or your customers.
  • Set an internal service-level expectation for how long "detection to individual notification" should take across your own vendor relationships, and flag any vendor contract that doesn't commit to a comparable window.
  • Confirm your incident response plan has a defined path for a breach at a vendor's vendor, since liability, notification obligations and customer communication all get harder to own cleanly the further removed the breached party is.
  • Review what categories of sensitive data (SSNs, IRS PINs, payment details) your professional services providers actually need to hold versus what they've simply accumulated over successive engagements.

Nobody in the Mercadien-Pinnacle chain did anything obviously wrong after the fact. That's precisely why it's worth studying: a breach notification process that follows every rule can still leave real people exposed for the better part of a year, and the fix isn't better crisis communications, it's shortening the chain before an incident ever happens. If you'd like help mapping the fourth-party exposure hiding inside your own vendor contracts, email sales@halfteck.com.

Explore more resources

Browse our full library of enterprise cloud, software, data and AI content.

View all resources