Active extortion or breach? Call +1 212 457 9797 · Beware impersonation — we e-mail only from @dilendorf.com

Video · HNW Cybercrime Defense

You Are the Target: Cybercrime & High-Net-Worth Families

In 2025, the FBI confirmed cybercrime losses in the United States crossed $20 billion for the first time — more than doubling since 2022. Criminals now use AI to clone voices, map family relationships, and bypass authentication systems at a scale not possible three years ago. This is not a technology problem.

Dilendorf Law Firm, New York 1,740 words, transcribed

In 2025, the FBI confirmed cybercrime losses in the United States crossed $20 billion for the first time — more than doubling since 2022.

Criminals now use AI to clone voices, map family relationships, and bypass authentication systems at a scale not possible three years ago. This is not a technology problem. It is a wealth preservation problem.

Full transcript

0:12 If you are a founder, a family office principal, or a high-net-worth investor — you are not a random target. You are a specific one.

0:22 In 2025, the FBI confirmed that cybercrime losses in the United States crossed $20 billion for the first time in history. That number has more than doubled since 2022.

0:38 And according to experts who track these trends closely, we are still in the early stages of this cycle. As AI becomes more sophisticated, attacks are becoming faster, more targeted, and more difficult to detect.

0:57 Criminals are using AI to clone voices, map family relationships, bypass authentication systems, and automate attacks at a scale that simply was not possible three years ago.

1:13 This is not a technology problem. It is a wealth preservation problem.

1:18 I'm Max Dilendorf. I'm a New York attorney, and I've been working in digital asset and crypto law since 2017.

1:26 Since 2019, I've focused specifically on cybercrime — helping clients recover assets, manage high-stakes incidents, and coordinate with federal agencies.

1:42 What sets our practice apart is the team behind it.

1:46 On cybercrime matters, our team includes retired FBI and Department of Justice cybercrime enforcement agents — professionals who spent their careers building federal cases, coordinating with prosecutors, and deciding which investigations warranted federal resources.

2:10 That institutional knowledge now helps our clients.

2:14 We don't just respond to incidents. We advise founders, family offices, and high-net-worth individuals on asset protection strategies built for the modern age.

2:30 And here is the hard truth most people don't want to hear.

2:35 You can have the most sophisticated legal structure in the world — offshore trusts, layered entities, privacy-optimized holding companies across multiple jurisdictions.

2:48 But if your phone is compromised, if your credentials are stolen, if your device itself is the point of entry — the structure becomes irrelevant.

3:00 You are the endpoint of failure. And that is where attackers go first.

3:07 In our practice, we see these attack patterns play out in real time. Let me walk you through exactly what we are seeing today. This is the one that surprises people most. Attackers do not strike immediately. They study you first — sometimes for weeks, sometimes for months. They learn your communication style, your relationships, your decision-making patterns, and your daily routine. Here is a pattern that we see consistently.

3:48 A compromised phone gives an attacker real-time visibility into your movements.

3:55 They know when you are flying from New York to Singapore. They know when your device goes offline at 35,000 feet. And they know that window — when you are unreachable, when your team cannot get to you, when no one can verify instructions — is exactly when to act. By the time you land, the damage may already be done. This is no longer just a digital threat — it is a physical one. Properties today are controlled through mobile applications. Gates. Alarms. Cameras. Access points.

4:39 If those systems are compromised through a hijacked phone or leaked contractor credentials, an attacker can disable your property protections or unlock your access points remotely.

4:55 In early 2025, a breach at a U.S. coastal estate allowed attackers to disable alarms and gain physical entry while the family was present. The breach started with a compromised app. It ended at the front gate. Digital compromise has become a physical threat. The boundary between cybersecurity and personal safety is gone.

5:27 AI now makes it significantly easier to identify high-net-worth individuals, map family relationships, and track real-time location signals — through compromised devices or public platforms like Instagram. We are seeing increased demand for kidnapping insurance as a direct result. This is not hypothetical. This is a documented, accelerating trend affecting ultra-high-net-worth families globally.

6:08 Coinbase. Kraken. Gemini. Binance.US. These are federally regulated platforms where clients completed full identity verifications, linked their bank accounts, and trusted the exchange with serious money. And clients on these platforms are still getting compromised. A client wakes up to find their account accessed overnight. Two-factor authentication changed. Assets transferred out in minutes to wallets.

6:44 The exchange's response? Terms of service. Go file a police report.

6:50 We are also seeing a sharp rise in attacks on payment platforms — Stripe, PayPal, and traditional banking portals — resulting in unauthorized transactions that clear before a single fraud alert fires. Attackers gain control of your website domain, take over your business email infrastructure, and shut down your company's online presence.

7:22 A professional attacker with admin access can redirect your domain, intercept your email communications, and impersonate your business — in under ten minutes.

7:36 Criminals convince your mobile carrier to transfer your phone number to a device they control.

7:44 From that moment, every SMS-based authentication code — every verification text, every password reset — goes to them, not you. In many cases these attacks are executed through basic social engineering of a carrier support agent.

8:03 They are surprisingly simple. And we see them constantly.

8:12 Sometimes used immediately for extortion. Sometimes held quietly for months and deployed later — often targeting high-profile individuals including executives, founders, celebrities, and public figures. The data is a weapon. And attackers are patient.

8:33 These are coordinated, cross-border operations.

8:37 They are targeting your identity, your access points, and your ability to move money.

8:43 Here is where most people fundamentally misunderstand how the legal system works.

8:48 Every platform you rely on — your crypto exchange, your bank, your phone carrier, your payment processor, companies like Apple and Stripe and Coinbase — has buried mandatory, binding arbitration clauses in their terms of service. You agreed to them.

9:07 You almost certainly never read them. That means when something goes wrong, your dispute is not going to a public courtroom. It is going into private arbitration — behind closed doors, with no press, no public record, and no jury.

9:23 When the service provider through which you were compromised tells you there is nothing they can do — that is often the beginning of the legal conversation, not the end of it.

9:35 These exchanges, these carriers, these platforms have specific contractual obligations around security, authentication standards, fraud detection, and account monitoring.

9:49 When they fail to meet those obligations — and their failure contributes to your loss — those failures may be actionable. My firm has filed more than 100 cybercrime-related arbitration cases at AAA, JAMS, and NAM — against major financial institutions and phone-carriers, including T-Mobile, Verizon, Coinbase, Gemini and others.

10:18 These cases are highly technical and evidence-driven. They turn on system logs, AI-driven compliance records, user agreements, liability frameworks, and expert witnesses.

10:31 We know exactly where institutional liability exposure lies.

10:38 Because these proceedings are private, they rarely become public. That makes how you build and present your case even more critical. One more thing most clients do not realize until it is too late. Cyber insurance is not a guaranteed safety net.

10:56 Claims are increasingly being denied — often because multi-factor authentication was not fully implemented across all systems as required by the policy.

11:09 The attack happened. The loss is real. But the insure company argues the contractual obligations of the policy were not met. The policy exists. The coverage does not.

11:25 According to industry data, between 25 and 40 percent of cyber insurance claims are now being denied. If you have cyber coverage, the time to review if it actually covers you is before an incident — not after.

11:43 When a cyber incident happens, time is everything.

11:47 The first 24 to 72 hours determine whether assets can be frozen, evidence preserved, and federal investigators have a real chance to act. After that window closes, recovery becomes exponentially harder. Most victims file with the FBI's Internet Crime Complaint Center — IC3. That is the right first step.

12:16 But thousands of complaints are filed every single day.

12:20 Most go nowhere — not because the cases are invalid, but because the reports are poorly structured and lack actionable evidence. This is where our retired FBI and DOJ agents change everything. They know exactly how federal investigators evaluate incoming complaints — because they spent careers making those decisions.

12:47 They know what a compelling IC3 report looks like from the inside. They know how to present evidence that maximizes the probability of federal resources being assigned to your case.

13:01 A well-drafted report can get traction. A generic one will likely be ignored.

13:08 When clients come to us, the response is immediate and coordinated.

13:13 We engage with federal and state law enforcement.

13:17 We structure and file IC3 reports built to move investigators.

13:24 We issue evidence preservation demands to exchanges, carriers, and hosting providers before critical logs are deleted. We coordinate asset tracing and dark web monitoring. And where appropriate, we handle controlled ransomware negotiations in full compliance with FinCEN guidance and OFAC sanctions requirements.

13:49 On the legal side, we analyze every governing contract and user agreement — because how your rights are defined in those documents determines your entire legal strategy.

14:03 And we represent clients in arbitration against the institutions that failed them.

14:09 The goal is simple. Mitigate risk immediately. Maximize the probability of recovery. And make sure the institutions that failed you are held accountable.

14:21 Beyond incident response, we design ownership and holding structures for clients in the United States and internationally — optimized for discretion, control, and resilience.

14:34 The goal is to make it materially harder for automated systems and bad actors to map your assets, your relationships, and your identity. But the core issue never changes.

14:48 Your phone. Your devices. Your credentials. That is where everything breaks.

14:53 Effective protection requires both legal architecture and personal discipline.

15:00 The structure matters. And so does every password, every authentication method, and every device you use to access your financial life. Both have to be right. At the same time.

15:14 We are still early in the cybercrime cycle. As AI, data exposure, and digital asset adoption continue to accelerate — the scale and sophistication of these attacks will only increase. For high-net-worth individuals and family offices, this is no longer just a cybersecurity issue. It is a core wealth risk. It belongs in the same conversation as tax planning, estate strategy, and investment management.

15:46 At a minimum — audit your digital footprint, including a dark web scan.

15:52 Secure your domain and registrar access. Stop using SMS-based authentication.

15:59 Separate your personal and financial communication channels. And establish a response protocol before anything happens. Cyber incidents do not announce themselves.

16:12 They happen fast. And they escalate faster. If you are dealing with an active incident — call us immediately. If you want to get ahead of this before something happens — schedule a confidential consultation at dilendorf.com.

16:29 Our team — attorneys, retired FBI agents, and DOJ cybercrime veterans — are ready to move the moment you call. I'm Max Dilendorf. Stay sharp.

A transcript of the recording, so it reads as speech rather than as prose. It explains the law in general terms and is not advice on your own situation, which turns on facts this video cannot know.

More on this subject

Discuss Your Matter

Confidential consultations by appointment.

Call us now Request consultation