• Current precious-metal spot prices
  • Gold $4,416.47 +40.00 (+0.91%)
  • Silver $65.78 +1.08 (+1.68%)
  • Platinum $1,772.60 +23.50 (+1.34%)
  • Palladium $1,324.70 +8.49 (+0.64%)
  • updated 23 hours ago
Login
Signup

What To Do If Your Gold IRA Custodian Has a Data Breach

By Goldiew Research & Editorial · Last reviewed: July 22, 2026 · 12 min read

Editorial transparency. Goldiew may earn a commission when you use a link on this page to connect with a partner company, at no extra cost to you. That commission never influences our research, ratings, or recommendations. We feature only companies we have researched and consider credible, and because we are not the company itself, we do not set its prices or terms. The information here is educational, not financial or legal advice.

Quick answer

A breach exposes your account data, not your physical metal

When a gold IRA custodian reports a data breach, your physical gold remains secure in a regulated depository under controls that no stolen credential can bypass. The real risks are identity theft and targeted phishing built from your exposed account details. Act on three fronts: freeze your credit at all three bureaus, reset your custodian login with a new password and multi-factor authentication, and treat any incoming contact that references your holdings with heightened skepticism until you verify it through an official channel.

What a Breach Actually Exposes

A data breach at a gold IRA custodian typically involves unauthorized access to customer account records held in the custodian’s administrative systems. Those records can include your full legal name, Social Security number, date of birth, mailing address, email address, account number, account balance, and transaction history. In some cases, copies of identity documents submitted during the KYC (know your customer) process are also stored.

That combination of data is genuinely dangerous in the hands of a skilled fraudster. Social Security numbers combined with full names and dates of birth are the raw material for new-account fraud, synthetic identity schemes, and IRS tax return theft. Account balance information tells an attacker exactly how valuable a target you are, which shapes how much effort they invest in follow-on social engineering.

What a breach does not expose is your physical metal. Your gold bars and coins are stored at a separate third-party depository, which maintains its own physical security, its own access controls, and its own records entirely independent of your custodian’s data systems. A depository withdrawal requires a documented, custodian-processed instruction routed through institutional channels with identity verification that goes far beyond a username and password. No attacker who steals your account data can walk up to a vault and claim your holdings.

Data typeHeld by custodian (potentially at risk)Held at depository (separate, not at risk)
Name, SSN, date of birth✓ In account records
Account balance and transaction history✓ In account records
Mailing address and contact details✓ In KYC files
Physical gold and silver holdings✓ Vaulted at regulated depository
Withdrawal authorization✓ Requires documented custodian instruction, separate channel

Understanding this separation matters before you decide how to respond. Your retirement assets are protected by the physical and operational gap between custodian records and depository storage. Your personal identity requires prompt action from you, but your metal does not require an emergency transfer or any hasty decision. For more on how depository storage protects your holdings, see our guide on insurance coverage at gold IRA depositories.

Your Legal Protections Under the GLBA Safeguards Rule

Gold IRA custodians are financial institutions under the Gramm-Leach-Bliley Act, which means the Federal Trade Commission’s Standards for Safeguarding Customer Information (16 CFR Part 314) apply directly to them. A 2023 amendment to that rule added an important customer protection: financial institutions that experience a security event affecting 500 or more customers must notify the FTC within 30 days of discovery. Customer notification obligations exist alongside that requirement, governed by the Safeguards Rule and by the breach notification statute of each state where the affected customers reside.

All 50 states have enacted their own breach notification laws. While the specific timelines, covered data categories, and enforcement mechanisms vary by jurisdiction, the consistent thread is that affected residents must be notified in a reasonably prompt manner after the breach is confirmed. Some state laws impose aggressive timelines and give residents the right to seek damages for delayed notification. If you believe your custodian failed to notify you in the timeframe your state requires, you can file a complaint directly with your state attorney general’s office.

What these laws cannot do is guarantee you receive notice before a breach becomes public. The Safeguards Rule’s 30-day window starts from the custodian’s internal discovery date, which you have no way to independently verify. If you learn of an incident through news coverage before a formal notification arrives, note the dates. That gap may be relevant if you later pursue a formal complaint. For a detailed overview of which agencies regulate gold IRA custodians and what enforcement tools they have, see our guide on who regulates gold IRA custodians.

Five Steps to Take When You Receive a Breach Notification

A breach notification letter can feel alarming. The five steps below address the realistic threats your exposed data creates. Most take under an hour. Work through them in order rather than reactively.

  1. 1
    Freeze your credit at all three bureaus

    A credit freeze prevents new credit accounts from being opened in your name by blocking lenders from accessing your report during applications. Since September 2018, freezes are free and permanent at Equifax, Experian, and TransUnion. You place and lift them at each bureau’s website in minutes, and there is no cap on how many times you can do it. A freeze does not affect your existing accounts, your credit score, or your ability to use current credit cards. The FTC’s IdentityTheft.gov walks through the process for each bureau at no cost.

  2. 2
    Reset your custodian credentials and enable MFA

    Even if the breach was at the database level with encrypted passwords, treat your old custodian password as compromised. Choose a strong, unique password not used on any other site. Enable multi-factor authentication if your custodian offers it. If they do not offer MFA for account logins, write that down. It is a legitimate question to raise in writing with the custodian’s security team. A platform that handles self-directed IRA assets and does not offer MFA deserves your scrutiny.

  3. 3
    Monitor your credit reports weekly for 12 months

    AnnualCreditReport.com, the official free site established by federal law under the Fair Credit Reporting Act, gives you free weekly access to your reports from all three bureaus. Review each report for accounts you did not open, credit inquiries you did not authorize, or address changes you did not request. Add a free fraud alert at each bureau in addition to the freeze. A fraud alert asks lenders to take extra verification steps before extending credit, and it renews automatically for one year without any action on your part.

  4. 4
    Enroll in the IRS Identity Protection PIN program

    If your Social Security number was among the data exposed, a fraudster may attempt to file a federal tax return in your name and redirect your refund before you file. The IRS Identity Protection PIN program issues a six-digit code each January that must accompany your return for it to be accepted. Without the current-year PIN, no return can be processed under your SSN. Enrollment is voluntary, open to all U.S. taxpayers, and free at IRS.gov/ippin. This single step directly closes the tax-return fraud angle that SSN exposure creates. Keep your PIN confidential. The IRS will never call or email to ask for it.

  5. 5
    Request written confirmation of your metal holdings

    Contact your custodian and ask for a current account statement confirming the type, weight, purity, and depository location of all metal held on your behalf. Compare that statement to your prior records. If there is any discrepancy, escalate in writing immediately and request an explanation before taking any other action. This is standard account hygiene after any security event, not a sign of distrust, and any legitimate custodian will provide it promptly.

The Scam Wave That Follows a Breach

Breach data rarely stays with the original attackers. It is commonly sold in bulk to downstream buyers who specialize in follow-on fraud. In the context of a gold IRA custodian breach, the most effective post-breach playbook targets account holders directly using the precise details the breach provided. A caller knows your name, your custodian’s name, your account number, and a figure close to your account balance. They claim to be customer service and report “suspicious activity” on your account. They need you to verify your identity immediately or your account will be locked.

Warning signs a call or message is fraudulent

  • The caller creates urgency: “you must act today” or “your account will be suspended.”
  • They ask for your full SSN, account password, or a one-time verification code they “just sent.”
  • They direct you to a new phone number or a website to “complete verification.”
  • They ask you to move funds or metal to a “secure temporary account” for your protection.
  • An email’s sender domain is a close misspelling of your custodian’s real domain (one letter changed, a hyphen added).
  • They reference the breach by name and offer a “free monitoring service” requiring a credit card to activate.

A legitimate custodian will never call and demand an immediate account transfer. If you receive a call that raises any of those flags, hang up, find your custodian’s phone number directly on their official website, and call that number yourself. Do not use a callback number provided by the original caller. Report suspicious contacts to the FTC at ReportFraud.ftc.gov and to the FINRA investor complaint center if the caller claims to be a licensed broker or financial advisor.

Phishing emails that follow a breach replicate your custodian’s visual identity precisely because the breach data may have included the exact template language used in legitimate communications. Before clicking any link in an email claiming to be from your custodian, hover over the link to inspect the full destination URL. If the domain does not exactly match the domain you normally use to log in, treat the email as fraudulent and report it to your custodian’s security contact. For a broader catalog of tactics fraudsters use in the precious metals space, see our guide on gold IRA scam red flags.

Questions to Ask Your Custodian After a Breach

Receiving a breach notification letter gives you standing to ask specific, detailed questions. A custodian with a sound security posture will welcome them. One that deflects or delays in providing answers is communicating something important about how they manage customer interests.

  • What specific categories of customer data were accessed or exfiltrated?
  • When did the unauthorized access begin and when was it discovered internally?
  • Has the FTC been notified within the 30-day window required by the Safeguards Rule?
  • What remediation steps have been implemented to prevent a recurrence?
  • Is identity theft protection being offered to affected customers, and for how long?
  • Can I receive written confirmation that my depository holdings have not been affected?
  • Who is the primary point of contact for ongoing security updates related to this event?

Keep a written log of the answers you receive, including the date and the name of the representative who responded. If the custodian’s answers are evasive, incomplete, or never arrive, you can file a formal complaint with the FTC at ftc.gov/complaint and with your state attorney general. Regulatory scrutiny of financial institution breach responses exists precisely because evasive handling causes additional consumer harm.

When to Consider Switching Custodians

A data breach is not automatically grounds for a custodian transfer. Transferring a self-directed IRA involves real costs, real timelines, and a window of administrative complexity. Before initiating one, evaluate what the breach reveals about the custodian.

A single incident, disclosed transparently, followed by detailed communication about what happened and what changed, is qualitatively different from a custodian that has a pattern of security lapses, that delayed notification well beyond legal requirements, or that cannot clearly answer the questions listed above. No custodian is immune to sophisticated attacks. The question is how they respond when one occurs.

If you do decide to evaluate alternatives, review the FTC complaint database, the Better Business Bureau file, and any state regulator enforcement history for prospective custodians. Ask every candidate the same questions about their information security program, their breach notification history, and their MFA capabilities before opening an account. The Safeguards Rule requires financial institutions to maintain and document a written information security program. Any custodian should be able to describe that program in general terms to a prospective customer.

Frequently Asked Questions

Can someone withdraw my gold using stolen account credentials?

No. Physical gold held in a self-directed IRA is stored at a third-party depository under the custodian’s instructions. Authorizing a withdrawal requires a documented, custodian-processed instruction that routes through institutional channels with identity verification that goes far beyond a username and password. A data breach at the custodian level does not give an attacker any ability to instruct or access the depository. The physical metal is operationally and physically separate from the custodian’s information systems, and depositories do not accept withdrawal requests from individuals.

Does my custodian legally have to notify me of a breach?

Yes, under two parallel frameworks. The FTC’s Safeguards Rule (16 CFR Part 314, 2023 amendment) requires financial institutions, including IRA custodians, to notify the FTC within 30 days of discovering a breach that affects 500 or more customers. Separately, all 50 states have enacted breach notification statutes that require direct notification to affected residents. The specific timelines and covered data types vary by state, but the obligation to notify customers exists independently of the federal Safeguards Rule. If you believe your custodian failed to notify you in the timeframe your state law requires, file a complaint with your state attorney general.

Is a credit freeze free and does it hurt my credit score?

Credit freezes have been free at all three major bureaus (Equifax, Experian, TransUnion) since September 2018, when the Economic Growth, Regulatory Relief, and Consumer Protection Act eliminated all fees. A freeze has no effect on your existing credit accounts or your credit score. It only prevents new credit accounts from being opened in your name by blocking lenders from running a hard inquiry during an application. You can temporarily lift a freeze in minutes when you legitimately need new credit and then re-freeze immediately afterward.

Should I move my gold IRA to a different custodian after a breach?

Evaluate the breach before acting. A single incident disclosed transparently, followed by thorough communication and genuine remediation, is different from a custodian with a pattern of security failures or one that delayed notification well beyond legal requirements. A transfer involves real costs and administrative complexity, and a competitor custodian is not automatically safer. Before deciding, review the FTC complaint database, the Better Business Bureau record, and any state regulator actions for both your current custodian and any alternative. If the custodian’s response to the breach has been evasive or incomplete, that is a stronger signal than the breach itself.

What is the IRS IP PIN and how does it protect me?

The IRS Identity Protection PIN is a six-digit code the IRS assigns annually to enrolled taxpayers. When your SSN is exposed in a breach, a fraudster may attempt to file a federal tax return in your name and claim your refund before you file. The IP PIN prevents this: no federal return can be electronically filed under your SSN without the current year’s PIN. Enrollment is voluntary, open year-round to all U.S. taxpayers, and free at IRS.gov/ippin. A new PIN is issued each January. Keep it strictly confidential. The IRS will never call, text, or email to ask for it.

What is the difference between custodian data and depository data?

Your custodian holds your account records: identity verification documents, transaction history, account balance, and correspondence. A depository holds your physical metal and maintains its own independent vault records showing what is allocated to your account. These are two separate organizations with entirely separate information systems. A breach at the custodian exposes account records. It does not compromise the depository’s data or physical security. Depositories operate under their own security frameworks, including compliance with standards set by COMEX, the LBMA, or their insurance carriers, which are independent of any custodian relationship.

Sources

  1. Federal Trade Commission, FTC Safeguards Rule: What Your Business Needs to Know, 16 CFR Part 314 (2023 amendment requiring FTC notification within 30 days for breaches affecting 500+ customers).
  2. Federal Trade Commission, What to Know About Credit Freezes and Fraud Alerts, consumer.ftc.gov.
  3. Federal Trade Commission, IdentityTheft.gov, official U.S. government identity theft reporting and recovery resource.
  4. Internal Revenue Service, Get an Identity Protection PIN (IP PIN), IRS.gov/ippin.
  5. Federal Trade Commission, Report Fraud, ReportFraud.ftc.gov.
  6. AnnualCreditReport.com, Free Annual Credit Reports (authorized by the Fair Credit Reporting Act, 15 U.S.C. 1681 et seq.).
  7. FINRA, Investment Scams, finra.org/investors.
  8. National Conference of State Legislatures, Security Breach Notification Laws (all 50 U.S. states have enacted notification statutes as of 2018), ncsl.org.

This guide is reviewed and updated quarterly to reflect changes in IRS rules, partner offers, and company policies. For questions, corrections, or to report inaccuracies, contact our editorial team via the contact page.

Last reviewed: July 22, 2026

editorial team
Goldiew Research & Editorial
Independent research on gold, jewelry, and precious metals, from selling and loans to gold IRAs. About our methodology →

Saving favorites is only available to logged-in users. Please log in or sign up to continue.

By continuing with Google you agree to our Terms and Privacy Policy.
or log in with email

🔒❔ Forgot your password? Reset it here.

Liking reviews is for logged-in users: please log in or sign up to continue.

By continuing with Google you agree to our Terms and Privacy Policy.
or log in with email

🔒❔ Forgot your password? Reset it here.

Login

By continuing with Google you agree to our Terms and Privacy Policy.
or log in with email

🖐️➡ No account yet? Sign up here.

🔒❔ Forgot your password? Reset it here.