Cyber Incident Takes 401(k) Platform Offline: Key Lessons

By: Neil Plein, CPFA™, AIF®, Lead Retirement Plan Consultant, Aldrich Wealth

If your retirement plan provider’s systems went dark tomorrow and stayed offline for weeks, would you know how contributions, participant transactions, and fiduciary responsibilities would be handled? 

This is not a hypothetical exercise. It is a real-world disruption affecting plan sponsors and participants right now. For more than two weeks, a cybersecurity incident has disrupted the retirement plan operations of a major retirement plan services provider. As of July 27, its benefits platform remains offline, and the incident remains under investigation. The provider says account balances and plan benefits have not been affected, but participants cannot view account information, change investments or beneficiaries, or request loans and distributions. Plan sponsors cannot submit payroll contribution files, and service representatives cannot access account information or process transactions. The provider has not yet determined whether any data was accessed. 

The dynamics of this incident bring to light an important realization, a cyber incident does not need to result in stolen assets or participant data to materially disrupt a retirement plan. When a critical provider becomes unavailable, plan operations can stop. The fiduciary question quickly broadens from “Was data taken?” to “Can the plan continue operating, can participants access their money, and who bears the consequences if it cannot?” 

Cybersecurity Threats and Retirement Plans

Cybersecurity has been a high priority for the Department of Labor (DOL) in recent years and in 2021 they gave retirement plan fiduciaries a framework to aid in evaluating service provider cybersecurity capabilities called, “Tips for Hiring a Service Provider with Strong Cybersecurity Practices.”   

DOL recommends asking about security standards and independent audits, prior incidents and responses, insurance, contractual responsibility, and breach-notification terms. Questions should be answered in writing and understood by plan fiduciaries, not just placed in a fiduciary file. This may require involving internal IT personnel, cybersecurity specialists, or other experts to sort through what are often highly technical responses.

Does Your Provider Have the Right Protections?

When asking service providers about their cybersecurity policies and practices, recent events suggest that it may be prudent to consider including scenario examples, such as:  

  • If your systems were completely unavailable for days or weeks, what would happen?
  • How would payroll contributions, investment changes, loans, distributions, and scheduled payments be handled?
  • What manual alternatives exist?
  • How would participants be notified?
  • What losses or delays are covered, by whom, and under what exclusions?

Further examples may require a bit more out of the box thinking, as analysis can extend beyond the service provider’s systems. As discussed in Deepfaked Fiduciary, suppose a deepfake leads to a fraudulent withdrawal request on a paper form which a plan fiduciary approves. If the provider follows the sponsor’s instruction, will its cyber guarantee cover the loss or treat it as an “off-system” event outside its environment, controls, and reimbursement coverage? 

Protecting Your Plans

A primary early lesson to take away from this most recent cyber event is straightforward: cybersecurity oversight is not just about preventing account theft. It is also about system availability, operational continuity, and the boundaries of financial responsibility. Fiduciaries should understand what happens when a platform is hacked, when it is unavailable and when fraud enters through a trusted human process so they can better identify high-risk scenarios, train team members, and take proactive measures to align risk dynamics with their cybersecurity policy and practices.  

Organizations continue to face complex fiduciary, cybersecurity, governance, and operational challenges. Aldrich Wealth’s Corporate Retirement Plans team works with retirement plan fiduciaries to help strengthen plan governance, evaluate fiduciary structures, oversee investment programs, and navigate evolving regulatory expectations. As a member of the Aldrich group of companies, Aldrich Solutions offers a wide array of cyber services including cybersecurity advisory, cybersecurity engineering, social engineering resilience, and vCISO Services. 

Please note, this article is provided for general educational purposes only and should not be construed as legal, cybersecurity, ERISA fiduciary, or investment advice. 

Meet the Author
Lead Retirement Plan Consultant

Neil Plein, CPFA, AIF®

Aldrich Wealth LP

Neil is a Certified Plan Fiduciary Advisor (CPFATM) and Accredited Investment Fiduciary (AIF®) who acts as the quarterback of a retirement plan. He guides employers through the overall plan management with the knowledge to do a deep dive into any aspect of plan operation. Neil connects the dots between internal staff and external service providers… Read more Neil Plein, CPFA, AIF®

Neil's Specialization
  • Corporate retirement plans
  • Recordkeeper selection
  • Strategic planning and consultation
  • One-to-one consulting participant meetings
  • Certified Plan Fiduciary Advisor (CPFATM)
  • Accredited Investment Fiduciary (AIF®)
Connect with Neil
Connect with us
Related Articles
2 Women working at desk in professional environment in daylight
Five Questions Plan Fiduciaries and Company Owners Should Ask About Their 401(k) Plan
Sunset overlooking the blue tater of a lake, where there is a sailboat in the middle of the water.
Aldrich Wealth Ranked No. 11 in Accounting Today’s 2026 Top Wealth Magnets

Looking for support or have a question?

Contact us to speak with one of our advisors.

[gravityform id="2" title="false" description="false" ajax="true"]