VOIDEXJournal

Family Office Cybersecurity: Protecting Wealthy Families Online

Family offices hold fortunes with small teams. How social engineering, wire fraud and staff devices put wealthy families at risk, and how to close the gaps.

By · 7 min read ·
Family Office Cybersecurity: Protecting Wealthy Families Online

A family office is one of the most attractive targets in the digital world. It manages serious wealth, it often runs with a team of a dozen people or fewer, and it depends on trust between people who know each other well. That combination is exactly what modern fraud is designed to exploit.

The large banks that family offices work with spend heavily on security. The family office itself, and the family behind it, often does not. The gap is rarely technology. It is process, habit and the channels people use to talk. This article looks at where the real risks sit, and at how a private, end-to-end encrypted platform like VOIDEX fits into a sensible plan.

Why family offices are targeted

Criminals follow value and weakness. A family office offers both. Payments are large and sometimes urgent. Decisions are made by a few people who trust each other's voices and writing styles. Staff often work across personal and professional devices. And the principals themselves are frequently public enough that their names, travel and business interests can be researched in an afternoon.

Unlike a listed company, a family office has no investor relations team, no large internal security department and often no formal rules for how instructions are given. "Just send it, I'll sign later" is a sentence that has cost families dearly.

The main threats

Social engineering

Almost every serious incident begins with a person being persuaded, not with a machine being broken. An email appears to come from the principal. A message arrives on a personal phone from a number claiming to be the family's banker. A caller knows the name of the chief financial officer, the property in the south of France and the name of the yacht. Each detail is harmless alone. Together they make a request feel real.

The defence is not cleverness. It is a rule that no instruction involving money, credentials or access is ever acted on through a single channel, however convincing it seems.

Wire fraud and payment redirection

The classic attack is business email compromise: an attacker takes over or imitates an email account and asks for a payment to be sent to a new account. The FBI has reported for years that this is among the most costly forms of cybercrime it tracks, with losses in the billions of dollars a year according to its Internet Crime Complaint Center. Family offices are especially exposed because payments are large and staff are used to acting on short instructions from a small number of people.

The fix is procedural. Changes to bank details should never be accepted by email alone. They should be confirmed by calling a number already on file, not one supplied in the message, and ideally by a second person.

Deepfakes of voices and faces

The newest variant uses synthetic audio and video. In early 2024, an employee at a multinational firm's Hong Kong office transferred around US$25 million after a video call in which the other participants, including a senior finance executive, were deepfakes, as reported by CNN. The engineering firm Arup later confirmed it was the company involved. The lesson for families is uncomfortable: a familiar face on a screen and a familiar voice on the phone are no longer proof of identity on their own.

Staff and household devices

The most sensitive information in a family often travels through the devices of people who are not the principal: assistants, drivers, house managers, nannies, pilots, security staff. They know schedules, addresses and travel plans. Their phones are often personal, shared with their own families, and running a mix of consumer apps. If one of those devices is compromised, the whole household's routine can be read.

Every person with access to the family's plans should be included in the security plan, given the right tools and told clearly why it matters.

Location and imagery

Photographs taken on phones commonly carry GPS coordinates, the device model and the time of capture. A single image shared from a residence can reveal where the family lives. We covered this in detail in what your photos reveal.

A practical framework

Good family office security is less about buying products and more about agreeing on a few clear rules and sticking to them.

  1. Separate channels by purpose. Payment instructions, family conversation, staff coordination and public activity should not all live in the same app on the same account.
  2. Verify out of band. Any request involving money, access or passwords is confirmed through a second, pre-agreed channel before anyone acts.
  3. Use end-to-end encryption for anything sensitive. In December 2024, the US Cybersecurity and Infrastructure Security Agency advised highly targeted people to use end-to-end encrypted communications rather than ordinary calls and text messages.
  4. Move away from SMS codes. Text message codes can be intercepted or redirected through a SIM swap. Authenticator apps or hardware security keys are stronger.
  5. Give staff proper tools. If the family expects discretion, the family should supply the channel that makes discretion possible.
  6. Plan for loss. Decide in advance what happens when a phone is lost, a staff member leaves or an account is taken over.
  7. Keep history short where it serves no purpose. Messages that no longer need to exist should not.

Private channels for a family and its people

A family office usually needs more than one conversation. There is the inner circle, there are the advisers, there is household staff, and there are projects: a property purchase, a wedding, a restoration, a yacht refit. Each group needs its own space, and people in one should not automatically see the others.

This is where structured private channels become useful. Instead of a dozen overlapping group chats on consumer apps, the family can hold its conversations in one place, with clear membership, clear rooms and clear control over who is invited.

How VOIDEX fits

VOIDEX is an invite-only, end-to-end encrypted platform owned by CNOTA. It is free and will remain free. There are no ads, no third-party trackers or ad pixels, and no selling of data. For a family office, that business model matters: the platform has no reason to know who the family is, what they talk about or where they go.

VOIDEX Messenger handles one-to-one and group chats, voice and video calls, voice notes, media and files. Direct messages use a hybrid post-quantum key agreement combining X25519 with ML-KEM-768, followed by a double ratchet with post-quantum re-keying, so every message has its own key. Identity signatures pair Ed25519 with ML-DSA-65. The reasoning behind this is covered in our piece on harvest now, decrypt later: family matters often stay sensitive for decades, which is exactly the timescale future quantum computers threaten.

For structured groups, VOIDEX Channels offers private channels encrypted with MLS, the IETF standard for group encryption (RFC 9420). A family can keep its inner circle, its advisers and its household staff in separate private channels, each with its own membership.

Several details address the specific threats above:

  • Key transparency. Every device key change is written to a public, append-only log, and VOIDEX clients refuse keys that are not in it. That makes a quietly substituted key, the digital version of an impostor joining a call, far harder to slip past anyone.
  • Calls with sealed setup. Voice and video calls run over WebRTC with DTLS-SRTP, and the call setup is sealed under the conversation key so the server cannot swap the encryption fingerprint.
  • Control over what leaves. Each chat has its own screenshot setting, messages can disappear, a sent message can be edited within 15 minutes and deleted for everyone.
  • Clean media. When a photo or video is posted publicly on VOIDEX, location and capture metadata are removed first, and a file that cannot be cleaned is refused rather than published.
  • Keys on devices. Keys are created on members' own devices. VOIDEX's servers store only public keys and ciphertext.

No messenger replaces the rule that money moves only after out of band verification. Encryption protects what is said. It cannot stop a person being persuaded. The strongest family offices combine both.

The recovery code, and why it matters here

Every VOIDEX member has a recovery code that opens their message history on a new device. VOIDEX never holds it, so a lost code cannot be restored by anyone, including VOIDEX. For a family office this is worth planning around: decide who keeps their own code safe, and how, before a phone goes missing on a trip. Members who prefer can switch the encrypted history copy off entirely. More on this in own your keys.

Honest limits

A private platform protects the conversation. It does not protect an unlocked phone left on a table, a screen photographed by a second device, or a staff member who decides to talk. Public posts in VOIDEX Space and public channels are not end-to-end encrypted, because they are meant to be seen, and VOIDEX labels them clearly. Good security is a set of precise promises and clear habits, not a single product.

Closing thought

Wealth has always needed protection, and the form of that protection changes with the threats. Walls and gates still matter. But for a modern family, the more likely point of failure is a message, a call or a photograph. Treat communications as an asset, give everyone around the family the tools to protect it, and agree the rules before they are tested.

VOIDEX is invite-only. Request an invitation for your family, or read the VOIDEX security report in full.

Sources

  • CISA, Mobile Communications Best Practice Guidance (December 2024): https://www.cisa.gov/resources-tools/resources/mobile-communications-best-practice-guidance
  • FBI Internet Crime Complaint Center: https://www.ic3.gov/
  • CNN, Finance worker pays out $25 million after video call with deepfake chief financial officer (February 2024): https://edition.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk/index.html
  • IETF, RFC 9420, The Messaging Layer Security Protocol: https://www.rfc-editor.org/rfc/rfc9420

Enter VOIDEX

VOIDEX is invite-only and free, with no ads and no trackers. Messages are protected by hybrid post-quantum encryption (X25519 with ML-KEM-768) and checked against a public key transparency log. VOIDEX runs in your browser and as apps for Windows and Mac, with iPhone and Android on the way.

Request access   Get the VOIDEX apps