ADT, Inc. Data Breach Notice (Oregon Attorney General)
If you are a customer of ADT, Inc., here’s what’s now in circulation.
ADT, Inc. notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on July 28, 2026. The filing puts the incident itself on April 20, 2026.
The April 20, 2026 breach at ADT, Inc. exposed personal information belonging to 331,536 people. The company filed its notification with the Oregon Department of Justice on July 28, 2026 — 99 days later. That gap between the incident and the filing is the most striking detail in the record.
What the 99-Day Interval Actually Means for You
State breach-notification laws give organisations time to investigate and contain an incident before they must notify affected individuals. A three-and-a-half-month delay is not uncommon, but it is long enough that many people first learn of the breach when the letter arrives. If you received correspondence from ADT about this matter, your records were among those included. If you have not received a letter, it is likely you were not affected. Anyone who has moved since April 20, 2026 should contact ADT directly to confirm whether their information was involved.
The Single Category Named in the Filing
The Oregon filing lists only one broad category: personal information. No passwords, no financial account numbers, no Social Security numbers, no driver’s license numbers, and no medical details appear in the disclosed categories. This is genuinely good news. The absence of these high-risk identifiers removes several of the most damaging pathways that usually follow a breach.
Because the record names only “personal information,” the exact fields taken remain unclear. In practice this often means names, addresses, dates of birth, phone numbers, or email addresses. These details do not expire. They remain useful for identity thieves, social-engineering attacks, and physical targeting for years.
What Attackers Can Still Do With Names and Contact Details
Even without government identifiers, a accurate name combined with current address, phone number, or email creates immediate risks. Criminals can use the information to craft convincing phishing messages that appear to come from ADT. They can attempt account takeover on other services where you reused contact details. They can sell the dataset on underground markets where it is combined with information from other breaches to build fuller profiles.
The lack of exposed passwords is important. You do not need to change your ADT account password because of this incident. That risk simply does not exist here. Focus instead on protecting the permanent parts of your identity that cannot be reissued.
How Long This Exposure Remains Relevant
Names and addresses do not lose value the way credit card numbers do. A street address from 2026 can still lead someone to your door in 2029. Phone numbers and email addresses often stay the same for a decade. The people whose records were included in this filing should treat the exposure as permanent and adjust their habits accordingly.
Because the filing does not disclose whether the data was copied or simply viewed, you must assume the worst-case scenario: that unknown parties now possess the information. This is the prudent position when the record is silent on exfiltration.
Why the Scale Matters
More than 331,000 Oregon residents were named in the filing. That volume reflects both the size of ADT’s customer base in the state and the breadth of the incident on April 20, 2026. Large customer populations increase the likelihood that any individual reader of this page was affected, which is why the direct letter from the company remains the only reliable way to know for certain.
Practical Steps That Address This Specific Exposure
- Place a fraud alert with the three major credit bureaus. Even without Social Security numbers exposed, names and addresses make it easier for someone to attempt new accounts in your name. A fraud alert forces creditors to verify your identity before opening anything new.
- Monitor your financial statements and credit reports for unfamiliar activity. Review accounts monthly for at least the next two years. Look for small test charges that often precede larger fraud.
- Treat every unexpected call or email claiming to be from ADT as suspicious. Verify the request by contacting the company through a known good number or login portal rather than replying to the message.
- Consider using a dedicated email address or virtual phone number for future security-system communications. Separating these contact points limits how much of your primary digital identity can be targeted if the data is reused in future attacks.
- Keep records of the breach letter and the dates involved. If identity theft occurs later, documentation showing when your information was exposed helps establish timelines with banks, credit bureaus, and law enforcement.
The record is narrow but clear. No high-risk identifiers were listed. The delay between the April 20 incident and the July 28 filing is the element that stands out. The letter you did or did not receive is still the decisive test of whether this particular breach concerns you personally. Where uncertainty remains, assume the personal information is now outside ADT’s control and act to limit what attackers can build from it.
Report details & sourcing
Related breaches
ADT 5.5–10 Million Customer Records Disclosed — April 2026
ADT confirmed unauthorized access to between 5.5 and 10 million customer records in April 2026. Expo…
Victory Personal Care, Inc Listed by nightspire Ransomware Group
Data is not available now.…
Victory Personal Care, Inc Listed by Nightspire Ransomware Group
Victory Personal Care, Inc was listed on the Nightspire ransomware leak site. The group claims to ha…