American First Finance Data Breach Notice (Oregon Attorney General)
If you received a notice from American First Finance, here’s what the filing says was exposed, and what to do about it.
American First Finance notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on September 12, 2025. The filing puts the incident itself on May 31, 2024.
The notice you received from American First Finance means that personal information belonging to you was included in an incident that occurred on May 31, 2024. The company filed its notification with the Oregon Department of Justice on September 12, 2025 — an interval of 469 days, or roughly 15.4 months.
Why the Long Delay Matters
That 15-month gap between the incident date and the filing date is the single most striking fact in the record. State notification rules allow additional time when an investigation remains open, but the length of this interval still leaves affected individuals waiting far longer than most expect before learning their information was exposed.
American First Finance has now notified 689,000 people. The filing lists only one broad category: personal information. No passwords, no financial account numbers with routing details, and no permanent government identifiers such as Social Security numbers are named in the record. This is genuinely good news. The absence of those high-risk fields sharply limits what an attacker could do with any data that may have been taken.
What Personal Information Exposure Actually Enables
When a company says “personal information” was involved, it typically covers name, address, date of birth, email, phone number, or similar contact and demographic details. These pieces on their own do not let someone open new credit in your name or drain an account. They do, however, provide the supporting details often used to make other stolen data more convincing — for example, helping an imposter pass security questions or strengthen a phishing attempt.
Because no passwords were exposed, there is no need to change any American First Finance login credentials because of this incident. The account itself remains secure in that respect. The real remaining risk is the long-term value of accurate personal details. Once this kind of information leaves a company’s control, it cannot be recalled. It can appear in dark-web markets for years.
How to Tell Whether You Were Included
American First Finance is required to notify affected individuals directly, usually by mail. If you have not received a letter, your information was almost certainly not part of the 689,000 records included in the filing. Letters are sent to the last known address the company holds. Anyone who has moved since May 31, 2024 should contact American First Finance directly to confirm whether their records were involved.
The Difference Between Reversible and Permanent Risk
Most of what was likely exposed here can still be managed. You can update contact details, add fraud alerts, and monitor accounts. Unlike a Social Security number or driver’s license that stays with you for life, the data described in this filing does not create permanent, unchangeable exposure. That distinction matters. It means the incident is serious but not catastrophic for most people.
The record does not disclose the root cause, whether data was copied or simply viewed, or how the company discovered the incident. Those details remain unknown to the public. What is known is narrow and specific: one broad category of personal information affecting 689,000 people, reported 469 days after the incident date.
Practical Steps That Address This Specific Exposure
- Place a fraud alert with the three major credit bureaus. This forces lenders to verify your identity before opening new accounts and lasts for one year (or longer if you request an extended alert).
- Review your credit reports now and again every four months. Free weekly reports are available at AnnualCreditReport.com. Look for accounts or inquiries you do not recognize.
- Enable two-factor authentication everywhere it is offered, especially on financial and government sites, using an authenticator app rather than SMS when possible.
- Treat unexpected calls, texts, or emails claiming to be from American First Finance as suspicious. Contact the company using a number from its official website rather than replying to the message.
- Consider identity theft protection services only if you want ongoing monitoring and insurance. The core protections above are free and usually sufficient when only personal information, not full identity-theft enablers, has been exposed.
The passage of 15 months before notification is the element that deserves the most attention. It explains why many people are only learning about the incident now. Focus on the concrete steps that reduce the remaining risk instead of worrying about what cannot be changed. The absence of passwords and sensitive identifiers in the filing keeps the practical danger lower than many data-breach letters suggest.
Report details & sourcing
Related breaches
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Livara Health Medical Group Data Breach Notice (California Attorney General)
Livara Health Medical Group notified California residents of a data breach in a filing reported to t…
Punch & Associates Investment Management, Inc. Data Breach Notice (Vermont Attorney General)
Punch & Associates Investment Management, Inc. notified Vermont residents of a data breach in a fili…