Skip to content
Back to Blog
low severity October 06, 2025 · 3 min read

AppFolio, Inc. Data Breach Notice (Oregon Attorney General)

If you received a notice from AppFolio, Inc., here’s what the filing says was exposed, and what to do about it.

AppFolio, Inc. notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on October 06, 2025. The filing puts the incident itself on August 08, 2025.

AppFolio, Inc. Data Breach Notice (Oregon Attorney General)

The filing from AppFolio, Inc. means that personal information belonging to 72,444 people is now outside the company’s control. If you received a notification letter, some of that information was yours.

Personal information exposed carries permanent risk

The record lists personal information as the category exposed in the August 08, 2025 incident. This typically includes name, address, Social Security number, and financial details. Unlike a password or credit card number, these pieces of information cannot be reissued. Once they leave the company, they remain usable for identity theft and fraud for years.

No passwords were exposed. That is genuine good news. You do not need to change any AppFolio password because of this incident, and the company has not placed your account login at direct risk.

What the 59-day gap actually tells you

The breach occurred on August 08, 2025. AppFolio filed the notice with Oregon authorities on October 06, 2025 — 59 days later. State law allows companies time to investigate and prepare notifications. The filing does not disclose when the company first discovered the incident, so it is not possible to know how long the information may have been accessible before they acted.

How to tell whether this filing includes you

AppFolio is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your information was not part of the 72,444 records included. However, if you have moved since August 08, 2025, a letter may have gone to an old address. In that case, contact AppFolio directly to confirm whether your records were involved.

What the exposed personal information enables

With a name paired with a Social Security number, someone can file fraudulent tax returns, open accounts in your name, or apply for government benefits. Addresses and financial details make it easier to build a convincing profile for impersonation or targeted scams. These risks do not expire when the news cycle moves on.

The absence of any permanent government or biographic identifiers beyond standard personal information in the filing limits some of the more exotic long-term tracking risks, but the core identity-theft exposure remains significant.

The uncertainty the filing leaves unresolved

The record does not state how the incident occurred, whether the data was copied and taken, or exactly which sub-categories of personal information applied to each person. It also does not reveal whether this was the result of a cyber attack, misconfiguration, or third-party involvement. Those details remain unknown to the public.

What you can still control

Even when personal information is exposed, you retain practical ways to reduce the damage. The key is focusing effort on the specific data that was lost rather than generic breach advice.

  • Place a fraud alert or credit freeze with the three major credit bureaus. This is the single most effective step when a Social Security number is involved. It forces lenders to verify your identity before opening new accounts.
  • Monitor your tax filings closely. Check IRS and state tax portals regularly for unexpected returns filed in your name. Consider filing your taxes as early as possible next year to block fraudulent submissions.
  • Review financial statements and Explanation of Benefits forms. Look for unfamiliar accounts, charges, or medical services every month. Early detection stops losses from growing.
  • Be extremely cautious with unsolicited contact. Anyone claiming to be from AppFolio, a bank, or government agency who already has some of your personal details may be using information taken in this incident. Hang up and call them back using a known good number.
  • Keep records of the notification letter. Save it with the filing date and reference number. You may need it later when dealing with banks, credit agencies, or identity theft recovery services.

The exposure of 72,444 people’s personal information is large by any measure. The filing itself offers no further explanation of why this volume of records was accessible on that date. What matters most now is recognizing that the information cannot be taken back and focusing on the protections that still work.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed October 06, 2025
Last reviewed July 22, 2026
Affected 72444
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email