Skip to content
Back to Blog
low severity October 30, 2025 · 3 min read

Berkeley Research Group, LLC Data Breach Notice (Oregon Attorney General)

If you received a notice from Berkeley Research Group, LLC, here’s what the filing says was exposed, and what to do about it.

Berkeley Research Group, LLC notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on October 30, 2025. The filing puts the incident itself on February 28, 2025.

Berkeley Research Group, LLC Data Breach Notice (Oregon Attorney General)

The filing from Berkeley Research Group, LLC shows that personal information belonging to 6,083 people was exposed on February 28, 2025. The organisation did not notify Oregon authorities until October 30, 2025 — an interval of 244 days, or roughly eight months.

Personal information that cannot be replaced

The record lists personal information as the category exposed in this incident. That typically includes names combined with identifiers such as Social Security numbers, dates of birth, addresses, or government ID numbers. Once this combination leaves an organisation’s control, it remains valuable to identity thieves for years because these details cannot be cancelled or reissued like a credit card.

No passwords were exposed. The filing does not list any login credentials, so there is no need to change any password connected to Berkeley Research Group. That is one piece of straightforward good news in an otherwise serious notice.

What this exposure enables

With the right mix of personal information, someone can attempt to open new accounts in your name, file fraudulent tax returns, or apply for government benefits. The risk does not disappear after a few months. Criminal networks routinely store and resell this data on underground markets, where it can surface long after the original breach.

The 244-day gap between the incident and the filing is the most striking fact in the record. Notification timelines vary by state law and by the time needed to complete an investigation, so the filing itself does not prove negligence. It does, however, mean that anyone affected had eight months of unknown exposure before they could begin protecting themselves.

How to determine whether this notice concerns you

Berkeley Research Group, LLC is required to notify affected individuals directly, usually by mail to the last known address on file. If you have not received a letter, your information was most likely not included in the group of 6,083 records. However, if you have moved since February 28, 2025, a letter may have gone to an old address. In that case, contact the organisation directly to confirm whether your records were involved.

The permanent nature of the exposed data

Unlike a credit card number that can be replaced within days, the core personal identifiers listed in this filing cannot be changed. A Social Security number stays with you for life. A date of birth never updates. This is why breach notices that include these fields receive more attention than those limited to payment-card data alone.

The absence of any mention of passwords or authentication credentials in the filing is significant. It means the immediate risk is identity theft and new-account fraud rather than someone hijacking your existing account with Berkeley Research Group.

What remains under your control

You cannot make the exposed information disappear, but you can limit what thieves can do with it. Monitoring your credit reports, placing appropriate alerts, and watching for unexpected tax documents or benefit claims are the practical steps that address the specific categories named in this incident.

The record does not disclose the initial access method, whether the data was encrypted at rest, or how long the information may have been accessible. Those details remain unknown to the public. The filing focuses solely on what was exposed and how many Oregon residents were affected.

Because the exposed category is personal information, the long-term concern is identity-related fraud rather than immediate account takeover. The eight-month delay before notification simply lengthens the window during which that fraud could have begun without your knowledge.

Placing the numbers in context

6,083 people is a substantial group for a single filing. The figure is printed beside this article and comes directly from the Oregon Attorney General’s record. It does not, by itself, indicate whether the breach was unusually large or simply reflects the organisation’s client base. What matters is whether your records were among those 6,083.

The letter remains the most reliable indicator. Absence of a letter from Berkeley Research Group after a reasonable waiting period usually means you were not affected, provided your address on file was current as of the February 28, 2025 incident date.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed October 30, 2025
Last reviewed July 22, 2026
Affected 6083
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email