Skip to content
Back to Blog
low severity January 28, 2025 · 4 min read

Berman & Rabin, P.A. Data Breach Notice (Oregon Attorney General)

If you received a notice from Berman & Rabin, P.A., here’s what the filing says was exposed, and what to do about it.

Berman & Rabin, P.A. notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on January 28, 2025. The filing puts the incident itself on July 05, 2024.

Berman & Rabin, P.A. Data Breach Notice (Oregon Attorney General)

The data breach at Berman & Rabin, P.A. means that personal information belonging to 151,893 people is now outside the law firm’s control. The incident occurred on July 05, 2024. The firm filed its notification with the Oregon Department of Justice on January 28, 2025 — an interval of 207 days.

What the 207-day gap actually tells you

State breach-notification laws give organisations time to investigate and determine who was affected before they must notify individuals. A gap of nearly seven months is not unusual when an investigation is complex, but it does mean that anyone whose information was taken has lived with that risk for most of a year without knowing it. The filing itself does not disclose when the firm first discovered the incident or whether data was copied and removed.

The single category named in the record

The Oregon filing lists only one broad category: personal information. No Social Security numbers, driver’s license numbers, financial account details, medical records, or passwords appear in the disclosed categories. This is genuine good news. Because no permanent government identifiers were exposed, the immediate risk of new account fraud opened in your name is lower than in many breaches.

That said, names combined with addresses and any case-related personal information tied to the firm’s legal work remain permanently sensitive. This data can still be used for targeted identity theft, tax fraud, phishing that sounds legitimate, or impersonation in future dealings with banks, insurers, or government agencies.

Why the absence of passwords matters

No credentials were part of the exposed data. You do not need to change any password connected to Berman & Rabin. Doing so would be unnecessary work that does not address the actual exposure. The records involved are the kind that cannot be “reset” the way a password can. Once they leave the firm’s systems they stay valuable to criminals for years.

How to tell whether this breach involves you

Berman & Rabin, P.A. is required to notify affected Oregon residents directly, usually by mail to the last known address. If you have not received a letter from the firm, your information was most likely not included. However, if you have moved since July 05, 2024, a letter may have gone to an old address. In that case, contact the firm directly to confirm whether your records were part of the incident.

What this exposure enables long-term

Even without a Social Security number, personal information from a law firm can be pieced together with data from other breaches to build convincing profiles. Criminals use these details to:

  • craft more believable spear-phishing emails that reference your past legal matters
  • file fraudulent unemployment claims or tax returns in your name
  • impersonate you when dealing with insurance companies or creditors

Because the data cannot be changed or revoked, the protective work you do now will need to last for years.

Practical steps that address this specific exposure

  • Place a fraud alert with the three major credit bureaus. A fraud alert forces lenders to verify your identity before opening new accounts. It is free, lasts one year, and can be renewed. This is the single most effective step for this type of breach.
  • Review your annual credit reports now and again in six months. Look for accounts or inquiries you do not recognise. You are entitled to one free report from each bureau every 12 months at AnnualCreditReport.com.
  • Monitor mail and email for unexpected tax documents or collection notices. Fraudulent tax returns are often filed in spring; early detection lets you file an identity theft affidavit with the IRS quickly.
  • Treat any unsolicited contact claiming to be from Berman & Rabin, an insurer, or a government agency with caution. Verify the request independently before providing any further information.
  • Consider freezing your credit if you do not expect to open new accounts soon. A freeze is stronger than a fraud alert and remains in place until you lift it. It is the best long-term protection when personal information has left an organisation’s control.

The filing establishes that personal information of 151,893 individuals was exposed in an incident on July 05, 2024. The 207 days that passed before the January 28, 2025 notification is the most concrete fact the record provides. No passwords or government identifiers were listed among the exposed data, which meaningfully limits some risks while leaving others that require ongoing vigilance. The letter you may or may not have received remains the clearest signal of whether your records were included. Where a letter is missing and you have changed address since the incident date, direct contact with the firm is the only way to be certain.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed January 28, 2025
Last reviewed July 22, 2026
Affected 151893
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email