Skip to content
Back to Blog
critical severity June 12, 2026 · 5 min read

Columbia Pacific Advisors, LLC Data Breach Notice (Washington Attorney General)

If you were named in this filing, here’s what the filing says was exposed, and what to do about it.

Columbia Pacific Advisors, LLC notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on June 12, 2026, and the notice lists name, social security number, driver's license or Washington ID card number, financial & banking information, full date of birth, passport number, health insurance policy or ID number and medical information among the information exposed. The filing puts the incident itself on November 28, 2025.

Columbia Pacific Advisors, LLC Data Breach Notice (Washington Attorney General)

The filing from Columbia Pacific Advisors, LLC means that if you were among the 1,585 Washington residents notified, your full Social Security number, date of birth, passport number, driver’s license or state ID, financial and banking details, health insurance ID, and medical information are now outside the firm’s control. These are not the kind of records that lose their value after a few months.

The breach occurred on November 28, 2025. The company filed its notice with the Washington Attorney General on June 12, 2026 — an interval of 196 days, or roughly six and a half months. That gap is the single most striking fact in the record.

A Social Security Number and Date of Birth Do Not Expire

Once your SSN and full date of birth are exposed together, they remain usable for identity theft indefinitely. Credit issuers, government agencies, and many financial institutions still treat that pair as primary proof of identity. Unlike a credit card or password, neither can be replaced on demand. The same permanence applies to your passport number and driver’s license or Washington ID number. These identifiers stay valid for years and can be combined with your name and date of birth to open accounts, file fraudulent tax returns, or request medical services in your name.

The filing also lists financial and banking information, health insurance policy numbers, and medical information. Medical records can be used to file false claims against your insurance or to build a profile that makes other fraud attempts more convincing. Health insurance IDs alone have allowed scammers to obtain care or prescription drugs that later appear on your explanation of benefits.

No Passwords or Credentials Were Exposed

The record contains no indication that any passwords, login credentials, or authentication details were involved. This is genuinely good news. You do not need to change any password connected to Columbia Pacific Advisors because none was placed at risk. The exposure is limited to the permanent and semi-permanent personal identifiers listed above.

What the 196-Day Gap Actually Means for You

The incident date and the filing date are the only two dates provided. The record is silent on when the company discovered the breach or how long the information may have been accessible. What matters to you is the outcome: your sensitive data left the company’s systems on or before November 28, 2025, and you were not told for nearly seven months. During that period the information could have been copied, sold, or used without your knowledge.

Because the organization is required by law to notify affected individuals directly, the most reliable way to determine whether you are in the group of 1,585 is whether you receive a letter. Letters are typically sent by post to the last known address. If you have not received one, it is likely your information was not included. However, if you have moved at any time since November 28, 2025, you should contact Columbia Pacific Advisors directly to confirm whether your records were part of this incident.

Why Medical and Insurance Details Raise Separate Concerns

Health insurance policy numbers and medical information can be monetized quickly on underground markets. Fraudulent claims often go undetected for months because many people do not review every explanation of benefits. A scammer with your name, date of birth, and insurance ID can schedule appointments or order equipment that gets billed to you, potentially affecting your future coverage or premiums.

The presence of both financial and banking information alongside government identifiers creates additional vectors. An attacker who obtains your SSN, date of birth, and bank account details has most of what is required to impersonate you with tax authorities, lenders, or benefits programs.

The Records Belong to Patients and Clients

Columbia Pacific Advisors, LLC holds records for individuals who received advisory or related services. The 1,585 people named in this filing had their sensitive personal and health-related data included in the incident. The categories listed — name, Social Security number, driver’s license or Washington ID, financial and banking information, full date of birth, passport number, health insurance ID, and medical information — represent what the filing states was exposed. Not every individual necessarily had every category; your own notification letter will specify what applied to you.

Identity Theft Remains the Primary Long-Term Risk

A Social Security number paired with a date of birth is the exact combination used to open credit in someone else’s name. Passport numbers allow creation of travel-related fraud. Driver’s license data can support fake identification documents. Medical and insurance details open pathways to healthcare fraud that can take years to untangle. These risks do not diminish after 90 days or six months. They persist for as long as the identifiers remain valid.

The filing does not disclose the root cause, whether the data was taken by an external actor, an insider, or through accidental exposure. Those details are not available to the public. What is available is the list of exposed categories and the number of people affected.

Practical Steps That Address This Specific Exposure

  • Place a fraud alert or credit freeze with the three major credit bureaus immediately. This prevents new accounts from being opened in your name using the exposed SSN and date of birth. A freeze is the stronger control and should be your default choice if you do not plan to apply for new credit soon.
  • Review your Explanation of Benefits statements from every health insurer you hold. Look for claims you did not incur. Because medical and insurance information was exposed, fraudulent billing is a realistic risk even months from now.
  • Monitor your bank and investment accounts daily for the next several weeks, then switch to weekly reviews. The financial and banking information listed makes unauthorized transfers or changes more plausible.
  • File your taxes early and use IRS Identity Protection PINs if offered. Tax-related fraud using stolen SSNs and dates of birth tends to peak in the first quarter; early filing reduces the window available to imposters.
  • Contact Columbia Pacific Advisors directly if you moved after November 28, 2025 and have not received a letter. Only they can confirm whether your specific records were included.

The exposure of full SSNs, passport numbers, dates of birth, and medical data creates a permanent increase in your risk of identity theft and fraud. The 196-day delay between the incident and the filing is the clearest signal that this event requires sustained attention rather than a one-time check. While you cannot make the exposed information disappear, you can still control how thoroughly you monitor the accounts and records that can be reached with it.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on Columbia Pacific Advisors, LLC.

  1. Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
  2. Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.
  3. Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
  4. Report the licence number to your state DMV. Most states will note the number as compromised, and some will issue a new one. It is the field that turns a stolen identity into a usable one in person.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Report details & sourcing

Severity Critical identifiers that cannot be reissued, alongside documents or accounts that can be misused now
Disclosed June 12, 2026
Last reviewed July 22, 2026
Affected 1585
Data exposed NameSocial Security NumberDriver's License or Washington ID Card NumberFinancial & Banking InformationFull Date of BirthPassport NumberHealth Insurance Policy or ID NumberMedical Information
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email