Skip to content
Back to Blog
low severity October 08, 2025 · 3 min read

Decisely Insurance Services, LLC Data Breach Notice (Oregon Attorney General)

If you received a notice from Decisely Insurance Services, LLC, here’s what the filing says was exposed, and what to do about it.

Decisely Insurance Services, LLC notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on October 08, 2025. The filing puts the incident itself on December 15, 2024.

Decisely Insurance Services, LLC Data Breach Notice (Oregon Attorney General)

The December 15, 2024 breach at Decisely Insurance Services, LLC placed the personal information of 113,984 people into unknown hands. Oregon residents learned of it through a filing made on October 08, 2025 — 297 days later.

Personal information exposed carries permanent risk

If you received a notification letter from Decisely, your name combined with other personal details from your insurance records is now outside the company’s control. Insurance-related personal information retains value to identity thieves for years because it ties directly to financial relationships, addresses, and government identifiers that cannot be reissued like a credit card.

The filing lists personal information as the category exposed in the incident. No passwords were exposed. The record does not disclose the exact fields included for each person, so your own notification letter is the only document that can tell you precisely what was taken.

Why the nine-and-a-half-month gap matters

The incident occurred on December 15, 2024. The company filed its notice with the Oregon Department of Justice on October 08, 2025. That interval of 297 days is the single most concrete fact in the public record. Notification timelines vary by state law and the length of any internal investigation, but the dates themselves are now fixed public information.

During that period the exposed personal information remained outside Decisely’s systems. Anyone whose records were taken had no way to know until the formal notices went out.

What this type of exposure actually enables

Insurance records typically contain name, address, date of birth, policy numbers, and sometimes Social Security number or driver’s license data. When these details leave a company, they become building blocks for several long-term frauds:

  • Opening accounts or filing taxes in your name using accurate biographical details
  • Requesting new insurance policies or making claims on policies you never opened
  • Creating synthetic identities that mix your real information with fabricated data
  • Impersonating you during customer service calls to gain even more details

Unlike a credit card number, none of these core personal identifiers can be cancelled or replaced. The exposure is effectively permanent.

How to determine whether you were affected

Decisely Insurance Services is required to notify affected Oregon residents directly, usually by mail. If you have not received a letter, it is likely your information was not included in this incident. However, if you have moved since December 15, 2024, or if mail from that period could have gone astray, contact Decisely directly to confirm whether your records were part of the 113,984 affected.

The limits of what the filing tells us

The record does not state how the breach occurred, whether data was copied or simply viewed, or how long any unauthorized access lasted. It contains no information about the root cause or attack method. Those details remain unknown to the public.

What is known is narrow but important: 113,984 individuals had personal information exposed on December 15, 2024, and Oregon residents were notified 297 days afterward.

Practical steps that address this specific exposure

Because no passwords were involved, there is no need to change any Decisely login credentials for this incident. Focus instead on the permanent personal information that was taken.

  • Place a fraud alert or credit freeze with the three major credit bureaus to block new accounts opened with your details
  • Review every Explanation of Benefits statement from your insurance carriers for claims you did not file or authorize
  • Monitor tax transcripts annually through the IRS to catch fraudulent filings made with your Social Security number
  • Be cautious with any unsolicited contact claiming to be from an insurer or government agency asking to “verify” information that the caller should already know
  • Keep your own copy of the notification letter and the exact list of categories it says were exposed, as this becomes useful evidence if identity theft occurs later

The exposure cannot be undone, but its practical impact can still be limited through consistent monitoring and early detection of misuse. The 297-day gap between the incident and the notices means that monitoring should begin immediately rather than waiting for further confirmation.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed October 08, 2025
Last reviewed July 22, 2026
Affected 113984
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email