Dulcich, Inc. Data Breach Notice (Oregon Attorney General)
If you received a notice from Dulcich, Inc., here’s what the filing says was exposed, and what to do about it.
Dulcich, Inc. notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on October 14, 2025. The filing puts the incident itself on June 24, 2024.
The filing from Dulcich, Inc. means that personal information belonging to 40,066 people is now outside the company’s control. The incident itself occurred on June 24, 2024. The notification to Oregon authorities was filed on October 14, 2025 — an interval of 477 days, or roughly 15.7 months.
Names and addresses are now permanently public
Once personal information leaves an organisation it cannot be recalled. For the individuals named in this filing, that information can be used to build profiles, attempt identity theft, or support more targeted fraud attempts long after the initial breach. The record lists personal information as the category exposed; no passwords, no financial account numbers, and no government identifiers such as Social Security numbers appear in the filing.
This absence is meaningful. Without a Social Security number or driver’s license number attached to the records, many common identity-theft pathways become harder for an attacker to pursue. The exposed data is still valuable for fraudsters who combine it with information obtained elsewhere, but it does not hand them the complete set of credentials needed to open accounts or file taxes in someone else’s name.
What the 15-month gap actually tells you
The time between the June 2024 incident and the October 2025 filing is the single most concrete fact in the record. Notification timelines vary by state law and by when an investigation concludes, so the gap alone does not prove fault. It does, however, mean that anyone whose information was taken had more than a year of potential exposure before they could be warned.
During that period the data could have circulated among criminals who specialise in buying and reselling personal details. The longer the delay, the greater the chance that copies of the information now exist in multiple places outside Dulcich’s systems.
How to determine whether this filing concerns you
Dulcich, Inc. is required to notify affected individuals directly, usually by mail to the last known address. If you have not received a letter, it is likely your information was not included. However, if you have moved since June 24, 2024, a letter may have gone to an old address. In that case, contact Dulcich, Inc. directly to confirm whether you were part of the group of 40,066 people named in the filing.
The permanent limits of what you can control
Because the exposed category is limited to personal information and contains no reissuable items such as credit cards or passwords, the main ongoing risk is the persistent use of your name combined with address history. Fraudsters can use this to attempt account takeover on services that rely on knowledge of past addresses rather than strong verification.
You cannot change your name or past addresses, but you can reduce the damage by monitoring for unexpected activity. The absence of passwords in the exposed data means you do not need to reset any credentials specifically because of this incident. That is one fewer urgent task in an already stressful situation.
Why the scale matters without implying carelessness
40,066 people is a large number. The figure represents every individual whose personal information was included in the incident that Dulcich, Inc. reported. It does not, by itself, reveal whether the breach stemmed from a single compromised record or a broader set of records; the filing provides no further technical detail.
What it does establish is that a substantial volume of personal information left the company’s custody on June 24, 2024. For anyone who receives the notification letter, the practical consequence is the same regardless of how many others were affected: their own records are now in unknown hands.
Realistic ongoing risks
The primary remaining threat is identity-related fraud that relies on basic personal details rather than high-value identifiers. This can include attempts to open utility accounts, apply for government benefits under another name, or use your address history to bypass weaker security questions on existing accounts.
Because the filing does not list medical information, financial data, or biometric details, the risk profile is narrower than many healthcare or banking breaches. That does not make it harmless; it simply means the most severe forms of identity theft are less directly enabled by this specific exposure.
Concrete steps that address this exact exposure
- Place a fraud alert with the three major credit bureaus. A fraud alert requires lenders to verify your identity before opening new accounts and lasts for one year. It is free and can be renewed.
- Review your annual credit reports now and again in six months. Look for accounts or inquiries you do not recognise. The gap between incident and notification increases the chance that fraudulent activity has already begun.
- Monitor bank and utility statements for unfamiliar charges. Even without account numbers exposed, fraudsters sometimes use name and address combinations to test small transactions first.
- Be cautious with unsolicited calls or emails that reference Dulcich or your past addresses. Scammers frequently use data from breaches to make their approach appear legitimate.
- If you receive the notification letter, follow any specific instructions it contains. The letter may offer additional monitoring services paid for by Dulcich, Inc.
The record is limited by design. It tells us what left the company, when the company reported it, and how many Oregon residents were named. It does not disclose the initial access method, whether encryption was in place, or the full chain of events between June 2024 and October 2025. Those details remain unknown to the public.
What you can act on is the information that was confirmed exposed and the time that has already passed. Focus your effort on the monitoring steps above rather than on changing data that cannot be changed. The letter remains the clearest signal of whether this filing applies to you personally. If none has arrived and you have not moved since the incident date, the odds are strong that your records were not included.
Report details & sourcing
Related breaches
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Trailer Transit Inc Listed by metaencryptor Ransomware Group
Nationwide power-only transport services with 40+ years of experience. Trust Trailer Transit for dep…
Navia Benefits Administration Breach — March 2026
2.7 million individuals had names, SSNs, DOBs, contact information, and benefits administration data…