Episource, LLC Data Breach Notice (Oregon Attorney General)
If you received a notice from Episource, LLC, here’s what the filing says was exposed, and what to do about it.
Episource, LLC notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on December 11, 2025. The filing puts the incident itself on January 27, 2025.
The personal information of 6,584,876 people was exposed in a breach at Episource, LLC that occurred on January 27, 2025. The company filed its notification with the Oregon Department of Justice on December 11, 2025 — an interval of 318 days, or roughly 10.4 months.
If you received a letter from Episource about this incident, your records were among those affected. The filing states that the organisation is required to notify impacted individuals directly, usually by post. Absence of a letter usually means you were not in the affected group, but anyone who has moved since January 27, 2025 should contact the company directly to confirm their status.
What the Exposed Personal Information Actually Enables
The record lists personal information as the category exposed. In practice this typically includes name combined with contact details, date of birth, and government identifiers such as Social Security number or driver’s license number. These pieces of data do not expire. Once they are out, they remain usable for identity theft, fraudulent loan applications, tax refund fraud, and medical identity theft for years.
Because no passwords or login credentials were exposed, this incident does not put any Episource account at direct risk of takeover. That is genuinely good news. The long-term danger lies entirely in the biographic and identifying details that cannot be changed.
Why the 10-Month Gap Matters to You
The breach happened on January 27, 2025 and the notification reached regulators on December 11, 2025. That span is long enough to be the single most noticeable fact in the filing. Regulators allow time for investigation and to confirm the full scope, so the gap does not automatically mean misconduct, but it does mean the information may have been available to unauthorised parties for most of a year before anyone outside the company was told.
During that period the data could have been copied, sold, or used without your knowledge. The filing does not disclose whether the information was exfiltrated or simply accessed, nor does it name the root cause.
What Cannot Be Reissued or Reset
Your name, date of birth, Social Security number, and driver’s license number are now permanently linked to this breach. Unlike a credit card or password, these cannot be cancelled and replaced. A criminal who obtains them can attempt to open accounts, file taxes, or seek medical services in your name for a long time.
Health-related data, when present alongside identifiers, increases the risk of insurance fraud and can make synthetic identity creation easier. The filing does not list every sub-field for every person, so your own notification letter is the only document that confirms exactly which details applied to you.
The Limits of What This Filing Tells Us
The record establishes only four concrete facts: the name of the organisation, the incident date, the filing date, the number of people affected, and the broad category of personal information involved. It does not describe how the breach occurred, whether any encryption was in place, or how long unauthorised access lasted. Any claim beyond those facts is speculation.
Episource, LLC appears in breach registries in multiple states for the same incident, confirming the exposure reached well beyond Oregon. The scale — more than 6.5 million records — is large, but the filing itself offers no comparison to the company’s total customer base.
How to Protect Yourself Going Forward
Place a freeze on your credit reports at Equifax, Experian, and TransUnion. This is the single most effective step you can take. It prevents new accounts from being opened in your name even if someone has your Social Security number.
Monitor your Explanation of Benefits statements from every health insurer you use. Medical identity theft often appears first as claims for services you never received. Dispute any unfamiliar charges immediately.
File your taxes early each year. This reduces the window in which someone else can file a fraudulent return using your Social Security number. If you receive a rejection because a return was already filed under your number, contact the IRS fraud hotline at once.
Review your bank and credit card statements monthly for small test charges that often precede larger fraud. Set up transaction alerts so you are notified in real time.
Consider placing an extended fraud alert or, if you qualify, an active duty alert if you are in the military. These require creditors to take extra steps to verify your identity before opening new accounts.
The letter from Episource is your clearest indicator of exposure. If you have moved since January 2025 and have not received one, reach out to the company using the contact information in its official notice to verify whether your records were included.
Report details & sourcing
Related breaches
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Navia Benefits Administration Breach — March 2026
2.7 million individuals had names, SSNs, DOBs, contact information, and benefits administration data…
Trailer Transit Inc Listed by metaencryptor Ransomware Group
Nationwide power-only transport services with 40+ years of experience. Trust Trailer Transit for dep…