Farmer Brothers Data Breach Notice (Oregon Attorney General)
If you received a notice from Farmer Brothers, here’s what the filing says was exposed, and what to do about it.
Farmer Brothers notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on September 09, 2025. The filing puts the incident itself on March 06, 2025.
The data breach at Farmer Brothers that occurred on March 06, 2025, and was filed with Oregon authorities on September 09, 2025 — an interval of 187 days — has placed the personal information of 14,470 people in an uncertain position. If you received a notification letter from the company, your records were among those involved.
That long gap between the incident date and the formal filing is the single most striking detail in the public record. While notification deadlines vary by state and depend on when an investigation concludes, nearly six months is substantial enough to stand out.
What the Filing Actually Discloses
The Oregon Attorney General’s record states that the breach exposed personal information. No other categories are named. This means the filing does not list Social Security numbers, driver’s license numbers, financial account details, medical information, or any government-issued identifiers. No passwords were exposed.
Because the record lists only the broad category of personal information, it is impossible to know from the filing exactly which fields applied to any specific individual. Your own notification letter is the only document that can tell you the precise details that were included in your record.
What This Exposure Means for Identity Theft Risk
Personal information such as names, addresses, dates of birth, and contact details retains value to identity thieves even years later. Unlike credit cards that can be canceled or passwords that can be changed, this type of data is persistent. Criminals can combine it with information obtained elsewhere to build convincing profiles for account takeover attempts, tax fraud, or phishing campaigns that appear more legitimate because they reference accurate background details.
The absence of stronger identifiers in the disclosed categories is genuinely good news. Without Social Security numbers or financial account information listed in the filing, the immediate risk of new account fraud or direct financial theft is lower than in many other breaches. However, the exposed personal information can still serve as the foundation for more sophisticated social engineering or be sold on underground markets where it is pieced together with other stolen records.
The Letter Is Your Confirmation
Farmer Brothers is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely that your information was not part of the group of 14,470 records involved. Letters are sent to the last known address the company has on file. Anyone who has moved since March 06, 2025 should contact Farmer Brothers directly to confirm whether their records were included.
Absence of a letter is usually a reliable signal that you were not affected, but it is not absolute proof. Direct confirmation from the company remains the only way to be certain if you have changed addresses since the incident.
Why the 187-Day Interval Matters
The time between March 06, 2025 and the September 09, 2025 filing is long enough to be newsworthy on its own. The record provides no discovery date and offers no explanation for the interval. State requirements allow flexibility while investigations are ongoing, so the gap does not automatically indicate wrongdoing. It does, however, mean that anyone whose information was taken waited nearly six months for official notice.
During that period the exposed personal information could have circulated. While the filing does not state whether data was exfiltrated or simply accessed, the practical reality for those affected is that the information is now outside the company’s control.
What Remains in Your Control
Even without high-risk identifiers listed, vigilance remains valuable. The people whose records were exposed cannot change their names, dates of birth, or past addresses, but they can still limit how that information is used against them.
Monitoring your credit reports and financial accounts for unexpected activity is one of the most practical ongoing protections. Placing a fraud alert or credit freeze provides an extra layer that forces lenders to verify identity before opening new accounts in your name. These steps are especially relevant when personal information has been confirmed exposed, even if stronger identifiers are not listed in the filing.
Continued awareness of phishing attempts is also important. Criminals who possess accurate personal details can craft messages that feel personal and credible. Any unsolicited contact that asks you to confirm information or click links should be treated with extra caution.
Practical Steps Specific to This Incident
- Contact Farmer Brothers using the information in your notification letter if you have moved since March 06, 2025 or have not received correspondence. Direct confirmation is the only way to know with certainty whether your records were included.
- Review your credit reports from Equifax, Experian, and TransUnion for any accounts or inquiries you do not recognize. The exposure of personal information makes it easier for thieves to attempt synthetic identity or existing-account fraud.
- Consider a fraud alert or credit freeze. A fraud alert requires lenders to take extra steps to verify your identity; a freeze prevents new accounts from being opened without your explicit permission. These measures address the long-term value of the exposed personal information.
- Monitor financial statements and tax documents closely over the next 12 to 24 months. Personal information can be used to file fraudulent tax returns or divert refunds.
- Treat unexpected communications with suspicion. Any call, email, or letter that references your Farmer Brothers relationship and asks for verification or personal details should be verified through official channels before responding.
The core reality of this breach is that 14,470 people’s personal information left Farmer Brothers’ control on March 06, 2025. The filing gives limited detail, but it is clear about the scale and the timing. Your notification letter remains the definitive source for what was taken from your specific record. With no passwords or high-risk identifiers listed, the immediate threat level is lower than in many publicized incidents, yet the exposed personal information still carries lasting implications that justify careful monitoring and protective steps.
Report details & sourcing
Related breaches
Livara Health Medical Group Data Breach Notice (California Attorney General)
Livara Health Medical Group notified California residents of a data breach in a filing reported to t…
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Punch & Associates Investment Management, Inc. Data Breach Notice (Vermont Attorney General)
Punch & Associates Investment Management, Inc. notified Vermont residents of a data breach in a fili…