Skip to content
Back to Blog
low severity October 09, 2024 · 4 min read

Fidelity Investments Data Breach Notice (Oregon Attorney General)

If you received a notice from Fidelity Investments, here’s what the filing says was exposed, and what to do about it.

Fidelity Investments notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on October 09, 2024. The filing puts the incident itself on August 17, 2024.

Fidelity Investments Data Breach Notice (Oregon Attorney General)

The August 17, 2024 breach at Fidelity Investments means that personal information belonging to 77,099 people is now outside the company’s control. The filing reached the Oregon Department of Justice on October 9, 2024 — 53 days after the incident date listed in the record.

Personal information carries permanent risk

The exposed category is listed simply as personal information. In practice this almost always includes name plus Social Security number or financial account details when a financial institution files a notice of this kind. Those two pieces together remain valuable to identity thieves for years. Unlike a credit card number that can be replaced, a Social Security number cannot be reissued on demand. Once it is loose, the risk does not expire.

No passwords were exposed. That is genuine good news. You do not need to change your Fidelity password because of this incident, and the account login itself was not compromised according to the filing.

What 77,099 affected records actually means

The scale reflects the size of Fidelity’s customer base rather than any detail about how the breach occurred. The record does not disclose the exact vector of initial access, whether data was copied or simply viewed, or which specific fields applied to every individual. It only confirms that personal information was involved and that Oregon residents were notified.

If you received a letter from Fidelity, your records were part of this group. Letters are sent to the last known address on file. If you have moved since August 17, 2024 and have not received anything, contact Fidelity directly to confirm whether you were included. Absence of a letter usually means you were not affected, but it is not absolute proof.

Why this exposure matters long after the headlines fade

Identity thieves do not need every piece of data at once. A name paired with a Social Security number is enough to open new accounts, file fraudulent tax returns, or apply for government benefits in your name. Financial account details can be used to attempt unauthorized transfers or to impersonate you when dealing with other institutions.

Because the data was taken from a major investment firm, it may also include details that help an attacker answer security questions at other banks or brokerages where you hold accounts. The exposure therefore increases risk across your entire financial life, not only at Fidelity.

The gap between incident and notification

The record shows the breach occurred on August 17 and the filing was made on October 9. That 53-day interval is the only timing information available. The filing does not state when Fidelity discovered the incident, so it is not possible to calculate how long any unauthorized access lasted. Different states have different notification deadlines once an investigation concludes; the record does not indicate whether this timeline met those requirements.

What you can still control

While some consequences of this breach cannot be undone, several practical steps remain effective. The most useful actions address the specific categories that were exposed rather than generic breach advice.

  • Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion immediately. A freeze stops new credit accounts from being opened in your name. It is free, reversible, and the single most effective step against new-account identity theft.
  • Monitor your annual tax transcript at IRS.gov. Request a transcript each year to catch fraudulent tax returns filed with your Social Security number. This is more reliable than waiting for a surprise notice from the IRS.
  • Review every financial statement and investment account for unfamiliar activity. Set up transaction alerts on all bank, brokerage, and credit-card accounts so you are notified of any movement in real time.
  • Be extremely cautious with unsolicited calls, emails, or texts claiming to be from Fidelity or any financial institution. Criminals now have enough of your personal information to sound convincing. Hang up and call the company using a number you look up yourself.
  • Consider identity theft protection services that include dark-web monitoring and insurance. While not a complete solution, continuous monitoring can alert you faster if your information appears for sale.

The letter from Fidelity is the definitive way to know whether your specific records were included. For everyone named in this filing, the exposed personal information creates a long-term identity theft risk that requires ongoing vigilance rather than a one-time fix. The absence of exposed passwords is the only silver lining in an otherwise serious compromise of customer data.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed October 09, 2024
Last reviewed July 22, 2026
Affected 77099
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email