Heritage Bank Data Breach Notice (Oregon Attorney General)
If you received a notice from Heritage Bank, here’s what the filing says was exposed, and what to do about it.
Heritage Bank notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on April 28, 2026. The filing puts the incident itself on March 02, 2026.
The personal information of 182,793 people was exposed in a data breach at Heritage Bank, according to a filing with the Oregon Department of Justice. The incident occurred on March 2, 2026, and the bank notified the state on April 28, 2026 — a gap of 57 days.
What This Exposure Actually Means for Those Affected
If you received a notification from Heritage Bank, your personal information is now in the hands of unknown parties. The filing lists personal information as the category exposed in this incident. No passwords, financial account numbers, or permanent government identifiers such as Social Security numbers were named in the record.
This is genuinely good news on the credential side. Because no passwords were exposed, there is no need to change any Heritage Bank password as a direct result of this breach. Your online banking credentials themselves remain secure from this particular incident.
The 57-Day Gap Between Incident and Notification
The record shows the breach took place on March 2 and the filing was made on April 28. That interval of nearly two months is the central timing fact in this disclosure. State notification rules allow organisations time to investigate and prepare notifications, so the gap alone does not prove negligence, but it is long enough to matter to anyone whose information was involved.
Heritage Bank is required to notify affected Oregon residents directly, usually by mail. If you have not received a letter, it is likely your information was not included. However, if you have moved since March 2, 2026, letters sent to your previous address may not have reached you. In that case, contact Heritage Bank directly to confirm whether you were in the affected group of 182,793 people.
Why Personal Information Still Carries Long-Term Risk
Even without Social Security numbers or financial details listed, the exposure of personal information can enable fraudsters to build convincing profiles. Names combined with addresses, phone numbers, dates of birth or other identifiers are frequently used in identity theft attempts, phishing campaigns, and social engineering attacks. This type of data does not expire the way a credit card number does.
The scale — nearly 183,000 individuals — makes this one of the larger banking-sector notifications in Oregon in recent years. The filing does not disclose the exact data elements taken for each person, the initial access method, or whether the intruder was external or internal. Those details remain unknown to the public.
What Remains Under Your Control
You cannot change the fact that this data has left Heritage Bank’s systems. You can, however, limit how useful it is to attackers by reducing other avenues they might exploit.
- Place a fraud alert with the three major credit bureaus. This forces lenders to verify your identity before opening new accounts and serves as an early warning if someone tries to use your details.
- Review your bank and credit card statements carefully for the next 12 to 24 months. Look for small test charges or unfamiliar transactions that could indicate account takeover attempts.
- Be extremely cautious with any unsolicited communication claiming to be from Heritage Bank. Criminals now have enough personal details to make phishing emails or phone calls appear legitimate.
- Consider credit monitoring or identity theft protection services that alert you to new inquiries or accounts opened in your name.
- If you notice suspicious activity, contact Heritage Bank immediately and file reports with both your local police and the Federal Trade Commission.
The absence of passwords and certain sensitive identifiers in the disclosed categories limits the direct risk to your Heritage Bank accounts. The remaining exposure centers on how that personal information might be combined with data from other breaches to impersonate you elsewhere.
This filing establishes only what was reported: an incident on March 2 affecting 182,793 people, disclosed 57 days later, with personal information listed as exposed. Everything beyond those facts — including the precise impact on any one individual — will be detailed in the notification letter you should have received.
Report details & sourcing
Related breaches
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
French FICOBA National Bank Account Registry Hack — February 2026
France's FICOBA national bank-account registry was breached in late February 2026, exposing tens of …
AYA Bank (Myanmar) Listed by The Crew Ransomware Group
AYA Bank (Myanmar) was listed on the The Crew ransomware leak site. The group claims to have stolen …