Skip to content
Back to Blog
low severity June 12, 2025 · 3 min read

McKay Wealth Management Data Breach Notice (Oregon Attorney General)

If you received a notice from McKay Wealth Management, here’s what the filing says was exposed, and what to do about it.

McKay Wealth Management notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on June 12, 2025. The filing puts the incident itself on June 28, 2024.

McKay Wealth Management Data Breach Notice (Oregon Attorney General)

The data breach at McKay Wealth Management means that personal information belonging to 9,162 people is now outside the firm’s control. The incident occurred on June 28, 2024. The company filed its notification with the Oregon Department of Justice on June 12, 2025 — 349 days later. That lengthy gap is the single most striking fact in the record.

If you received a letter from McKay Wealth Management, your personal information was included in this incident. The organisation is required to notify affected individuals directly, usually by post. Absence of a letter usually means you were not in the affected group, but anyone who has moved since June 28, 2024 should contact the firm directly to confirm their status.

Personal Information Has Permanent Value for Identity Thieves

The filing lists personal information as the category exposed. No passwords, no financial account numbers with authentication details, and no government identifiers that cannot be replaced were named. Even so, the data that was taken retains long-term usefulness for fraudsters.

Thieves can combine personal details with information obtained elsewhere to build convincing profiles. They may attempt to open new accounts, file fraudulent tax returns, or impersonate you in dealings with other financial institutions. Because this information cannot be changed the way a credit card or password can, the exposure creates a risk that lasts for years.

The record does not disclose the exact fields beyond the broad category of personal information, nor does it state whether data was actually exfiltrated. What matters to you is that the firm has now formally acknowledged the loss of these records.

What the 349-Day Delay Actually Means

State notification laws give organisations time to investigate and contain an incident before they must notify affected residents. An interval of nearly twelve months is unusually long. The filing itself offers no explanation for the delay, and the record contains no discovery date, so it is impossible to know how much of that time was spent investigating versus how long the firm waited before filing.

What is certain is that more than eleven months passed between the incident date of June 28, 2024 and the public filing on June 12, 2025. During that period, anyone whose information was taken had no way to know their records were at risk.

The Limits of What This Filing Tells Us

This document does not reveal how the breach occurred, whether a third party was involved, or what security measures were in place. It simply records that an incident took place, that personal information was exposed, and that 9,162 Oregon residents were affected. Any claim beyond those facts is not supported by the official record.

The absence of passwords in the exposed categories is genuinely good news. You do not need to change any password connected to McKay Wealth Management because of this incident. That particular risk does not apply here.

How to Protect Yourself Going Forward

Because the exposed information cannot be revoked, your focus must shift to detection and monitoring rather than prevention of the initial leak.

  • Place a fraud alert or credit freeze with the three major credit bureaus. This makes it harder for someone to open new accounts in your name using the stolen personal details.
  • Review your tax filings carefully in the coming years. Identity thieves sometimes use personal information to file fraudulent returns before you do.
  • Monitor financial statements and credit reports for unfamiliar activity. Look for accounts or inquiries you did not authorise.
  • Be extremely cautious with any unsolicited contact that asks you to verify personal details. Scammers may already possess some of your information from this breach and will use it to sound legitimate.
  • Contact McKay Wealth Management directly if you have moved since June 2024 or never received a notification letter. Only the company can confirm whether your specific records were included.

The exposure of 9,162 people’s personal information creates a lasting but manageable risk. The information cannot be taken back, but the steps above limit what thieves can do with it. Stay vigilant, use the monitoring tools available to you, and treat any unexpected financial contact with scepticism. That is the practical reality this breach leaves you with.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed June 12, 2025
Last reviewed July 22, 2026
Affected 9162
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email