Skip to content
Back to Blog
low severity June 27, 2024 · 3 min read

Morrison Child and Family Services Data Breach Notice (Oregon Attorney General)

If you received a notice from Morrison Child and Family Services, here’s what the filing says was exposed, and what to do about it.

Morrison Child and Family Services notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on June 27, 2024.

Morrison Child and Family Services Data Breach Notice (Oregon Attorney General)

The filing from Morrison Child and Family Services, submitted to the Oregon Department of Justice on June 27, 2024, states that personal information belonging to 2,042 people was exposed. If you received a notification from the organisation, this means some of your records held by them are now in the hands of an unauthorised party.

Personal information does not expire

Unlike a credit card or password that can be replaced, the personal information listed in this filing cannot be changed. Once it has left Morrison Child and Family Services’ control, it remains usable for identity theft, fraud, or targeted social engineering for years. The record does not disclose passwords, and no credential exposure occurred in this incident. That is genuinely good news: your accounts with them are not at immediate risk of takeover because of this breach.

What matters most is the permanence of the exposed personal information. Names combined with addresses, dates of birth, or other identifiers create a foundation that criminals can build on long after the news cycle has moved on. The filing does not state exactly which specific data fields beyond the broad category of personal information were taken, nor does it confirm whether the data was copied and removed. In the absence of those details, treat the exposed information as available to whoever accessed it.

What the 2,042-person filing tells you about the records involved

Morrison Child and Family Services provides support services to children and families. The people named in this filing are therefore likely current or former clients, patients, or their guardians whose records contain sensitive personal details tied to those services. The organisation is required by law to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your information was not part of this incident. However, if you have moved since the time the records were created, contact Morrison Child and Family Services directly to confirm whether you were included.

The scale — 2,042 individuals — is significant for an organisation of this type. The filing itself offers no further explanation of how the exposure occurred or how long the information may have been accessible. Those facts remain unknown to the public.

Why this exposure stays relevant for years

Personal information exposed today can be combined with data from other breaches to build convincing profiles. A criminal who already holds pieces of your identity from elsewhere now has another confirmed source. This increases the risk of successful impersonation when applying for credit, government benefits, or opening new accounts in your name.

Because no permanent government identifiers such as Social Security numbers are confirmed in the exposed categories, the immediate risk of certain high-impact identity theft scenarios is lower than in breaches that include them. Still, the personal information that was exposed does not lose its value over time. It can support ongoing fraud attempts or be sold on underground markets where it retains utility for a long period.

How to reduce the risk that remains under your control

  • Place a fraud alert with the three major credit bureaus. This makes it harder for someone to open new accounts in your name using any personal details obtained in this or any other incident.
  • Review your credit reports for unfamiliar accounts or inquiries. Do this at least once per year; the fraud alert will usually prompt the bureaus to notify you of activity.
  • Monitor statements from any financial accounts linked to the services you received from Morrison Child and Family Services. Look for charges or changes you do not recognise.
  • Be wary of unsolicited contact claiming to be from the organisation or government agencies. Use the personal information from this breach to make phishing or impersonation attempts more convincing.
  • Contact Morrison Child and Family Services directly if you have changed addresses since your records were created. Ask them to confirm whether you were among the 2,042 people included in the filing.

The letter you may have received is the most reliable way to know for certain whether your records were affected. The filing does not provide an incident date, only the June 27, 2024 notification date, so there is no additional timeline to assess. Focus on the steps you can still take: limit how the exposed personal information can be used against you, stay alert for follow-on fraud, and treat this as a permanent addition to your identity risk profile rather than a one-time event.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed June 27, 2024
Last reviewed July 22, 2026
Affected 2042
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email