Skip to content
Back to Blog
low severity August 13, 2025 · 3 min read

Morrow Equipment Data Breach Notice (Oregon Attorney General)

If you received a notice from Morrow Equipment, here’s what the filing says was exposed, and what to do about it.

Morrow Equipment notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on August 13, 2025. The filing puts the incident itself on June 12, 2025.

Morrow Equipment Data Breach Notice (Oregon Attorney General)

The Morrow Equipment data breach means that personal information belonging to 1,660 people is now outside the company’s control. The filing, submitted to the Oregon Department of Justice, states the incident occurred on June 12, 2025 and was reported on August 13, 2025 — an interval of 62 days.

Personal Information Is Now in Unknown Hands

The record lists personal information as the category exposed in this incident. That single category carries long-term consequences because names combined with other identifying details do not expire. While the filing does not specify every sub-field, the exposure of personal information typically enables identity thieves to attempt new account fraud, tax refund fraud, or medical identity theft using details they should never have possessed.

No passwords were exposed. This is genuinely good news. You do not need to change any Morrow Equipment password, and the company’s customer accounts themselves are not at direct risk from this breach.

What the 62-Day Gap Actually Means

Sixty-two days passed between the incident date of June 12, 2025 and the filing on August 13, 2025. Notification timelines vary by state law and by when an internal investigation concludes. The record does not disclose when Morrow Equipment first discovered the breach, so it is not possible to calculate any gap between discovery and notification. The only timing facts available are the two dates printed beside this article.

How to Know If This Breach Affects You

Morrow Equipment is required to notify affected individuals directly, usually by mail. If you have not received a letter, your information was likely not included in the group of 1,660 people. However, if you have moved since June 12, 2025, a letter may have gone to an old address. In that case, contact Morrow Equipment directly to confirm whether your records were involved.

The Permanent Nature of Personal Information

Unlike a credit card or password that can be replaced or reset, personal information cannot be reissued. Once it leaves a company’s systems, it remains usable for fraud indefinitely. The 1,660 affected individuals now share a permanent risk that did not exist before June 12, 2025. Credit monitoring and identity theft protection services can detect some misuse, but they cannot prevent every form of fraud that uses stolen personal details.

What This Exposure Enables

Thieves who obtain personal information can combine it with publicly available data or information from other breaches to build convincing synthetic identities or to impersonate real people. Common outcomes include unauthorized loans, fraudulent tax returns, and attempts to open utility accounts or government benefits in someone else’s name. Because the filing lists only personal information, the exposure centers on identity-related fraud rather than immediate account takeover.

The Limits of What the Record Tells Us

The Oregon Attorney General filing does not disclose the root cause, whether any encryption was in place, or how the information left Morrow Equipment’s control. It also does not state which specific pieces of personal information applied to each of the 1,660 people. Your own notification letter, if you received one, is the only document that can answer those questions for your situation.

Practical Steps That Address This Exposure

  • Place a fraud alert with the three major credit bureaus. A fraud alert requires lenders to verify your identity before opening new accounts and lasts for one year.
  • Review your credit reports from Equifax, Experian, and TransUnion. Look for accounts or inquiries you do not recognize. You are entitled to one free report from each bureau every week at AnnualCreditReport.com.
  • Monitor tax transcripts. Request an IRS transcript each year to ensure no one has filed a return using your Social Security number.
  • Be cautious with unsolicited calls or emails claiming to be from government agencies or financial institutions. Verify requests independently before providing any information.
  • If you receive a letter from Morrow Equipment, follow the specific instructions it contains. The company may offer additional services such as credit monitoring.

The core reality of this breach is that personal information belonging to 1,660 Oregon residents left Morrow Equipment’s systems on or around June 12, 2025. While the precise details vary by individual, the exposure itself is permanent. The most effective response is early detection of any misuse combined with vigilance that treats your personal information as a valuable target that now sits in unknown hands.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed August 13, 2025
Last reviewed July 22, 2026
Affected 1660
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email