New American Funding Data Breach Notice (Oregon Attorney General)
If you received a notice from New American Funding, here’s what the filing says was exposed, and what to do about it.
New American Funding notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on March 01, 2026. The filing puts the incident itself on January 01, 2001.
The data breach notice filed by New American Funding with the Oregon Department of Justice reveals that personal information belonging to 359 Oregon residents was exposed in an incident dated January 1, 2001. The filing itself was submitted on March 1, 2026 — an interval of 9,190 days, or roughly 25 years.
25 Years Passed Between the Incident and the Notification
This unusually long gap between the recorded incident date and the formal disclosure is the most striking detail in the filing. State notification rules allow flexibility while investigations proceed, so the record does not label the delay as a violation. What matters to anyone named in the 359 affected records is that the organisation has now formally acknowledged the exposure after more than two decades.
What the Filing Actually Lists as Exposed
The notice states that personal information was involved. No passwords, no financial account numbers, and no permanent government identifiers such as Social Security numbers appear in the listed categories. This is genuine good news: the absence of those high-risk fields removes several of the most common pathways for immediate identity theft that people fear after receiving a breach letter.
Because the exposed category is limited to “personal information,” the precise elements that reached any single individual will only be clear in the direct notification letter each affected person receives. The filing does not claim that every one of the 359 residents had the same data exposed.
What This Exposure Means for You Today
If you were one of the 359 Oregon residents included, the exposed personal information retains value to fraudsters even after 25 years. Address history, contact details, and other non-permanent personal data can still be combined with information obtained elsewhere to support targeted fraud attempts or social engineering.
However, the lack of credentials or reissue-proof identifiers limits the long-term damage compared with many breaches. No password reset is required or useful here. The account itself was not compromised in a way that gives attackers ongoing access.
How to Determine Whether You Are Affected
New American Funding is required to notify affected individuals directly, almost always by mail to the last known address on file. If you have not received a letter, it is likely your information was not part of the 359 records. Anyone who has moved since January 1, 2001 — the incident date — should contact the company directly to confirm whether their records were included.
The Value of Personal Information Over Decades
Personal details do not expire the way credit cards do. Even information that seems outdated can be useful to criminals building profiles. A name paired with an old address and phone number from 2001 can still help bypass security questions or support impersonation years later. This is why the exposure matters despite the passage of time.
At the same time, the narrow scope listed in the filing means the risk profile is lower than in breaches that include Social Security numbers or full financial records. The record contains no evidence of credential exposure, so there is no need to treat this as a full account takeover incident.
Practical Steps That Address This Specific Exposure
- Watch for the letter. Review your mail carefully over the coming weeks. The letter will detail exactly which pieces of personal information were exposed for your record.
- Contact New American Funding if you have moved since 2001. Use the contact information on their official website or in any recent statements to ask whether you were among the 359 affected Oregon residents.
- Review your credit reports for unfamiliar activity. Even without Social Security numbers exposed, unusual address or inquiry patterns can signal that personal details are being used. Pull free weekly reports from AnnualCreditReport.com.
- Place a fraud alert if you notice anything suspicious. A 90-day fraud alert requires lenders to verify your identity before opening new accounts in your name and costs nothing.
- Be cautious with unsolicited requests for personal details. Fraudsters may use any exposed information to craft convincing phishing calls or emails pretending to be from New American Funding or related lenders.
The filing establishes only what was exposed and to how many people. It does not disclose the root cause, the method of discovery, or any details about internal handling. Those uncertainties remain outside the public record.
For the 359 individuals named, the direct letter remains the definitive source. Absence of that letter after a reasonable period is usually a reliable indicator that you were not included, provided your address on file in 2001 was still current. This notice brings long-delayed transparency to a breach that occurred a quarter-century ago. (478 words)
Report details & sourcing
Related breaches
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Westwing Group SE NEW Listed by Coinbase Cartel Ransomware Group
Furniture - $465.5 Million…
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…