Skip to content
Back to Blog
low severity July 28, 2025 · 3 min read

New American Funding, LLC Data Breach Notice (Oregon Attorney General)

If you received a notice from New American Funding, LLC, here’s what the filing says was exposed, and what to do about it.

New American Funding, LLC notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on July 28, 2025. The filing puts the incident itself on June 06, 2025.

New American Funding, LLC Data Breach Notice (Oregon Attorney General)

The personal information of 456 people was exposed in a breach at New American Funding, LLC on June 6, 2025. The company filed notice of the incident with the Oregon Department of Justice on July 28, 2025 — 52 days later.

If you received a letter from New American Funding about this incident, your records were among those affected. The filing does not disclose the exact type of personal information exposed beyond naming it as personal information. No passwords, no financial account numbers with credentials, and no permanent government identifiers such as Social Security numbers were listed in the categories.

What This Exposure Means for You

Because the record lists only “personal information,” the details included could range from basic contact data to more sensitive items such as address history. What matters most is that this type of information does not expire. While the company has not confirmed the precise fields, any address history or identity details that were taken can still be used by fraudsters months or years from now to support synthetic identity attempts or to pass verification checks on new accounts.

The absence of passwords in the exposed categories is genuinely good news. There is no need to change any password you use with New American Funding because none was compromised. The risk lies entirely in the non-credential personal data that cannot be rotated or replaced.

The 52-Day Gap Between Incident and Notification

The breach occurred on June 6 and the filing reached Oregon authorities on July 28. That interval is the most concrete timing detail available. State law sets different clocks for investigation and notification; the record does not state when the company discovered the incident, so it is not possible to judge the speed of their response beyond noting the 52 days that passed between the incident date and the filing date.

How to Know for Certain Whether You Are Affected

New American Funding is required to notify affected Oregon residents directly, usually by mail. If you have not received a letter, it is likely your information was not included. However, if you have moved since June 6, 2025, a letter may have gone to an old address. In that case, contact the company directly using the information in any prior statements or on their official website to confirm whether your records were part of the group of 456.

Why Personal Information Retains Value Long After a Breach

Unlike a credit card that can be canceled and reissued, personal details such as address history become part of a permanent profile that fraudsters combine with data from other sources. Even limited personal information can help an attacker clear “knowledge-based” verification questions when opening new accounts, requesting credit, or filing fraudulent tax returns. The value does not decay quickly, which is why this category remains the central concern in the filing.

What You Can Still Control

You cannot change what may have been taken, but you retain strong practical defenses. Monitoring your credit reports and accounts for unexpected activity remains the most effective step. Because the exposed data is personal rather than account-specific credentials, the focus is on watching for new-account fraud rather than immediate takeover of your existing New American Funding relationship.

The filing establishes that 456 Oregon residents were affected. It does not name the initial access method, whether data was copied, or any details about the organization’s security posture. Those facts remain outside the public record.

Place a freeze on your credit files with the three major bureaus if you have not done so already. This prevents new accounts from being opened in your name without your explicit permission and is more powerful than simple monitoring. Review your Explanation of Benefits and tax transcripts annually even if medical or tax data is not explicitly named here, because personal information often travels with those records in secondary fraud attempts. Consider placing a fraud alert if you prefer not to freeze your files. Finally, keep records of the notification letter and the dates above; they will be useful if any identity-theft activity appears later.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed July 28, 2025
Last reviewed July 22, 2026
Affected 456
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email