Nth Degree Investment Group Data Breach Notice (Oregon Attorney General)
If you received a notice from Nth Degree Investment Group, here’s what the filing says was exposed, and what to do about it.
Nth Degree Investment Group notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on June 25, 2025. The filing puts the incident itself on December 12, 2024.
The filing from Nth Degree Investment Group states that personal information belonging to 36,169 people was exposed in an incident on December 12, 2024. The organisation submitted its notification to the Oregon Department of Justice on June 25, 2025 — 195 days later.
If you received a letter, your records were part of this incident
The company is required to notify affected individuals directly, usually by mail. If you have not received any letter from Nth Degree Investment Group, it is likely your information was not included. However, if you have moved since December 2024, contact the firm directly to confirm whether you were affected. Absence of a letter is usually a positive sign, but only the organisation holds the definitive list.
What personal information means in practice
The record lists personal information as the exposed category. In regulatory filings this typically covers name combined with one or more identifying details such as address, date of birth, Social Security number, driver’s license number, or financial account information. These combinations remain valuable to identity thieves long after the breach because they cannot be cancelled or reissued like a credit card.
No passwords were exposed. The filing does not list any credential-related data, so there is no need to change passwords for your Nth Degree account as a direct result of this incident. That is genuinely good news and removes one common source of immediate worry.
The long delay is the most noticeable fact
Six and a half months passed between the December 12, 2024 incident date and the June 25, 2025 filing. Notification timelines vary by the complexity of the investigation and by state requirements, so the record does not establish whether this interval was unusual. It does, however, give you a clear picture of how long the organisation took to reach this public disclosure.
What this exposure enables
With personal information in the wrong hands, the main risks are identity theft and fraudulent account opening. A name plus Social Security number or date of birth can be used to file fraudulent tax returns, open new credit lines, or impersonate you with government agencies. These threats do not expire quickly. The information does not lose its value after a few months the way stolen payment cards often do.
Because the filing only names “personal information” rather than listing every field for every person, your own notification letter is the only document that can tell you exactly which pieces of your data were confirmed exposed. Treat the broadest plausible case until you see that letter.
What you can still control
Even though some of the exposed data cannot be changed, several protective steps remain effective and should be prioritised in this order:
- Place a fraud alert or credit freeze with the three major credit bureaus. This is the single most effective action after an SSN or driver’s license exposure. It forces lenders to verify your identity before opening new accounts.
- Monitor your credit reports weekly for the next year. Free weekly reports are available from AnnualCreditReport.com. Look for accounts or inquiries you do not recognise.
- File your taxes early and respond immediately to any IRS notices. Identity thieves sometimes use stolen details to file fraudulent returns before the legitimate taxpayer does.
- Review monthly statements from every financial institution and investment account. Even small unfamiliar transactions should be challenged at once.
- Be wary of unsolicited calls, emails, or texts claiming to be from Nth Degree Investment Group. Scammers now have enough personal details to sound convincing; never provide additional information or click links in response.
The absence of any mention of passwords or login credentials in the filing means your existing Nth Degree account password remains a reliable protection for that relationship. Continue using a unique, strong password, but you do not need to rotate it solely because of this breach.
This incident involved 36,169 people, a substantial number that reflects the scale of the organisation’s client base in the states covered by the filing. The record itself does not disclose the root cause, whether encryption was in place, or how access was obtained. Those details remain unknown outside the investigation.
Focus on the steps above that address the permanent identifiers that were most likely included. The letter from Nth Degree Investment Group remains the definitive source for your personal situation. If you have moved since the December 2024 incident date and have not received correspondence, reach out to them to verify your status.
Report details & sourcing
Related breaches
Punch & Associates Investment Management, Inc. Data Breach Notice (Vermont Attorney General)
Punch & Associates Investment Management, Inc. notified Vermont residents of a data breach in a fili…
Livara Health Medical Group Data Breach Notice (California Attorney General)
Livara Health Medical Group notified California residents of a data breach in a filing reported to t…
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…