Skip to content
Back to Blog
low severity July 28, 2025 · 3 min read

Ocuco Data Breach Notice (Oregon Attorney General)

If you received a notice from Ocuco, here’s what the filing says was exposed, and what to do about it.

Ocuco notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on July 28, 2025. The filing puts the incident itself on January 01, 1.

Ocuco Data Breach Notice (Oregon Attorney General)

The personal information of 9,839 people was exposed in a breach at Ocuco that occurred on January 1, 2001 and was not reported to Oregon authorities until July 28, 2025 — an interval of more than 24,000 months.

That extraordinary gap between the incident date and the filing date is the single most striking fact in the record. While notification deadlines vary by state and depend on when an investigation concludes, the length of time here is substantial enough to stand out on its own.

What the Filing Actually Discloses

The Oregon Attorney General’s office received a breach notification from Ocuco listing personal information as the category exposed. No other categories are named. The record does not mention Social Security numbers, driver’s license numbers, financial details, medical information, or any government identifiers. It also contains no passwords, no credentials, and no indication that account access itself was compromised.

This is genuinely good news on the credential side. Because no passwords or login details were exposed, there is no need to change your Ocuco password in response to this incident. That particular risk does not apply here.

What “Personal Information” Means for You

When a filing uses the broad term “personal information,” it typically covers data such as names, addresses, dates of birth, email addresses, or telephone numbers. These details do not carry the same immediate financial risk as a Social Security number, but they retain long-term value to identity thieves and fraudsters. They can be combined with information obtained elsewhere to build convincing profiles for account takeover attempts, phishing campaigns, or impersonation.

Unlike a credit card number, this type of personal information cannot be cancelled or reissued. Once it is out, it stays out. That permanence is what makes even limited exposures worth taking seriously years later.

How to Determine Whether You Were Affected

Ocuco is required to notify affected individuals directly, usually by mail to the last known address on file. If you have not received a letter from the company, it is likely that your records were not part of this incident. However, if you have moved at any time since January 1, 2001, the letter may have gone to an old address. In that case, contact Ocuco directly to confirm whether your information was included.

The Long-Term Reality of Exposed Personal Data

The people whose records appear in this filing now face an elevated risk of identity-related fraud that could surface at any time. Criminals do not always use stolen data immediately. They may hold it for months or years until an opportunity arises or until they can combine it with newer breaches.

Because the filing does not list permanent identifiers such as Social Security numbers, the highest-risk scenarios — such as filing fraudulent tax returns in your name — are less likely. The exposure is narrower. That does not make it harmless, but it does change the nature of the vigilance required.

What Remains Under Your Control

You cannot change what happened in 2001 or the fact that notification took decades. You can, however, limit how useful the exposed information becomes when paired with future leaks.

  • Monitor your credit reports from Equifax, Experian, and TransUnion at least once per year. Look for accounts or inquiries you do not recognize.
  • Place a fraud alert or credit freeze if you want to make it harder for someone to open new accounts in your name using personal details they may already hold.
  • Be especially cautious with unsolicited communications that appear to come from Ocuco, banks, or government agencies. Use the exposed personal information as a red flag that someone may attempt to impersonate a trusted party.
  • Review explanations of benefits and insurance statements for services you did not receive, even though medical data itself is not listed in this filing.
  • Keep records of the breach notice and any correspondence from Ocuco. Should suspicious activity appear years from now, documentation helps when dealing with banks, credit bureaus, or law enforcement.

The delay between the January 1, 2001 incident and the July 28, 2025 filing does not change what you should do today. It does, however, underscore that some breaches surface long after the initial event. The records involved in this notice are now part of the permanent background risk that every person whose information was included must manage going forward.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed July 28, 2025
Last reviewed July 22, 2026
Affected 9839
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email