OneDigital Investment Advisors LLC Data Breach Notice (Oregon Attorney General)
If you received a notice from OneDigital Investment Advisors LLC, here’s what the filing says was exposed, and what to do about it.
OneDigital Investment Advisors LLC notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on April 20, 2026. The filing puts the incident itself on August 12, 2025.
The August 12, 2025 breach at OneDigital Investment Advisors LLC placed the personal information of 535 Oregon residents into unknown hands. The company did not notify the state until April 20, 2026 — 251 days later.
251 Days Passed Between the Incident and Notification
That eight-month gap is the single most striking fact in the filing. State law sets different clocks depending on when an investigation concludes, so the record does not label the delay as improper. It does, however, give you the exact dates and the exact count of people involved. OneDigital Investment Advisors LLC reported the incident to the Oregon Department of Justice on April 20, 2026, listing an incident date of August 12, 2025 and confirming that personal information belonging to 535 individuals was exposed.
What the Filing Actually Lists — and What It Does Not
The record names only one category: personal information. No passwords, no financial account numbers, no medical details, and no government identifiers such as Social Security numbers are listed. Because the filing does not disclose the precise fields, you cannot assume the worst or dismiss the risk. The letter you may receive from the company is the only document that can tell you exactly which elements of your record were included.
If you have not received a letter, it is likely that your information was not part of the 535 records affected. Letters are sent to the last known address on file. Anyone who has moved since August 12, 2025 should contact OneDigital Investment Advisors LLC directly to confirm whether they were included.
The Risk That Remains When Personal Information Is Exposed
Even limited personal information can be valuable to fraudsters. When combined with data obtained elsewhere, it can help impersonate you, open accounts in your name, or answer security questions on other services. The exposure does not decay. Unlike a credit card that can be canceled, once personal details leave a company’s control they cannot be recalled or reissued.
The filing establishes that no credentials were exposed. You do not need to change any password connected to OneDigital Investment Advisors LLC because of this incident. That is genuine good news and removes one common source of immediate panic.
What the 535-Person Scale Actually Tells You
535 people is a precise number. It is large enough to matter and small enough to suggest the breach was contained to a specific dataset rather than the entire client base. The filing does not describe how the incident occurred, whether data was copied, or how long any unauthorized access lasted. Those details remain unknown.
How to Determine If This Affects You
The company is required to notify affected individuals directly, usually by mail. Watch for that letter. Its presence confirms you are in the group; its absence is the strongest available signal that you are not. If you changed addresses after August 12, 2025, reach out to OneDigital Investment Advisors LLC to verify your status rather than relying on mail forwarding.
Practical Steps That Address This Specific Exposure
- Place a fraud alert with the three major credit bureaus. A fraud alert makes it harder for someone to open new accounts using any personal details that may have been exposed.
- Review your credit reports now and again in three months. Look for accounts or inquiries you do not recognize. The exposure of personal information can enable synthetic identity attempts that surface slowly.
- Monitor statements and tax documents carefully in the coming year. Personal information helps scammers file fraudulent tax returns or redirect legitimate refunds.
- Be wary of unsolicited calls or emails claiming to be from OneDigital or related financial partners. Use the contact information on your statements rather than replying to messages that arrive after a breach notice.
- Keep records of the letter and the filing date. If identity theft occurs later, these documents help prove when and where the information was exposed.
The record is narrow by design. It tells you who filed, when they filed, how many Oregon residents were listed, and that personal information was involved. Everything beyond those facts remains undisclosed. The 251-day interval between the August 12, 2025 incident and the April 20, 2026 filing is now public. Use the letter as your primary indicator of exposure, treat the personal information as permanent once released, and focus your effort on the controls you can still influence: credit monitoring, fraud alerts, and careful verification of any future financial activity.
Report details & sourcing
Related breaches
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Canadian Investment Regulatory Org (CIRO) 750K — January 2026
The Canadian Investment Regulatory Organization (CIRO) disclosed a phishing-vector breach affecting …
ReliaQuest, LLC Listed by Shinyhunters Ransomware Group
This time the post is about you, not us. Let Mandiant report and advise on us accurately, go away. D…