Pyramid Advisors Limited Partnership d/b/a Pyramid Global Hospitality Data Breach Notice (Oregon Attorney General)
If you received a notice from Pyramid Advisors Limited Partnership, here’s what the filing says was exposed, and what to do about it.
Pyramid Advisors Limited Partnership d/b/a Pyramid Global Hospitality notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on February 25, 2026. The filing puts the incident itself on August 13, 2025.
The personal information of 139,899 people was exposed in a breach at Pyramid Advisors Limited Partnership, doing business as Pyramid Global Hospitality. The incident occurred on August 13, 2025. The company filed its notification with Oregon authorities on February 25, 2026 — 196 days later.
What the 196-day gap means for you
That interval between the breach date and the official filing is the single most striking fact in the record. While notification deadlines vary by state and depend on when an investigation concludes, nearly six and a half months is long enough that many affected individuals received their letters only recently. If you have an address on file with Pyramid Global Hospitality from before August 13, 2025, there is a strong likelihood you were among those notified by post.
Absence of a letter usually means your records were not part of the exposed group. However, anyone who has moved since the incident date should contact the company directly to confirm whether their information was included.
The only data category named in the filing
The Oregon filing lists a single broad category: personal information. No passwords, no financial account numbers, no Social Security numbers, no driver’s license numbers, and no medical details appear in the disclosed categories. This is genuine good news. The absence of these high-risk identifiers removes several of the most damaging vectors that typically follow a breach.
Because no permanent government or biographic identifiers were exposed, the long-term risk profile is lower than in many similar incidents. The exposed personal information still carries value for identity thieves and fraudsters, but it lacks the core pieces that enable new account fraud or tax fraud at scale.
What this exposure actually enables
Names combined with addresses, dates of birth, or contact details can still be used to attempt impersonation on existing accounts, craft more convincing phishing emails, or enrich data profiles bought on underground markets. The information retains value for years because it cannot be cancelled or reissued like a credit card.
However, without a Social Security number or comparable identifier, the barrier to committing major identity theft is significantly higher. Criminals usually need that missing piece to open new lines of credit or file fraudulent tax returns in your name.
Why the lack of credential exposure matters
No credentials were exposed in this incident. That means you do not need to change any passwords related to Pyramid Global Hospitality. Following generic “change all your passwords” advice here would waste your time and distract from the protections that actually help.
Your accounts with the company itself are not at direct risk of takeover from this breach. The threat lies in how the personal details might be combined with information obtained elsewhere to target you through other channels.
How to check whether you are affected and what to watch for
The company is required to notify affected individuals directly, typically by mail. Start there. Review any letter you received for the exact fields confirmed in your case. The filing lists categories that applied to the incident overall, not necessarily to every person.
Monitor your credit reports and bank statements for unusual activity. Place a fraud alert with the three major credit bureaus if you have not done so in the past year. Be especially cautious about unsolicited calls, texts, or emails that reference your stay or booking at a Pyramid Global Hospitality property. These are common vectors when personal details surface in criminal circles.
Consider whether you need to freeze your credit. Given that no Social Security numbers were exposed, a freeze may be more protection than this specific incident requires, but it remains one of the strongest controls available if you want to eliminate new-account fraud risk entirely.
Finally, keep records of the notification letter and the dates involved. Should anything suspicious appear later, having the official timeline from the Oregon filing strengthens any dispute or fraud claim you may need to make.
Report details & sourcing
Related breaches
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Clinical Associates of the Finger Lakes (CAFL) Listed by Barracuda Ransomware Group
The company mishandled its clients' and employees' data, which is why it was leaked. We extracted al…
Instituto Ferrero de Neurología y Sueño Listed by kazu Ransomware Group
Instituto Ferrero de Neurología y Sueño (IFN) is a specialized medical center in Argentina that focu…