Schauermann Thayer Law Firm Data Breach Notice (Oregon Attorney General)
If you received a notice from Schauermann Thayer Law Firm, here’s what the filing says was exposed, and what to do about it.
Schauermann Thayer Law Firm notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on April 28, 2025. The filing puts the incident itself on August 14, 2024.
The Schauermann Thayer Law Firm notified Oregon residents that a data breach affecting 2,577 people occurred on August 14, 2024. The firm filed the notice with the Oregon Department of Justice on April 28, 2025 — 257 days later.
That eight-and-a-half-month gap is the single most striking fact in the record. While notification deadlines vary by state and depend on when an investigation concludes, the interval is long enough to matter to anyone whose information may have been exposed.
What the Filing Actually Disclosed
The record lists only one category of exposed information: personal information. No passwords, no financial account numbers, no Social Security numbers, and no government identifiers were named in the filing. This is genuine good news. The absence of those high-risk identifiers sharply limits what an attacker could do with any data taken.
Because the firm is a law firm, the personal information almost certainly included names, addresses, and details tied to legal cases handled by the firm. Those records remain permanently sensitive. They cannot be cancelled or reissued like a credit card. Once exposed, they can fuel targeted identity fraud, impersonation attempts, or scams that reference specific case matters to appear legitimate.
What This Exposure Enables
Attackers who obtain names paired with case-related personal details can craft convincing phishing emails or phone calls that reference real matters the firm handled. A scammer who knows you had a real estate closing, estate matter, or family law case in 2023 or 2024 can sound far more credible than a random caller.
The information also increases the risk of impersonation in future interactions with banks, insurers, or government agencies. While the lack of Social Security numbers or financial data makes immediate large-scale fraud more difficult, the combination of identity details and legal context still has long-term value on the information black market.
How to Determine Whether You Were Affected
The law firm is required to notify affected individuals directly, usually by mail. If you have not received a letter from Schauermann Thayer, it is likely your information was not included. However, if you have moved since August 14, 2024, the letter may have gone to an old address. In that case, contact the firm directly to confirm whether your records were part of the incident.
The Permanent Nature of Legal Records
Unlike a password or credit card, the core facts of your relationship with a law firm cannot be changed. Your name, the fact that you were a client, and the general subject of your legal matter remain fixed. This is why the exposure of even limited personal information from a law firm carries weight years after the incident.
The 257-day delay between the breach date and the notification date means any data taken had ample time to circulate before the public or affected individuals learned of it. That timeline cannot be undone. What you can control now is how you respond to the increased risk of targeted social engineering.
Protecting Yourself Going Forward
Stay alert for unsolicited contact that references your prior legal matters. Verify any request for information or money by contacting the firm using a phone number you already know to be legitimate, never one provided in an email or text.
Review your credit reports and bank statements for any unfamiliar activity, even though financial account numbers were not listed as exposed. Consider placing a fraud alert with the major credit bureaus as a low-effort precaution.
Be especially cautious with tax-related communications in the coming years. Scammers often use personal details from past professional relationships to file fraudulent returns or claim refunds.
Finally, treat any unexpected request for personal verification that references your history with Schauermann Thayer as suspicious until proven otherwise. The combination of your name and case context is the exact material that makes targeted scams effective.
The filing establishes that 2,577 Oregon residents were affected. No further technical details about how the breach occurred or how it was discovered are public. What matters most to you is that limited but permanent personal information left the firm’s control more than eight months before anyone outside the investigation was told.
Report details & sourcing
Related breaches
Livara Health Medical Group Data Breach Notice (California Attorney General)
Livara Health Medical Group notified California residents of a data breach in a filing reported to t…
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Punch & Associates Investment Management, Inc. Data Breach Notice (Vermont Attorney General)
Punch & Associates Investment Management, Inc. notified Vermont residents of a data breach in a fili…