Skip to content
Back to Blog
low severity October 31, 2024 · 3 min read

SelectBlinds Data Breach Notice (Oregon Attorney General)

If you received a notice from SelectBlinds, here’s what the filing says was exposed, and what to do about it.

SelectBlinds notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on October 31, 2024. The filing puts the incident itself on January 07, 2024.

SelectBlinds Data Breach Notice (Oregon Attorney General)

The data breach at SelectBlinds that occurred on January 07, 2024, and was filed with the Oregon Attorney General on October 31, 2024, affects 206,238 people. That 298-day gap between the incident and the official filing is the most striking detail in the record.

Personal information from 206,238 customers is now outside the company’s control

If you received a notification from SelectBlinds, your personal information was included in an incident that took nearly ten months to reach regulators. The filing lists only one category: personal information. No passwords, no financial account numbers, and no government identifiers such as Social Security numbers or driver’s license numbers appear in the exposed categories.

This is genuinely good news on the credential side. Because no passwords were exposed, there is no need to change your SelectBlinds account password. The account itself remains secure from this incident. The risk lies entirely in the non-credential personal details that cannot be reissued or canceled the way a credit card can.

What long-term personal information actually enables

Names combined with addresses and other personal details retain value for identity thieves long after a breach. Criminals can use them to build synthetic identities, file fraudulent tax returns, open accounts in your name, or attempt to redirect mail and packages. While the exact fields beyond “personal information” are not detailed in the filing, the scale—more than 206,000 customers—suggests the data came from order or customer records.

Unlike a credit card number that can be replaced, once this information leaves the company it cannot be taken back. The 298 days between the January 07, 2024 incident and the October 31, 2024 filing means the information has had time to circulate. That interval is the central fact readers need to weigh when deciding how seriously to treat this notice.

How to determine whether you were affected

SelectBlinds is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your records were not part of the exposed group. However, if you have moved since January 07, 2024, a letter may have gone to an old address. In that case, contact SelectBlinds customer service directly to confirm whether your information was included.

The difference between permanent and replaceable data

The filing does not list any permanent government identifiers. This significantly limits the most dangerous forms of identity theft that rely on Social Security numbers or driver’s license numbers. What remains exposed is information that can support fraud but does not give an attacker the complete keys to government-backed identity systems.

That distinction matters. It means your primary focus should be on monitoring for account takeover attempts and fraudulent new accounts rather than immediate worry about tax fraud or full identity theft that requires a stolen SSN.

Practical steps that address this specific exposure

  • Place a fraud alert with the three major credit bureaus. A fraud alert forces lenders to verify your identity before opening new accounts and lasts 90 days, giving you time to assess any fallout.
  • Review your credit reports for unfamiliar accounts or inquiries. You are entitled to one free report per bureau every week at AnnualCreditReport.com. Look for anything opened after January 2024.
  • Monitor your bank and credit card statements closely for the next 12 months. Watch for small test charges or unfamiliar transactions that often precede larger fraud.
  • Be extremely cautious with unsolicited calls, texts, or emails claiming to be from SelectBlinds, government agencies, or banks. Criminals with personal details often use them to sound legitimate in phishing attempts.
  • Consider identity theft protection services that include dark web monitoring for your name and address combinations. While not a guarantee, these services can alert you faster if your details appear for sale.

The long delay between the January 07, 2024 breach and the October 31, 2024 filing does not change what you can control today. The absence of passwords and sensitive identifiers in the exposed categories limits the damage compared with many other breaches. Focus your effort on the monitoring and fraud-alert steps above. Those actions directly address the type of personal information that was actually placed at risk.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed October 31, 2024
Last reviewed July 22, 2026
Affected 206238
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email