Skip to content
Back to Blog
low severity March 18, 2026 · 4 min read

The Michael Larson Co., PC Data Breach Notice (Oregon Attorney General)

If you received a notice from The Michael Larson Co., PC, here’s what the filing says was exposed, and what to do about it.

The Michael Larson Co., PC notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on March 18, 2026. The filing puts the incident itself on January 29, 2026.

The Michael Larson Co., PC Data Breach Notice (Oregon Attorney General)

The Michael Larson Co., PC has notified 250 Oregon residents that their personal information was exposed in an incident on January 29, 2026. The firm filed the notice with the Oregon Department of Justice on March 18, 2026 — 48 days later.

What the Exposure Actually Means for You

If you received a letter from The Michael Larson Co., PC, your personal information was among the records involved in this incident. The filing lists personal information as the category exposed. No passwords, financial account numbers, Social Security numbers, driver’s license numbers, or medical details appear in the disclosed categories.

That absence matters. Because no permanent government identifiers or financial data were listed, the long-term identity theft risk that often follows a breach is lower here than in many similar incidents. The records do not give someone the ability to open new accounts in your name or file fraudulent tax returns using information taken from this event.

The Gap Between Incident and Notification

The breach occurred on January 29 and the filing reached the state on March 18. That six-week interval is neither unusually fast nor unusually slow under Oregon’s notification rules. The record does not disclose when the firm discovered the incident, so it is not possible to know how quickly they acted after learning of it. What matters is that notification has now been sent to the affected individuals.

How to Know If You Were Affected

The Michael Larson Co., PC is required to notify each person whose information was included, usually by mail to the last known address. If you have not received a letter, it is likely your records were not part of the 250 affected. However, if you have moved since January 29, 2026, a letter may have gone to an old address. In that case, contact the firm directly to confirm whether your information was involved.

Why Personal Information Still Carries Risk

Even without the most sensitive identifiers, exposed personal information can be combined with data from other sources to build a more complete profile. Fraudsters buy and sell such details on underground markets. While this single incident does not give attackers everything they need for major identity theft, it can still contribute to nuisance fraud, phishing attempts tailored to you, or impersonation in customer service calls.

The good news is that without passwords or account credentials listed, your existing accounts with The Michael Larson Co., PC are not directly at risk from this breach. You do not need to change any passwords because of this incident.

What Remains Under Your Control

Because the exposed data does not include reissuable items like credit cards or permanent identifiers like a Social Security number, your options focus on vigilance rather than emergency replacement. The most practical steps involve watching for misuse of the specific personal details that may have been taken and reducing how easily those details can be leveraged in combination with information already available elsewhere.

  • Review your recent statements and explanations of any accounts you hold with The Michael Larson Co., PC for any unfamiliar activity.
  • Place a fraud alert with the three major credit bureaus if you have not done so in the past year. This forces lenders to verify your identity before opening new accounts.
  • Be especially cautious with unsolicited calls or emails that reference any personal details the firm would have held about you. Hang up or delete and contact the company using a known good number or address.
  • Monitor your mail and email for any new account openings or tax documents you did not expect. Report anything suspicious immediately.

The Limits of What This Filing Tells Us

The record does not describe how the incident occurred, whether data was copied or simply viewed, or what security measures were in place. Those details remain unknown to the public. The filing establishes only that an event took place on January 29 affecting 250 people and that personal information was involved.

This incident is modest in scale compared with many reported breaches, yet any exposure of personal information justifies attention. The fact that stronger identifiers were not listed in the categories is genuinely helpful. It narrows the realistic threats you face and spares you some of the more disruptive protective steps required when Social Security numbers or financial data are confirmed lost.

Stay alert for the letter if you have not received it, act on the monitoring steps above, and treat this as one more data point in the broader reality that personal information travels farther than most people expect. No further action is required beyond reasonable caution.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed March 18, 2026
Last reviewed July 22, 2026
Affected 250
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email