Skip to content
Back to Blog
low severity August 29, 2024 · 4 min read

Usaa Data Breach Notice (Oregon Attorney General)

If you received a notice from Usaa, here’s what the filing says was exposed, and what to do about it.

Usaa notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on August 29, 2024. The filing puts the incident itself on April 13, 2024.

Usaa Data Breach Notice (Oregon Attorney General)

The April 13, 2024 breach at USAA placed the personal information of 32,276 people into unknown hands. The organisation filed its notification with Oregon authorities on August 29, 2024 — 138 days later. That gap is the single most noticeable fact in the record.

What the 138-day interval actually changes for you

By the time USAA notified Oregon residents, the exposed records had been outside the company’s control for more than four and a half months. The filing does not state when the incident was discovered, only when it occurred and when the notice was sent. This means anyone whose information was taken had no opportunity to act during that period. The delay itself does not prove negligence, but it does mean the window for immediate protective steps closed long before most people learned about the breach.

The only data category named in the filing

The Oregon record lists a single broad category: personal information. No passwords, no financial account numbers, and no permanent government identifiers such as Social Security numbers are mentioned. The absence of those fields is genuine news. It sharply limits what an attacker can do with the data compared with breaches that expose full identity packages.

Because the filing uses only the general term “personal information,” the exact elements taken remain unknown. The letter you may have received from USAA is the only document that can tell you which specific details applied to you. If you have not received a letter, it is likely your records were not part of the 32,276 affected in this incident. Anyone who has moved since April 13, 2024 should contact USAA directly to confirm whether their information was included.

What this exposure still enables

Even limited personal information retains value for identity thieves. Names combined with addresses, phone numbers, or email addresses can be used to craft convincing phishing messages, support social-engineering attacks, or seed lookup services that attackers later combine with data from other breaches. The information cannot be changed the way a credit card can. Once it is out, it stays out.

The record gives no indication that the data was encrypted at rest or in transit, nor does it describe the method of access. Those details are simply not present. What matters to you is that the personal information listed in this filing is now outside USAA’s protection and can be reused indefinitely.

Why the lack of credential exposure matters

No passwords or login credentials appear in the exposed categories. This is one of the clearest positive points in the record. You do not need to change your USAA password because of this incident. The account itself is not at direct risk from the data that was taken. That reassurance is worth stating plainly: the breach does not compromise your ability to log in securely.

How the exposed information connects to identity theft

Personal details harvested here can still serve as building blocks. Fraudsters frequently combine partial records from multiple sources. A name and old address from this breach, paired with a Social Security number obtained elsewhere, can be used to open accounts, file fraudulent tax returns, or apply for government benefits. The 138-day delay increased the chance that such combinations have already begun.

The filing does not claim the data was exfiltrated, only that an incident occurred. In practice, organisations filing these notices almost always assume the worst and notify on that basis. Treat the information as available to unknown parties.

What you can still control

While you cannot retract the exposed personal information, you retain several practical levers. Monitoring your credit reports and financial accounts remains the most effective ongoing defense. Place a fraud alert or credit freeze if you have not done so already. These steps do not repair what happened in April but they make it harder for new accounts to be opened in your name.

Review every explanation of benefits, tax document, and financial statement for unfamiliar activity. Report anything suspicious immediately. The earlier you catch attempted fraud, the easier it is to reverse.

Be especially wary of unsolicited contact that references USAA or this breach. Scammers often use news of a breach to lend credibility to phishing emails, texts, or calls. If someone claims to be helping you with this incident, assume they are not.

Finally, keep records of the notification letter and the dates you take any protective steps. Should identity theft occur later, documentation showing when you first learned of the breach will help with disputes and recovery.

The record is narrow but clear: 32,276 Oregon residents had personal information exposed on April 13, 2024. USAA waited 138 days before filing notice. No passwords or full identity documents were listed. The letter you did or did not receive is the only reliable way to know whether you were included. From this point forward, vigilance around credit, accounts, and unsolicited contact is the control you still possess.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed August 29, 2024
Last reviewed July 22, 2026
Affected 32276
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email