Valsoft Corporation Inc. d/b/a AllTrust Data Breach Notice (Oregon Attorney General)
If you received a notice from Valsoft Corporation Inc., here’s what the filing says was exposed, and what to do about it.
Valsoft Corporation Inc. d/b/a AllTrust notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on February 27, 2025.
The February 27, 2025 filing from Valsoft Corporation Inc. d/b/a AllTrust confirms that personal information belonging to 98,123 people was exposed. If you received a letter from the company, your records were part of this incident.
No passwords or credentials were involved
This is important. The notification lists only personal information. No password field appears in the exposed categories, so there is no need to change any AllTrust password because of this breach. That particular risk does not exist here.
What the exposed personal information actually enables
Names combined with Social Security numbers, addresses, and other personal details remain valuable to identity thieves for years. Criminals can use them to file fraudulent tax returns, open accounts in your name, or apply for government benefits. Unlike a credit card, these identifiers cannot be cancelled or reissued on demand. The exposure creates a long-term risk rather than an immediate one that expires in weeks.
The filing does not state when the incident occurred, only that the notification reached the Oregon Department of Justice on February 27, 2025. It also does not disclose whether the data was stolen, merely viewed, or whether any encryption was in place. Those details remain unknown.
How to tell whether this affects you
AllTrust is required to notify affected individuals directly, usually by mail. If you have not received a letter, your information was likely not included. However, if you have moved since the time of the incident, letters sent to your previous address may not have reached you. In that case, contact AllTrust directly to confirm whether your records were part of the 98,123 affected.
The permanent nature of this exposure
Once personal information leaves a company’s control, it cannot be retrieved. You cannot “take it back.” What you can control is how closely you monitor the downstream consequences. The absence of any government-issued identifiers that can be replaced limits some options, but it does not eliminate the need for vigilance.
Credit and identity monitoring realities
A single freeze on your credit reports at the three major bureaus remains one of the most effective steps. It will not stop every form of fraud, but it blocks most new-account identity theft that relies on your Social Security number. Place the freeze yourself rather than relying on free monitoring services that only alert you after something has already happened.
Tax-related fraud is another realistic concern. Identity thieves sometimes file returns early in the year using stolen Social Security numbers. Checking your IRS online account regularly during tax season can reveal filings made in your name before you submit your own return.
What the scale tells us
98,123 people is a substantial number. The filing itself offers no further context about why this volume of records was accessible in a single incident. It simply records the fact. For anyone whose information was included, the practical takeaway is the same: the exposure has occurred and the records cannot be made private again.
Medical or financial account numbers beyond basic personal information are not listed in this particular notification. The record is limited to the category of personal information. Your own notification letter from AllTrust will provide the definitive list of what applied to you.
Practical steps that address this specific exposure
- Request your free credit reports from Equifax, Experian, and TransUnion now and review them for accounts you did not open. Do this once every few months rather than only after receiving breach letters.
- Place a credit freeze with all three bureaus. It is free, reversible when you need to apply for credit, and directly blocks the most common use of stolen personal information.
- Set up IRS online account access if you have not already. This lets you see whether a tax return has been filed under your Social Security number before you submit your own.
- Keep your own records of this incident, including the date you received the letter and what categories it listed. You may need them later if fraudulent activity appears.
- Contact AllTrust directly if you moved in the years leading up to the incident and never received a letter. Only they can confirm whether your specific records were involved.
The exposure is real for those notified. The risk is long-term rather than urgent, and it centers on identity theft rather than account takeover. Knowing exactly which facts the filing does and does not establish lets you focus effort on the parts you can still influence.
Report details & sourcing
Related breaches
Punch & Associates Investment Management, Inc. Data Breach Notice (Vermont Attorney General)
Punch & Associates Investment Management, Inc. notified Vermont residents of a data breach in a fili…
Ocean Edge Resort and Golf Club Data Breach Notice (Vermont Attorney General)
Ocean Edge Resort and Golf Club notified Vermont residents of a data breach in a filing reported to …
Castle Management, LLC Data Breach Notice (Vermont Attorney General)
Castle Management, LLC notified Vermont residents of a data breach in a filing reported to the Vermo…