LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › A&A Services, d/b/a Sav-Rx Data Breach Notice (Oregon Attorney General)

HIGH severityConfirmedHow we verify

A&A Services, d/b/a Sav-Rx Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·May 24, 2024
A&A Services, d/b/a Sav-Rx Data Breach Notice (Oregon Attorney General)

Reported May 24, 2024. Approximately 2812336 people affected.

HIGH
Severity
2812336
People affected
1
Data types exposed
May 24, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

A&A Services, doing business as Sav-Rx, disclosed a data breach on May 24, 2024 that exposed the personal information of 2,812,336 individuals, according to a notice filed with the Oregon Attorney General. Individuals are urged to review the notice and take steps to determine whether their data was affected.

Severity & verification
HIGH severityConfirmed
Data types not itemised.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
2812336 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Organizations that handle large volumes of personal data continue to face persistent pressure from cyber incidents that can expose millions of records in a single event. Pharmacy benefit and related administrative services sit squarely in that landscape because they routinely process identity and health-adjacent information at scale. Against that backdrop, a notice filed with Oregon authorities in May 2024 brought a substantial incident involving A&A Services, doing business as Sav-Rx, into public view.

A&A Services, d/b/a Sav-Rx, notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on May 24, 2024. The notice indicates that approximately 2,812,336 people were affected. Public detail on the incident remains limited beyond the reported headcount and the characterization of exposed material as personal information. The scale alone makes the event consequential for individuals who may have had dealings with the company or its programs.

Breaking down the breach

According to the Oregon Attorney General-related notice, A&A Services, d/b/a Sav-Rx, reported the matter on May 24, 2024. The filing states that 2,812,336 individuals were affected. The breach notification describes the exposed material as personal information; no further breakdown of specific data elements, no timeline of intrusion or discovery, and no description of the technical method appear in the disclosed facts. Whether the incident involved unauthorized access to systems, a third-party compromise, or another vector is undisclosed. No threat actor has been attributed in the available record.

The notice was directed at least in part to Oregon residents, consistent with state breach-notification requirements, though the total affected figure is national in scale. Beyond the headcount, the date of the regulatory filing, and the general label of personal information, public detail on the mechanics and full scope of the event is limited.

How a breach like this happens

Incidents that result in large-scale exposure of personal information typically begin with an initial foothold—often obtained through phishing, compromised credentials, unpatched remote services, or misuse of legitimate access. Once inside an environment, attackers may move laterally, locate databases or file stores containing identity data, and exfiltrate material over days or weeks before detection. In other cases, a misconfigured cloud storage location or a vulnerable application programming interface can expose records without a prolonged intrusion.

Organizations in benefits administration and related services frequently maintain centralized systems that aggregate enrollee or member data for claims processing, eligibility checks, and customer support. Those systems are attractive targets because a single repository can hold records for millions of people. Detection often lags the initial compromise; notification to regulators and individuals then follows forensic review and legal assessment of what was accessed or acquired. None of these general patterns is confirmed as the path taken in the Sav-Rx matter; they simply describe how events of this reported magnitude commonly unfold when no specific method has been disclosed.

About A&A Services, d/b/a Sav-Rx

A&A Services, operating as Sav-Rx, functions in the pharmacy-benefit and related administrative services sector. Companies of this type typically manage prescription-drug programs, process claims, coordinate with pharmacies and plan sponsors, and maintain records needed to verify eligibility and deliver benefits. That work necessarily involves collecting and storing personal information tied to individuals covered by employer, union, or other group plans.

Because such organizations sit between patients, employers, insurers, and pharmacies, a breach affecting them can reach people who never interacted directly with the company under its own brand. The reported figure of more than 2.8 million affected individuals underscores the breadth of data such an operation may hold. A compromise at this layer of the healthcare-adjacent supply chain therefore carries consequences well beyond a single employer or health plan.

The information in question

The breach notification characterizes the exposed material as personal information. Exact data elements—such as names, addresses, dates of birth, Social Security numbers, member identifiers, or health-related details—are not itemized in the facts provided. Organizations performing pharmacy-benefit and administrative services ordinarily maintain identity data, contact information, plan or member numbers, and sometimes limited clinical or prescription-related fields required for claims and eligibility. Whether any or all of those categories were involved in this incident remains unconfirmed. Readers should treat the precise contents as undisclosed rather than assume a full inventory of sensitive fields.

The real-world impact

For affected individuals, exposure of personal information creates durable risks of identity theft, account takeover, and targeted social-engineering attempts. Even when only basic identifiers are involved, criminals can combine them with other leaked data sets to open fraudulent accounts, file false claims, or craft convincing phishing messages. Because pharmacy-benefit records can link a person to a specific employer or plan, the information may also support more tailored fraud. Monitoring for unusual credit activity, unfamiliar medical or pharmacy bills, and unexpected account changes becomes a practical necessity for those who believe they may be included.

For the organization, an incident of this reported size typically triggers regulatory scrutiny, notification costs, potential litigation, and the need to strengthen controls and monitoring. Trust with plan sponsors and members can erode even when the company is itself a victim of unauthorized access. The absence of public detail on root cause or containment leaves open questions that only further disclosures or independent reporting can resolve.

What to do if you're exposed

If you have reason to believe your information was involved, begin by placing a fraud alert or credit freeze with the major consumer reporting agencies and review credit reports and explanation-of-benefits statements for unfamiliar activity. Change passwords on related accounts, enable multi-factor authentication where available, and remain alert to phishing that references pharmacy benefits or recent “security updates.” Keep records of any notice you receive from the company. As an additional check, you can run a free exposure scan of your email address to see whether it has already appeared in known breach data sets, which may help you gauge whether further monitoring is warranted.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyA&A Services, d/b/a Sav-Rx security record
74/100
DoxxScan™ · Moderate doxx risk
B- 75Above-average record

1 reported incident on record.

See A&A Services, d/b/a Sav-Rx’s full breach history →

More recent breaches

American Intercontinental University System Data Breach Notice (Oregon Attorney General)December 3, 2024Wireless Communications, Inc. dba Cellular Plus Data Breach Notice (Oregon Attorney General)October 25, 20245.11, Inc. Data Breach Notice (Oregon Attorney General)October 5, 2024Station. Bank and. Change health care Data Breach Notice (Oregon Attorney General)October 4, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the A&A Services, d/b/a Sav-Rx Data Breach Notice (Oregon Attorney General) →

Source: Oregon Department of Justice breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram