American Lending Center Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
American Lending Center disclosed a data breach to the Oregon Attorney General on May 12, 2026, after discovering that personal information of 123,158 individuals had been exposed in an incident that occurred on July 24, 2025. Anyone who provided data to the organization is advised to review the official notice and take steps to monitor their accounts.
American Lending Center has notified people that personal information was involved in a data breach, according to a filing reported to the Oregon Department of Justice. The notice matters because the filing lists a large number of people potentially affected, and because lenders routinely hold the kinds of records that can be misused for identity fraud and account takeover if they fall into the wrong hands.
Public detail is limited to what appears in that regulatory notice. The organization reported the matter on May 12, 2026, and placed the incident itself on July 24, 2025. Exactly how the intrusion unfolded, what systems were touched, and which specific data fields were confirmed exposed beyond the broad category of personal information are not spelled out in the facts available here.
Breaking down the breach
According to the Oregon Attorney General–related breach notice headline and the reported summary, American Lending Center notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on May 12, 2026. That filing puts the incident on July 24, 2025.
The same record states that 123,158 people were affected. The data types named as exposed are described as personal information, per the breach notification. No further breakdown of file names, databases, attack method, ransom demand, or confirmed exfiltration volume is included in the provided facts. No threat group is attributed in those facts, and none should be assumed.
There is a substantial gap between the stated incident date (July 24, 2025) and the reported notification date (May 12, 2026). The facts do not explain that interval, so any reason for the delay remains undisclosed in this record.
How a breach like this happens
In general terms—not as a description of this specific case—incidents that lead to “personal information” notices often begin with stolen login credentials, a vulnerable remote access service, a phishing message that yields a foothold, or unpatched software on a server that faces the internet. Once inside, an intruder may move through internal systems, search for customer or loan files, and copy data for later use or sale.
Organizations sometimes learn of a problem through their own monitoring, a service provider alert, law enforcement contact, or unusual account activity reported by customers. Investigation then tries to establish when access began, which accounts or systems were involved, and whether data was taken. That work can take weeks or months, which is one reason public notices can lag the underlying event. None of these typical patterns is confirmed for American Lending Center in the facts given; they are background only.
American Lending Center and its sector
American Lending Center, as its name indicates, operates in consumer or commercial lending. Firms in this sector typically collect and retain information needed to evaluate credit, service loans, and meet regulatory and tax obligations. That can include identifying details, contact data, financial account references, income or employment-related records, and documentation tied to applications and ongoing payments.
A breach at a lender is consequential because the same records used to underwrite and service credit are also useful to criminals who want to open new accounts, take over existing ones, or craft convincing fraud. Even when a notice only says “personal information,” the sector context explains why people take such notices seriously. The facts here do not allege negligence or describe security controls; they only establish that a notice was filed and that a large population was reported as affected.
The information in question
The breach record names exposed data types as personal information, per the breach notification. It does not list Social Security numbers, driver’s license numbers, bank account numbers, credit scores, or other specific fields as confirmed elements of this incident. Those details are unconfirmed in the facts provided.
Organizations of this kind commonly hold government identifiers, addresses, dates of birth, loan files, and payment-related data in the ordinary course of business. That is general sector background, not a statement of what was proven taken here. Until a fuller inventory is published by the organization or a regulator, the exact contents of the exposed set should be treated as limited to what the notice actually says: personal information, affecting 123,158 people as reported.
What's at stake
For individuals, the practical risks center on identity theft, fraudulent credit applications, phishing that references real loan or personal details, and long-term monitoring burdens. Even partial personal information can help an attacker pass weak verification checks or pressure someone into sharing more.
For the organization, stakes include regulatory scrutiny, the cost of investigation and notification, potential civil claims, and erosion of borrower trust. The filing with Oregon authorities underscores that state breach-notification rules are in play for residents covered by that notice. The facts do not report financial losses, lawsuits, or findings of fault.
- Reported people affected: 123,158
- Incident date stated in the filing: July 24, 2025
- Notification reported to the Oregon Department of Justice: May 12, 2026
- Data described in the notice: personal information (no finer inventory in the given facts)
- Threat actor: not attributed in the facts
If your data was in this breach
If you have a relationship with American Lending Center or receive an official notice, treat the communication seriously. Use contact channels you verify independently rather than links or numbers in unexpected messages. Consider placing fraud alerts or credit freezes with the major credit bureaus, reviewing loan and bank statements for unfamiliar activity, and documenting any suspicious credit inquiries.
Change passwords on related financial accounts, enable multi-factor authentication where available, and be cautious of follow-on phishing that cites a “lending center breach” to request more data. Keep copies of any notice you receive. For a simple additional check, you can run a free exposure scan of your email to see whether your address has appeared in known breach datasets, which may help you prioritize further monitoring even when a single company’s full file inventory remains limited in public detail.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Kaniksu Community Health Data Breach Notice (Oregon Attorney General)Craneware, Inc. Data Breach Notice (Oregon Attorney General)See's Candies Data Breach Notice (Oregon Attorney General)zHealth, Inc. Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.