LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Barrett-Jackson Holdings, LLC Data Breach Notice (Oregon Attorney General)

MEDIUM severityConfirmedHow we verify

Barrett-Jackson Holdings, LLC Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 31, 2025
Barrett-Jackson Holdings, LLC Data Breach Notice (Oregon Attorney General)

Reported July 31, 2025. Approximately 20651 people affected.

MEDIUM
Severity
20651
People affected
1
Data types exposed
July 31, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Barrett-Jackson Holdings, LLC has notified the Oregon Attorney General of a data breach affecting 20,651 individuals that came to light on July 31, 2025. Anyone who received notice or believes their personal information may have been exposed should review the company’s statement and consider placing a credit freeze or fraud alert.

Severity & verification
MEDIUM severityConfirmed
Data types not itemised.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
20651 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Barrett-Jackson Holdings, LLC notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on July 31, 2025. According to that notice, the incident affected 20,651 people and involved personal information. Public detail beyond the filing remains limited, yet the scale and the nature of the data make the event consequential for anyone who has done business with the company.

The disclosure itself is the primary source of what is known so far. No further technical timeline, attack method, or expanded inventory of records has been released in the materials available for this account.

Breaking down the breach

On July 31, 2025, Barrett-Jackson Holdings, LLC submitted a data-breach notice to the Oregon Attorney General’s office. The filing states that 20,651 individuals were affected and that the exposed material consisted of personal information as described in the breach notification. The company directed the notice at Oregon residents, which is the geographic scope reflected in the public record.

Beyond those figures and the broad category of “personal information,” the notice does not supply a detailed chronology of when the intrusion began, how long unauthorized access lasted, or which systems were involved. Method of compromise, whether ransomware or another vector was used, and any forensic findings remain undisclosed in the available filing. The public record therefore establishes the fact of notification, the headcount of people affected, and the general type of data, but little else about the technical course of the incident.

How a breach like this happens

Incidents that lead to notifications of this kind typically begin with an attacker gaining an initial foothold—often through stolen credentials, a phishing message, an unpatched remote-access service, or a compromised third-party vendor. Once inside, the intruder may move laterally, locate databases or file shares that contain customer or employee records, and copy or exfiltrate that material. In many cases the organization discovers the activity only after unusual network traffic, an extortion demand, or a routine security review surfaces the problem.

After containment, companies are generally required by state law to assess whose information was involved and to notify affected residents and regulators within set deadlines. The Oregon filing reflects that notification step. Because no specific threat group has been attributed in the public materials for this event, any discussion of motive or tactics stays at the level of common patterns rather than claims about this particular case.

About Barrett-Jackson Holdings, LLC

Barrett-Jackson Holdings, LLC is the corporate entity behind the well-known Barrett-Jackson collector-car auctions and related events. The business operates large public auctions, private sales, and associated services that bring together consignors, bidders, sponsors, and staff. Organizations in this sector routinely collect names, contact details, bidding and purchase records, payment-related information, and sometimes identification documents needed for high-value transactions and compliance.

A breach affecting tens of thousands of people is consequential because the company’s customer base includes individuals who have entrusted it with personal and financial details in the course of buying or selling vehicles that can be worth substantial sums. Even when only a general category of “personal information” is named, the volume of records and the trust relationship make timely, accurate notification important.

The information in question

The Oregon notice identifies the exposed data as personal information per the breach notification. It does not publish a more granular list—such as specific fields like Social Security numbers, driver’s-license numbers, financial account data, or dates of birth—in the summary available here. Exact contents therefore remain unconfirmed beyond that broad label.

Companies that run auctions and high-value sales typically hold names, addresses, email addresses, phone numbers, transaction histories, and sometimes government-issued identification or payment details. Whether any or all of those elements were present in the affected systems in this incident is not stated in the public filing. Readers should treat the confirmed category as “personal information” and avoid assuming any narrower inventory until the organization or regulators provide it.

The real-world impact

For the 20,651 people counted in the notice, the practical risks center on the misuse of personal information: targeted phishing that references a real auction or purchase, account-takeover attempts if login credentials or recovery data were involved, or identity-related fraud if more sensitive identifiers were present. Because the precise data elements are not itemized publicly, the severity for any single individual cannot be ranked from the filing alone; the prudent stance is to treat the exposure as real and to monitor for unusual activity.

For Barrett-Jackson Holdings, LLC the consequences include the cost of investigation, notification, and potential credit-monitoring offers, as well as reputational pressure from customers who expect strong protection of the details they supply when consigning or bidding on vehicles. Regulatory follow-up under state breach laws is also possible. None of these outcomes has been quantified in the materials reviewed for this article; they are the ordinary downstream effects of a notice of this size.

Were you affected?

If you have registered for Barrett-Jackson events, consigned a vehicle, placed bids, or otherwise shared personal details with the company, review any direct notice you may have received from them. Place fraud alerts or credit freezes if you believe sensitive identifiers could be involved, and watch financial and email accounts for unexpected messages that reference auctions or prior purchases. Change passwords on related accounts and enable multi-factor authentication where available.

You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets. Doing so provides an additional, independent signal and does not replace official notices from the company itself. Stay alert to further updates from Barrett-Jackson Holdings, LLC or from state authorities as more confirmed detail, if any, becomes public.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyBarrett-Jackson Holdings, LLC security record
74/100
DoxxScan™ · Moderate doxx risk
B 80Good record

1 reported incident on record.

See Barrett-Jackson Holdings, LLC’s full breach history →

More recent breaches

Decisely Insurance Services Data Breach Notice (Oregon Attorney General)December 30, 2025Apro, LLC d/ Data Breach Notice (Oregon Attorney General)December 29, 2025Apro, LLC d/b/a United Pacific Data Breach Notice (Oregon Attorney General)December 29, 2025CareOregon Data Breach Notice (Oregon Attorney General)December 26, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Barrett-Jackson Holdings, LLC Data Breach Notice (Oregon Attorney General) →

Source: Oregon Department of Justice breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram