Berkeley Research Group, LLC Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
Berkeley Research Group, LLC disclosed a data breach affecting 6,083 individuals on October 30, 2025. The breach occurred on February 28, 2025, exposing personal information. Individuals should check their status and take appropriate protective steps.
Berkeley Research Group, LLC notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on October 30, 2025. The filing places the incident itself on February 28, 2025, and states that 6,083 people were affected. Public detail identifies the exposed material as personal information, without further itemization in the notice.
For individuals whose data may have been involved, the gap between the February incident date and the October reporting date, together with the limited description of what was taken, makes clear, practical steps more useful than speculation. The notice matters because consulting and expert-services firms routinely handle sensitive personal and professional records tied to clients, matters, and personnel.
What happened
According to the Oregon Attorney General filing, Berkeley Research Group, LLC experienced a data breach on February 28, 2025. The organization later submitted a breach notice that was reported on October 30, 2025, advising Oregon residents and identifying 6,083 affected individuals. The notification characterizes the exposed data as personal information. No public detail in the filing describes the technical method of intrusion, the systems involved, the duration of unauthorized access, or whether data was exfiltrated, encrypted, or merely accessed. Scale beyond the stated headcount of affected people, and any geographic distribution outside Oregon residents named in the notice, remains undisclosed.
How a breach like this happens
Incidents that lead to notifications of this kind commonly begin with compromised credentials, a vulnerable remote-access service, a phishing message that yields a foothold, or exploitation of an unpatched application. Once inside a network, an attacker may move laterally, locate file shares or databases that contain personal records, and copy or stage data for removal. In other cases the initial access is limited to a single system that already holds the relevant files. Organizations often discover the activity weeks or months later through unusual outbound traffic, endpoint alerts, law-enforcement notice, or routine audit. Because no specific threat group or technique is attributed in the Berkeley Research Group filing, any reconstruction of the exact path remains general background rather than a description of this event. Defenders typically respond by isolating affected systems, resetting credentials, engaging forensic specialists, and determining notification obligations under state law.
About Berkeley Research Group, LLC
Berkeley Research Group, LLC is a professional-services firm that provides consulting, expert testimony, and advisory work across disputes, investigations, regulatory matters, and corporate strategy. Firms in this sector routinely collect and retain personal information belonging to employees, contractors, clients, opposing parties, and individuals named in case files or due-diligence materials. That information can include names, contact details, government identifiers, financial or employment records, and other data necessary to perform engagements. A breach at such an organization is consequential because the same records that support legitimate professional work can, if misused, enable identity theft, targeted fraud, or reputational harm. The firm’s role as a trusted holder of sensitive material also means clients and counterparties may face secondary exposure even when they were not the direct target of the intrusion.
What was likely exposed
The breach notification names the exposed data types as personal information. It does not list specific data elements such as Social Security numbers, driver’s-license numbers, financial account details, or medical information. Organizations of this kind typically hold names, addresses, dates of birth, contact information, government-issued identifiers, employment or compensation data, and records tied to legal or consulting matters. Whether any of those categories were present in the systems involved in the February 28, 2025 incident is unconfirmed; the public record states only “personal information.” Readers should treat the exact contents as undisclosed beyond that phrase and should not assume particular fields were or were not included.
The real-world impact
For the 6,083 people identified in the notice, the primary risks are conventional identity-related harms: fraudulent account openings, tax-refund fraud, social-engineering attempts that reference real personal details, and long-term monitoring burdens. Because the notice does not specify which data elements were involved, the severity for any single person cannot be ranked from public information alone. The organization faces regulatory notification duties, potential civil exposure, forensic and remediation costs, and the need to communicate with clients whose matters may have touched the affected systems. Delayed discovery or notification can increase the window during which stolen data might be misused before individuals can take protective steps. None of these consequences establish negligence as a proven fact; they simply describe the ordinary downstream effects of a confirmed personal-information breach of this size.
If your data was in this breach
If you believe you are among those notified, begin by reading the official notice carefully for any free credit-monitoring offer and enrollment deadline. Place a fraud alert or credit freeze with the major consumer reporting agencies, and monitor financial and credit accounts for unfamiliar activity. Change passwords on important accounts, especially if you reused credentials associated with the firm, and enable multi-factor authentication where available. Keep records of any suspicious contacts that appear to reference the breach. You can also run a free exposure scan of your email address to check whether that address or related information has already appeared in known breach data sets, which can help you prioritize further monitoring.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Decisely Insurance Services Data Breach Notice (Oregon Attorney General)Apro, LLC d/ Data Breach Notice (Oregon Attorney General)Apro, LLC d/b/a United Pacific Data Breach Notice (Oregon Attorney General)CareOregon Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.