Berman & Rabin, P.A. Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
Berman & Rabin, P.A. disclosed a data breach to the Oregon Attorney General on January 28, 2025, affecting 151,893 individuals. The breach occurred on July 5, 2024, exposing personal information; anyone who received services from the firm should verify their status and follow the steps outlined in the notice.
Law firms and professional practices remain frequent targets in a threat landscape where attackers prize concentrated stores of client identity data, case records, and financial details. Against that backdrop, a notice filed with Oregon authorities has brought a large-scale incident at Berman & Rabin, P.A. into public view.
According to the filing reported to the Oregon Department of Justice on January 28, 2025, the firm notified Oregon residents of a data breach. The same notice places the underlying incident on July 5, 2024, and states that 151,893 people were affected. The disclosed data category is described simply as personal information. Exact technical methods, the full geographic scope beyond the Oregon notice, and any further forensic findings remain limited in the public record.
What happened
Berman & Rabin, P.A. submitted a data-breach notice that was reported to the Oregon Attorney General’s office, via the Oregon Department of Justice, on January 28, 2025. That filing states the incident itself occurred on July 5, 2024. The notice indicates 151,893 individuals were affected and characterizes the exposed material as personal information.
Public detail stops there. The filing does not describe how the intrusion was detected, what systems were involved, whether ransomware or other malware was used, or how long unauthorized access lasted. No threat actor is named in the available notice, and no additional quantitative or technical particulars have been supplied in the record summarized here.
How a breach like this happens
Incidents that later appear in state attorney-general filings often begin with common initial access paths: phishing messages that harvest credentials, exploitation of unpatched remote-access or web-application flaws, or use of previously stolen passwords. Once inside a network, an attacker may move laterally, locate file shares or document-management systems that hold client and employee records, and copy data for later use or sale.
In professional-services environments the same pattern frequently appears. Attackers look for repositories that concentrate names, addresses, dates of birth, Social Security numbers, financial account details, or case-related correspondence. Detection can lag weeks or months, which is why the gap between an incident date and a regulatory filing date is not unusual. None of these general patterns is confirmed as the method used against Berman & Rabin, P.A.; they simply illustrate how breaches of this broad type typically unfold when no specific actor or technique has been publicly attributed.
About Berman & Rabin, P.A.
Berman & Rabin, P.A. is a professional association—commonly a law firm or similar licensed practice. Organizations of this kind routinely collect and retain sensitive personal data in the ordinary course of representing clients, managing employment records, and conducting financial or litigation-related work. That data can include identity documents, contact information, financial particulars, and case files that are both confidential and valuable to criminals.
A breach affecting more than 150,000 people is therefore consequential. It can expose clients, employees, and other individuals whose information was entrusted to the firm, and it can create regulatory, reputational, and operational burdens for the organization itself. The Oregon notice is one formal channel through which such an event becomes visible to residents of that state; other jurisdictions or federal reporting may exist but are not detailed in the facts at hand.
The information in question
The breach notification identifies the exposed material as personal information. No more granular inventory—such as specific fields, document types, or whether Social Security numbers, financial account data, or health-related details were included—appears in the summarized filing.
Law firms and comparable professional practices typically hold names, addresses, dates of birth, government identification numbers, bank or payment details, and correspondence tied to legal matters. Because the notice does not confirm which of these elements were actually involved, any precise list remains unconfirmed. Readers should treat the category “personal information” as the only verified description and avoid assuming additional data types were compromised.
Why it matters
For the 151,893 people referenced in the notice, the practical risks include identity theft, targeted phishing that references real personal details, and fraudulent account openings or credit applications. Even when the exact data elements are not fully enumerated, “personal information” in a professional-services context is often sufficient for social-engineering or fraud attempts that can take months to detect and reverse.
For the firm, the consequences include the cost of investigation and notification, potential regulatory scrutiny, possible civil claims, and the need to strengthen access controls and monitoring. Clients may also reassess how their sensitive materials are stored. None of these outcomes requires a finding of negligence; they follow from the simple fact that a large volume of personal data left the organization’s control.
Were you affected?
If you have been a client, employee, or other contact of Berman & Rabin, P.A., review any official notice you may have received and follow the guidance it contains. Place a fraud alert or credit freeze with the major consumer reporting agencies if you believe sensitive identifiers were involved, and monitor financial and credit statements for unfamiliar activity. Change passwords on any accounts that reused credentials associated with the firm, and be alert for unsolicited messages that appear to reference the breach.
You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets. Doing so provides one additional, practical data point while you wait for any further official updates.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Decisely Insurance Services Data Breach Notice (Oregon Attorney General)Apro, LLC d/ Data Breach Notice (Oregon Attorney General)Apro, LLC d/b/a United Pacific Data Breach Notice (Oregon Attorney General)CareOregon Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.