Berry Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
The Berry Data Breach Notice (Oregon Attorney General) (reported April 25, 2024) exposed Personal information (per the breach notification) belonging to roughly 1107354 people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
More than 1.1 million people may have had personal information involved when Berry experienced a data security incident in September 2023. The company later notified Oregon residents through a filing with the Oregon Department of Justice, making the scale and timing a matter of public record. For anyone whose details were held by Berry, the practical question is straightforward: what is known, what remains unconfirmed, and what sensible steps reduce follow-on risk.
Public detail is limited to the notification itself. The filing reported on April 25, 2024, places the incident on September 12, 2023, and states that personal information was involved. Exact contents of the exposed records, the technical method of access, and any full national breakdown beyond the Oregon notice are not expanded in the available disclosure.
Inside the incident
According to the breach notice filed with the Oregon Attorney General’s office and reported to the Oregon Department of Justice on April 25, 2024, Berry identified a data security incident dated September 12, 2023. The filing indicates that 1,107,354 people were affected. The notice characterizes the exposed material as personal information; it does not itemize further fields, file types, or systems in the summary available from that report.
No public description in the filing details how the incident was discovered, how long unauthorized access may have lasted, or whether data was exfiltrated, encrypted, or merely accessed. Timing between the September 2023 incident date and the April 2024 Oregon notification is part of the record; reasons for that interval are not stated in the disclosure. No threat actor is named or attributed in the facts provided.
How a breach like this happens
Incidents that lead to notices of this kind commonly begin with compromised credentials, a vulnerable remote service, a phishing message that yields access, or an unpatched system reachable from the internet. Once inside a network, an intruder may move laterally, locate databases or file stores that contain customer, employee, or partner records, and copy or encrypt material before defenders fully contain the activity.
Organizations then investigate, determine what categories of data were involved, and issue notices required by state law when residents’ personal information meets statutory thresholds. The technical path is often undisclosed in consumer-facing notices, which focus on the fact of exposure, the approximate population affected, and recommended precautions rather than forensic narrative. Nothing in the Berry filing attributes a specific group or technique; the pattern above is general background only.
About Berry
Berry is the organization named in the Oregon Attorney General data-breach notice. Entities operating under that name in commercial contexts typically manage large volumes of customer, employee, or business-partner records in the course of manufacturing, packaging, distribution, or related services. Such organizations routinely hold names, contact details, account or employee identifiers, and other personal information needed for operations, payroll, shipping, or customer support.
A breach affecting more than a million people is consequential because the same centralized systems that support scale also concentrate data. When those systems are involved in an incident, the downstream effects can reach individuals who had no direct relationship with every internal process yet whose information was stored for legitimate business reasons. The Oregon filing establishes that Berry treated the event as meeting state notification criteria for personal information.
What was likely exposed
The breach notification names “personal information” as the category exposed. It does not list specific data elements such as Social Security numbers, financial account numbers, driver’s license data, or medical details. Public detail on exact fields is therefore limited.
Organizations of this type commonly maintain names, addresses, phone numbers, email addresses, dates of birth, employee or customer identifiers, and sometimes government ID or financial data depending on the business function. Whether any of those more sensitive elements were present in the affected systems in this incident is unconfirmed by the filing. Readers should treat the exposed set as personal information as stated, without assuming particular high-risk fields unless a later official notice specifies them.
Why it matters
When personal information is involved at this scale, affected people face elevated risk of targeted phishing, account takeover attempts, and identity fraud that relies on pieced-together personal details. Even limited data can be combined with information from other sources to make fraudulent outreach more convincing. For the organization, the incident creates regulatory notification duties, potential follow-on inquiries, remediation costs, and lasting questions from customers and partners about data handling.
The gap between the September 2023 incident date and the April 2024 Oregon report means some individuals may only recently have learned they were included. Delayed awareness does not change the underlying exposure; it simply shortens the window in which people can monitor accounts and place fraud alerts. Concrete harm is not automatic—many breaches produce no immediate misuse—but the volume reported makes sustained vigilance reasonable rather than alarmist.
If your data was in this breach
Start with the basics: treat unsolicited messages that reference Berry or urge urgent action with skepticism, and verify any request through official channels you already trust. Review bank, credit-card, and online account statements for unfamiliar activity. Consider a fraud alert or credit freeze with the major credit bureaus if you believe sensitive identifiers may have been involved; freezes are reversible and limit new-credit openings in your name. Keep records of any notice you received and the date you acted on it.
If you want a quick check on whether your email address has appeared in other known breach datasets, you can run a free exposure scan of your email. That step does not confirm or deny inclusion in this specific Berry incident, but it can surface additional exposed credentials worth changing. Update passwords on important accounts, enable multi-factor authentication where available, and continue monitoring for unusual activity over the coming months. Official updates, if any, would come from Berry or the relevant state authorities rather than third-party summaries.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Stiiizy Inc. Data Breach Notice (Oregon Attorney General)Norwex USA, Inc. Data Breach Notice (Oregon Attorney General)American Addiction Centers, Inc. Data Breach Notice (Oregon Attorney General)Oregon Reproductive Medicine, LLC Data Breach Notice (Oregon Attorney General)Latest breaches
Read GalaxyWarden’s full analysis of the Berry Data Breach Notice (Oregon Attorney General) →
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.