LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Columbia Pacific Advisors, LLC Data Breach Notice (Washington Attorney General)

CRITICAL severityConfirmedHow we verify

Columbia Pacific Advisors, LLC Data Breach Notice (Washington Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 12, 2026
Columbia Pacific Advisors, LLC Data Breach Notice (Washington Attorney General)

Occurred November 28, 2025 · publicly disclosed June 12, 2026. Approximately 1585 people affected.

CRITICAL
Severity
1585
People affected
8
Data types exposed
June 12, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Columbia Pacific Advisors, LLC disclosed a data breach on June 12, 2026, affecting 1,585 individuals after an intrusion that occurred on November 28, 2025. The exposed records include names, Social Security numbers, driver’s license or Washington ID card numbers, financial and banking information, and full dates of birth; anyone who received notice or believes their information may be involved should review the company’s guidance and monitor their accounts.

Severity & verification
CRITICAL severityConfirmed
Exposes government-ID/financial/medical data.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
1585 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Columbia Pacific Advisors, LLC notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on June 12, 2026. The notice states that the incident itself occurred on November 28, 2025, and that 1,585 people were affected. Among the information listed as exposed are names, Social Security numbers, driver’s license or Washington ID card numbers, financial and banking information, full dates of birth, passport numbers, health insurance policy or ID numbers, and medical information.

For people whose records were involved, the combination of identity, financial, and health-related data raises concrete risks of fraud and misuse. Public detail beyond the Attorney General filing remains limited; what follows sticks to what that notice reports and to general context about this type of incident.

Breaking down the breach

According to the Washington Attorney General filing, Columbia Pacific Advisors, LLC experienced a data breach dated November 28, 2025. The firm’s notice to affected Washington residents was reported on June 12, 2026. The filing identifies 1,585 people as affected and enumerates the categories of information exposed: name, Social Security number, driver’s license or Washington ID card number, financial and banking information, full date of birth, passport number, health insurance policy or ID number, and medical information.

The public record does not describe how the incident was discovered, what systems were involved, whether ransomware or another intrusion method was used, or how long unauthorized access lasted. No threat actor is named in the disclosure. Timing between the November 2025 incident date and the June 2026 regulatory notice is stated in the filing; reasons for that interval are not explained in the available summary.

How a breach like this happens

Incidents that lead to notices of this kind often begin with stolen credentials, a compromised remote-access pathway, a phishing message that yields login access, or exploitation of an unpatched internet-facing system. Once inside a network, an intruder may move laterally, locate file shares or databases that hold client or employee records, and copy data for later use or sale. In other cases, a vendor or cloud service used by the organization is breached, and the customer’s data is taken from that third-party environment.

Organizations that handle investment, advisory, or wealth-related work typically store identity documents and financial account details in order to open accounts, meet regulatory know-your-customer rules, and service clients. When those repositories are reached without authorization, the result is often a notification listing precisely the kinds of fields named in this filing. None of this general pattern attributes a specific method or actor to the Columbia Pacific Advisors event; the filing itself does not supply that technical detail.

Who is Columbia Pacific Advisors, LLC?

Columbia Pacific Advisors, LLC is a firm operating in the investment and financial-advisory sector. Firms in this line of work commonly collect and retain personal identifiers, tax and banking details, and sometimes health- or insurance-related information when it is relevant to estate, trust, or benefits planning. They are entrusted with sensitive records because accurate identity and financial data are required to manage accounts and comply with securities and privacy rules.

A breach at such an organization matters because the data sets are concentrated and high-value for identity theft and financial fraud. Clients and others whose information was stored for legitimate business purposes can face lasting exposure even when the firm itself continues normal operations. The Washington notice indicates that at least some affected individuals were Washington residents, which is why the Attorney General received the filing.

What data was at risk

The Attorney General filing explicitly lists the following as among the information exposed: name, Social Security number, driver’s license or Washington ID card number, financial and banking information, full date of birth, passport number, health insurance policy or ID number, and medical information. Those categories come directly from the notice; the public summary does not itemize every field in every record or confirm that every affected person had every data type on file.

Where a notice names both government identity numbers and financial and medical data, the practical concern is that the same individual may have enough attributes exposed to support new-account fraud, tax-related misuse, or insurance-related scams. Exact contents of each person’s file remain as described in the company’s notice to those individuals; nothing beyond the listed categories is confirmed in the material summarized here.

The real-world impact

For affected people, the main risks are identity theft, fraudulent credit or bank applications, and misuse of health-insurance or medical details. Social Security numbers and dates of birth paired with government ID numbers are commonly used to impersonate someone at financial institutions or government agencies. Passport numbers and driver’s license data can support further document fraud. Financial and banking information can be abused for unauthorized transfers or account takeover attempts. Medical and health-insurance identifiers can be used in billing fraud or to obtain care in someone else’s name.

For the organization, consequences typically include notification costs, regulatory scrutiny, possible credit-monitoring offers, and reputational harm among clients who entrusted it with sensitive records. The filing does not state whether monitoring services were offered, what remediation steps were taken, or whether any financial losses to individuals have been confirmed. Those points remain outside the public summary.

Were you affected?

If you were a client, employee, or other contact of Columbia Pacific Advisors, LLC and you receive an official breach notice, read it carefully and follow the instructions it provides. Consider placing a fraud alert or credit freeze with the major credit bureaus, monitoring bank and credit-card statements, and treating unsolicited calls or emails that reference the incident with caution. Keep the notice for your records if you later need to dispute fraudulent accounts.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets, which may help you decide how closely to watch your accounts going forward.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyColumbia Pacific Advisors, LLC security record
52/100
DoxxScan™ · Elevated doxx risk
D+ 56Weak record

1 reported incident on record.

See Columbia Pacific Advisors, LLC’s full breach history →
RelatedMore incidents at Columbia Pacific Advisors, LLC

More recent breaches

Quatrro Business Support Services, Inc. Data Breach Notice (Washington Attorney General)September 9, 2026Hibbett Retail, Inc. Data Breach Notice (Washington Attorney General)September 8, 2026Bimbo Bakeries USA (Oracle) Data Breach Notice (Washington Attorney General)September 4, 2026Catalyst Brands LLC Data Breach Notice (Washington Attorney General)September 4, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Columbia Pacific Advisors, LLC Data Breach Notice (Washington Attorney General) →

Source: Washington State Attorney General breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram