McKay Wealth Management Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
McKay Wealth Management disclosed a data breach affecting 9,162 individuals on June 12, 2025; the breach itself occurred on June 28, 2024, exposing personal information. If you received notice or believe your information was held by the firm, review the notice from the Oregon Attorney General and follow the recommended steps to protect your data.
Financial-services firms remain frequent targets in a threat landscape where attackers seek concentrated stores of identity and account data. Against that backdrop, McKay Wealth Management’s notice to Oregon authorities documents a concrete incident affecting thousands of people and underscores why even smaller wealth-management practices sit inside the same risk environment as larger institutions.
According to a filing reported to the Oregon Department of Justice on June 12, 2025, McKay Wealth Management notified Oregon residents of a data breach. The filing places the incident itself on June 28, 2024, and states that 9,162 people were affected. The notice describes the exposed material as personal information. Public detail beyond those points is limited, yet the scale and sector make the event material for anyone who has done business with the firm.
What happened
McKay Wealth Management submitted a data-breach notice that was reported to the Oregon Attorney General’s office / Department of Justice on June 12, 2025. That filing identifies the date of the incident as June 28, 2024, and reports 9,162 individuals affected. The notification characterizes the exposed data as personal information. The public record available from the filing does not describe the technical method of intrusion, the systems involved, how long unauthorized access lasted, or whether data was exfiltrated, encrypted, or merely accessed. No threat actor is named in the disclosed materials. What is established is the sequence of dates, the headcount of people notified, and the broad category of data referenced in the notice.
How a breach like this happens
Incidents affecting professional-services and wealth-management firms commonly begin with one of several well-understood paths. Credential theft through phishing or reused passwords can give an outsider a foothold in email or remote-access systems. Unpatched software, misconfigured cloud storage, or compromised vendor accounts can open other routes. Once inside, an attacker may search for client files, contact lists, tax documents, or identity records that are useful for fraud or resale. In many cases the organization discovers the activity weeks or months later through unusual login patterns, law-enforcement tips, or internal audits, after which it begins forensic review and regulatory notification. None of these general patterns is confirmed as the cause of the McKay Wealth Management incident; they simply describe how breaches of this type typically unfold when method details remain undisclosed.
Who is McKay Wealth Management?
McKay Wealth Management is a wealth-management organization—the kind of firm that advises clients on investments, retirement planning, and related financial matters. Firms in this sector routinely maintain records needed to serve clients: names, contact details, Social Security or tax identifiers, account and portfolio information, beneficiary data, and correspondence that can reveal financial circumstances. Because the relationship is built on trust and long-term personal data, a breach at such an organization is consequential even when the exact technical story is sparse. Clients and prospects may have supplied sensitive identifiers precisely because the firm needs them to open accounts, file taxes, or manage assets. The Oregon filing indicates the firm took the step of notifying residents and regulators after the June 28, 2024 incident, consistent with state breach-notification expectations.
What data was at risk
The breach notification names the exposed material as personal information. It does not publish a further itemized inventory in the summary available here—no confirmed list of Social Security numbers, driver’s-license data, account numbers, or other specific fields. Organizations of this type typically hold identity and financial records necessary for advisory work; whether any particular field was involved in this incident remains unconfirmed beyond the notice’s reference to personal information. Readers should treat the precise contents as limited to what the filing states and should not assume additional categories without further official detail.
The real-world impact
For the 9,162 people counted in the notice, the practical risks center on identity misuse and targeted fraud. Personal information can be combined with other leaked or publicly available data to open credit accounts, file false tax returns, or craft convincing phishing messages that reference a real financial relationship. Even when account credentials themselves are not confirmed as exposed, knowledge that someone is a client of a wealth-management firm can make social-engineering attempts more persuasive. For the organization, the consequences include notification costs, potential regulatory follow-up, reputational strain, and the operational burden of supporting clients who need monitoring or document replacement. Because the incident date and the reporting date are nearly a year apart, some affected individuals may only recently have learned they were included, which can delay protective steps.
If your data was in this breach
If you have been a client or prospect of McKay Wealth Management, or if you received a notice tied to this filing, treat the situation as a prompt for ordinary, high-value hygiene rather than panic. Practical first steps include:
- Review any official notice you received for the exact data elements the firm believes were involved and for any enrollment offers such as credit monitoring.
- Place a fraud alert or credit freeze with the major credit bureaus if identity elements may have been exposed, and monitor credit reports and financial statements for unfamiliar activity.
- Be skeptical of unsolicited calls, texts, or emails that reference the breach or your accounts; contact the firm only through verified channels you already trust.
- Change passwords on related financial and email accounts, and enable multi-factor authentication where available.
- Retain copies of the notice and any correspondence in case you later need to document the incident for banks or tax authorities.
You can also run a free exposure scan of your email address to check whether that address has already appeared in other known breach data sets, which helps you judge how widely your information may already be circulating. Stay alert for official updates from the firm or from Oregon authorities if additional confirmed detail is released. Public information on this incident remains bounded by the June 12, 2025 filing and the facts it contains; anything beyond those points should be treated as unconfirmed until further notice.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Decisely Insurance Services Data Breach Notice (Oregon Attorney General)Apro, LLC d/b/a United Pacific Data Breach Notice (Oregon Attorney General)Apro, LLC d/ Data Breach Notice (Oregon Attorney General)CareOregon Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.