Morrison Child and Family Services Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
Morrison Child and Family Services has disclosed a data breach affecting 2,042 individuals, with the notice posted on the Oregon Attorney General’s breach-reporting site on June 27, 2024. Individuals who received services from the organization should review the full notice and consider placing a fraud alert or credit freeze if their personal information was exposed.
Morrison Child and Family Services notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on June 27, 2024. According to that notice, the incident affected 2,042 people and involved personal information. Public detail beyond those points remains limited, yet the disclosure matters because the organization works with children and families whose records can include sensitive identifying and service-related details.
The Oregon Attorney General’s report establishes the core facts now on the public record: the organization, the reporting date, the number of people notified, and the broad category of data described as personal information. No further technical findings, timelines, or methods have been released in the materials summarized here.
What happened
Morrison Child and Family Services submitted a data-breach notice that was reported to the Oregon Department of Justice on June 27, 2024. The filing states that 2,042 individuals were affected and that personal information was involved. The available summary does not describe how the incident was discovered, whether systems were encrypted or copied, how long unauthorized access lasted, or what specific technical vector was used. Those particulars are undisclosed in the public notice as summarized.
What is confirmed is the organization’s formal notification to Oregon residents and the regulator, the headcount of people included in the notice, and the characterization of the exposed material as personal information. No dollar figures, file counts, or named threat actors appear in the reported facts.
How a breach like this happens
Incidents that lead to notices of this kind often begin with compromised credentials, a phishing message that yields remote access, an unpatched internet-facing system, or a misconfigured cloud storage location. Once an attacker or unauthorized party gains a foothold, they may search for databases, document repositories, or backup files that contain names, contact details, and other identifiers. In many cases the activity is detected only after unusual outbound traffic, ransomware notes, or later review of access logs.
Organizations that serve children and families commonly store records across case-management platforms, email, and shared drives. When those systems are reached without authorization, the resulting exposure is typically described in regulatory filings as “personal information” even when the precise fields remain unpublished. No specific intrusion method or criminal group has been attributed in the Morrison notice summarized here; the foregoing is general background on how similar events commonly unfold, not a reconstruction of this incident.
About Morrison Child and Family Services
Morrison Child and Family Services is a provider of behavioral health, foster-care, and family-support services. Organizations in this sector routinely maintain records needed to deliver care, coordinate with courts or schools, and meet licensing and funding requirements. Those records can include names, addresses, dates of birth, contact information, and service histories for children, parents, guardians, and staff.
A breach affecting such an organization is consequential because the people served often include minors and families in vulnerable circumstances. Even when only a high-level category such as “personal information” is named, the potential presence of identifiers tied to behavioral-health or child-welfare involvement raises the stakes for those whose data may have been involved. The June 2024 Oregon filing places this event on the public record for the 2,042 people the organization determined were affected.
What data was at risk
The breach notification names the exposed data as personal information. No further breakdown—such as Social Security numbers, medical details, financial account numbers, or specific document types—is provided in the reported facts. Exact contents therefore remain unconfirmed beyond that broad label.
Organizations that deliver child and family services typically hold demographic identifiers, contact data, and case-related notes required for treatment, placement, or support. Whether any of those more sensitive fields were present in the material involved in this incident has not been detailed in the public summary. Readers should treat only the stated category—“personal information”—as established by the notice.
Why it matters
For the 2,042 people included in the notice, the practical risks center on misuse of identifying details: targeted phishing, account takeover attempts that rely on known personal facts, or longer-term identity-related fraud. Because the organization serves children and families, any exposure can also create secondary concerns about stigma or unwanted contact if service involvement becomes known to third parties.
For Morrison Child and Family Services, the incident triggers legal notification duties, potential regulatory follow-up, and the operational cost of investigation and support for affected individuals. The public filing itself does not assign fault or describe security shortcomings; it simply records that a breach involving personal information was determined and reported. The absence of richer technical detail means affected people must rely on the organization’s direct notices and on standard protective steps rather than on a full public forensic account.
Were you affected?
If you have received a letter or email from Morrison Child and Family Services about this incident, follow the instructions in that notice, including any offer of credit monitoring or identity-protection services. Even without a letter, consider placing a fraud alert with the major credit bureaus, reviewing account statements, and being cautious of unexpected messages that reference the organization or request personal details. You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets. Keep records of any correspondence and monitor for unusual activity over the coming months, as misuse of personal information sometimes surfaces well after the initial notice date.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Stiiizy Inc. Data Breach Notice (Oregon Attorney General)American Addiction Centers, Inc. Data Breach Notice (Oregon Attorney General)Norwex USA, Inc. Data Breach Notice (Oregon Attorney General)Oregon Reproductive Medicine, LLC Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.