LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › New American Funding Data Breach Notice (Oregon Attorney General)

MEDIUM severityConfirmedHow we verify

New American Funding Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·March 1, 2026
New American Funding Data Breach Notice (Oregon Attorney General)

Occurred January 01, 2001 · publicly disclosed March 1, 2026. Approximately 359 people affected.

MEDIUM
Severity
359
People affected
1
Data types exposed
March 1, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

New American Funding disclosed a data breach to the Oregon Attorney General on March 01, 2026, notifying 359 individuals that their personal information had been exposed. Anyone who received a notice or believes they may have been affected should review the details and take steps to protect their information.

Severity & verification
MEDIUM severityConfirmed
Data types not itemised.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
359 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

A notice filed with Oregon authorities says New American Funding has told residents that personal information was involved in a data breach affecting a limited number of people. For anyone who has borrowed through, applied with, or otherwise shared details with a mortgage lender, even a relatively small incident can raise practical questions about identity theft, account misuse, and long-term monitoring of credit and personal records.

According to the Oregon Attorney General breach notice, the company reported the matter on March 01, 2026, and the filing lists 359 people affected. Public detail beyond that filing is limited; what is known comes from the notification itself rather than a fuller technical disclosure.

Inside the incident

New American Funding notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on March 01, 2026. The same filing places the incident itself on January 01, 2001. The notice identifies the exposed material as personal information, without a public breakdown in the available record of every field or system involved.

The reported scale is 359 people affected. How the intrusion or exposure occurred, how long unauthorized access lasted if any, whether a third party was involved, and what containment steps were taken are not described in the facts available from the notice. No threat group is attributed in the disclosure. Readers should treat the January 01, 2001 incident date as stated in the filing; the notice does not explain the long gap between that date and the March 01, 2026 report to Oregon authorities.

How a breach like this happens

In general terms, incidents that lead to “personal information” notices often follow familiar paths. Attackers or insiders may obtain credentials through phishing, reuse of passwords from other breaches, or malware on an employee device. Misconfigured cloud storage, exposed databases, or overly broad access to customer files can also leave records reachable without a dramatic “hack.” Ransomware and other extortion-driven attacks sometimes include data theft before systems are locked, though nothing in this notice confirms that pattern here.

Once access exists, bulk export of customer or applicant files, email archives, or backup copies can move large amounts of data quickly. Detection may come from unusual login activity, a vendor alert, law-enforcement contact, or internal audit—timelines vary widely. Organizations then assess what was taken, who must be notified under state law, and how to secure remaining systems. None of these general patterns should be read as a confirmed method for this specific New American Funding matter; the public filing does not describe the technical cause.

About New American Funding

New American Funding operates in the mortgage and home-finance sector, a line of business that routinely collects and retains sensitive personal and financial information in order to underwrite loans, service accounts, and meet regulatory obligations. Firms in this sector typically handle identity documents, income and employment data, credit-related information, property details, and contact records across applications, closings, and ongoing servicing.

A breach affecting a mortgage lender is consequential because the same data that supports a legitimate loan can also be used to open new credit, file fraudulent claims, or socially engineer banks, employers, or government agencies. Even when the headcount of notified individuals is in the hundreds rather than the millions, the depth of financial data such companies often hold can make each record more useful to criminals than a simple email-password pair from a consumer website. The Oregon notice establishes that personal information was involved for 359 people; it does not, by itself, prove wider compromise of every customer or system.

The information in question

The breach notification names the exposed data as personal information. It does not publicly itemize specific fields such as Social Security numbers, driver’s license numbers, full financial account numbers, or medical data in the facts provided. Exact contents beyond that label remain unconfirmed in the available record.

Organizations of this kind typically hold names, addresses, phone numbers, dates of birth, government identifiers, income and employment details, credit and banking information related to mortgage applications or servicing, and property-related records. That is background about the sector, not a confirmed inventory of what left New American Funding’s control in this incident. Until a fuller notice or official update lists concrete data elements, affected people should assume sensitive identity and financial attributes could be in scope and act accordingly, without treating any unlisted field as proven fact.

What's at stake

For individuals, the main risks are identity theft, new-account fraud, tax- or benefits-related fraud, and targeted phishing that references a real mortgage or home-purchase context. Criminals who obtain personal information may combine it with data from other breaches to pass knowledge-based verification or to pressure people into wiring money or sharing one-time codes. Harm is not automatic—many exposed records are never successfully abused—but the window of risk can last years, especially if government identifiers were included.

For the organization, consequences can include regulatory scrutiny, notification and credit-monitoring costs, civil claims, and reputational damage among borrowers and partners. State attorneys general receive these filings so that residents and oversight bodies have a formal record. The notice does not establish negligence as a legal finding; it records that a breach involving personal information was reported for 359 people, with the incident date given as January 01, 2001 and the Oregon report dated March 01, 2026.

What to do if you're exposed

If you have a relationship with New American Funding or receive a breach letter, treat the notice seriously. Read any official communication carefully for the data types it lists and for any offer of credit monitoring or identity-protection services, and keep a copy. Consider placing a free fraud alert or credit freeze with the major credit bureaus, monitoring bank and credit-card statements, and filing your taxes early if identity theft is a concern. Be skeptical of unexpected calls or emails that claim to “verify” your mortgage or Social Security information; use contact channels you look up independently.

Change passwords on related financial accounts, enable multi-factor authentication where available, and avoid reusing passwords across sites. If you are unsure whether your email address has appeared in other known breach datasets, you can run a free exposure scan of your email to check whether your information has surfaced in known breach data, then prioritize securing those accounts. For personalized legal or credit advice, consult official state resources or a qualified professional; public filings give a baseline, not a full picture of every individual’s risk.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyNew American Funding security record
71/100
DoxxScan™ · Moderate doxx risk
B- 75Above-average record

2 reported incidents on record.

See New American Funding’s full breach history →
RelatedMore incidents at New American Funding

More recent breaches

Poppins Payroll Data Breach Notice (Oregon Attorney General)September 30, 2026Midvale Indemnity Data Breach Notice (Oregon Attorney General)September 30, 2026City of McMinnville Data Breach Notice (Oregon Attorney General)September 29, 2026Lamb Weston Holdings, Inc. Data Breach Notice (Oregon Attorney General)September 29, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the New American Funding Data Breach Notice (Oregon Attorney General) →

Source: Oregon Department of Justice breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram