New American Funding, LLC Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
New American Funding, LLC disclosed a data breach to the Oregon Attorney General on July 28, 2025, after unauthorized access occurred on June 06, 2025 that exposed personal information of 456 individuals. Anyone who received services from the company should review the notice and take the recommended steps if their information was affected.
New American Funding, LLC notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on July 28, 2025. According to that notice, the incident itself occurred on June 6, 2025, and 456 people were affected. The notification describes the exposed material as personal information.
Public detail remains limited to what appears in the Oregon filing. The scale of the notice is modest in absolute numbers, yet any exposure of personal information held by a mortgage lender carries practical consequences for the individuals named in the records and for the firm’s ongoing obligations to protect customer data.
Breaking down the breach
The Oregon Attorney General’s public record shows that New American Funding, LLC submitted a data-breach notice on July 28, 2025. The filing states that the underlying incident took place on June 6, 2025. It identifies 456 affected individuals and characterizes the exposed data as personal information.
No further technical particulars—such as the precise attack vector, the systems involved, the duration of unauthorized access, or whether data were encrypted—are included in the disclosed summary. The notice does not attribute the event to any named threat group. What is known is therefore confined to the dates, the headcount of 456, and the broad category of personal information.
How a breach like this happens
Incidents that result in notices of this kind typically begin with unauthorized access to systems that store customer or employee records. Common pathways include compromised credentials, phishing messages that lead to account takeover, exploitation of unpatched software, or misconfigured cloud storage. Once inside, an attacker may copy files containing names, contact details, financial identifiers, or other personal data.
In many cases the organization discovers the activity days or weeks later through internal monitoring, law-enforcement notification, or external reporting. After containment, firms are generally required by state law to notify residents whose information may have been involved and to file with the relevant attorney general. The Oregon notice follows that pattern; the specific method used against New American Funding remains undisclosed.
Who is New American Funding, LLC?
New American Funding, LLC is a mortgage lender that originates and services home loans for individual borrowers. Companies in this sector routinely collect and retain substantial volumes of personal and financial data: Social Security numbers, income documentation, credit histories, property addresses, bank-account details, and government-issued identification. That information is necessary to underwrite loans, comply with anti-money-laundering rules, and service existing mortgages.
Because the data set is both sensitive and relatively complete, a breach at a mortgage lender can expose individuals to identity-theft and fraud risks that extend well beyond a simple email-address leak. Even a notice covering a few hundred people can therefore carry outsized practical weight for those affected.
The information in question
The Oregon filing states that personal information was exposed. It does not itemize the exact fields. Organizations of this type ordinarily hold full names, postal and email addresses, dates of birth, Social Security numbers, driver’s-license or passport numbers, loan-account numbers, income and employment records, and banking details used for payments or disbursements.
Whether any or all of those elements were present in the specific files involved in the June 6, 2025 incident is unconfirmed in the public notice. Readers should treat the exposed set as personal information whose precise composition has not been further detailed by the company or the regulator.
The real-world impact
For the 456 individuals covered by the notice, the primary risks are identity theft, account takeover, and targeted phishing that leverages accurate personal details. Fraudsters who obtain mortgage-related data can attempt to open new credit lines, file false tax returns, or socially engineer banks and government agencies. Even when the absolute number of affected people is limited, the depth of information typical of lending files raises the potential harm per person.
For New American Funding, LLC the consequences include regulatory scrutiny, the cost of notification and credit-monitoring offers if provided, possible civil claims, and reputational damage among current and prospective borrowers. The firm must also demonstrate that it has contained the incident and strengthened controls—steps that are standard after any confirmed exposure of personal information.
What to do if you're exposed
If you believe you are among the 456 people referenced in the Oregon notice, or if you have been a New American Funding customer, consider the following immediate steps:
- Review any official letter or email from the company for the exact data elements it says were involved and for any offer of credit monitoring.
- Place a free fraud alert or credit freeze with the three nationwide credit bureaus to hinder new-account fraud.
- Monitor bank, credit-card, and loan statements for unfamiliar activity and report anomalies promptly.
- Be alert for phishing messages that reference your mortgage or personal details; verify any request through official channels.
- File your taxes early if a Social Security number may have been exposed, reducing the window for fraudulent returns.
- Run a free exposure scan of your email address to check whether that address has already appeared in other known breach data sets.
These measures do not eliminate risk, but they reduce the chance that exposed personal information will be successfully misused. Continue to treat unsolicited contacts with caution and keep records of any correspondence related to the June 2025 incident.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Decisely Insurance Services Data Breach Notice (Oregon Attorney General)Apro, LLC d/b/a United Pacific Data Breach Notice (Oregon Attorney General)Apro, LLC d/ Data Breach Notice (Oregon Attorney General)CareOregon Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.