OneDigital Investment Advisors LLC Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
OneDigital Investment Advisors LLC reported a data breach to the Oregon Attorney General on April 20, 2026, stating that personal information of 535 individuals had been exposed after the breach occurred on August 12, 2025. If you received services from OneDigital Investment Advisors LLC, review the official notice and consider placing a fraud alert or credit freeze.
Investment advisory firms sit at a high-value intersection of personal identity and financial life, which is why they remain steady targets in a threat landscape defined by credential theft, business-email compromise, and opportunistic access to client records. When a firm that handles investment advice must notify residents through a state attorney general, the event is not abstract: it is a concrete signal that personal information tied to financial relationships may have left the environment where it was meant to stay.
OneDigital Investment Advisors LLC notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on April 20, 2026. That filing places the incident itself on August 12, 2025, and states that 535 people were affected. Public detail beyond those points is limited; what is confirmed is a formal notice describing exposure of personal information and a months-long gap between the stated incident date and the Oregon report.
Breaking down the breach
According to the Oregon Attorney General breach notice, OneDigital Investment Advisors LLC experienced a data incident dated August 12, 2025. The organization later submitted a filing to the Oregon Department of Justice, reported on April 20, 2026, advising Oregon residents of the event. The notice identifies 535 people as affected and characterizes the exposed material as personal information, consistent with the language of the breach notification.
The public record provided here does not describe how the incident was discovered, whether systems were encrypted or exfiltrated, what technical vector was involved, or how long unauthorized access lasted. It also does not break down how many of the 535 individuals were Oregon residents versus people in other states who may have been counted in a broader population. Timing between the August 12, 2025 incident date and the April 20, 2026 Oregon filing is stated in the notice; reasons for that interval are not explained in the facts available for this account. No threat group is named in the disclosure, and no leak-site claim is part of the given record.
How a breach like this happens
Incidents affecting professional services and advisory firms typically begin with ordinary weak points rather than cinematic intrusion. Stolen or reused passwords, phishing messages that harvest credentials, compromised vendor accounts, misconfigured remote access, or malware on a workstation can all open a path into email, document stores, or client-management systems. Once inside, an attacker may search for files that look like client lists, onboarding packets, tax-related forms, or identity documents—material that is routine in advisory work and valuable for fraud.
In many cases the organization learns of the problem through unusual login activity, a security tool alert, a customer report, or a later forensic review. Containment then involves cutting off access, preserving logs, determining what repositories were reachable, and deciding who must be notified under state law. None of that sequence is confirmed for this specific event; it is the general pattern behind notices that, like this one, report a date of incident, a count of people affected, and a category such as personal information without publishing a full technical post-mortem.
About OneDigital Investment Advisors LLC
OneDigital Investment Advisors LLC operates in the investment advisory sector. Firms of this type provide portfolio guidance, retirement and wealth-related advice, and related financial services to individuals and sometimes to employers or plan participants. In the ordinary course of business they collect and retain information needed to verify identity, open and service accounts, meet regulatory obligations, and communicate about investments and fees.
That role makes a breach consequential even when the public notice is brief. Clients and prospects entrust advisors with details that link real-world identity to money movement and long-term planning. A compromise does not automatically mean funds were stolen, but it does mean the confidentiality of the relationship—and the records that support it—may have been impaired. For a regulated advisory business, notification duties, client trust, and operational continuity all come into play when personal information is reported as exposed.
What data was at risk
The Oregon notice names the exposed data as personal information, per the breach notification. It does not itemize fields such as Social Security numbers, account numbers, dates of birth, driver’s license data, or contact details in the facts provided here. Those specifics remain unconfirmed in the public summary available for this article.
Organizations in investment advisory work commonly hold names, addresses, phone numbers, email addresses, government identifiers, financial account or custodian references, beneficiary information, and documents used for know-your-customer and tax reporting. That is typical sector practice, not a statement of what was proven taken in this incident. Readers should treat only “personal information” as the disclosed category and regard any finer inventory as undisclosed unless a later official notice expands it.
What's at stake
For affected people, the practical risks are identity misuse and targeted fraud. Personal information can be combined with other leaked or publicly available data to attempt account takeovers, tax refund fraud, new-credit applications, or convincing phishing that references a real advisory relationship. Even without confirmed financial account numbers in the notice, identity elements alone can support social-engineering attacks against banks, employers, or family members.
For the firm, stakes include regulatory notification obligations, potential follow-on inquiries, cost of investigation and client support, and erosion of confidence among people who expected confidentiality as part of professional advice. The reported scale—535 individuals—is modest compared with some mass retail breaches, but impact is personal rather than statistical: each affected person may need to monitor credit, tax transcripts, and financial accounts for a prolonged period. Nothing in the given facts establishes negligence or assigns blame; the notice establishes that an incident occurred and that personal information was involved for the stated population.
If your data was in this breach
If you have a relationship with OneDigital Investment Advisors LLC or receive a formal notice tied to this event, treat the communication seriously. Keep the letter or email; use contact channels printed on the notice rather than links from unexpected messages. Consider placing a fraud alert with the major credit bureaus, reviewing credit reports and bank and brokerage statements for unfamiliar activity, and being cautious of anyone who contacts you claiming to help “resolve” the breach while asking for passwords, remote access, or payment.
Where a notice offers credit monitoring or identity-protection enrollment, read the terms and deadlines carefully. Change passwords on related email and financial accounts, and enable multi-factor authentication where available. As a further check, you can run a free exposure scan of your email address to see whether that address has already appeared in known breach datasets elsewhere—useful context, though it will not replace the official notice for this incident or confirm whether your file was among the 535 people named in the Oregon filing.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
ASOS US Sales LLC Data Breach Notice (Oregon Attorney General)BestCare treatment Services, Inc. Data Breach Notice (Oregon Attorney General)Boston Health Care for the Homeless Program Data Breach Notice (Oregon Attorney General)American Addiction Centers Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.