Perkins Law Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
Perkins Law disclosed a data breach to the Oregon Attorney General on January 22, 2025, indicating that personal information of 753 individuals was exposed after an incident that occurred on October 09, 2024. Anyone who received notice or believes their information may be involved should review the details provided by Perkins Law and follow recommended steps to protect their data.
A law firm’s client and contact records are among the most sensitive files a person can have on file with a professional. When Perkins Law reported a data breach affecting 753 people, the practical question for anyone who has dealt with the firm is straightforward: whether personal information tied to a legal matter may now sit outside the firm’s control, and what that means for identity risk, privacy, and follow-up with the firm or state authorities.
According to a filing reported to the Oregon Department of Justice on January 22, 2025, Perkins Law notified Oregon residents of a data breach. The same filing places the incident itself on October 09, 2024. Public detail beyond that notice—how the intrusion occurred, which systems were involved, and a full inventory of every field exposed—is limited. What is confirmed is the headcount, the date of the incident as reported, the reporting date, and that the notice describes exposed personal information.
What happened
Perkins Law submitted a data breach notice reflected in Oregon Attorney General reporting. The organization is identified as Perkins Law. The incident date given in the filing is October 09, 2024. The notice to the Oregon Department of Justice is dated January 22, 2025. The number of people affected is reported as 753.
The breach notification describes the exposed material as personal information. The public record summarized here does not name a threat actor, does not describe a ransom demand, does not list specific file names or system types, and does not publish a technical root-cause analysis. Timing between the stated incident date and the January 2025 filing leaves a multi-month gap; the reasons for that interval are not detailed in the facts available for this account.
No dollar loss figure, no list of specific document categories beyond the general label of personal information, and no confirmation of whether data was exfiltrated, encrypted in place, or both appear in the structured facts. Readers should treat only the reported dates, the count of 753 people, the Oregon filing, and the “personal information” characterization as established from the disclosure.
How a breach like this happens
Incidents that end in law-firm breach notices often follow patterns seen across professional services, even when a particular case does not publish its method. Attackers commonly obtain an initial foothold through stolen or guessed remote-access credentials, a malicious email attachment or link that runs on a staff workstation, or an unpatched internet-facing service. From a single mailbox or laptop, movement inside a network can reach document management systems, email archives, billing platforms, or shared drives where client intake forms and correspondence live.
Once inside, the activity that matters to affected people is usually collection or copying of files that contain names, contact details, government identifiers, financial references, or case-related narratives. Some intrusions end in encryption and a disruption of operations; others prioritize quiet theft. Law firms are frequent targets in the broader economy because the same systems that support representation also concentrate high-value personal and confidential data. None of this general background assigns a named group or a proven technique to the Perkins Law event; the disclosure does not attribute a specific actor or attack path.
Detection may come from unusual login alerts, endpoint security tools, a client complaint, or later discovery during routine IT work. Notification to regulators and residents then follows legal timelines that vary by state. The Oregon filing in this matter is the public marker that the firm treated the event as a reportable breach involving personal information of a defined population.
Who is Perkins Law?
Perkins Law is a law practice. Firms of this kind handle confidential client matters, intake paperwork, correspondence, billing, and often identity documents needed to open or pursue a case. Even a small or mid-sized practice can hold Social Security numbers, driver’s license data, financial account references, medical or family details relevant to a dispute, and extensive free-text notes. That concentration of trust is why a breach at a law office is consequential: the data was shared for legal representation, not for open circulation.
A breach notice directed to Oregon residents and filed with the Oregon Department of Justice indicates that at least some affected individuals are tied to Oregon for notification purposes. The firm’s full geographic footprint, practice areas, and internal security program are not spelled out in the breach facts provided here. What matters for risk is the role such an organization plays: it is a custodian of personal and often privileged or sensitive information, so unauthorized access can affect both privacy and, in some situations, the confidentiality expectations around legal work.
What was likely exposed
The breach notification names exposed data as personal information. It does not, in the facts given, itemize every field. For a law firm, personal information in a breach notice commonly can include combinations of name, address, phone, email, date of birth, and government-issued identifiers, and may in other cases extend to financial or case-specific details—but those finer categories are not confirmed here as fact for this incident.
Exact contents remain only partly described in public summary form. Affected people should rely on the individual notice they receive from the firm, if any, for the categories applicable to them rather than assuming a full standard list.
- Confirmed from the disclosure: personal information, as stated in the breach notification.
- Confirmed scale: 753 people reported affected.
- Unconfirmed in the available facts: precise data elements (for example, whether Social Security numbers, financial accounts, or health-related fields were included), full file inventories, and whether every affected person had the same data types involved.
- Unconfirmed: technical method of access and any third-party vendor role.
Why it matters
For individuals, exposure of personal information raises durable risks: account takeover attempts, targeted phishing that references a real legal matter, new credit or identity applications in someone else’s name, and long-term uncertainty about where copies of the data reside. Even without a published menu of every data element, a formal breach notice signals that the firm concluded the legal threshold for notifying residents was met.
For the organization, a reported incident affects client trust, regulatory expectations, possible contractual duties to clients, and the cost of investigation, notification, and remediation. Law practices also face professional obligations around confidentiality; a cybersecurity event can intersect with those duties even when the public notice uses the broad phrase “personal information.”
The gap between the October 09, 2024 incident date and the January 22, 2025 reporting date means some people may only recently have learned of an event that, per the filing, began months earlier. That delay—whatever its cause—can shorten the window in which monitoring and password changes feel preventive rather than reactive. Still, concrete harm is not automatic for every person in a headcount of 753; risk depends on what was actually tied to each individual and how that information is misused, if at all.
Were you affected?
If you are a current or former client, opposing party with records at the firm, employee, or other person who provided personal information to Perkins Law, treat the Oregon notice as a reason to verify your status rather than to assume you are included or excluded. Watch for a written notice from the firm; keep it. Review financial and credit activity for unfamiliar inquiries or accounts. Prefer official firm contact channels you already trust if you need clarification—do not rely on unexpected emails or messages that urge immediate payment or password entry.
Practical first steps include changing passwords on email and financial accounts if those addresses or identifiers were used with the firm, enabling multi-factor authentication where available, and considering a fraud alert or credit freeze with major credit bureaus if your notice or situation suggests government identifiers may have been involved. Document dates of any suspicious contact. You can also run a free exposure scan of your email to check whether your information has surfaced in known breach data, which can complement—but not replace—the firm’s own notification about this specific incident.
Public detail on this event remains anchored to the Oregon filing: incident date October 09, 2024, report January 22, 2025, 753 people, and personal information as described in the breach notification. Anything beyond that should be confirmed through official notices or further disclosures, not assumed.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Decisely Insurance Services Data Breach Notice (Oregon Attorney General)Apro, LLC d/ Data Breach Notice (Oregon Attorney General)Apro, LLC d/b/a United Pacific Data Breach Notice (Oregon Attorney General)CareOregon Data Breach Notice (Oregon Attorney General)Latest breaches
Read GalaxyWarden’s full analysis of the Perkins Law Data Breach Notice (Oregon Attorney General) →
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.