Pyramid Advisors Limited Partnership d/b/a Pyramid Global Hospitality Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
Pyramid Advisors Limited Partnership d/b/a Pyramid Global Hospitality disclosed a data breach on February 25, 2026, affecting 139,899 individuals. The breach occurred on August 13, 2025, exposing personal information; affected individuals should check their status and take appropriate protective steps.
Pyramid Advisors Limited Partnership, doing business as Pyramid Global Hospitality, notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on February 25, 2026. The notice places the incident itself on August 13, 2025, and states that 139,899 people were affected. The filing describes the exposed material as personal information.
Because the company operates in hospitality management, a breach of this scale can reach guests, employees, and other individuals whose records the firm holds. Public detail beyond the Oregon notice remains limited.
Inside the incident
According to the Oregon Attorney General filing, Pyramid Advisors Limited Partnership d/b/a Pyramid Global Hospitality experienced a data incident dated August 13, 2025. The company later submitted a breach notice that was reported on February 25, 2026. That notice identifies 139,899 affected individuals and characterizes the exposed data as personal information.
The filing does not describe the technical method of intrusion, the systems involved, how long unauthorized access lasted, or whether data was exfiltrated, encrypted, or merely accessed. No threat actor is named. Timing between the August 2025 incident date and the February 2026 reporting date is stated in the notice; the reasons for that interval are not explained in the public summary.
How a breach like this happens
Incidents that lead to notices of this kind commonly begin with compromised credentials, a vulnerable remote-access service, a phishing message that yields a foothold, or unpatched software on a network that stores business records. Once inside, an attacker may move laterally, locate databases or file shares containing personal information, and copy or lock those materials.
Organizations then investigate, determine the scope of affected records, and issue legally required notices. The precise path in any single case is often undisclosed while forensics continue or for operational-security reasons. Nothing in the Oregon filing attributes this event to a named group or spells out the entry vector, so the above remains general background rather than a description of what occurred here.
Pyramid Advisors Limited Partnership d/b/a Pyramid Global Hospitality and its sector
Pyramid Global Hospitality is the operating name of Pyramid Advisors Limited Partnership, a firm active in hotel and hospitality management. Companies in this sector typically oversee properties, reservations, guest services, payroll, and vendor relationships. In the ordinary course of business they collect and retain names, contact details, payment-related data, employment records, and other personal information belonging to guests, staff, and business partners.
A breach affecting nearly 140,000 people is consequential because hospitality operators sit at the intersection of consumer travel data and workforce records. Even when only “personal information” is named, the volume alone means a large number of individuals may need to monitor accounts and documents tied to stays, employment, or related services. The Oregon notice confirms the count and the broad data category; it does not further map which properties or business lines were involved.
The information in question
The breach notification names the exposed material as personal information. It does not itemize fields such as Social Security numbers, driver’s-license data, financial account numbers, or medical details. Public detail on exact data elements is therefore limited to that general description.
Hospitality and management firms commonly hold guest reservation and contact data, employee onboarding and payroll information, and business-contact records. Whether any of those specific categories were present in this incident is unconfirmed. Readers should treat the exposed set as personal information of unspecified composition until the company or regulators provide a fuller inventory.
The real-world impact
For affected individuals, the primary risks are misuse of personal information for fraud, targeted phishing, or account takeover attempts that rely on details already known to the attacker. Even without a public list of every data element, a confirmed exposure of personal information at this scale warrants heightened caution around identity documents, financial accounts, and unsolicited messages that reference travel or employment.
For the organization, consequences include regulatory notification duties, potential follow-on inquiries, remediation costs, and reputational strain with guests and employees. The filing itself does not assign fault or quantify financial loss; those matters lie outside the disclosed facts.
If your data was in this breach
If you believe you may be among the 139,899 people referenced in the notice, practical first steps include the following:
- Review any direct notice you receive from Pyramid Global Hospitality for the specific data elements it lists and any offered credit-monitoring or support services.
- Place fraud alerts or credit freezes with the major consumer reporting agencies if you are concerned about new-account fraud.
- Monitor bank, credit-card, and other financial statements for unfamiliar activity and change passwords on accounts that reuse credentials tied to email or hospitality logins.
- Treat unexpected emails, texts, or calls that reference a hotel stay, employment, or this incident with skepticism; verify through official channels before sharing further information.
- Run a free exposure scan of your email address to check whether that address has already appeared in other known breach data sets, which can help you prioritize password changes and monitoring.
Keep records of any notices and correspondence. Exact next steps may vary by state of residence and by the final inventory of data types the company confirms. Public detail on this incident remains anchored to the Oregon filing dated February 25, 2026, and the August 13, 2025 incident date it reports.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Boston Health Care for the Homeless Program Data Breach Notice (Oregon Attorney General)Integrated Specialty Coverages, LLC (“ISC”) Data Breach Notice (Oregon Attorney General)Wilmer Cutler Pickering Hale and Dorr LLP Data Breach Notice (Oregon Attorney General)The Moody Bible Institute of Chicago Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.