LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Pyramid Advisors Limited Partnership d/b/a Pyramid Global Hospitality Data Breach Notice (Oregon Attorney General)

MEDIUM severityConfirmedHow we verify

Pyramid Advisors Limited Partnership d/b/a Pyramid Global Hospitality Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·February 25, 2026
Pyramid Advisors Limited Partnership d/b/a Pyramid Global Hospitality Data Breach Notice (Oregon Attorney General)

Occurred August 13, 2025 · publicly disclosed February 25, 2026. Approximately 139899 people affected.

MEDIUM
Severity
139899
People affected
1
Data types exposed
February 25, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Pyramid Advisors Limited Partnership d/b/a Pyramid Global Hospitality disclosed a data breach on February 25, 2026, affecting 139,899 individuals. The breach occurred on August 13, 2025, exposing personal information; affected individuals should check their status and take appropriate protective steps.

Severity & verification
MEDIUM severityConfirmed
Data types not itemised.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
139899 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Pyramid Advisors Limited Partnership, doing business as Pyramid Global Hospitality, notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on February 25, 2026. The notice places the incident itself on August 13, 2025, and states that 139,899 people were affected. The filing describes the exposed material as personal information.

Because the company operates in hospitality management, a breach of this scale can reach guests, employees, and other individuals whose records the firm holds. Public detail beyond the Oregon notice remains limited.

Inside the incident

According to the Oregon Attorney General filing, Pyramid Advisors Limited Partnership d/b/a Pyramid Global Hospitality experienced a data incident dated August 13, 2025. The company later submitted a breach notice that was reported on February 25, 2026. That notice identifies 139,899 affected individuals and characterizes the exposed data as personal information.

The filing does not describe the technical method of intrusion, the systems involved, how long unauthorized access lasted, or whether data was exfiltrated, encrypted, or merely accessed. No threat actor is named. Timing between the August 2025 incident date and the February 2026 reporting date is stated in the notice; the reasons for that interval are not explained in the public summary.

How a breach like this happens

Incidents that lead to notices of this kind commonly begin with compromised credentials, a vulnerable remote-access service, a phishing message that yields a foothold, or unpatched software on a network that stores business records. Once inside, an attacker may move laterally, locate databases or file shares containing personal information, and copy or lock those materials.

Organizations then investigate, determine the scope of affected records, and issue legally required notices. The precise path in any single case is often undisclosed while forensics continue or for operational-security reasons. Nothing in the Oregon filing attributes this event to a named group or spells out the entry vector, so the above remains general background rather than a description of what occurred here.

Pyramid Advisors Limited Partnership d/b/a Pyramid Global Hospitality and its sector

Pyramid Global Hospitality is the operating name of Pyramid Advisors Limited Partnership, a firm active in hotel and hospitality management. Companies in this sector typically oversee properties, reservations, guest services, payroll, and vendor relationships. In the ordinary course of business they collect and retain names, contact details, payment-related data, employment records, and other personal information belonging to guests, staff, and business partners.

A breach affecting nearly 140,000 people is consequential because hospitality operators sit at the intersection of consumer travel data and workforce records. Even when only “personal information” is named, the volume alone means a large number of individuals may need to monitor accounts and documents tied to stays, employment, or related services. The Oregon notice confirms the count and the broad data category; it does not further map which properties or business lines were involved.

The information in question

The breach notification names the exposed material as personal information. It does not itemize fields such as Social Security numbers, driver’s-license data, financial account numbers, or medical details. Public detail on exact data elements is therefore limited to that general description.

Hospitality and management firms commonly hold guest reservation and contact data, employee onboarding and payroll information, and business-contact records. Whether any of those specific categories were present in this incident is unconfirmed. Readers should treat the exposed set as personal information of unspecified composition until the company or regulators provide a fuller inventory.

The real-world impact

For affected individuals, the primary risks are misuse of personal information for fraud, targeted phishing, or account takeover attempts that rely on details already known to the attacker. Even without a public list of every data element, a confirmed exposure of personal information at this scale warrants heightened caution around identity documents, financial accounts, and unsolicited messages that reference travel or employment.

For the organization, consequences include regulatory notification duties, potential follow-on inquiries, remediation costs, and reputational strain with guests and employees. The filing itself does not assign fault or quantify financial loss; those matters lie outside the disclosed facts.

If your data was in this breach

If you believe you may be among the 139,899 people referenced in the notice, practical first steps include the following:

Keep records of any notices and correspondence. Exact next steps may vary by state of residence and by the final inventory of data types the company confirms. Public detail on this incident remains anchored to the Oregon filing dated February 25, 2026, and the August 13, 2025 incident date it reports.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyPyramid Advisors Limited Partnership security record
74/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Pyramid Advisors Limited Partnership’s full breach history →

More recent breaches

Boston Health Care for the Homeless Program Data Breach Notice (Oregon Attorney General)September 3, 2026Integrated Specialty Coverages, LLC (“ISC”) Data Breach Notice (Oregon Attorney General)August 27, 2026Wilmer Cutler Pickering Hale and Dorr LLP Data Breach Notice (Oregon Attorney General)August 5, 2026The Moody Bible Institute of Chicago Data Breach Notice (Oregon Attorney General)July 31, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Pyramid Advisors Limited Partnership d/b/a Pyramid Global Hospitality Data Breach Notice (Oregon Attorney General) →

Source: Oregon Department of Justice breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram