TEAM Software Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
TEAM Software notified the Oregon Attorney General on November 12, 2024 that a data breach affecting 99,525 individuals had occurred. The notification states that personal information was exposed, and affected individuals are advised to review the notice to determine whether their data was involved and what protective steps, if any, are recommended.
TEAM Software notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on November 12, 2024. The filing places the incident itself on July 25, 2024, and states that 99,525 people were affected. Public detail centers on exposure of personal information as described in the breach notification; further technical specifics have not been laid out in the available disclosure.
For people whose data may have been involved, the gap between the July incident date and the November reporting date, together with the scale of the notified population, makes clear why the notice matters even when full forensic detail remains limited.
What happened
According to the Oregon Attorney General–related notice, TEAM Software experienced a data incident dated July 25, 2024. The company later filed notice with the Oregon Department of Justice, with that filing reported on November 12, 2024, and informed Oregon residents. The disclosure identifies 99,525 people as affected and characterizes the exposed material as personal information per the breach notification.
The public record provided here does not describe the intrusion method, whether ransomware or another form of unauthorized access was involved, how long systems were exposed, or which specific systems were touched. No threat actor is named in the facts. Timing of discovery relative to the July 25 date, containment steps, and any law-enforcement involvement are likewise undisclosed in the material available for this account.
How a breach like this happens
Incidents that lead to notices of this kind commonly begin with unauthorized access to corporate networks or cloud environments. Typical entry paths—described here only as general background, not as findings about this case—include compromised credentials, phishing that yields login details, unpatched remote-access services, or misconfigured storage that becomes reachable from the internet. Once inside, an attacker may move laterally, locate databases or file shares holding customer or employee records, and copy data for later use or sale.
Organizations often learn of the event through internal monitoring, unusual outbound traffic, a ransom demand, or notification from a third party. Investigation then focuses on scope: which accounts or systems were reached, what data categories were accessible, and whether the information left the environment. Notification timelines are shaped by state law, the time needed to identify residents, and coordination with regulators. None of these general patterns should be read as a confirmed sequence for the TEAM Software incident; the disclosure simply does not supply that level of technical narrative.
About TEAM Software
TEAM Software provides workforce-management and business software used heavily in the cleaning, janitorial, and facility-services sector. Products in this category typically support scheduling, timekeeping, payroll-related workflows, customer and site management, and related operational data for service contractors and their clients. Companies in this space routinely hold identifying details for employees, contractors, and sometimes end customers or property contacts, because those records are required to run day-to-day operations and billing.
A breach affecting a vendor that sits in the middle of many service businesses can therefore touch a wide population—workers whose pay and identity data flow through the platform, as well as business contacts tied to client sites. The Oregon filing’s count of nearly 100,000 affected individuals underscores that reach even when the full customer base and geographic spread are not itemized in the notice summary.
What data was at risk
The breach notification, as reflected in the Oregon filing summary, names personal information as the category of data exposed. It does not publish a granular inventory—such as whether Social Security numbers, driver’s license data, financial account numbers, dates of birth, or home addresses were included—in the facts provided here.
Organizations that supply workforce and facility-services software commonly maintain names, contact details, employment or contractor identifiers, and other elements needed for payroll, compliance, and site access. Those are the kinds of records that could, in principle, be at risk in an incident of this type. Because the exact field-level contents are not confirmed in the disclosed material, it is accurate only to say that personal information was reported as exposed and that the precise mix remains unconfirmed beyond that description.
The real-world impact
For affected individuals, exposure of personal information raises practical risks of identity theft, targeted phishing, and account takeover attempts that reuse leaked details. Even when full financial credentials are not confirmed as part of a notice, names combined with other identifiers can help fraudsters open new accounts, file false claims, or craft convincing social-engineering messages. People may need to monitor credit reports, place fraud alerts or freezes, and treat unexpected requests for verification with extra caution for an extended period.
For TEAM Software and the service businesses that rely on its platforms, the consequences include notification costs, potential regulatory follow-up, customer and employee inquiries, and the operational work of hardening systems after an incident. Trust in a vendor that holds workforce data can be strained until scope and remediation are clearer. The nearly 100,000-person figure reported in the Oregon filing indicates a material population that may need ongoing vigilance, regardless of whether every person experiences direct fraud.
Were you affected?
If you work in cleaning or facility services, contract through firms that use TEAM Software tools, or otherwise have a relationship that could place your information in the company’s systems, review any notice you received and follow the guidance it contains. Consider monitoring financial and credit activity, enabling multi-factor authentication on important accounts, and being skeptical of unsolicited messages that reference the breach or ask you to “verify” data. You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets, which can help you prioritize password changes and further monitoring.
Public detail on this incident remains limited to the Oregon filing’s core points: an incident dated July 25, 2024, notice activity reported November 12, 2024, 99,525 people affected, and personal information named in the notification. Further clarity, if it becomes available from the company or regulators, should be weighed against those What's Publicly Reported rather than against speculation.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Stiiizy Inc. Data Breach Notice (Oregon Attorney General)Norwex USA, Inc. Data Breach Notice (Oregon Attorney General)American Addiction Centers, Inc. Data Breach Notice (Oregon Attorney General)Oregon Reproductive Medicine, LLC Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.