LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › The Michael Larson Co., PC Data Breach Notice (Oregon Attorney General)

MEDIUM severityConfirmedHow we verify

The Michael Larson Co., PC Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·March 18, 2026
The Michael Larson Co., PC Data Breach Notice (Oregon Attorney General)

Occurred January 29, 2026 · publicly disclosed March 18, 2026. Approximately 250 people affected.

MEDIUM
Severity
250
People affected
1
Data types exposed
March 18, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Michael Larson Co., PC Data Breach Notice was disclosed to the Oregon Attorney General on March 18, 2026, after the breach occurred on January 29, 2026. Anyone who may have been among the 250 individuals whose personal information was exposed should review the notice and take any recommended protective steps.

Severity & verification
MEDIUM severityConfirmed
Data types not itemised.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
250 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Organizations that hold client records continue to face steady pressure from opportunistic cybercrime, phishing, and compromised credentials, even when they are small professional firms rather than large enterprises. Notices filed with state attorneys general remain one of the clearest public signals that personal data may have been exposed.

The Michael Larson Co., PC notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on March 18, 2026. That filing places the incident itself on January 29, 2026, and states that 250 people were affected. The notice describes exposure of personal information. Exact technical details of how the incident unfolded are not set out in the public summary available here, so the picture remains limited to what the company reported to the state.

What happened

According to the Oregon Attorney General filing, The Michael Larson Co., PC experienced a data incident on January 29, 2026. The firm later submitted a breach notice that was reported on March 18, 2026. The filing indicates that 250 individuals were affected and that personal information was involved, consistent with the breach notification language used in the report.

Public detail beyond those points is limited. The available summary does not describe the attack method, whether systems were encrypted or data was exfiltrated, how long unauthorized access lasted, or which specific systems were involved. No threat actor is named in the disclosure. Readers should treat only the dated filing, the affected-person count, and the stated category of personal information as confirmed from the notice itself.

How a breach like this happens

Incidents affecting professional services firms often follow familiar patterns, even when a particular case does not spell out the path taken. Attackers commonly gain an initial foothold through phishing email, reused or weak passwords, remote-access tools left exposed, or malware on a workstation that later reaches shared file storage or practice-management systems.

Once inside, an intruder may search for client lists, tax or accounting workpapers, identity documents, or backup copies. In some cases the goal is quiet theft of data for later fraud; in others it is ransomware that locks systems and pressures the organization to pay. Small and mid-size practices can be attractive targets because they hold concentrated personal and financial records yet may have fewer dedicated security staff than large corporations. None of this assigns a specific technique to the January 2026 event at The Michael Larson Co., PC; it only describes how breaches of this general type typically unfold when method is undisclosed.

Who is The Michael Larson Co., PC?

The Michael Larson Co., PC is a professional corporation. Firms structured this way commonly provide accounting, tax, bookkeeping, or related advisory services to individuals and businesses. Organizations in that sector routinely collect and retain names, addresses, Social Security numbers or taxpayer identification numbers, financial account details, income information, and correspondence needed to prepare returns or advise clients.

A breach at such a firm is consequential because the data is often sufficient to support tax-related identity theft, fraudulent filings, or account takeover. Even a relatively small affected population—here reported as 250 people—can face lasting administrative burden if identifiers and financial details were exposed. The Oregon filing shows the firm took the step of notifying residents and the state regulator, which is the formal channel many U.S. states require when personal information of residents may have been compromised.

What data was at risk

The breach notification, as reflected in the Oregon report, names personal information as the category of data involved. It does not itemize every field in the public summary provided here. For a professional services firm of this kind, personal information in client files often includes contact details, government identifiers, and financial or tax-related records; however, the exact contents of what was accessed or acquired in this incident remain unconfirmed beyond the broad label in the notice.

No public figure is given in the facts for the volume of files, specific document types, or whether data was viewed, copied, or only potentially accessible. Anyone who received a direct notice from the firm should rely on that letter for the description of their own information.

The real-world impact

For affected individuals, the practical risks center on misuse of personal information: attempts to open credit, file fraudulent tax returns, or socially engineer banks and agencies using accurate identity details. Monitoring credit reports, watching for unexpected IRS or state tax correspondence, and treating unsolicited requests for further personal data with caution are standard responses after this kind of notice.

For the organization, consequences can include notification costs, regulatory follow-up, possible credit-monitoring offers, reputational strain with clients, and the operational work of investigating and securing systems. The filing does not state whether the firm offered specific remedies, and no dollar amounts or findings of fault appear in the facts. Impact should be understood as potential rather than as proven fraud against every person counted in the 250 figure.

Were you affected?

If you are a client or former client of The Michael Larson Co., PC and you receive an official breach letter, read it carefully for the date of the incident, the description of your data, and any support the firm is offering. Even without a letter, people who shared personal or tax information with the firm around the relevant period may wish to take basic protective steps.

Public reporting on this matter rests on the Oregon Department of Justice filing dated March 18, 2026, for an incident dated January 29, 2026, affecting 250 people and involving personal information as described in the company’s notice. Further technical or forensic detail has not been included in the summary available for this article.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyThe Michael Larson Co., PC security record
74/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See The Michael Larson Co., PC’s full breach history →

More recent breaches

ASOS US Sales LLC Data Breach Notice (Oregon Attorney General)September 9, 2026BestCare treatment Services, Inc. Data Breach Notice (Oregon Attorney General)September 8, 2026Boston Health Care for the Homeless Program Data Breach Notice (Oregon Attorney General)September 3, 2026American Addiction Centers Data Breach Notice (Oregon Attorney General)September 3, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the The Michael Larson Co., PC Data Breach Notice (Oregon Attorney General) →

Source: Oregon Department of Justice breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram