DataBreachPayment.com
MonitoringOregon AG filing · March 18, 2026

The The Michael Larson Co., PC Data Breach: Incident Facts and Free Case Review

The Michael Larson Co., PC functions as a specialized professional services firm, operating within the legal and financial advisory sector to provide comprehensive counsel, estate planning, corporate governance, and complex tax strategy. Because of the sophisticated nature of their practice, the firm routinely collects, analyzes, and maintains vast repositories of highly sensitive client records. This includes not only corporate financial statements and transactional histories, but also deeply confidential personal information such as Social Security numbers, banking details, asset portfolios, and detailed legal documentation required for high-stakes litigation and financial structuring.

Received a The Michael Larson Co., PC notification letter? Find out in minutes if you qualify for compensation.

Free case review
State
Oregon
Breach date
January 29, 2026
Reported
March 18, 2026

What may have been exposed

  • Full Name
  • Social Security Number
  • Date of Birth
  • Wage and Compensation Information
  • Tax Return Information
  • Direct Deposit Account Details
  • Financial Account Number
  • Home Address

In 2026, official disclosures submitted to the Oregon Attorney General revealed that The Michael Larson Co., PC experienced a significant cybersecurity incident compromising their digital infrastructure. While the exact vector of the attack remains under ongoing forensic investigation, breaches affecting legal and professional services firms typically involve sophisticated cybercriminal enterprises executing unauthorized network intrusions, ransomware deployments, or third-party vendor compromises. These threat actors specifically target professional firms because law and accounting practices serve as central hubs for high-value financial data and confidential communications, making their networks prime targets for exploitation and extortion.

Preliminary indications suggest that the unauthorized access exposed a devastating array of private information, creating severe, long-term risks for affected individuals. The compromised data fields commonly include full legal names, dates of birth, Social Security numbers, banking account and routing numbers, tax return filings, and confidential legal or financial correspondence. Exposure of this magnitude strips away fundamental privacy protections, leaving victims highly vulnerable to sophisticated identity theft, fraudulent tax filings, unauthorized credit card openings, and targeted financial account takeovers that can take years to detect and resolve.

As a custodian of heavily regulated financial and personal data, The Michael Larson Co., PC was legally obligated to implement robust administrative, physical, and technical safeguards to protect client and employee files. Under state data breach notification statutes, common law negligence standards, and applicable federal regulatory frameworks governing professional confidentiality and data security, the firm had a duty to maintain adequate encryption, robust firewall architectures, and comprehensive access controls. The occurrence of a widespread data breach strongly suggests a potential failure to satisfy these foundational security obligations, raising serious questions regarding the adequacy of the firm's defensive posture.

Receiving an official data breach notification letter from The Michael Larson Co., PC serves as formal legal admission that your private records were compromised due to corporate negligence. This notification establishes the legal standing necessary to participate in a class action lawsuit aimed at holding the firm accountable for failing to secure your sensitive information. Individuals whose data was exposed do not need to prove that they have already suffered direct financial loss to seek legal recourse; the increased risk of future identity theft and the loss of privacy are actionable damages under the law. Our firm evaluates these cases on a contingency fee basis, ensuring that you pay absolutely nothing out of pocket unless we successfully recover compensation on your behalf.

Received the The Michael Larson Co., PC notification letter? The The Michael Larson Co., PC case file tracks this filing.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Guard against tax fraud

    File your tax return as early as possible and consider requesting an IRS Identity Protection PIN so no one can file a fraudulent return in your name.

  • Watch your financial accounts

    Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: Oregon Attorney General filing

Related data breach cases