Understanding your The Michael Larson Co., PC data breach notification letter
If a The Michael Larson Co., PC letter arrived in your mailbox, here is what it means, why you received it, and the free steps you can take right now.
Why you received this letter
The Michael Larson Co., PC functions as a specialized professional services firm, operating within the legal and financial advisory sector to provide comprehensive counsel, estate planning, corporate governance, and complex tax strategy. Because of the sophisticated nature of their practice, the firm routinely collects, analyzes, and maintains vast repositories of highly sensitive client records. This includes not only corporate financial statements and transactional histories, but also deeply confidential personal information such as Social Security numbers, banking details, asset portfolios, and detailed legal documentation required for high-stakes litigation and financial structuring. In 2026, official disclosures submitted to the Oregon Attorney General revealed that The Michael Larson Co., PC experienced a significant cybersecurity incident compromising their digital infrastructure. While the exact vector of the attack remains under ongoing forensic investigation, breaches affecting legal and professional services firms typically involve sophisticated cybercriminal enterprises executing unauthorized network intrusions, ransomware deployments, or third-party vendor compromises. These threat actors specifically target professional firms because law and accounting practices serve as central hubs for high-value financial data and confidential communications, making their networks prime targets for exploitation and extortion. Preliminary indications suggest that the unauthorized access exposed a devastating array of private information, creating severe, long-term risks for affected individuals. The compromised data fields commonly include full legal names, dates of birth, Social Security numbers, banking account and routing numbers, tax return filings, and confidential legal or financial correspondence. Exposure of this magnitude strips away fundamental privacy protections, leaving victims highly vulnerable to sophisticated identity theft, fraudulent tax filings, unauthorized credit card openings, and targeted financial account takeovers that can take years to detect and resolve. As a custodian of heavily regulated financial and personal data, The Michael Larson Co., PC was legally obligated to implement robust administrative, physical, and technical safeguards to protect client and employee files. Under state data breach notification statutes, common law negligence standards, and applicable federal regulatory frameworks governing professional confidentiality and data security, the firm had a duty to maintain adequate encryption, robust firewall architectures, and comprehensive access controls. The occurrence of a widespread data breach strongly suggests a potential failure to satisfy these foundational security obligations, raising serious questions regarding the adequacy of the firm's defensive posture. Receiving an official data breach notification letter from The Michael Larson Co., PC serves as formal legal admission that your private records were compromised due to corporate negligence. This notification establishes the legal standing necessary to participate in a class action lawsuit aimed at holding the firm accountable for failing to secure your sensitive information. Individuals whose data was exposed do not need to prove that they have already suffered direct financial loss to seek legal recourse; the increased risk of future identity theft and the loss of privacy are actionable damages under the law. Our firm evaluates these cases on a contingency fee basis, ensuring that you pay absolutely nothing out of pocket unless we successfully recover compensation on your behalf.
Information the filing reports as involved
- Full Name
- Social Security Number
- Date of Birth
- Wage and Compensation Information
- Tax Return Information
- Direct Deposit Account Details
- Financial Account Number
- Home Address
What to do after the letter
Confirm the notice is genuine
A legitimate The Michael Larson Co., PC notice references the specific incident reported to the Oregon Attorney General and describes which categories of your information were involved. Compare the letter against the public filing before acting on any links or phone numbers it contains.
Keep the letter — it is your proof of connection
The notification letter is the document that ties your personal information to this incident. Keep the original and photograph it. If you later request a case review, this letter is the strongest evidence that you were among the affected individuals.
Protect your accounts and credit
Depending on what was exposed, consider a free credit freeze with all three bureaus, new passwords for reused credentials, and monitoring of financial statements. These steps are free and do not require you to wait for anyone's permission.
Check the record against the public filing
You can verify the The Michael Larson Co., PC incident against the filing reported to the Oregon Attorney General. This registry summarizes what was filed; it does not provide legal advice.
This page summarizes a data breach reported to the Oregon Attorney General for informational purposes. DataBreachCaseFile.com is a neutral reference registry and does not provide legal advice.