RB American Group LLC Reports Employee Data Breach in Oregon
RB American Group LLC confirmed a data security incident, detected on April 8, 2026, which led to the exposure of sensitive employee information. The breach, reported on August 28, 2026, impacts individuals whose Full Name, Social Security Number, and other personal data were compromised, raising concerns about potential identity theft and financial fraud.
- State
- Oregon
- Breach date
- April 8, 2026
- Reported
- August 28, 2026
What may have been exposed
- Full Name
- Social Security Number
- Date of Birth
- Mailing Address
- Wage and Compensation Information
- Tax Return Information
- Direct Deposit Account Details
- Phone Number
RB American Group LLC, operating within the hospitality and restaurant sectors, identified a data security incident affecting its systems on April 8, 2026. The company officially reported this breach on August 28, 2026, acknowledging that unauthorized parties may have accessed sensitive employee data.
The compromised information includes Full Name, Social Security Number, Date of Birth, Mailing Address, Wage and Compensation Information, Tax Return Information, Direct Deposit Account Details, and Phone Number. The exposure of these core identifiers and financial details presents a significant risk for affected individuals, potentially leading to identity theft, financial fraud, and unauthorized access to personal accounts.
Individuals who receive notification from RB American Group LLC should remain vigilant. It is strongly recommended to monitor credit reports for any suspicious activity, place fraud alerts with credit bureaus, and review financial account statements regularly. Activating any offered credit monitoring services is also a prudent step to help detect and prevent potential misuse of exposed data.
This documentation of the RB American Group LLC data breach is based on information provided in official regulatory filings made by the company. These public records detail the scope of the incident and the categories of personal data that were compromised, serving as a transparent accounting of the event for affected parties and the public.
Source: Oregon Attorney General filing