Were you recently affected by a data breach?

Opportune LLP Data Breach

Opportune LLP, a vendor providing royalty payment services to oil and gas companies including Phillips 66, discovered a cybersecurity incident where an unauthorized actor accessed its network, exposing personal information of royalty interest owners. The company is offering complimentary credit monitoring to affected individuals.

Opportune LLP
Date of Breach: On or about June 22, 2026
CAU logo

Who was affected:

Clients of Opportune LLP

Impacted Data:

Full name in combination with other personal information (specific data elements not publicly disclosed)

Opportune LLP, a business advisory and vendor services firm serving the oil and gas industry, recently notified individuals that a cybersecurity incident may have exposed their personal information. Opportune LP, a subsidiary of Opportune LLP, provides royalty interest payment and accounting services on behalf of energy companies, including Phillips 66, which is how it came to hold the personal data of royalty interest owners.

Companies that are trusted with sensitive financial and identifying information, even as third-party vendors rather than direct customers, have a responsibility to protect that data from unauthorized access.

Opportune LLP’s Data Breach Investigation

According to a notification letter filed with the California Attorney General, Opportune LLP determined that an unauthorized actor gained access to its network environment as part of a cybersecurity incident. Once the issue was discovered, Opportune worked to contain the threat, secure its internal systems, and launch an investigation with the assistance of outside cybersecurity professionals. The company has stated that after an extensive forensic investigation and a complex manual document review, it determined that systems initially accessed on or about June 22, 2026, contained personal information belonging to individuals whose data Opportune LP had received in the course of facilitating royalty interest payments for its energy-industry clients.

Opportune has not published a public estimate of how many individuals nationwide were affected by this incident, though the notification was filed with California’s Attorney General as required by the state’s data breach notification law, which generally requires notice once an incident is determined to affect a threshold number of state residents. The public version of Opportune’s notification letter redacts the specific combination of personal data elements involved for the individual recipient, a practice common in sample notices filed with state regulators to protect the very information the letter describes without disclosing exactly what was compromised for any one person.

Third-party vendors that process financial and identifying information on behalf of other companies, such as Opportune’s role in administering royalty interest payments for the oil and gas industry, are an increasingly common target for cybercriminals. Vendors of this kind often hold large volumes of sensitive information belonging to people who have no direct relationship with the vendor itself and may not even be aware that the vendor holds their data at all, which can make it harder for affected individuals to learn that they are impacted until a formal notification arrives. This is part of why data breach notification laws exist, so that people are informed even when the entity that suffered the breach is not the company they directly do business with.

Breaches involving vendors that handle royalty, payment, or accounting information carry particular risk because the exposed data frequently includes the kind of identifying information used to open new accounts or redirect payments, including full names in combination with financial or identifying details. When a bad actor gains unauthorized access to a network like this, the resulting exposure can enable identity theft, account takeover, or fraudulent redirection of payments the affected individual was legitimately owed.

Opportune’s timeline shows a gap of roughly two months between when its systems were first accessed, on or about June 22, 2026, and when the company determined, on August 18, 2026, that personal information had actually been involved. This kind of delay between initial unauthorized access and a final determination of what data was compromised is common in incidents that require a detailed forensic review and manual document analysis, since simply confirming that a network was accessed does not tell an investigator, on its own, which specific files or records were exposed.

In the meantime, Opportune has stated that it is not aware of any actual misuse of affected individuals’ information as a direct result of this incident, but is nonetheless offering complimentary credit monitoring services out of an abundance of caution. Individuals who receive a notification letter from Opportune should take it seriously regardless of whether they have noticed any suspicious activity yet, since identity thieves do not always act immediately after obtaining stolen data.

Royalty interest payments are a common part of the energy industry, where mineral rights owners and landowners receive periodic payments tied to oil and gas production on their property, and the vendors that administer those payments necessarily collect the payee’s name, address, tax identification information, and banking details in order to process the payment. That combination of information, if exposed, can be attractive to fraudsters attempting to redirect future royalty payments or open new accounts in the payee’s name, which is part of why prompt notification and credit monitoring are standard responses to an incident like this one.

When Did This Breach Occur?

Opportune has stated that its network was accessed on or about June 22, 2026. The company did not discover that personal information had been compromised until August 18, 2026, after a forensic investigation and a detailed manual document review determined which records had actually been affected. Opportune sent notification letters to affected individuals and reported the incident to the California Attorney General’s office, as required under state law.

What Information Was Breached?

Opportune’s notification letter states that the information involved included the recipient’s full name in combination with certain other personal data elements specific to that individual. The publicly filed version of the notice does not disclose a single universal list of data categories affecting every recipient, since the specific combination of information exposed appears to have varied by individual. Opportune is offering affected individuals complimentary credit monitoring services as a precaution.

What You Can Do

If you received a notification letter from Opportune, consider taking the following steps:

  • Enroll in the complimentary credit monitoring service Opportune is offering, if eligible
  • Place a fraud alert or security freeze on your credit files with Equifax, Experian, and TransUnion
  • Review your financial account statements and credit reports regularly for unfamiliar activity
  • Report any suspicious activity to your local law enforcement agency and file a police report if needed
  • File a complaint with the Federal Trade Commission at identitytheft.gov if you believe your information has been misused

File a Data Breach Lawsuit Against Opportune LLP

If your personal information was exposed as a result of this incident and you have experienced identity theft, fraud, or other harm, you may have legal options.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Reported incident occurred July 31, 2026; notification sent September 18, 2026
Date of Breach: Alleged incident reported to have occurred August 28, 2026; publicly reported September 17, 2026
Date of Breach: Reported to the Vermont Attorney General's Office on September 18, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.