Aldrich Services LLP, an accounting and advisory firm based in Lake Oswego, Oregon, began sending data breach notices on October 1, 2026. The firm says an employee email account was involved.
Aldrich Services LLP’s Data Breach Investigation
Aldrich Services LLP is an accounting and business advisory firm with an office in Lake Oswego, Oregon. In a notice dated October 1, 2026 and filed with the Massachusetts Attorney General, the firm told affected people that it had detected an event involving one of its employee email accounts. It says it moved quickly to secure that account and investigate the activity, notified law enforcement, and is notifying relevant regulators.
The notice does not give the date the unauthorized activity began, the date it was discovered, or the number of people whose information was in the account. It says a review of the potentially affected data identified each recipient’s name together with certain other personal data elements. The filed copy is a sample letter in which that line was left as an unfilled merge field, so the specific categories of information have not been publicly described. We are not guessing at that list.
The firm states that it has no indication of identity theft or fraud as a result of the event. That statement reflects what the firm knew when it wrote the letter, and it does not rule out later misuse. Information taken from an email account can be used long after the original incident, so many people choose to take protective steps even when no misuse has been reported yet.
Aldrich is offering complimentary access to 24 months of credit and identity monitoring through Experian. Because of privacy restrictions, the firm says people must complete the activation process themselves using the instructions and engagement number in their own letter. The enrollment deadline shown in the sample letter is January 29, 2027, and the letter lists a toll-free Experian line for questions.
The firm also says it is reviewing and enhancing its policies and procedures, as appropriate, to limit the chance of a similar event happening again. The notice does not describe what safeguards were in place before the event or what specific changes are planned.
Accounting and tax firms keep a particular kind of record. Client files often include tax returns, identification numbers, bank account details, payroll records and the financial statements of both individuals and businesses. Email accounts at such firms frequently contain attachments sent back and forth with clients, which is why a single compromised mailbox can hold a lot of sensitive information. We do not know which of these kinds of records, if any, were in the affected account.
When names are combined with sensitive identifiers, the main risks include identity theft, fraudulent tax filings, new account applications in someone else’s name, and phishing that references a real accounting relationship. These are general risks tied to this type of incident, not confirmed facts about what happened to any individual’s information.
Email compromises are among the most common ways personal data is exposed at professional services firms. Attackers typically gain access through a stolen or guessed password, a phishing message that tricks an employee into entering credentials, or a login prompt that mimics a real service. Once inside a mailbox, they can search years of messages and attachments, which is why firms often have to review the full contents of an account before they can say who was affected. That review is slow, and it explains why notices frequently arrive well after the underlying event.
The firm has not said how the account was accessed, how long the unauthorized person had access, or whether the information was copied or only viewable. Those details usually matter for assessing risk, and they are the kind of facts that tend to surface later through regulator filings or court documents. Until then, the practical approach is to treat the notice seriously, use the free monitoring offered, and keep copies of every letter and call you make about it.
If you are a current or former client, employee or business contact of the firm, watch for a letter and keep it. We will update this page if Aldrich or a regulator publishes more detail, such as the dates of the event, the data types involved, or the number of people notified.
When Did This Breach Occur?
The notice is dated October 1, 2026. Aldrich Services LLP has not publicly stated when the unauthorized access to the employee email account began or when it was discovered.
What Information Was Breached?
The firm says its review identified each recipient’s name together with certain other personal data elements. The filed sample letter does not list those elements, and the firm has not published a universal list of the categories of information involved.
What You Can Do
If you received a notice from Aldrich Services LLP, consider these steps:
- Enroll in the complimentary 24-month Experian monitoring using the instructions and engagement number in your letter, before the stated deadline.
- Review your bank and card statements and any tax account activity for anything you do not recognize.
- Check your credit reports for free at annualcreditreport.com and consider a fraud alert or credit freeze with Equifax, Experian and TransUnion.
- Consider requesting an IRS Identity Protection PIN, and be cautious of messages that mention your accountant or tax documents.
- Report suspected identity theft to the Federal Trade Commission and your state Attorney General.
File a Data Breach Lawsuit Against Aldrich Services LLP
If you received a notice that your information may have been involved in an Aldrich Services LLP data breach, or you believe your information was put at risk, you may be entitled to compensation. Firms that hold financial records are expected to take reasonable steps to protect them, and people affected by a breach can face a lasting risk of identity theft and fraud.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.