City of McMinnville Data Breach Lawsuit Investigation

Active investigation · Free, confidential case review
Call (954) 799-5914
Data Breaches / City of McMinnville
Active investigation Data breach · Municipal Government Notices mailed Sep 29, 2026

Received a September 2026 breach notice from City of McMinnville?

Dapeer Law, P.A. is investigating a potential class action against the City of McMinnville, Oregon, on behalf of residents, employees, and other individuals whose personal information may have been accessed and copied in the June to July 2026 network intrusion affecting the City's systems.

Submit your claim → See what to do No fee unless we recover for you
Breach window
Jun 1 to Jul 18, 2026
Unauthorized network access
Notification delay
About 2.5 months
Discovered Jul 2026, notices Sep 2026
Credit monitoring
12 months
Through Cyberscout (TransUnion)
Eligibility

Who may qualify

You may be eligible to participate in a class action if any of the following applies:

  • You received a data breach notification letter from City of McMinnville dated September 2026.
  • Your letter offered enrollment in 12 months of free Cyberscout single-bureau credit monitoring (a TransUnion company).
  • You had personal or financial information held by the City of McMinnville in its capacity as a municipal government, for example as a resident, utility customer, or current or former City employee.
  • No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
  • Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.

Not sure if you qualify?

Send us your notice, we'll confirm your eligibility at no cost.

Check eligibility →
Background

What happened

On or about July 15, 2026, the City of McMinnville, Oregon became aware of unusual activity in its network environment. According to the notice letter the City filed with the California Attorney General, an investigation determined that an unauthorized party accessed the City's network between June 1 and July 18, 2026, and that certain information may have been accessed and copied without authorization during that period. In early August 2026, ransomware-tracking sites reported that the RansomHouse group had listed the City of McMinnville on its leak site; the City's notice does not name the group responsible.

The City completed its review of the affected data on September 22, 2026, and its notice was posted by the California Attorney General on September 29, 2026, roughly two and a half months after the intrusion was discovered. The letter states that the impacted information varied by individual and lists each recipient's specific data elements in that person's own letter, so the public notice does not itemize the categories involved. The City is offering 12 months of Single Bureau Credit Monitoring, Credit Report, and Credit Score services through Cyberscout, a TransUnion company, at no charge. The total number of people affected has not been publicly disclosed. Exactly which data elements were taken, whether the City's security controls met reasonable standards, and why notification took more than two months are among the issues being evaluated.

Municipal governments hold a wide range of sensitive records about residents and employees, including identity, payroll, tax, utility billing, and public-service records. When that information is copied by an unauthorized party, particularly in an incident linked to a ransomware group with a public leak site, affected individuals can face an elevated risk of identity theft, financial fraud, and targeted phishing. Recipients should read their letter carefully for the specific categories of information listed for them.

Network intrusion Data copied Municipal government Oregon RansomHouse claim California AG filing
Action plan

What to do if you received a letter

1

Keep your notice letter

Do not discard your City of McMinnville breach notice. The letter lists the specific categories of your information that were involved, contains your Cyberscout activation code, and is important evidence if you decide to participate in a lawsuit.

2

Enroll in the free 12-month credit monitoring

Enroll in the Cyberscout (TransUnion) single-bureau credit monitoring offered in your letter at bfs.cyberscout.com/activate within 90 days of the date of your letter, using the unique code in the letter. Accepting this benefit does not waive your right to pursue legal action.

3

Place a fraud alert or credit freeze

Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide. Also review your bank, credit-card, and City utility statements for unfamiliar transactions.

4

Speak with a data breach attorney

Consultations with Dapeer Law are free and confidential. We'll review your City of McMinnville notice, explain your options, and advise whether you may be eligible to join a class action.

Submit your notice for a free review

Two minutes online. A licensed attorney reviews every submission.

Submit your claim →
Timeline

Breach timeline

Jun 1 to Jul 18, 2026 Passed
Unauthorized access to City of McMinnville network
Jul 15, 2026 Passed
City becomes aware of unusual network activity
Aug 2026 Passed
RansomHouse group reportedly lists the City on its leak site
Sep 22, 2026 Passed
Review of affected data completed
Sep 29, 2026 Passed
Notice posted by California Attorney General
Pending Active
Potential class action filing
Statutes of limitations vary by state and legal theory, typically one to six years. Waiting can permanently bar your claim.
Possible recovery

Compensation you may be entitled to

Out-of-pocket expenses

Credit freezes, identity restoration services, and other costs incurred responding to the breach.

Time spent monitoring

Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.

Identity theft & fraud losses

Unreimbursed funds stolen from accounts, unauthorized credit lines, or tax refund fraud tied to the breach.

Statutory damages

Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.

Injunctive relief

Court orders requiring the City of McMinnville to implement stronger data-security practices going forward, including improved network monitoring, faster breach-notification timelines, and ongoing third-party security testing.

Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.

FAQ

Common questions

I received a data breach letter from City of McMinnville. What should I do? +

Keep your City of McMinnville notice letter, enroll in the free 12-month Cyberscout (TransUnion) credit monitoring at bfs.cyberscout.com/activate within 90 days of your letter's date, place a free fraud alert or security freeze with the three nationwide credit bureaus, review your bank, credit-card, and utility statements for unfamiliar activity, document any time or money you spend responding to the breach, and consider speaking with a data breach attorney about your legal options.

Am I eligible to join a class action against City of McMinnville? +

If you received a data breach notice from the City of McMinnville in 2026, you are likely a candidate for a free case evaluation. Eligibility for any future legal action will also depend on your state of residence, the categories of your data listed in your letter, and any documented losses or out-of-pocket expenses, including time spent responding to identity-theft concerns.

How much money could I receive from a class action lawsuit? +

Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.

What personal information was exposed in the breach? +

The City's public notice states that the impacted information varied by individual and does not list the categories involved. Each recipient's letter identifies the specific data elements tied to that person's records. Because municipal systems can hold identity, payroll, tax, and utility billing records, review your own letter carefully to see what was listed for you.

Did City of McMinnville offer free credit monitoring? +

Yes. The City is offering 12 months of Single Bureau Credit Monitoring, Credit Report, and Credit Score services through Cyberscout, a TransUnion company, at no charge. You must enroll at bfs.cyberscout.com/activate within 90 days of the date of your letter using the activation code it contains. Enrolling does not waive your right to pursue legal claims.

How many people were affected by the City of McMinnville breach? +

The City has not publicly disclosed the total number of people affected. The notice states that 8 Rhode Island residents were involved, which reflects only one state's count. This page will be updated as more information becomes available.

Is there a deadline to take legal action? +

Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.

How do I get a copy of the official breach notice? +

A copy of the City of McMinnville's notice letter is available through the California Attorney General's data breach website, linked in the Sources & References section below. If you received a letter but no longer have it, Dapeer Law can help you obtain a copy as part of a free consultation.

References

Sources & references

Attorney advertising. This page is provided for informational purposes only. It does not constitute legal advice or form an attorney-client relationship. Dapeer Law, P.A. is not affiliated with City of McMinnville, Oregon, Cyberscout, or any credit bureau. Prior results do not guarantee a similar outcome. All information regarding the data incident is drawn from the official notification filed with California Attorney General on September 29, 2026.
Free, confidential case review

Don't let the deadline decide for you. Submit your claim today.

You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.

Why Dapeer Law

Practice focusConsumer class actions
Licensed inFL · NY · NJ · IL
Case review fee$0
Response timeSame business day
Free case review
Confidential · 2 minutes
Submit claim →
Previous
Previous

Poppins Payroll Data Breach Lawsuit Investigation

Next
Next

Nishiyamato Academy of California Data Breach Lawsuit Investigation