Confirmed breach. Intrusion Aug 12, 2025–Aug 18, 2025, discovered Aug 22, 2025 — the first regulatory filing landed 229 days later (flagged late). 28,414 individuals reported across the linked filings.
Regulatory clocksWashington✗ WA AG >90dMaine✗ ME AG >90d · 229dVermont✗ VT AG >45 bdayCalifornia✗ CA 60-day late · 229dTexas✗ TX AG >30dOregon✗ OR AG >45dFull clock table in Litigation Timeline
State AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforced
Affected (total reported)
28,414
Data types
—
Jurisdictions
8
CA IN ME NH OR TX VT WA
12days
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
Linked filings
8
all State AG
Affected residents by state
per-filing reported counts
IN28,414
TX916
WA565
OR535
NH163
ME73
VT35
State AGs report only their own residents; bars show per-filing counts.
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
When the intrusion reportedly occurred, per the linked filings
Breach discoveredletter-grounded
Aug 22, 2025
Reported by WASHINGTON AG, MAINE AG, VERMONT AG, CALIFORNIA AG, NEW HAMPSHIRE AG, OREGON AG filings
122 days
Breach discoveredconflicts with Aug 22, 2025AG web form
Dec 22, 2025
Reported by TEXAS AG filing
107 days
8 State AG filingsApr 8, 2026 – Apr 20, 2026ExpandCollapse
WAMECANHINVTTXOR
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
OneDigital Investment Advisors LLC, a finance sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2025-08-22 and filed notice on 2026-04-08. 565 Washington residents were affected. 229 days elapsed between awareness and notification. 10 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 565
WA AG >90d
🦞Maine State AGlinked via multistate filing link · 100%
Aug 12-18, 2025: unauthorized actor accessed and copied OneDigital data in Salesforce via compromise of Drift app (Salesloft). OneDigital notified Aug 22, 2025. Data involved: name and SSN. 73 of 28,414 total affected are Maine residents. Notices mailed Apr 8, 2026. Experian credit monitoring (12 months) offered.
Affected (this filing): 73
ME AG >90d · 229dME resident >180d · 229d
🐻California State AGlinked via multistate filing link · 100%
OneDigital Investment Advisors LLC notified customers of a data security event involving a third-party application. Between August 12-18, 2025, an unauthorized actor potentially accessed and copied customer data stored in Salesforce due to a compromise of the Drift application (managed by Salesloft). OneDigital was notified by Salesforce on August 22, 2025. The incident did not involve a compromise of OneDigital's internal network. Affected data includes names and other personal information. OneDigital engaged forensic specialists, confirmed system security, and is offering credit monitoring.
CA 60-day late · 229dCA AG copy ≤15d · 0d
⛰️New Hampshire State AGlinked via multistate filing link · 95%
OneDigital Investment Advisors LLC notified the New Hampshire Attorney General of a data event involving its third-party vendors, Salesforce and Salesloft (Drift). Between August 12-18, 2025, an unauthorized actor accessed and copied customer data (names and SSNs) from the Drift application. Approximately 163 New Hampshire residents were affected. OneDigital engaged forensic specialists, notified regulators, and provided 12 months of credit monitoring via Experian. The incident did not compromise OneDigital's internal network.
Affected (this filing): 163
🏎️Indiana State AGlinked via multistate filing link · 95%
OneDigital Investment Advisors LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2025-08-12 and was reported on 2026-04-08. 96 Indiana residents were affected. 28,414 individuals affected in total.
Affected (this filing): 28,414
🍁Vermont State AGlinked via multistate filing link · 95%
OneDigital Investment Advisors LLC notified Vermont AG that a third-party CRM provider (Salesforce/Drift) was compromised between Aug 12-18, 2025. Data accessed included names, SSNs, and ITINs. 35 Vermont residents notified on Apr 8, 2026. Credit monitoring offered.
Affected (this filing): 35
VT AG >45 bday
⭐Texas State AGlinked via operator-confirmed · 100%
OneDigital Investment Advisors LLC based in Atlanta, Georgia, a financial services entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-12-22 and reported on 2026-04-10. 916 Texas residents were affected. 28,414 individuals affected in total. Types of information involved: Social Security Number Information;Financial Information (e.g. account number, credit or debit card number). Consumers were notified via U.S. Mail.
OneDigital Investment Advisors LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2026-04-20. The breach occurred during 8/12/2025 - 8/18/2025. The breach was discovered on 8/22/2025. 535 individuals were affected. Notice was sent on 4/8/2026.