Chemeketa Community College staff data exposed in Carruth Compliance breach

Organization
Chemeketa Community College
Exploit
Third-Party Data Breach
Industry
Education

Chemeketa Community College told employees in January 2025 that their personal information had been exposed in a breach at Carruth Compliance Consulting, the Oregon firm that administered the college's 403(b) and 457(b) retirement savings plans.

Carruth said it detected suspicious activity on December 21, 2024 and determined that parts of its network had been accessed without authorization between December 19 and December 26, with files copied from its systems. It began notifying client organizations on January 13, 2025.

Chemeketa said anyone employed by the college between 2008 and January 2025 could be affected, whether or not they took part in a retirement plan, because the college supplied employee records to Carruth for compliance monitoring. Exposed fields could include names, Social Security numbers, dates of birth, mailing and email addresses, compensation and retirement contribution amounts. For people who had dealt with Carruth directly, financial account details, driver's license numbers, W-2 information, medical billing records and tax filings were also potentially involved.

The college said its own systems were not compromised and that it found no evidence of tampering with retirement accounts. It suspended further transactions through Carruth and moved to a different plan administrator. Carruth offered affected individuals free credit monitoring and identity restoration through IDX.

Oregon Public Broadcasting reported that Portland Public Schools, Salem-Keizer, Beaverton and Hillsboro were also affected. Comparitech later counted at least 57 institutions and more than 216,000 people in total, with 7,408 attributed to Chemeketa, and reported that the Skira ransomware group claimed the attack.

Sources