
Carruth Compliance Consulting Data Breach
Carruth Compliance Consulting (Carruth) provides third-party administrative services for 403(b) and 457(b) retirement plans and monitors contribution compliance for employees of public schools and non-profit organizations, including Southern Oregon Education Service District. On January 13, 2025, SOESD was notified by Carruth that it experienced a data security incident. Carruth reported that upon learning of the Incident, they began working with third-party specialists to investigate the activity, and then notified the Federal Bureau of Investigation. An investigation revealed that unauthorized access to Carruthās network had occurred resulting in a compromise of sensitive employee data for Carruthās clients, including SOESD.
Frequently Asked Questions
Am I affected?
This data breach potentially impacts all employees who have been employed by SOESD between 2014 and December of 2024.Ā While Carruth provided third party administrative services for SOESDās 403(b) and 457(b) retirement savings plan, the Districtās original contract with Carruth included options for Carruth to provide services monitoring the Districtās compliance with IRS regulations for all employees. To be on the safe side, we are assuming that all SOESD employees during this time frame have been impacted by this breach, and we encourage everyone to take the steps listed below.
What information was compromised?
The compromised information at Carruth may include employeesā name, Social Security number, dates of birth, and financial account information. In some cases, it could also include driver’s license number, and for those who may have applied for a hardship loan it could include W-2 information, medical billing information (but not medical records), and tax filings. Carruth reported that if you or others provided them with the personal information of your beneficiaries, their information may also have been affected in this Incident.
What is SOESD doing?
SOESD isĀ working with legal counsel and Carruth to understand the full scope of the breach and to ensure they are taking appropriate steps to mitigate the impact on our employees.
We are providing this FAQ and will continue to update it with the latest information as it becomes available.
Since Carruth has refused to send individual notifications to present and former employees, SOESD is working with data privacy experts to send out individual notifications via mail, which is the preferred method to notify impacted staff.Ā Those letters should be sent as soon as possible.
Since Carruth was unable to process employee contributions to 403(b) and 457(b) accounts in January, they are returning all funds, and SOESD is working to then distribute the funding to employee 403(b) and 457(b) accounts.
What can I do?
Enroll in Credit Monitoring and Identity Restoration Services: Carruth is offering free credit monitoring and identity restoration services through IDX. To enroll, please call IDX at 877-720-7895.
Who is IDX?
IDX is a leading data incident response services provider that helps protect people who may be affected by data security incidents. Carruth retained IDX to provide complimentary credit monitoring and identity protection services to our employees and answer questions you may have about the incident.
I am having trouble enrolling with IDX. Is someone from SOESD able to assist me with enrolling in the services provided by IDX?
Each impacted individual must enroll separately in the services provided by IDX. In order to enroll in the services provided by IDX, you must contact IDX at 877-720-7895 and provide them with information they request.
Monitor Your Accounts: Regularly review your bank accounts, credit card statements, and other financial accounts for any suspicious activity. If you see anything unusual, you can report it to your financial institution immediately.
Check Your Credit Reports: You are entitled to one free credit report annually from each of the three major credit reporting bureaus (Equifax, Experian, and TransUnion). Visit www.annualcreditreport.com or call 877-322-8228 to order your free reports.
Consider Placing a Fraud Alert or Credit Freeze on your Credit Report: You can place a fraud alert or credit freeze on your credit report to help protect yourself from identity theft. See details below.
Report Any Suspicious Activity: If you suspect you are a victim of identity theft, report it to the Federal Trade Commission (FTC) at www.identitytheft.gov or 877-ID-THEFT (877-438-4338). You should also file a police report.
Fraud Alerts & Credit Freezes
Fraud Alerts and Credit Freezes
- Fraud Alert: A fraud alert notifies creditors to verify your identity before issuing new credit. You can place an initial fraud alert (lasting one year) or an extended fraud alert (lasting seven years) if you are already a victim of identity theft.
- Credit Freeze: A credit freeze prevents credit bureaus from releasing your credit report without your explicit consent. This makes it harder for identity thieves to open accounts in your name.
How to place a fraud alert or credit freeze, contact the three major credit reporting bureaus
- Equifax:Ā 888-298-0045 or https://www.equifax.com/personal/credit-report-services/
- Experian:Ā 888-397-3742 or https://www.experian.com/help/
- TransUnion:Ā 800-916-8800 or https://www.transunion.com/credit-help
Additional Resource
Federal Trade Commission (FTC): www.identitytheft.gov