If you were affected, free legal review is available — no obligation.
Learn how to participate in the class action and what compensation you may be entitled to.
Join the Class Action →Use our verification tool to confirm your letter matches this official AG filing.
Verify My Notice LetterThis case file references a public filing made with the state filing in OR. This website is not affiliated with, endorsed by, or operated by any state government agency.
Avery Products Corporation was the subject of a data breach notification filed with the OR Attorney General. The AG filing was recorded on January 16, 2025. The breach or discovery date reported in the filing is July 18, 2024.
From the AG filing description
Avery Products Corporation is a globally recognized manufacturer and distributor of office supplies, labeling solutions, and software platforms utilized by millions of businesses, educational institutions, and individual consumers. Operating at the intersection of consumer goods and digital technology, the company collects and maintains vast repositories of sensitive data. This includes extensive corporate accounts, business-to-business vendor information, employee records, and data submitted through digital customization platforms and online accounts. Because Avery serves as a staple in supply chains and administrative workflows across the country, its digital ecosystem is a massive repository of proprietary and personally identifiable information, making it an attractive target for malicious cyber actors seeking high-value institutional and consumer data. In 2025, Avery Products Corporation reported a significant security incident to the Oregon Attorney General, joining a growing number of corporate entities facing sophisticated cyber attacks. While the exact vector of the breach continues to be evaluated through ongoing forensic investigations, incidents affecting manufacturing and consumer-facing technology conglomerates typically involve unauthorized access to internal enterprise networks, compromised employee credentials, or vulnerabilities within third-party vendor software supply chains. Modern cybercriminals frequently deploy targeted malware and ransomware to infiltrate corporate servers, bypassing legacy perimeter defenses to exfiltrate confidential files before security teams can detect or contain the intrusion. The data compromised in the Avery Products Corporation security incident exposes victims to severe, long-term risks of identity theft and financial fraud. Depending on the nature of the specific compromised database, exposed records may include full legal names, physical and email addresses, telephone numbers, account credentials, and potentially sensitive corporate or financial documentation. When cybercriminals obtain this combination of personal identifiers, victims face heightened threats of targeted phishing schemes, unauthorized account takeovers, fraudulent credit applications opened in their names, and synthetic identity fraud. The exposure of business account data further risks corporate espionage and supply chain vulnerabilities, leaving affected individuals and entities to bear the administrative and financial burden of monitoring their identities and accounts for years to come. As a commercial entity entrusted with sensitive personal and business data, Avery Products Corporation was bound by strict legal and regulatory obligations to secure its digital infrastructure under state data protection statutes, including the Oregon Consumer Identity Theft Protection Act, and applicable common law standards of care. These legal frameworks mandate that companies implement robust administrative, technical, and physical safeguards—such as multi-factor authentication, endpoint detection and response systems, network segmentation, and regular vulnerability assessments—to protect consumer and employee data. The occurrence of a widespread data breach strongly suggests a failure in these fundamental security protocols, raising serious questions regarding whether Avery satisfied its legal duty of care to protect the confidential information entrusted to its systems. Receiving a data breach notification letter from Avery Products Corporation is not merely an administrative inconvenience; it is a formal acknowledgment by the company that your confidential information was compromised due to inadequate security measures. Legally, this notification establishes the standing necessary to participate in a class action lawsuit aimed at holding Avery accountable for failing to safeguard your data. Plaintiffs in these actions seek compensation for out-of-pocket losses, the cost of credit monitoring services, and the lost time spent mitigating identity theft risks, all without needing to prove that financial loss has already occurred. Our firm investigates these data breach matters on a strict contingency fee basis, meaning you pay no upfront costs or out-of-pocket legal fees, and we only recover compensation if we successfully secure a recovery on your behalf.
Under the Oregon Consumer Information Protection Act, you may have a legal claim against Avery Products Corporation if any of the following apply:
Common categories of compensation in data breach class actions
Courts recognize that the time spent monitoring accounts, placing credit freezes, and dealing with the aftermath of a breach has real economic value. This category of damages is recoverable even without direct financial loss.
Direct financial losses resulting from the breach — unauthorized charges, fraudulent transfers, or fees incurred through fraud — are recoverable as compensatory damages. Banks may reverse some charges; a class action recovers the remainder and associated costs.
When login credentials are exposed, the costs of downstream account compromises — password managers, security audits, and recovery costs for hijacked downstream accounts — can be recovered. Courts in recent class actions have awarded damages for credential exposure even without proven misuse.
Several state data breach laws provide for statutory minimum damages — fixed amounts recoverable per affected individual regardless of actual loss. These provisions exist specifically to make legal action viable for victims who have not yet experienced direct harm.
Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.
No. Under Oregon Consumer Information Protection Act and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.
Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.
Banks may reverse fraudulent charges, but they are not obligated to compensate you for time lost, stress, or indirect damages. A class action claim against the breached company can recover those additional categories of harm.
Statutes of limitations for data breach claims vary by state but typically run 2–4 years. Depending on when you learned of the breach, you may still have time. Contact our office for a free eligibility review — there is no cost to find out.
Accepting free credit monitoring from Avery Products Corporation does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.
Not necessarily. Many data breach victims are never notified directly. If your personal information was held by Avery Products Corporation during the relevant period, you may still qualify even without receiving a letter. A free eligibility review can confirm your status.
Most data breach class actions resolve within 18 to 36 months, though timelines vary by court and complexity. Your participation requires minimal effort — typically completing a claim form. Our office handles all litigation; you are notified when a settlement is reached.
Applicable State Law
This breach was reported under the Oregon Consumer Information Protection Act, which mandates notification and establishes your right to seek damages.
Avery Products Corporation breach?
Free case review · No fee unless you win