OneMain Financial Group, LLC, one of the country’s largest consumer installment lenders, has notified the Texas Attorney General that 15,472 Texas customers’ names, addresses, and Social Security numbers were exposed in a data breach — but the company’s filing doesn’t say how the breach happened or when.
OneMain Financial Group, LLC, a subsidiary of OneMain Holdings, Inc. and one of the largest consumer installment lenders in the country, filed a data breach report with the Texas Attorney General on September 25, 2026. According to that filing, 15,472 Texas residents had their names, addresses, and Social Security numbers affected, and notice was sent by U.S. mail. The filing does not disclose when the breach occurred, when OneMain discovered it, or how the intrusion happened — details that are notably absent given the scale of the filing.
Source: Texas Attorney General data security breach report, published 09/25/2026.
What Information Was Exposed
The Texas filing confirms that affected customers’ names, addresses, and Social Security numbers were involved. Social Security numbers are among the most sensitive categories of personal information a company can expose — they’re difficult or impossible to change and can be used to open new credit accounts, file fraudulent tax returns, or commit other forms of identity theft for years after a breach.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
A Notably Thin Public Filing
What’s unusual about this breach is how little OneMain has disclosed. The Texas filing gives a population count and a data-type list, but nothing about when the breach happened, how OneMain discovered it, or how long the gap was between discovery and notice. For a national lender with customers well beyond Texas, that also raises an obvious question: how many people outside Texas were affected? Texas requires public reporting once a threshold number of state residents is affected; OneMain’s presence in nearly every state means the true number of affected customers could be considerably larger than 15,472.
Not to Be Confused With OneMain’s 2022 Breach
OneMain previously disclosed a separate data breach involving California customers tied to a 2022 incident. This is a new and different matter — the Texas filing reflects a breach reported in September 2026, and nothing in the public record ties it to the earlier 2022 incident.
What You Can Do Now
- If you’re a OneMain Financial customer, especially in Texas, watch for a notice letter and enroll in any credit monitoring services offered
- Place a fraud alert or credit freeze with the three major credit bureaus, given that Social Security numbers were confirmed exposed
- Monitor your credit reports and financial accounts closely for unauthorized activity or new accounts you didn’t open
- Watch for phishing attempts referencing OneMain Financial or your loan account
- Contact us for a free case review if you received a notice letter from OneMain, or if you’re a OneMain customer concerned about this breach
Do You Have Legal Options?
Consumer lenders that collect Social Security numbers as part of the loan application and underwriting process have a legal duty to secure that information. If you’re a OneMain Financial customer whose information was exposed, you may have legal options.
If you received a data breach notice from OneMain Financial, contact Emery | Reddy today for a free case review.
FAQ
What information was exposed in the OneMain Financial breach?
OneMain’s Texas regulatory filing confirms names, addresses, and Social Security numbers of 15,472 Texas residents were affected.
How many people are affected nationally?
OneMain has only disclosed the Texas figure of 15,472. Given that OneMain operates branches in most U.S. states, the true national number is likely higher, but no national total has been released.
When did the breach happen?
OneMain’s public filing does not disclose when the breach occurred, when it was discovered, or how it happened.
Is this related to OneMain’s 2022 data breach?
No. OneMain previously disclosed a separate breach involving California residents tied to a 2022 incident. This is a new matter reported in September 2026, with no stated connection to the earlier breach.
Do I have a legal claim?
Consumer lenders have a legal duty to protect the Social Security numbers and personal information they collect from customers. If you’re a OneMain Financial customer and received a notice letter, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.