OneMain Financial Group data breach (2026): what was exposed and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
OneMain Financial Group’s Texas breach report, published September 25, 2026, lists 15,472 affected Texas residents, names, addresses and Social Security information. The register says consumers were notified by U.S. mail. It does not establish a nationwide total.
What is known, and what is still missing
The primary Texas listing does not state the incident date, discovery date or access method. This summary therefore does not assign an attack method or combine dates from separate law-firm reports with the official filing.
The three named data categories do not mean every OneMain customer was involved. Your mailed letter should identify the information that applied to you and any monitoring offer. Keep it and verify its instructions through a trusted OneMain contact channel.
Sources
- Texas Attorney General: Data-security breach reports, OneMain Financial Group row, published September 25, 2026; checked October 2, 2026.
- FTC: Credit freezes and fraud alerts
- IdentityTheft.gov
What to do now
- Keep your notice. It identifies the data categories that applied to you and any enrollment deadline.
- Verify the notice through the organization’s official website or a contact number you already trust. Do not use an unexpected message’s links or share passwords or one-time codes.
- If Social Security or other identity information was involved, consider a free credit freeze with each of the three major U.S. bureaus. A freeze helps restrict new credit; it does not stop transactions on existing accounts.
- Review bank and card statements. Contact the institution about unfamiliar transactions.
- Use IdentityTheft.gov if someone is using your identity. Enroll in any monitoring offer through the verified notice’s instructions.
For help interpreting a letter, see a company emailed me about a breach.
What a Delist scan can tell you
A free Delist scan checks personal-data exposure on the sources we cover. It does not inspect this organization’s systems, establish whether your record was involved in this incident, or erase breach dumps. Paid listing-removal work requires separate authorization.
This summary is compiled from public notices and reporting available when this page was last updated. Figures may change as investigations continue. Confirm your own exposure and any assistance offer with the organization named in your notice.
Inclusion is a record of a publicly reported incident, not an allegation of wrongdoing or negligence.
Does the Texas filing say when or how the incident happened?
No. The primary listing records 15,472 affected Texas residents, names, addresses and Social Security information. Its September 25, 2026 publication date is not an incident date, and it does not establish a nationwide total or access method.
Frequently asked questions
Is 15,472 a nationwide affected-person count?
No. It is the Texas resident count in the Attorney General register.
How do I find the information that applied to me?
Keep your mailed notice and verify it through a trusted OneMain contact channel. The public listing does not show each person’s record or assistance terms.
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
- TransUnion data breach (2025)
- 700Credit data breach (2025)
- Infutor-linked exposure (2026)
- First 48 hours after a data breach
- How to freeze your credit
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.