OneMain Financial Group data breach (2026): what was exposed and what to do

Updated Corrections

October 3, 2026

We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.

OneMain Financial Group’s Texas breach report, published September 25, 2026, lists 15,472 affected Texas residents, names, addresses and Social Security information. The register says consumers were notified by U.S. mail. It does not establish a nationwide total.

What is known, and what is still missing

The primary Texas listing does not state the incident date, discovery date or access method. This summary therefore does not assign an attack method or combine dates from separate law-firm reports with the official filing.

The three named data categories do not mean every OneMain customer was involved. Your mailed letter should identify the information that applied to you and any monitoring offer. Keep it and verify its instructions through a trusted OneMain contact channel.

Sources

What to do now

  1. Keep your notice. It identifies the data categories that applied to you and any enrollment deadline.
  2. Verify the notice through the organization’s official website or a contact number you already trust. Do not use an unexpected message’s links or share passwords or one-time codes.
  3. If Social Security or other identity information was involved, consider a free credit freeze with each of the three major U.S. bureaus. A freeze helps restrict new credit; it does not stop transactions on existing accounts.
  4. Review bank and card statements. Contact the institution about unfamiliar transactions.
  5. Use IdentityTheft.gov if someone is using your identity. Enroll in any monitoring offer through the verified notice’s instructions.

For help interpreting a letter, see a company emailed me about a breach.

What a Delist scan can tell you

A free Delist scan checks personal-data exposure on the sources we cover. It does not inspect this organization’s systems, establish whether your record was involved in this incident, or erase breach dumps. Paid listing-removal work requires separate authorization.

This summary is compiled from public notices and reporting available when this page was last updated. Figures may change as investigations continue. Confirm your own exposure and any assistance offer with the organization named in your notice.

Inclusion is a record of a publicly reported incident, not an allegation of wrongdoing or negligence.

Does the Texas filing say when or how the incident happened?

No. The primary listing records 15,472 affected Texas residents, names, addresses and Social Security information. Its September 25, 2026 publication date is not an incident date, and it does not establish a nationwide total or access method.

Frequently asked questions

Is 15,472 a nationwide affected-person count?

No. It is the Texas resident count in the Attorney General register.

How do I find the information that applied to me?

Keep your mailed notice and verify it through a trusted OneMain contact channel. The public listing does not show each person’s record or assistance terms.

What to do after a breach

A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.

More breaches

Free personal data exposure scan

We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.