Were you recently affected by a data breach?

First Financial Equipment Leasing Data Breach

First Financial Equipment Leasing, a California-based equipment leasing company, disclosed a data breach to state regulators that affected 35,693 individuals. The incident took place on February 9, 2026, and the types of personal information involved have not been fully detailed publicly.

First Financial Equipment Leasing
Date of Breach: February 9, 2026
CAU logo

Who was affected:

Clients of First Financial Equipment Leasing

Impacted Data:

Specific data types not publicly disclosed; may include names, contact details, Social Security numbers, government ID numbers or health information

First Financial Equipment Leasing, the trade name of California-based First Financial Holdings LLC, has disclosed a data breach affecting 35,693 individuals in the United States. The incident took place on February 9, 2026, and the company later reported it to state regulators.

Companies that finance equipment hold applicant, customer and employee records, including identity and financial details. When that information may have been exposed, the people it belongs to deserve clear answers about what happened and how to protect themselves.

First Financial Equipment Leasing’s Data Breach Investigation

First Financial Holdings LLC is a California-based company that does business as First Financial Equipment Leasing. The company provides equipment leasing and financing to businesses, a line of work that involves collecting detailed information from the people who apply for, guarantee and manage those lease agreements. That includes owners, officers, employees and other individuals tied to a business account.

According to the public breach database entries we reviewed, the company reported to state regulators that 35,693 individuals in the United States were affected. The figure appears in a year-to-date breach report published by a state Attorney General’s office, and the same incident is also listed by several other state regulators. Multi-state filings are a normal part of the breach reporting process, because an organization that notifies residents of different states typically files a separate notice with each state’s regulator.

The incident took place on February 9, 2026. The company reported it to regulators several months later, which means affected individuals may only recently have received, or may still be waiting for, a written notice in the mail. Notice letters often arrive well after an incident, since an organization generally needs time to investigate what happened, identify whose information was involved, and gather current mailing addresses.

Several important facts have not been made public in the sources we reviewed. We could not confirm how the incident happened, which systems were affected, when the company first detected a problem, or exactly which categories of personal information relate to each person. This page does not guess at any of those points. The aggregator listing we reviewed states that the specific types of information compromised have not been detailed in the available public filing, and it notes that the information may include items such as names, contact details, Social Security numbers, government identification numbers or health information. That is a general statement about what such incidents can involve, not a confirmed list for this company.

Because the specifics are limited, it helps to understand what kinds of information businesses in the leasing and finance sector typically hold. A lease or financing application commonly asks for a person’s name, home address, phone number, date of birth and Social Security number, and sometimes a driver’s license or other government identification number. Guarantors and business owners are often asked for financial statements and banking details as well. If any of that kind of information is exposed, it can be combined with other data to commit fraud.

Social Security numbers and dates of birth are especially sensitive because, unlike a card number, they cannot easily be replaced. Criminals can use them to open new credit accounts, file fraudulent tax returns, apply for loans, or try to take over existing accounts. The harm does not always show up immediately. Stolen data can circulate for a long time before it is misused, which is why people who receive a notice are encouraged to stay alert well beyond the first few weeks.

Financial services and leasing companies are frequent targets of data theft because they hold concentrated, high-value records. Criminals who gain access to one system can sometimes reach a large number of customer files at once. Companies in this sector also depend on outside vendors for payment processing, document storage and software, and an incident at any link in that chain can expose records belonging to many people.

If you receive a letter from First Financial Equipment Leasing or First Financial Holdings, read it carefully and keep it. A notice usually explains what information relates to you, what protective services are offered, and how to reach a dedicated contact for questions. If you have not received a letter but believe your information may have been involved, for example because you applied for or guaranteed a lease, you can reach out to the company directly and ask whether your records were affected.

It is also sensible to review your own records. Check your credit reports and financial statements for anything unfamiliar, and be careful with unexpected calls, emails or texts that mention the company or a lease account. Scammers often follow publicized incidents with messages that claim to come from the affected organization, hoping to trick anxious recipients into handing over more personal information.

For people who want to understand options beyond personal precautions, a data breach class action is one way affected individuals can seek accountability from an organization that did not adequately protect their information. Whether a claim is viable depends on facts that are still emerging, which is why speaking with a lawyer about your own situation is a reasonable next step.

When Did This Breach Occur?

The incident took place on February 9, 2026, according to the public breach database entry we reviewed. The company’s date of discovery and the full period of unauthorized access have not been made public in the sources we reviewed.

The company reported the incident to state regulators several months after it occurred. If you receive a letter, it may describe the timeline in more detail for your own situation, so keep it with your records.

What Information Was Breached?

The specific categories of information involved have not been confirmed in the public filing we reviewed. The company has not published a detailed breakdown, and the items can differ from one person to another.

Your notice letter, if you receive one, is the best source for which details relate to you. Until you know, it is reasonable to treat identity and financial information as potentially at risk.

What You Can Do

If you received a notice from First Financial Equipment Leasing or believe you may be affected, consider these steps:

  • Enroll in any credit monitoring or identity protection services the notice offers, and keep the letter and its enrollment deadline.
  • Place a free fraud alert or a credit freeze with Equifax, Experian and TransUnion, and get your reports free at annualcreditreport.com.
  • Review bank, card and tax records for activity you do not recognize, and consider an Identity Protection PIN from the IRS.
  • Be skeptical of unexpected calls, texts or emails that mention the company, and report suspected identity theft to the Federal Trade Commission at identitytheft.gov and to your state Attorney General.

File a Data Breach Lawsuit Against First Financial Equipment Leasing

If your personal information may have been exposed in this incident, you may have legal options. Organizations that hold sensitive personal information are expected to safeguard it, and a class action can help hold an organization accountable when it fails to do so.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: February 9, 2026
Date of Breach: Not publicly disclosed (notice filed October 8, 2026)
Date of Breach: Not publicly disclosed (notice filed October 8, 2026)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.