HILT-Trust 2020-A, headquartered at 30 Hudson Yards in New York, and its underlying trusts and affiliates recently disclosed a data security incident affecting more than 6,100 individuals. Companies that hold sensitive personal and financial information, including Social Security numbers and dates of birth, have a legal and ethical responsibility to protect that data from unauthorized access, and to notify affected individuals promptly when a breach occurs.
HILT-Trust 2020-A and its underlying trusts and affiliates’s Data Breach Investigation
Class Action U is investigating a data breach involving HILT-Trust 2020-A and its underlying trusts and affiliates. According to filings made with the Texas and Vermont Attorneys General, the breach affected at least 6,100 residents of Texas and 91 residents of Vermont, for a reported total of at least 6,191 individuals nationwide. The filings indicate that affected individuals’ names, addresses, Social Security numbers, and dates of birth may have been compromised.
As of this writing, HILT-Trust 2020-A has not publicly disclosed the specific cause of the breach, how the unauthorized access occurred, or the exact dates on which the incident was discovered. This is common in the early stages of a breach notification process, when the investigating company is still working with forensic experts and legal counsel before releasing full details to the public. Class Action U will continue to monitor this matter and update this page as additional information becomes available.
Data breaches involving financial trusts and similar entities are a growing target for cybercriminals because these organizations typically maintain large repositories of highly sensitive personal and financial information tied to loans, leases, or other financial instruments, on behalf of thousands of consumers at once. A single successful intrusion can expose the type of information, Social Security numbers, full names, home addresses, and dates of birth, that is most valuable for identity theft, fraudulent account openings, and tax-refund fraud. Attackers who obtain this combination of data can often bypass basic identity-verification checks used by banks, lenders, and government agencies, making breaches of this kind especially consequential for the people affected.
Entities that service or hold interests in structured finance vehicles, such as trusts formed to hold pools of consumer loans or leases, often rely on third-party vendors, loan servicers, and data-processing systems to manage day-to-day recordkeeping. Each of these third-party touchpoints represents an additional potential point of entry for a cyberattack, and a single compromised vendor can expose data belonging to consumers across multiple, otherwise unrelated financial products. This layered structure is part of why breach notifications tied to trusts and similar financial entities can sometimes take longer to fully investigate than breaches at a single, simpler business, and why the precise cause may not be disclosed even after the initial notification has already gone out to regulators and affected individuals.
Under both Texas and Vermont law, companies that experience a breach involving residents’ sensitive personal information are required to notify the state Attorney General’s office, generally within a defined window after the breach is discovered, alongside directly notifying the affected individuals themselves. These state notification requirements exist to give consumers an early opportunity to take protective action, such as freezing their credit or monitoring their accounts, before stolen information can be misused. When multiple states are involved, as appears to be the case here given filings identified in both Texas and Vermont, the reported number of affected individuals in any single state’s filing may reflect only that state’s residents rather than the full nationwide scope of the incident, meaning the true total number of people affected nationwide could be higher than any one filing indicates on its own.
For individuals whose Social Security numbers and dates of birth have been exposed, the risk extends well beyond simple credit card fraud. This combination of static, largely unchangeable identifiers is frequently used by criminals to open new lines of credit, file fraudulent tax returns, or pass identity-verification checks at financial institutions that were never designed to detect a stolen but technically accurate identity. Because Social Security numbers cannot easily be changed the way a compromised credit card number can, individuals affected by this type of breach often face an elevated, long-term risk of identity theft that can persist for years after the original incident, making early protective action particularly important.
When Did This Breach Occur?
The exact date the breach occurred or was first discovered by HILT-Trust 2020-A has not been publicly disclosed. What is known is that the incident was reported to state regulators, including the Texas Attorney General’s Office and the Vermont Attorney General’s Office, with both filings dated September 9, 2026. Class Action U will update this section if HILT-Trust 2020-A releases additional information about the timeline of the breach.
What Information Was Breached?
Based on the notifications filed with state Attorneys General, the following categories of personal information may have been exposed in this breach:
- Full names
- Home addresses
- Social Security numbers
- Dates of birth
This combination of information can be used by criminals to commit identity theft, open fraudulent financial accounts, or file fraudulent tax returns in an affected individual’s name.
What You Can Do
If you have received a notice that your information may have been involved in this breach, or if you believe you may be affected, consider taking the following steps to protect yourself:
- Monitor your bank and credit card statements closely for any unauthorized activity.
- Place a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion).
- Review your credit reports regularly for accounts you do not recognize.
- Be cautious of phishing emails, calls, or texts that reference this breach and ask for personal information.
- Consider enrolling in identity theft protection or credit monitoring services if offered by the company.
File a Data Breach Lawsuit Against HILT-Trust 2020-A and its underlying trusts and affiliates
If your personal information was compromised in the HILT-Trust 2020-A data breach, you may be entitled to compensation. Companies that fail to adequately protect consumers’ sensitive data can be held legally accountable for the resulting harm.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.