HILT-Trust 2020-A Data Breach Investigation
A data incident involving HILT-Trust 2020-A and its underlying trusts and affiliates was reported through state regulatory filings, although the available information does not identify when the event occurred or was discovered. The reported information may include names, addresses, dates of birth, and Social Security numbers. Strauss Borrelli PLLC is investigating the reported incident and its potential impact. If you received a notice or believe you may be affected, fill out the secure contact form on this page to ask whether you may qualify to pursue a claim.
Key Facts at a Glance
- Entity Involved: HILT-Trust 2020-A and its underlying trusts and affiliates (Financial Trust)
- Incident Type: Not specified in the available regulatory information
- Date of Incident: Not reported
- Discovery Date: Not reported
- Official Notice Date: Not reported
- Exposed Information: Names, addresses, dates of birth, and Social Security numbers may have been involved
- Affected Population: Regulatory filing data reports 41,153 individuals
- Public Listing Date: September 9, 2026
What Happened?
According to structured regulatory information, a data incident involving HILT-Trust 2020-A and its underlying trusts and affiliates was publicly listed in connection with state attorney general filings in Texas and Vermont on September 9, 2026. The filing data reports an affected population of 41,153 individuals. However, the available information does not specify the incident date, discovery date, consumer notice date, or technical cause of the event.
It is therefore unclear from the available record whether the reported matter involved unauthorized system access, ransomware, a compromised vendor, or another security issue. The information also does not establish whether every listed individual had the same data elements involved or whether any personal information has been misused. People who receive a notice should review it carefully because an individual notice may provide details specific to that person, including the categories of information potentially affected and any protective services being offered.
What Information Was Exposed?
The regulatory data identifies names, home addresses, dates of birth, and Social Security numbers as information that may have been involved. These data elements can be especially sensitive when combined because they may help criminals impersonate an individual or answer identity-verification questions.
For an incident involving a financial trust, potential risks may include fraudulent loan applications, account-verification calls or texts, unauthorized password-reset attempts, and convincing messages that impersonate a financial institution. A name and address could also be used to make a phishing message appear legitimate. The reported involvement of personal information does not, by itself, establish that identity theft or financial fraud has occurred.
What Should You Do Next?
- Review any notice carefully: Confirm which entity sent the notice, what information it says may have been involved, and whether it offers enrollment in credit monitoring or identity-protection services. Keep a copy for your records.
- Consider freezing your credit: A security freeze can make it harder for someone to open a new loan or credit account in your name. You must contact Equifax, Experian, and TransUnion separately to place freezes.
- Check your credit reports: Review reports for unfamiliar accounts, addresses, hard inquiries, or loans. You can obtain reports through AnnualCreditReport.com and dispute information you believe is inaccurate.
- Watch for financial impersonation scams: Be cautious of calls, emails, or texts requesting account credentials, one-time passcodes, wire transfers, or identity verification. Contact financial institutions through a trusted website, statement, or payment card rather than using links in unexpected messages.
- Document suspicious activity: Save notices, screenshots, emails, credit reports, receipts, and records of time spent addressing the incident. Report suspected identity theft through IdentityTheft.gov and contact relevant financial institutions promptly.
Your Legal Rights
Individuals affected by a reported data incident may have rights under state privacy, consumer-protection, data-security, or breach-notification laws. Depending on the facts and applicable law, potentially affected people may be able to seek remedies for unreimbursed losses, fraudulent charges, credit-monitoring expenses, lost time, or other documented harm.
Whether a claim is available depends on factors such as residency, the information involved, the adequacy and timing of notice, evidence of misuse, and the relationship between the individual and the entities involved. Receiving a notice does not automatically establish liability or guarantee compensation. Preserve relevant documents and consider speaking with a qualified attorney about your circumstances and applicable deadlines. This information is general and is not individualized legal advice.
Why Hire Strauss Borrelli PLLC?
Strauss Borrelli PLLC represents consumers in privacy and data-security matters and investigates whether organizations used reasonable safeguards and provided legally sufficient notice. The firm can review available information, evaluate potential claims, explain the legal process, and help affected individuals understand whether they may have options. A consultation does not guarantee that a claim can be filed or that compensation will be recovered.
If you received a breach notification letter from HILT-Trust 2020-A:
We would like to speak with you about your rights and potential legal remedies in response to this data breach. Please fill out the form, below, or contact us at 872.263.1100 or sam@straussborrelli.com.










