OneMain Financial Group, LLC

May 2026 · Graded Verified · Financial Services · Government record
OneMain Financial Group, LLCMay 2026
Not yet quantified
VVerified
Three years after New York regulators fined OneMain $4.25 million for cybersecurity failures that they said increased the company's vulnerability to unauthorized access to customer information, OneMain has disclosed that an unauthorized actor gained access to its systems and acquired personal information belonging to 122,783 people, including Social Security numbers. The company has not disclosed how the attacker got in, leaving unresolved whether the breach involved the same access-management or application-security control areas at the center of the 2023 enforcement action. No SEC disclosure was filed for this event, no mention of it in the latest 10Q and while an investigation hasn't tied this incident to any prior cybersecurity deficiencies, 4.25 mm reasons with no statement by NYDFS that the deficiences were closed sure makes you go hmmmm.
Financial Services
California AG breach notification
About this record
This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.
← The complete On the Government Record ledger ← Back to the index