Data Breach & Privacy
Blog > Data Breach & Privacy
Hilldun Data Breach: What Affected Individuals Need to Know
Hilldun Corporation, a New York City financial-services company, has disclosed a data breach that exposed Social Security numbers and other sensitive information after a ransomware group claimed to have stolen company data. If you received a notice, here is what was involved and what steps you can take.

What Happened in the Hilldun Data Breach
A timeline of the financial-services company's security incident
Hilldun Corporation, founded in 1958, is a New York City-based financial-services company that specializes in accounts receivable financing and factoring services for businesses in the fashion and consumer-products industries. According to reporting on the incident, on September 22, 2025, a threat group known as PLAY posted on the Tor network claiming it had obtained data from the company, and announced plans to publish the stolen data on September 25, 2025.
The breach was reported to multiple state regulators, including the Vermont Attorney General and the Massachusetts Attorney General, both on July 24, 2026. The gap between the threat actor’s September 2025 claim and the July 2026 notifications reflects the time often required to investigate an incident, review affected data, and identify the individuals whose information was involved.
What Information Was Exposed in the Hilldun Breach
The categories of sensitive data involved
The PLAY group claimed to have stolen a broad range of sensitive information, including confidential client documents, budget records, payroll information, accounting files, tax records, identification documents, and financial information. According to reporting on the incident, the types of personal information confirmed to have been exposed included Social Security numbers, financial account information, credit and debit card numbers, and driver’s licenses. The Vermont Attorney General’s breach-notice list categorizes the Hilldun filing as involving Social Security numbers.
When Social Security numbers, financial account details, and payment card numbers are exposed together, affected individuals may face a heightened risk of financial identity theft and fraud. Because a threat actor publicly claimed to have obtained and intended to publish the data, potentially affected individuals should treat the risk of misuse seriously.
Who Is Affected and What the Risks Are
Understanding your exposure
Hilldun provides financing and factoring services to businesses, so affected individuals may include people whose information the company maintained in connection with those services, as well as employees whose payroll or tax records were involved. The full number of individuals affected was not publicly stated at the time of writing; the Vermont Attorney General’s list reflects only the count of Vermont residents.
Because the stolen data reportedly included identification documents and financial records, and because the PLAY group signaled an intent to publish it, remaining vigilant is important. Data exposed in ransomware and extortion incidents can circulate for a long time, so monitoring your accounts over an extended period is prudent.
What to Do If You Received a Hilldun Data Breach Notice
Practical protective steps you can take today
Keep your notification letter, as it identifies the specific information involved in your case and any protective services offered. Monitor your financial accounts and credit card statements closely for unauthorized activity, and review your free credit reports at AnnualCreditReport.com for unfamiliar accounts. Given that Social Security numbers were involved, consider placing a fraud alert or a credit freeze with the three major credit bureaus at no cost.
Be cautious of phishing emails, calls, or texts that reference Hilldun or the breach, as scammers sometimes use breach news to craft convincing messages. Beyond these self-protective steps, a legal professional can help you understand whether you may be entitled to compensation and what your rights are.
See our guide to the MBE CPAs data breach lawsuit if you were affected by that incident.
FAQs
A threat group called PLAY claimed on September 22, 2025 that it had obtained Hilldun data and announced plans to publish it on September 25, 2025. Hilldun reported the breach to the Vermont and Massachusetts Attorneys General on July 24, 2026.
According to reporting, the personal information confirmed exposed included Social Security numbers, financial account information, credit and debit card numbers, and driver's licenses. The PLAY group also claimed to have taken payroll, accounting, tax, and identification records.
A threat group known as PLAY publicly claimed responsibility, posting on the Tor network that it had obtained the company's data.
The total number of affected individuals was not publicly stated at the time of writing. State attorney general listings, such as Vermont's, reflect only the number of residents in that state.
If you received a notification letter from Hilldun, your information may have been involved. Your individual notice is the definitive source for which categories of your information were affected.
You may have legal options if your information was exposed. A legal professional can review your situation during a free consultation and explain whether you may be entitled to compensation.

