Blog > Data Breach & Privacy

Hilldun Data Breach: What Affected Individuals Need to Know

Hilldun Corporation, a New York City financial-services company, has disclosed a data breach that exposed Social Security numbers and other sensitive information after a ransomware group claimed to have stolen company data. If you received a notice, here is what was involved and what steps you can take.

Hilldun Data Breach: What Affected Individuals Need to Know

What Happened in the Hilldun Data Breach

A timeline of the financial-services company's security incident

Hilldun Corporation, founded in 1958, is a New York City-based financial-services company that specializes in accounts receivable financing and factoring services for businesses in the fashion and consumer-products industries. According to reporting on the incident, on September 22, 2025, a threat group known as PLAY posted on the Tor network claiming it had obtained data from the company, and announced plans to publish the stolen data on September 25, 2025.

The breach was reported to multiple state regulators, including the Vermont Attorney General and the Massachusetts Attorney General, both on July 24, 2026. The gap between the threat actor’s September 2025 claim and the July 2026 notifications reflects the time often required to investigate an incident, review affected data, and identify the individuals whose information was involved.

What Information Was Exposed in the Hilldun Breach

The categories of sensitive data involved

The PLAY group claimed to have stolen a broad range of sensitive information, including confidential client documents, budget records, payroll information, accounting files, tax records, identification documents, and financial information. According to reporting on the incident, the types of personal information confirmed to have been exposed included Social Security numbers, financial account information, credit and debit card numbers, and driver’s licenses. The Vermont Attorney General’s breach-notice list categorizes the Hilldun filing as involving Social Security numbers.

When Social Security numbers, financial account details, and payment card numbers are exposed together, affected individuals may face a heightened risk of financial identity theft and fraud. Because a threat actor publicly claimed to have obtained and intended to publish the data, potentially affected individuals should treat the risk of misuse seriously.

Who Is Affected and What the Risks Are

Understanding your exposure

Hilldun provides financing and factoring services to businesses, so affected individuals may include people whose information the company maintained in connection with those services, as well as employees whose payroll or tax records were involved. The full number of individuals affected was not publicly stated at the time of writing; the Vermont Attorney General’s list reflects only the count of Vermont residents.

Because the stolen data reportedly included identification documents and financial records, and because the PLAY group signaled an intent to publish it, remaining vigilant is important. Data exposed in ransomware and extortion incidents can circulate for a long time, so monitoring your accounts over an extended period is prudent.

What to Do If You Received a Hilldun Data Breach Notice

Practical protective steps you can take today

Keep your notification letter, as it identifies the specific information involved in your case and any protective services offered. Monitor your financial accounts and credit card statements closely for unauthorized activity, and review your free credit reports at AnnualCreditReport.com for unfamiliar accounts. Given that Social Security numbers were involved, consider placing a fraud alert or a credit freeze with the three major credit bureaus at no cost.

Be cautious of phishing emails, calls, or texts that reference Hilldun or the breach, as scammers sometimes use breach news to craft convincing messages. Beyond these self-protective steps, a legal professional can help you understand whether you may be entitled to compensation and what your rights are.

See our guide to the MBE CPAs data breach lawsuit if you were affected by that incident.

FAQs

A threat group called PLAY claimed on September 22, 2025 that it had obtained Hilldun data and announced plans to publish it on September 25, 2025. Hilldun reported the breach to the Vermont and Massachusetts Attorneys General on July 24, 2026.

According to reporting, the personal information confirmed exposed included Social Security numbers, financial account information, credit and debit card numbers, and driver's licenses. The PLAY group also claimed to have taken payroll, accounting, tax, and identification records.

A threat group known as PLAY publicly claimed responsibility, posting on the Tor network that it had obtained the company's data.

The total number of affected individuals was not publicly stated at the time of writing. State attorney general listings, such as Vermont's, reflect only the number of residents in that state.

If you received a notification letter from Hilldun, your information may have been involved. Your individual notice is the definitive source for which categories of your information were affected.

You may have legal options if your information was exposed. A legal professional can review your situation during a free consultation and explain whether you may be entitled to compensation.

Related Content

Guides, nearby offices, and related practice areas.

Start Your Free Case Review

4.9 out of 2,521 reviews
  • Available 24/7
  • Hablamos Español
  • Nationally-Recognized Powerhouse Team
As seen in:

We'll contact you within minutes

No fees unless you get paid.

By submitting this form, you knowingly, voluntarily, and expressly consent to receive from Wilshire Law Firm telephone calls, emails, and SMS text messages, including those made using an automatic telephone dialing system (auto-dialer), artificial intelligence (AI), and/or pre-recorded or artificial voice messages. These communications are for the purpose of providing prompt consultation regarding your potential case. You understand that by providing your telephone number, you are granting permission to be contacted for this purpose, even if your number is on a federal or state Do-Not-Call registry. Consent is not required as a condition of retaining Wilshire Law Firm. Message and data rates may apply. You may revoke your consent to receive calls, texts, or emails at any time by replying “STOP” to any text message, calling 888-557-3271, filling out the form at wilshirelawfirm.com/do-not-contact or by any other reasonable method. For more information, refer to our Privacy Policy.

Locations

Find your nearest office — serving all of California and employment clients in Oregon and Washington.

Appointments required for office visits

Beverly HillsIrvineLos AngelesOaklandRiversideSacramentoSan DiegoTorrance