VT · AG Filing: Sep 9, 2026 · Recently disclosed — legal window is open
No cost. No obligation. If your data was exposed by HILT-Trust 2020-A, you may be entitled to financial compensation.
Start Free Review →Based on the data types reported in this filing:
Your SSN is the master key to your identity. Once exposed, criminals can open new lines of credit, take out loans, or file taxes in your name.
Combined with a name and other leaked data, date of birth helps criminals pass identity verification questions at banks and government agencies.
HILT-Trust 2020-A was the subject of a data breach notification filed with the VT Attorney General. The AG filing was recorded on September 9, 2026.
From the AG filing description
HILT-Trust 2020-A operates within the specialized structured finance and investment sector, functioning as an issuing entity or special purpose vehicle holding substantial portfolios of consumer or commercial credit assets. Because of its core operations, the entity and its third-party collateral managers, servicers, and trustees maintain vast repositories of sensitive individual financial and personal data. This includes detailed credit applications, investor account records, asset-backed security documentation, and underlying borrower files. The organization occupies a critical nexus in modern capital markets, aggregating high-value financial dossiers that make it an extraordinarily lucrative target for sophisticated cybercriminal syndicates seeking to monetize non-public personal information. In 2026, HILT-Trust 2020-A officially reported a significant security incident to the Vermont Attorney General's Office, alerting state regulators and impacted consumers to a compromise of its network infrastructure or that of its administrative vendors. While the precise mechanics of the intrusion continue to be investigated, incidents of this nature within structured finance entities typically involve unauthorized access to legacy loan servicing databases, compromised cloud storage environments, or sophisticated ransomware deployments. Such breaches often exploit vulnerabilities in administrative access controls or third-party vendor connections, allowing threat actors to dwell undetected within corporate systems and siphon off bulk data repositories before detection occurs. The breach exposed a dangerous mosaic of sensitive personal and financial identifiers, creating immediate and long-term vulnerabilities for affected individuals. The compromised information routinely includes full legal names, Social Security numbers, dates of birth, banking routing and account numbers, mortgage or loan balances, and detailed transaction histories. When combined, these data points provide identity thieves with everything required to execute seamless financial account takeovers, fraudulent loan originations, and devastating tax fraud. Unlike transient credit card breaches, the permanent nature of compromised Social Security numbers and underlying financial account details means victims face a lifetime horizon of heightened exposure to synthetic identity theft and recurring financial fraud. As an entity handling sensitive financial and consumer data, HILT-Trust 2020-A was legally bound by stringent regulatory frameworks, including the Gramm-Leach-Bliley Act (GLBA) and state-level consumer protection statutes, to maintain robust administrative, technical, and physical safeguards. The GLBA Safeguards Rule mandates that financial institutions establish comprehensive security programs to protect customer records against foreseeable threats and unauthorized access. The occurrence of a data breach of this magnitude serves as strong prima facie evidence that the institution failed to maintain reasonable cybersecurity protocols, neglected necessary vulnerability patch management, or failed to properly vet and monitor third-party vendors with access to sensitive systems. Receiving an official data breach notification letter from HILT-Trust 2020-A is a formal admission by the organization that your private, legally protected information was compromised due to inadequate security measures. Under established consumer protection jurisprudence, this notification establishes the necessary legal standing to initiate or participate in a class action lawsuit aimed at holding the company accountable. Importantly, affected individuals do not need to prove that they have already suffered actual financial loss or identity theft to pursue legal remedies; the increased risk of future harm and the costs associated with mitigating that risk are legally actionable injuries. Our firm is actively investigating potential class action claims on behalf of all impacted individuals, and we handle these cases strictly on a contingency fee basis—meaning you pay nothing out of pocket and owe no fees unless we successfully recover compensation on your behalf.
You may have been affected by the HILT-Trust 2020-A data breach if:
Common categories of compensation in data breach class actions
The hours spent responding to a data breach — canceling accounts, contacting credit bureaus, updating passwords, and investigating fraud — represent compensable economic harm in data breach litigation.
Once your SSN is exposed, protection becomes an ongoing expense. Plaintiffs in data breach settlements have recovered costs for credit freezes, identity protection subscriptions, and time spent dealing with fraudulent accounts — sometimes covering multiple years of exposure.
Fees charged to close and reopen accounts, issue replacement cards, or dispute fraudulent transactions are recoverable in data breach litigation. So are the costs of overdrafts, late payments, and credit damage caused by unauthorized activity.
Data breach victims regularly report anxiety, loss of sleep, and ongoing fear of identity theft. These non-economic harms are cognizable injuries in data breach litigation, particularly in cases involving SSN or medical record exposure.
Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.
Applicable State Law
This breach was reported under the Vermont Security Breach Notice Act, which mandates notification and establishes your right to seek damages.
No. Under Vermont Security Breach Notice Act and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.
Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.
Immediately place a free credit freeze at all three bureaus (Equifax, Experian, TransUnion). A freeze blocks new accounts from being opened in your name. Then file a complaint with the FTC at IdentityTheft.gov and contact our office — SSN exposure is one of the most serious breach types.
Banks may reverse fraudulent charges, but they are not obligated to compensate you for time lost, stress, or indirect damages. A class action claim against the breached company can recover those additional categories of harm.
State statutes of limitations for data breach claims typically run 2–4 years from the date of the breach or its discovery. Because this breach was recently disclosed, the window is open — but acting early preserves your options and strengthens the case.
Accepting free credit monitoring from HILT-Trust 2020-A does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.
Not necessarily. Many data breach victims are never notified directly. If your personal information was held by HILT-Trust 2020-A during the relevant period, you may still qualify even without receiving a letter. A free eligibility review can confirm your status.
Learn how to participate in the class action and what compensation you may be entitled to.
Join the Class Action →Use our verification tool to confirm your letter matches this official AG filing.
Verify My Notice LetterThis case file references a public filing made with the state filing in VT. This website is not affiliated with, endorsed by, or operated by any state government agency.
Case review window ends November 4, 2026 — review your letter.
Review Your Letter →HILT-Trust 2020-A breach?
Free case review · No fee unless you win