▼
Allegations Only · No Settlement Yet
This article describes class action complaints. The statements below are unproven
allegations. OneMain Financial Group, LLC has not been found liable, there is no certified class,
and nothing to claim at this time. This page is informational and is not legal advice.
OneMain Financial Group, LLC, a lender that makes personal installment loans, began mailing data breach
notices on September 28, 2026. According to the company’s sample letter, filed with the California
Attorney General, OneMain discovered unauthorized activity on its systems in May, stopped it, and hired
a cybersecurity and forensic firm to investigate. The investigation found evidence that data containing
personal information was accessed or acquired on May 5, 2026. OneMain said there was no evidence of
unauthorized access to customer accounts and that it had received no reports of fraud tied to the
incident.
Within days, customers began suing. At least nine proposed class actions were filed against OneMain in
the U.S. District Court for the District of Maryland between September 28 and October 2, 2026, beginning
with Harris v. OneMain Financial Group, LLC, No. 1:26-cv-03823, and Chess v. OneMain Financial
Group, LLC, No. 1:26-cv-03826, both filed September 28. No court has ruled on any of the allegations.
Free settlement alerts
Get notified when new class actions open to claims
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
Status
At Least Nine Complaints Filed
September 28 – October 2, 2026 · D. Md. · no class certified
Data Exposed
Names, addresses and Social Security numbers
Per the complaints, citing OneMain’s Texas Attorney General filing · notice also lists other account-related information
Free Credit Monitoring
24 months through TransUnion
Offered in OneMain’s notice · enrollment deadline December 31, 2026
Can I Claim?
No — nothing to claim yet
Three public records describe the breach, and they do not line up perfectly:
- OneMain’s notice letter says unauthorized activity was discovered in May and that data was
accessed or acquired on May 5, 2026. It lists the affected information as name, address and other
account-related information; the sample filed with California blacks out one additional item in that
list.
- Oregon Department of Justice: OneMain’s report lists breach dates of May 5 to May 12, 2026,
a discovery date of August 18, 2026, notices sent September 28, 2026, and 960 affected Oregon
residents.
- Texas Attorney General: the complaints cite OneMain’s September 25, 2026 filing there as the
source for the exposed data types, including Social Security numbers.
The May discovery date in the letter and the August 18 date in Oregon’s record may reflect different
stages of the investigation; OneMain has not explained the difference publicly. No nationwide count of
affected people appears in any of these records or in the complaints reviewed for this page.
OneMain’s letter offers 24 months of complimentary credit monitoring and identity restoration through
TransUnion, administered by Cyberscout, with enrollment open through December 31, 2026 using a code printed
in the letter.
The two complaints that are publicly available, Harris and Chess, make nearly identical
allegations. The plaintiff in Harris describes himself as a OneMain customer and the plaintiff in
Chess as a former customer. They allege that:
- OneMain did not use reasonable security practices for the information it held, such as
encrypting it or deleting it when no longer needed
- The files accessed in the breach contained unencrypted personal information
- Customers now face a long-term risk of identity theft and fraud, including loans taken out in
their names, because Social Security numbers cannot easily be changed
The complaints also allege, on information and belief, that the stolen information was published on the
dark web. OneMain has said it had no reports of fraud linked to the incident, and none of the allegations
has been tested in court.
Both available complaints propose a nationwide class of all individuals residing in the United States
whose private information was accessed or acquired by an unauthorized party in the data breach. OneMain,
its affiliates and the assigned judge are excluded. The definition is a proposal; a court would have to
certify a class before anyone is formally part of the case, and consolidation could change it.
Harris and Chess each bring four claims for the nationwide class: negligence, negligence per
se, breach of implied contract and unjust enrichment. They seek actual and statutory damages, restitution,
injunctive relief, an order requiring OneMain to fund lifetime credit monitoring and identity theft
insurance, interest, and attorneys’ fees. Those are requests, not amounts anyone has been awarded.
All are in the U.S. District Court for the District of Maryland:
- Harris v. OneMain Financial Group, LLC, No. 1:26-cv-03823 (filed September 28, 2026)
- Chess v. OneMain Financial Group, LLC, No. 1:26-cv-03826 (filed September 28, 2026)
- Fedorchak v. OneMain Financial Group, LLC, No. 1:26-cv-03845 (filed September 29, 2026)
- Adams v. OneMain Financial Group, LLC, No. 1:26-cv-03860 (filed September 29, 2026)
- Velazquez v. OneMain Financial Group, LLC, No. 1:26-cv-04052 (filed September 30, 2026)
- Longoria v. OneMain Financial Group, LLC, No. 1:26-cv-04109 (filed October 1, 2026)
- Clayton v. OneMain Financial Group, LLC, No. 1:26-cv-04117 (filed October 1, 2026)
- Gordon v. OneMain Financial Group, No. 1:26-cv-04141 (filed October 1, 2026)
- Delapaz v. OneMain Financial Group, LLC, No. 1:26-cv-04149 (filed October 2, 2026)
More may be filed. The page describes the claims in the Harris and Chess complaints, the two
available publicly; the others have not been reviewed and may differ in their details.
With this many suits in one court, the next step is usually a motion to consolidate them into a single
case and appoint lead counsel. OneMain would then respond to a consolidated complaint, often with a motion
to dismiss. The case could also settle; data breach settlements typically reimburse documented losses and
sometimes pay a flat amount, and they require a claim form.
There is nothing to file in the lawsuits now. The TransUnion enrollment offer in OneMain’s letter is a
separate, company-run program with its own December 31, 2026 deadline. If a settlement is reached, people
who received notices would normally be told how to file a claim.
Is there a OneMain Financial data breach class action?
Yes. At least nine proposed class actions were filed against OneMain Financial Group, LLC in the U.S. District Court for the District of Maryland between September 28 and October 2, 2026. All are at the complaint stage. No class has been certified, there is no settlement, and there is nothing to claim yet.
What information was exposed in the OneMain breach?
The complaints, citing OneMain’s filing with the Texas Attorney General, say the breach exposed names, addresses and Social Security numbers. OneMain’s sample notice letter says a person’s name, address and other account-related information were affected; the sample filed with California blacks out one of the listed data types.
How many people were affected by the OneMain data breach?
OneMain reported 960 affected Oregon residents to the Oregon Department of Justice. A nationwide total has not appeared in the official sources reviewed for this page: OneMain’s sample notice does not state one, and neither do the two complaints.
What is OneMain offering people who got a breach notice?
OneMain’s notice offers 24 months of complimentary credit monitoring and identity restoration services through TransUnion, administered by Cyberscout. The letter says the activation code must be used to enroll by December 31, 2026. The offer is separate from the lawsuits.
What happens next in the OneMain lawsuits?
When many suits over the same breach are filed in the same court, they are commonly consolidated into one case with appointed lead counsel. OneMain would then respond, often with a motion to dismiss. The case could also settle; if it does, people who received notices would normally be told how to file a claim.
• Class Action Complaint, Harris v. OneMain Financial Group, LLC, No. 1:26-cv-03823 (D. Md., filed September 28, 2026):
Harris complaint (PDF)
and docket.
• Class Action Complaint, Chess v. OneMain Financial Group, LLC, No. 1:26-cv-03826 (D. Md., filed September 28, 2026):
Chess complaint (PDF).
• Fedorchak v. OneMain Financial Group, LLC docket.
• OneMain Financial sample consumer notice filed with the California Attorney General (dated September 28, 2026):
OneMain breach notice (PDF).
• Oregon Department of Justice:
Consumer Protection data breach database (OneMain Financial entry reported September 28, 2026).
For more class actions keep scrolling below.
Status
Complaints Filed — No Class Certified
First Cases
Harris v. OneMain Financial Group, LLC · Chess v. OneMain Financial Group, LLC
Case Numbers
1:26-cv-03823 · 1:26-cv-03826 (and at least seven more)
Court
U.S. District Court, District of Maryland
Breach Dates
May 5–12, 2026 (per Oregon DOJ report)
Notices Sent
September 28, 2026