HILT-Trust 2020-A Data Breach Class Action Lawsuit Investigation

Data breach law firm Abington Cole + Ellery is investigating potential legal claims related to the HILT-Trust 2020-A data breach, which reportedly affected about 41,153 individuals and may have exposed NAME / ADDRESS / SSN / DOB.


JOIN THIS INVESTIGATION: If you are interested in potentially volunteering to serve as a class representative in a class action lawsuit against HILT-Trust 2020-A, please submit your information to be considered:

You may also open the form here: HILT-Trust 2020-A Data Breach Lawsuit Form. An attorney-client relationship is not formed by submitting information through this website.

HILT-Trust 2020-A Data Breach: Key Facts

Entity: HILT-Trust 2020-A
Location: New York, NY
Incident Type: UNDISCLOSED
Number Affected: APPROXIMATELY 41,153
Data Involved: NAME / ADDRESS / SSN / DOB
Date Began: UNDISCLOSED
Date Discovered: UNDISCLOSED
Date Ended: UNDISCLOSED
Notice Date: September 9, 2026
Credit Monitoring: UNCONFIRMED
Status: Class Action Lawsuit Investigation


What happened in the HILT-Trust 2020-A data breach?

HILT-Trust 2020-A recently reported a data breach involving sensitive personal information. The incident became public on September 9, 2026, when it was reported to the Texas and Vermont Attorneys General. The Texas filing identifies the reporting entity more broadly as “HILT-Trust 2020-A and its underlying trusts and affiliates” and provides a New York address. Vermont classifies HILT-Trust 2020-A as a financial-services organization. Vermont Attorney General Security Breach Notices; Texas Attorney General Data Security Breach Reports

According to the Texas Attorney General’s data breach registry, the HILT-Trust 2020-A breach affected 6,100 Texas residents. The compromised information may have included individuals’ names, addresses, Social Security numbers, dates of birth, and an additional category listed only as “other.” The filing does not explain what information falls within that unspecified category. The Vermont Attorney General separately reports that 91 Vermont residents were affected and identifies Social Security numbers as the compromised data category. Approximately 41,153 people are believed to have been affected nationwide.

HILT-Trust 2020-A reportedly provided written notice to affected individuals by U.S. mail. The information exposed may have varied from person to person, and the regulatory filings do not establish that every affected individual had every listed category of information compromised.

At this stage, important details about how the HILT-Trust 2020-A data breach occurred remain undisclosed. The available government records do not identify the initial attack vector or state whether the incident involved ransomware, phishing, stolen credentials, a compromised vendor, or another form of unauthorized access. They also do not provide the dates on which the unauthorized activity began or ended, when the incident was discovered, or when the investigation determined that personal information was involved. No public finding of data misuse appears in the reviewed filings.

The key confirmed date is September 9, 2026, when the HILT-Trust 2020-A breach was reported in Texas and Vermont. Because the public filings presently contain only limited information, further details may emerge through consumer notification letters, amended regulatory reports, or subsequent disclosures. Any description of the breach’s cause or internal timeline beyond the facts above would currently be speculative.


How did the HILT-Trust 2020-A breach occur?

The precise cause of the HILT-Trust 2020-A data breach has not yet been publicly disclosed. The available Texas and Vermont Attorney General records do not explain whether the incident resulted from hacking, phishing, ransomware, stolen credentials, an employee error, or a compromised third-party service provider. Vermont Attorney General Security Breach Notices; Texas Attorney General Data Security Breach Reports


When did the HILT-Trust 2020-A breach occur?

The date or period when the HILT-Trust 2020-A data breach occurred has not been publicly disclosed. The available government records do not identify when unauthorized access began or ended, or when the incident was discovered. Vermont Attorney General Security Breach Notices; Texas Attorney General Data Security Breach Reports


How many people were affected by the HILT-Trust 2020-A breach?

Approximately 41,153 individuals were affected by the HILT-Trust 2020-A data breach. According to the Texas Attorney General’s data breach registry, 6,100 Texas residents were affected. The Vermont Attorney General separately reports that 91 Vermont residents were affected. Vermont Attorney General Security Breach Notices; Texas Attorney General Data Security Breach Reports


What information was exposed in the HILT-Trust 2020-A breach?


Has HILT-Trust 2020-A offered free credit monitoring and/or identity theft protection services?

There is currently no public confirmation that HILT-Trust 2020-A offered free credit monitoring or identity-theft protection services.

The Texas Attorney General filing confirms that affected individuals were notified by U.S. mail, but it does not identify any monitoring provider, enrollment period, or complimentary protection service. Vermont’s public registry likewise does not include that information, and its website does not publish the underlying consumer-notification letters. Vermont Attorney General Security Breach Notices; Texas Attorney General Data Security Breach Reports


HILT-Trust 2020-A data breach timeline:

Date Event
UNCONFIRMED Unauthorized activity began.
UNCONFIRMED HILT-Trust 2020-A discovered the incident.
UNCONFIRMED Unauthorized activity ended.
UNCONFIRMED Data breach investigation concluded.
September 9, 2026 HILT-Trust 2020-A began notifying affected individuals.

What is HILT-Trust 2020-A?

HILT-Trust 2020-A, which appears to be affiliated with the Hilton Grand Vacations Trust 2020-A, is a Delaware-based special-purpose trust affiliated with Hilton Grand Vacations Inc. The trust was established in 2020 as a financing vehicle to issue $300 million in asset-backed securities supported by a pool of fixed-rate vacation-ownership loans originated by Hilton Resorts Corporation or its subsidiaries. HILT-Trust 2020-A functions as a securitization entity rather than a hotel, resort, or consumer-facing vacation company. Hilton Grand Vacations Completes $300 Million Term Securitization


What should you do if you received a HILT-Trust 2020-A data breach letter?

If you received a HILT-Trust 2020-A data breach letter, take the notice seriously because the exposed information may include names, addresses, dates of birth, and Social Security numbers. Consider taking these steps:

    • Confirm the letter is authentic. Avoid clicking unfamiliar links or scanning QR codes in the notice until you verify them independently. Compare the letter with the information published by the state attorney general or contact the organization using previously known contact information.
    • Review the notice carefully. Determine which information belonging to you was affected, whether the letter provides an enrollment deadline, and whether complimentary credit monitoring or identity-theft protection is offered.
    • Consider freezing your credit. Contact Equifax, Experian, and TransUnion separately to place a free security freeze. A freeze makes it more difficult for someone to open a new credit account in your name, remains effective until you lift it, and does not affect your credit score. The FTC considers a freeze especially important when a Social Security number has been exposed. FTC: Credit Freezes and Fraud Alerts
    • Consider placing a fraud alert. An initial fraud alert instructs potential creditors to verify your identity before extending new credit. Contacting one of the three major credit bureaus is sufficient because that bureau must notify the other two. FTC: Credit Freezes and Fraud Alerts
    • Review your credit reports. Obtain reports from all three bureaus through AnnualCreditReport.com, the federally authorized source. Look for unfamiliar accounts, credit inquiries, addresses, or collection activity.
    • Monitor financial and government accounts. Review bank, credit-card, retirement, and loan statements for unauthorized activity. Create or secure your my Social Security account and review your earnings history for irregularities.
    • Consider obtaining an IRS Identity Protection PIN. An IP PIN prevents another person from filing a federal tax return using your Social Security number. Eligible taxpayers can request one through: IRS: Get an identity protection PIN (IP PIN)
    • Watch for targeted scams. Criminals may combine an exposed name, address, birth date, and Social Security number to create convincing calls, emails, or letters. Do not provide passwords, verification codes, or additional personal information in response to unsolicited communications.
    • Report suspected identity theft promptly. If you discover fraudulent activity, contact the affected institution, dispute inaccurate credit-report entries, and visit IdentityTheft.gov to create an FTC Identity Theft Report and personalized recovery plan.
    • Preserve your records. Keep the breach letter, its envelope, monitoring-enrollment confirmation, credit reports, correspondence, receipts, and documentation of any fraudulent transactions or time spent addressing the incident. These materials may be important if you later need to dispute fraud or establish losses.

Sources and additional information about the data breach:


Class Action FAQ

A class action lawsuit is a case brought on behalf of a group of people who were harmed in a similar way by the same company or organization.

A class representative, sometimes called a named plaintiff or lead plaintiff, is a person who volunteers to bring the lawsuit on behalf of the larger group. They help represent the interests of everyone in the class. There may be more than one class representative in a class action.

A person who was harmed may start a class action if many other people were harmed in a similar way.

Usually, no. In many class action cases, the lawyers are paid only if the case is successful.

Sometimes you do not need to do anything. Other times, you may need to submit a claim form by a deadline to receive money or benefits.


Infographic summarizing the HILT-Trust 2020-A data breach, including the number of affected individuals, the categories of information involved, and the publicly confirmed reporting timeline.
HILT-Trust 2020-A data breach infographic summarizing the number of people affected, the types of information involved, and the publicly confirmed timeline. Information current as of September 9, 2026.


About This Data Breach Resource

This page was created to give affected individuals and researchers a clear, comprehensive explanation of the HILT-Trust 2020-A data breach. It summarizes what is currently known about the incident, including the timeline, how the breach was discovered, the types of information involved, the number of people affected when available, important notice dates, and steps individuals may want to take after receiving a data breach notification.

This resource is independently written and organized to help readers understand the breach without having to review multiple notices, state attorney general filings, company statements, and related materials. When available, this page relies on primary sources and identifies key facts, unanswered questions, and updates as new information becomes public.

This page is especially relevant for readers searching for information about the HILT-Trust 2020-A data breach, HILT-Trust 2020-A data breach notice, HILT-Trust 2020-A class action investigation, what information was exposed, how many people were affected, and what affected individuals should do next.

Abington Cole + Ellery reviews data breach incidents involving sensitive personal information, financial information, and protected health information. This page is intended to help affected individuals understand the publicly reported facts, the types of information that may have been involved, and practical steps that may reduce the risk of identity theft or medical identity theft.

The information on this webpage is provided for general informational purposes only and does not constitute legal advice. Nothing on this page should be relied upon as legal advice for any particular situation. Submitting information through this page does not create an attorney-client relationship.

For more information about steps you can take to possibly reduce the risk harm arising from a data breach, please review the following article: What are some steps you can take if you've been the victim of a data breach?

This website is not associated with nor authorized by HILT-Trust 2020-A or any affiliated companies. If you have received any other data breach notifications, you may want to review Abington Cole + Ellery's current list of data breach investigations.