Borrowers who took out a few hundred dollars from a neighborhood installment lender are now among 51,073 Texans whose names, Social Security numbers and driver’s license numbers were caught up in a network intrusion at World Acceptance Corporation. The Greenville, South Carolina, company, which operates as World Finance, noticed unauthorized activity in its network on or about Aug. 24, 2026. Mailed notices began going out Sept. 30, limited to individuals with valid mailing address records.
The company’s own notice gives no headcount at all. The Texas figure comes from the report filed with the Texas Attorney General, and only one other state, Massachusetts, has a published count so far.
A Lender With 1,009 Branches in 16 States
World Acceptance’s annual report for the fiscal year ended March 31, 2026 describes 1,009 branches in 16 states, with more than 100 each in Texas and Georgia. Installment loans made up 82.9 percent of revenue, with traditional loans running from $400 to $5,300 and an average origination of $2,015. The filing says the company generally serves people with limited access to other sources of consumer credit.
Texas is one of the two states where the lender has more than 100 branches, and the state’s data security breach report portal is where the 51,073 figure was filed; the portal’s table loads dynamically and showed no rows when checked, so the number is taken from ClaimDepot’s transcription of that report.
The same annual report says the company also prepared about 91,000 tax returns in fiscal 2026, offers tax advance loans of $500 to $7,000, and sells credit insurance, non-file insurance and auto club memberships as an agent. The notice does not say which of those business lines held the records involved, so the product mix of the 51,073 people is not public.
Three Identifiers, Not Always All Three
The company’s notice of data security incident, dated Sept. 30, lists three data types: name, Social Security number and driver’s license number. It adds a qualifier that matters for the 51,073 count: “Not all information was impacted for each individual.” Some of the 51,073 therefore had a Social Security number exposed without a license number, or the reverse, and the notice does not break the group down.
The timeline in the notice is short. External cybersecurity professionals ran a forensic investigation after Aug. 24, and on or about Sept. 8 the company confirmed whose names and addresses were involved and what kind of data it was. The notice says the data may have been accessed or acquired on or around Aug. 24 and that the company has no evidence the information has been or will be used for identity theft as a direct result of the incident.
ClaimDepot’s page on the incident adds that the company began notifying state attorneys general on Sept. 30 and lists filings in 13 states, among them California, Maine, Massachusetts, Texas and Washington. Beyond Texas, only Massachusetts has a published count: 15 residents.
The Sept. 8 confirmation date is the one the company ties to knowing whose data was involved. Between Aug. 24 and that date, the notice describes only the work of the outside forensic team, and it names no executive, no attacker and no method.
Epiq’s 24 Months of Alerts and the Freeze Decision
The Massachusetts filing, a consumer letter posted by the state, says single-bureau credit alerts, a credit report and a credit score are provided at no charge for 24 months from enrollment, through Epiq’s Privacy Solutions ID service. Enrollment requires an activation code from the letter. The company’s notice says individuals whose Social Security numbers were potentially involved were offered the service, and the letter is signed by the corporation, not by a named executive.
The notice lists an incident call center and a postal address of 104 S. Main St. in Greenville for Maryland residents. It also points recipients toward the standard defenses: a fraud alert or security freeze, free credit reports, and regular review of account statements. The Federal Trade Commission says a freeze stops anyone from opening a new credit account in the person’s name until it is lifted, and that a fraud alert, which lasts a year, makes lenders verify identity first.
Separate help desks handle separate jobs. The Massachusetts letter gives enrollment help on a line separate from the response line, and sends recipients to annualcreditreport.com for free reports and to the FTC’s identity-theft line, 1-877-438-4338, for recovery guidance. Mail for the enrollment program goes to a processing center in Suwanee, Georgia, which is not the lender’s Greenville headquarters.
The two numbers on the record are 51,073 in Texas and 15 in Massachusetts, which ClaimDepot’s litigation tracker adds up to 51,088 across the two states it could count, with the remaining attorney-general filings on its list carrying no published count.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview