Heights Finance Data Breach Impacts at Least 1.2 Million Individuals

A massive data breach affecting over 1.2 million individuals has come to light, with consumer lender Heights Finance Holdings Co. disclosing that hackers gained access to a cloud-based platform used for customer data storage in early May. The company has since secured the platform and assured customers that its loan management systems and other computer systems or networks were not affected.

The breach is believed to have occurred when hackers accessed the third-party cloud-based platform, which stores personal and financial information of Heights’ customers. This sensitive data includes names, addresses, email addresses, phone numbers, Social Security numbers, government ID numbers, driver’s license numbers, bank account information, account details, dates of birth, and other information shared with the company.

The affected individuals include those who received a loan through Heights, inquired about or applied for a loan product (including through a third-party), or were former borrowers of Curo Management or its related brands. Notably, over 734,828 individuals in Texas, 486,463 in South Carolina, and smaller numbers in New Hampshire and Vermont have been impacted.

Heights is providing the affected individuals with two years of free credit monitoring and identity protection services to help mitigate potential harm from the breach. While the company has not named the threat actor behind the data breach, its monitoring of the dark web suggests that the stolen information has not yet been shared publicly.

This incident serves as a stark reminder of the importance of robust cybersecurity measures in protecting sensitive customer data. With more and more organizations moving to cloud-based platforms for data storage, ensuring the security of these systems is paramount. While Heights Finance has taken steps to secure its platform, this breach highlights the ongoing threat posed by sophisticated hackers.

The company’s handling of the incident, including prompt notification of affected individuals and provision of free credit monitoring services, demonstrates a commitment to transparency and customer care in the face of adversity. As the cybersecurity landscape continues to evolve, it is crucial that organizations prioritize data protection and stay vigilant against potential threats.

Ultimately, this breach serves as a warning to customers: even if an organization’s operations are not directly impacted, sensitive information can still be compromised through a third-party platform. It is essential for individuals to remain vigilant and take proactive steps to protect their personal and financial information in the wake of such incidents.

To stay safe online, we recommend that readers review their credit reports regularly, monitor their account activity closely, and consider implementing additional security measures, such as two-factor authentication and password managers. By taking these precautions, you can help mitigate potential harm from data breaches like this one.


Source: SecurityWeek — 2026-08-18