Skip to content
Beveiligingsnieuws

Heights Finance data breach: 1.2 million affected

Heights Finance datalek

A consumer lender is warning customers and other potentially affected individuals after a Heights Finance data breach involving stolen personal and financial information. The company says the incident impacted at least 1.2 million people and that it was caused by unauthorized access to a third-party cloud-based system used to store customer data.

In an incident notice, Heights Finance Holdings Co. explained that the discovery happened in early May. According to the notice, hackers gained access to the third-party platform that supports customer data storage, rather than directly entering the lender’s core systems.

What happened in the Heights Finance data breach

Heights says the intrusion targeted a cloud-based platform used for storing customer information. After identifying the issue, the company stated that it secured the platform and that its day-to-day operations were not disrupted because the incident was limited to the third-party environment.

To reinforce its response, Heights reports that it activated incident response protocols immediately and engaged external cybersecurity specialists to investigate the activity. The company also said it reported the incident to federal law enforcement.

In its statement, Heights emphasized that the event did not impact its loan management systems or other computer systems and networks.

Which data attackers accessed

During the incident, the attackers accessed and stole a range of personal and financial details. The information mentioned in the notification includes both contact and identity data, as well as account-related records.

Based on the notice, affected information may include:

  • Names and addresses
  • Email addresses and phone numbers
  • Social Security numbers
  • Government ID numbers
  • Driver’s license numbers
  • Bank account information
  • Account details
  • Dates of birth
  • Other information customers shared with the company

Because the breach involved data stored in a third-party platform, customers may be notified if their records were present there at the time of the incident.

Who may be affected

Heights’ notice indicates the potential for involvement depends on how a person interacted with the lender and related entities. The company says information may be involved if someone received a loan through Heights or if they inquired about or applied for a loan product, including through a third party.

The company also notes that data may be involved for people who were former borrowers of Curo Management or any of its former or current related brands. That language broadens the possible pool beyond only recent customers.

Estimated number of impacted individuals by state

According to information referenced in notices sent to Attorney General’s Offices in multiple states, more than 1.2 million individuals have potentially been affected. Heights listed the following state-level figures:

  • Texas: 734,828
  • South Carolina: 486,463
  • New Hampshire: 26
  • Vermont: 21

These numbers reflect the counts cited in the state notifications, and they align with the company’s overall statement that the incident affects at least 1.2 million people.

Credit monitoring and identity protection offered

Heights says it is providing support to impacted individuals. The company is offering 24 months of free credit monitoring and identity protection services.

This type of service is typically designed to help people detect potential misuse of personal data and respond more quickly if fraudulent activity occurs.

Dark web monitoring and public claims

The lender also addressed what it has found after monitoring related to the incident. Heights reports that its dark web monitoring has found no evidence that the stolen information has been shared.

In addition, Heights has not publicly named the threat actor behind the breach. SecurityWeek also reports that it has not seen any known ransomware or extortion group claiming responsibility.

While the absence of a public claim and no observed sharing does not eliminate risk, it suggests that the attacker’s actions may have been limited to theft and that widespread disclosure has not been confirmed.

Why third-party cloud systems increase breach risk

This incident highlights a common challenge for organizations that rely on third-party services. When customer data is stored or processed through external platforms—especially cloud-based systems—an attacker may attempt to compromise the supplier instead of breaking into the customer-facing organization directly.

Heights’ statement that it did not affect its loan management systems or other internal networks indicates that the compromise was contained to the third-party environment. However, even contained access can still be damaging when the third-party platform holds sensitive information.

What impacted individuals should consider next

If you receive a notice tied to the Heights Finance data breach, focus on practical steps during the remediation period:

  • Enroll in the credit monitoring and identity protection services offered by the company.
  • Review account activity regularly and watch for unusual transactions or changes to personal records.
  • Be cautious about phishing or scam messages that reference the breach.
  • Store the notification materials and keep track of timelines for when protection services begin.

Even when monitoring tools report no evidence of data sharing, stolen identifiers such as Social Security numbers and government IDs can remain valuable for fraud attempts over time.

Bottom line

The Heights Finance data breach stems from unauthorized access to a third-party cloud platform used to store customer data. Heights says the incident did not affect its core loan management systems and that it has secured the affected environment and launched an investigation with specialized help.

Still, the company reports that stolen data may involve at least 1.2 million people, including sensitive identity and account information. With 24 months of monitoring and identity protection, Heights is aiming to reduce harm while authorities and cybersecurity teams assess the broader impact.

Source: https://www.securityweek.com/heights-finance-data-breach-impacts-at-least-1-2-million-individuals/