VYPR
breachPublished Aug 18, 2026· 1 source

Heights Finance Data Breach Exposes Sensitive Information of Over 1.2 Million Individuals

Consumer lender Heights Finance is notifying over 1.2 million people that their personal and financial information was stolen in a data breach originating from a third-party platform.

Consumer lender Heights Finance Holdings Co. is in the process of notifying more than 1.2 million individuals that their sensitive personal and financial data was compromised in a significant data breach.

The incident came to light in early May when Heights Finance discovered unauthorized access to a third-party cloud-based platform that was being used for the storage of customer data. The company stated that the platform has since been secured and that its core operations were not impacted by the breach, as the compromise was confined to the external cloud service.

"It did not affect any of our loan management systems or other computer systems or networks," Heights said in a statement. "We immediately activated our incident response protocols, brought in outside cybersecurity specialists to investigate, and reported the incident to federal law enforcement."

The attackers successfully accessed and exfiltrated a wide array of personal and financial information. This includes names, addresses, email addresses, phone numbers, Social Security numbers, government identification numbers, driver's license numbers, bank account details, account information, dates of birth, and other data that customers had provided to the company. The lender noted that individuals who received, inquired about, or applied for a loan through Heights, or former borrowers of Curo Management and its related brands, may have had their data involved.

Official notices sent to state Attorneys General's Offices indicate that at least 1.2 million individuals have been affected. Specifically, the breach impacted 734,828 individuals in Texas, 486,463 in South Carolina, 26 in New Hampshire, and 21 in Vermont. The full scope of affected individuals across all states is still being determined.

In response to the breach, Heights Finance is offering affected individuals 24 months of complimentary credit monitoring and identity protection services. The company also stated that its monitoring of the dark web has not yet revealed any evidence that the stolen information has been shared or sold by the attackers.

As of the reporting, Heights Finance has not publicly identified the threat actor responsible for the data breach, and no known ransomware or extortion groups have claimed responsibility for the incident. This breach underscores the persistent risks associated with third-party data storage and the critical importance of robust supply chain security measures for financial institutions.

The incident serves as a stark reminder of the ongoing threat landscape, where sensitive personal and financial data remains a prime target for cybercriminals. The compromise of such extensive data sets can lead to identity theft, financial fraud, and other malicious activities, necessitating vigilant security practices from both organizations and consumers.

Synthesized by Vypr AI