VYPR
breachPublished Aug 17, 2026· 1 source

Loan Company Breach Exposes Financial Data and SSNs of Nearly 750,000 Customers

Debt consolidator LoanMe, operating as Heights Finance, suffered a data breach in May, compromising sensitive financial information and Social Security numbers of approximately 750,000 individuals.

A significant data breach at debt consolidation company Heights Finance has exposed the sensitive financial information and Social Security numbers of nearly 750,000 individuals. The breach, discovered on May 7, impacted customers who had received a loan or inquired about loan products from the company and its related brands, including Curo Management.

The compromised data includes a wide range of personal and financial details. Attackers gained access to customer contact information such as addresses, banking details including account and routing numbers, and government-issued identification numbers like Social Security numbers, tax IDs, driver's license numbers, and state IDs. Any personal information shared during customer service interactions was also potentially accessed.

Heights Finance, which operates dozens of personal loan companies across Alabama, Tennessee, Georgia, Texas, and South Carolina, stated that the intrusion was limited to a third-party hosted cloud-based platform used for data storage. The company emphasized that its core loan management systems and other internal networks were not affected by the incident. "We have since confirmed that the cloud-based platform is secure and that there is no ongoing security threat," a company statement read.

While no specific hacking group has claimed responsibility for the attack, Heights Finance has engaged a cybersecurity firm to monitor the dark web for any signs of the stolen data being trafficked. As of the company's notification, the firm had not found any evidence of the compromised information appearing on dark web forums or marketplaces.

The breach affects a broad customer base, encompassing anyone who received a loan or expressed interest in loan products through Heights Finance or its associated entities. The company has over 285 offices spread across 11 states, underscoring the wide geographic reach of the affected customer pool.

This incident brings to light past scrutiny of Heights Finance. The company was previously sued by the federal government for allegedly targeting borrowers in financial distress, with prosecutors claiming the company generated more revenue from fees charged to struggling refinancers than from timely payers. That case was later dismissed.

Heights Finance has notified regulators and is working to inform affected customers about the breach and the potential risks. The company advises customers to remain vigilant against potential identity theft and financial fraud. Further details regarding the specific attack vector and the full extent of the compromise are still under investigation.

The incident serves as a stark reminder of the persistent threats facing financial institutions and the critical importance of robust security measures for third-party cloud storage solutions. The exposure of such sensitive data underscores the ongoing challenges in protecting customer information in an increasingly digitized financial landscape.

Synthesized by Vypr AI