Heights Finance Breach Exposes Data of 1.2M People

Hackers accessed a third-party cloud platform in early May and stole personal and financial data, including Social Security numbers and bank account details, affecting 1.2 million people.

Heights Finance Holdings reported that hackers accessed a third-party cloud-based platform used to store customer data in early May and removed personal and financial information for more than 1.2 million people.

The company discovered unauthorized access in early May and secured the platform. Heights reported the incident was limited to the cloud platform and did not affect its loan management systems or other company networks. “It did not affect any of our loan management systems or other computer systems or networks. We immediately activated our incident response protocols, brought in outside cybersecurity specialists to investigate, and reported the incident to federal law enforcement,” the lender wrote.

Hackers accessed and removed a range of customer information that may include names, addresses, email addresses, phone numbers, Social Security numbers, government ID numbers, driver’s license numbers, bank account information, account details, dates of birth and other information customers provided.

Heights reported affected individuals may include anyone who received a loan through Heights, applied for or inquired about a loan product (including through third parties), or who was a former borrower of Curo Management or any related brands.

Notices filed with state attorneys general show the number of affected people exceeds 1.2 million. The filings list 734,828 impacted individuals in Texas and 486,463 in South Carolina, along with smaller counts in New Hampshire (26) and Vermont (21). The company did not provide a full nationwide breakdown beyond those notices.

Heights engaged outside cybersecurity specialists to investigate the incident and notified federal law enforcement. The company is offering 24 months of free credit monitoring and identity protection services to people whose information was exposed. Heights reported its monitoring of the dark web has not found evidence that the stolen information has been shared.

The company has not identified the party responsible for the breach, and security researchers have not observed any public claims of responsibility from known ransomware or extortion groups.

Heights is notifying affected customers by mail and said its core loan operations remain operational while it works to contain the incident and strengthen data protections.

Articles by this author