Published · 5d agoSecurity3 min read
Heights Finance says its loan systems held. 1.2 million records went anyway.
The lender reports no intrusion into its own networks. The loss happened inside a third-party cloud store holding Social Security numbers, bank details and files on people who only ever applied.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Heights Finance Holdings Co. is notifying over 1.2 million people that their personal and financial information was stolen in a data breach after hackers accessed a third-party cloud-based platform used for customer data storage.
- Heights says: "It did not affect any of our loan management systems or other computer systems or networks. We immediately activated our incident response protocols, brought in outside cybersecurity specialists to investigate, and reported the incident to federal law enforcement."
- Heights Finance said the breach was discovered on May 7 when a hacker gained access to a cloud-based platform hosted by a third party that it uses to store some customer data.
- Based on notices sent to Attorney General's Offices in several states, the affected counts are 734,828 in Texas, 486,463 in South Carolina, 26 in New Hampshire and 21 in Vermont.
- The four disclosed state notice figures sum to 1,221,338 individuals.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Consumer lender Heights Finance Holdings Co. is notifying more than 1.2 million people that their personal and financial information was stolen from a third-party cloud platform it used to store customer data [1]. The company also says the intrusion went no further: "It did not affect any of our loan management systems or other computer systems or networks" [2].
Both things are true, and that is the uncomfortable part. Every control that worked sat on the enterprise side of a boundary the attacker never needed to cross.
Heights discovered the access on May 7, when a hacker reached a cloud-based platform hosted by a third party where it kept some customer records [3]. State attorney general notices put the scale at 734,828 people in Texas, 486,463 in South Carolina, 26 in New Hampshire and 21 in Vermont [4], a total of 1,221,338 across those four filings [5]. Texas alone accounts for about 60 percent of that figure [6]. The Record, which reported the Texas notice, framed the incident around roughly 750,000 customers [7]; the multi-state tally is nearly twice that, which is what happens when disclosure arrives state by state.
What left the platform was a full identity kit: names, addresses, email addresses, phone numbers, Social Security numbers, government ID numbers, driver's license numbers, bank account information, account details and dates of birth [8]. According to The Record, the banking data ranged from account numbers to routing numbers, the government IDs included tax IDs and state IDs, and anything shared during customer service interactions was in scope as well [9].
Exposure was not limited to borrowers. Heights says information may be involved if a person received a loan, inquired about or applied for a loan product including through a third party, or was a former borrower of Curo Management or any of its former or current related brands [10]. A vendor data store was therefore holding declined applicants and legacy-brand records, which is a retention decision, not an incident.
Note where the assurances point. The platform has been secured and there is no ongoing security threat, per Heights [11]. Its retained specialist is scanning dark web forums and marketplaces and has found no evidence the stolen data has surfaced [12]. Affected individuals get 24 months of credit monitoring and identity protection [13]. Every one of those statements describes systems and outcomes the lender does not operate or control. No threat actor has been named, and SecurityWeek has seen no ransomware or extortion group claim the breach [14], which drains most of the reassurance out of a clean dark web scan: data quietly sold does not get posted.
Heights is a substantial operation, Greenville-based with more than 285 offices across 11 states [15] and dozens of personal loan companies in Alabama, Tennessee, Georgia, Texas and South Carolina [16]. The Record also notes the company was sued by the federal government over refinancing practices, with prosecutors alleging it targeted borrowers struggling to repay in order to harvest fees from "frequent, payment-stressed refinancers" [17], and that the case was dismissed shortly after the Trump administration took office [18].
Watch for the platform to be named, because neither published account identifies it or its operator [19], and a shared store with 1.2 million records from one tenant likely has other tenants. Watch the state-by-state totals climb past 1,221,338 as more attorneys general post notices [5]. And watch whether an extortion claim ever appears; if it does not, the negative dark web finding will have proven nothing.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Heights Finance Holdings Co. is notifying over 1.2 million people that their personal and financial information was stolen in a data breach after hackers accessed a third-party cloud-based platform used for customer data storage.
ReportedView cited source - [2]
Heights says: "It did not affect any of our loan management systems or other computer systems or networks. We immediately activated our incident response protocols, brought in outside cybersecurity specialists to investigate, and reported the incident to federal law enforcement."
- [3]
Heights Finance said the breach was discovered on May 7 when a hacker gained access to a cloud-based platform hosted by a third party that it uses to store some customer data.
ReportedView cited source - [4]
Based on notices sent to Attorney General's Offices in several states, the affected counts are 734,828 in Texas, 486,463 in South Carolina, 26 in New Hampshire and 21 in Vermont.
ReportedView cited source - [7]
The Record reported that cybercriminals breached the cloud system of the debt consolidation loan company in May, stealing sensitive financial and personal data on about 750,000 customers, and that Heights told regulators in Texas that 734,828 people were affected.
- [8]
The stolen data included names, addresses, email addresses, phone numbers, Social Security numbers, government ID numbers, driver's license numbers, bank account information, account details, dates of birth and other information customers shared with the company.
ReportedView cited source
Sources & coverage · 5 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- therecord.media5d agoNearly 750k had financial info, SSNs leaked in South Carolina loan company breach
- securityweek.comIonut Arghire5d agoHeights Finance Data Breach Impacts at Least 1.2 Million Individuals
- malwarebytes.com5d agoHeights Finance data breach: What customers need to know



