Skip to content

Security5 publishers3 min readPublished Updated

Heights Finance says its loan systems held. 1.2 million records went anyway.

The lender reports no intrusion into its own networks. The loss happened inside a third-party cloud store holding Social Security numbers, bank details and files on people who only ever applied.

The Watch · Security desk

Illustration accompanying Heights Finance says its loan systems held. 1.2 million records went anyway.

What happened

  • Heights Finance Holdings Co. is notifying over 1.2 million people that their personal and financial information was stolen in a data breach after hackers accessed a third-party cloud-based platform used for customer data storage.
  • Heights says: "It did not affect any of our loan management systems or other computer systems or networks. We immediately activated our incident response protocols, brought in outside cybersecurity specialists to investigate, and reported the incident to federal law enforcement."
  • Heights Finance said the breach was discovered on May 7 when a hacker gained access to a cloud-based platform hosted by a third party that it uses to store some customer data.
  • Based on notices sent to Attorney General's Offices in several states, the affected counts are 734,828 in Texas, 486,463 in South Carolina, 26 in New Hampshire and 21 in Vermont.
  • The four disclosed state notice figures sum to 1,221,338 individuals.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Consumer lender Heights Finance Holdings Co. is notifying more than 1.2 million people that their personal and financial information was stolen from a third-party cloud platform it used to store customer data [1]. The company also says the intrusion went no further: "It did not affect any of our loan management systems or other computer systems or networks" [2].

Both things are true, and that is the uncomfortable part. Every control that worked sat on the enterprise side of a boundary the attacker never needed to cross.

Heights discovered the access on May 7, when a hacker reached a cloud-based platform hosted by a third party where it kept some customer records [3]. State attorney general notices put the scale at 734,828 people in Texas, 486,463 in South Carolina, 26 in New Hampshire and 21 in Vermont [4], a total of 1,221,338 across those four filings [5]. Texas alone accounts for about 60 percent of that figure [6]. The Record, which reported the Texas notice, framed the incident around roughly 750,000 customers [7]; the multi-state tally is nearly twice that, which is what happens when disclosure arrives state by state.

What left the platform was a full identity kit: names, addresses, email addresses, phone numbers, Social Security numbers, government ID numbers, driver's license numbers, bank account information, account details and dates of birth [8]. According to The Record, the banking data ranged from account numbers to routing numbers, the government IDs included tax IDs and state IDs, and anything shared during customer service interactions was in scope as well [9].

Exposure was not limited to borrowers. Heights says information may be involved if a person received a loan, inquired about or applied for a loan product including through a third party, or was a former borrower of Curo Management or any of its former or current related brands [10]. A vendor data store was therefore holding declined applicants and legacy-brand records, which is a retention decision, not an incident.

Note where the assurances point. The platform has been secured and there is no ongoing security threat, per Heights [11]. Its retained specialist is scanning dark web forums and marketplaces and has found no evidence the stolen data has surfaced [12]. Affected individuals get 24 months of credit monitoring and identity protection [13]. Every one of those statements describes systems and outcomes the lender does not operate or control. No threat actor has been named, and SecurityWeek has seen no ransomware or extortion group claim the breach [14], which drains most of the reassurance out of a clean dark web scan: data quietly sold does not get posted.

Heights is a substantial operation, Greenville-based with more than 285 offices across 11 states [15] and dozens of personal loan companies in Alabama, Tennessee, Georgia, Texas and South Carolina [16]. The Record also notes the company was sued by the federal government over refinancing practices, with prosecutors alleging it targeted borrowers struggling to repay in order to harvest fees from "frequent, payment-stressed refinancers" [17], and that the case was dismissed shortly after the Trump administration took office [18].

Watch for the platform to be named, because neither published account identifies it or its operator [19], and a shared store with 1.2 million records from one tenant likely has other tenants. Watch the state-by-state totals climb past 1,221,338 as more attorneys general post notices [5]. And watch whether an extortion claim ever appears; if it does not, the negative dark web finding will have proven nothing.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories