Heights Finance breach may expose Social Security and bank data for loan customers
Heights Finance said an intruder reached a third-party cloud platform holding customer information, with a Texas filing citing about 735,000 people. Potentially exposed data can include Social Security numbers, bank account details, and contact information.
Heights Finance Holdings told customers that an unauthorized party accessed a third-party cloud platform used to store loan-related information, according to the company breach notice and Malwarebytes reporting on Aug. 18.
The firm discovered the intrusion on May 7. Investigators found the intruder may have viewed or copied data in that cloud environment. A Texas regulatory filing cited by The Record and summarized by Malwarebytes mentioned 734,828 affected people. That figure should not be treated as a final nationwide total because Heights operates personal loan companies across several states, including Alabama, Tennessee, Georgia, Texas, and South Carolina.
People who may be affected include Heights Finance borrowers, people who inquired about or applied for loans, and some customers tied to former parent company CURO Management and related brands.
Data that may have been exposed includes names, addresses, phone numbers, emails, bank names, account and routing numbers, Social Security numbers, tax IDs, driver licenses or state IDs, dates of birth, and personal details shared in customer service talks. That mix is useful to identity thieves and phishing crews.
Heights Finance posted instructions and protection enrollment details on its website. People who get a letter should follow those steps. Anyone who thinks they may be included but has no letter should use contact methods published on the official site, not a number from an unexpected text, email, or search ad.
After a breach like this, criminals often send fake help desk calls or refund offers. Hang up on surprise callers. Monitor bank and credit accounts. Consider a credit freeze with the major bureaus if your Social Security number may be involved.
Go Deeper
What company was breached?
Heights Finance Holdings, a consumer installment lender with operations in several Southern states and ties to former CURO-related brands.
How many people may be affected?
A Texas filing cited about 734,828 people. Malwarebytes cautioned that the number may not equal a final nationwide count.
What data is at risk?
Contact details, bank account information, Social Security or tax IDs, driver licenses, dates of birth, and other personal notes from customer service.
When was it found?
Heights Finance said it discovered unauthorized access to a third-party cloud platform on May 7.
What should I do today?
Read only official Heights Finance notices, enroll in offered monitoring if eligible, watch accounts for fraud, and ignore cold calls that claim to fix the breach for a fee.
More us
Amazon job scam texts promise hundreds a day for short remote work
Scammers are again sending texts that claim to be Amazon recruiters offering hundreds of dollars a day for about 90 minutes of remote work. Cybersecur
Aug 18usCBP San Diego seizes about 67 million dollars in drugs across July busts
Customs and Border Protection officers in the San Diego Field Office seized 8,359 pounds of narcotics during 144 smuggling attempts in July, DHS said.
Aug 18usPentagon orders 30 universities to audit foreign ties by August 31
The Defense Department ordered 30 U.S. universities to review academic, financial, and research ties to foreign entities of concern by Aug. 31 or risk
Aug 18