US consumer lender Heights Finance has disclosed a data breach affecting more than 1.2 million customers, loan applicants, and former borrowers after hackers gained unauthorised access to a third-party cloud platform used to store customer records. Regulatory filings that surfaced this week put the exposed dataset among the largest finance-sector disclosures of the month, with Social Security numbers, bank account and routing numbers, driver’s licence numbers, and dates of birth all confirmed as compromised.
What happened
Heights Finance, which operates through subsidiary Curo Management and related consumer-lending brands, discovered the intrusion on May 7, 2026. The compromise was limited to a third-party, cloud-hosted platform used for customer data storage; the company says its internal loan management systems and broader network were not affected. Following a forensic investigation, Heights began notifying state attorneys general and affected individuals from August 11 onward, with filings to Vermont on August 11 and Texas on August 14.
State-level notifications confirm at least 734,828 affected individuals in Texas and 486,463 in South Carolina, alongside smaller counts in Vermont and New Hampshire — more than 1.2 million from those four states alone, with the true national total likely higher once remaining state filings are accounted for.
What was exposed
The compromised records include names, home addresses, phone numbers, email addresses, Social Security numbers, tax identification numbers, driver’s licence or state ID numbers, dates of birth, bank names, and account and routing numbers. Some records also reportedly included details shared during customer service interactions. This is a high-value combination for identity theft and account takeover fraud: attackers holding SSNs alongside bank account and routing numbers can attempt both new-account fraud and direct unauthorised transactions.
No ransomware group or extortion actor has publicly claimed responsibility, and Heights Finance says dark web monitoring has found no evidence the stolen data has been published or offered for sale to date. That absence of a claim does not rule out a financially motivated actor operating quietly, or a sale conducted through private channels rather than public leak sites.
Why it matters for finance
The incident is another reminder that a lender’s own security posture is only as strong as its weakest third-party integration. Heights Finance’s core systems were reportedly untouched — the exposure came entirely through an outsourced cloud storage platform, underscoring how vendor and supply-chain risk continues to be the primary breach vector for consumer finance firms handling large volumes of sensitive applicant data. With over three months elapsing between discovery (May 7) and public disclosure (mid-August), affected consumers had an extended window during which stolen data could have circulated before receiving notice or credit monitoring.
Recommended actions
- Finance and lending firms should inventory all third-party and cloud platforms holding customer PII, and confirm contractual breach-notification and audit rights extend to those vendors, not just internal systems.
- Consumers notified by Heights Finance should enrol in the offered 24-month credit monitoring and identity protection service, place a credit freeze with the major bureaus, and monitor bank accounts for unauthorised activity.
- Security teams at similarly structured lenders should review data minimisation practices for third-party platforms — limiting what SSNs, bank details, and ID numbers are retained outside core, more tightly controlled systems reduces the blast radius of any single vendor compromise.
- Incident response planners should benchmark disclosure timelines against this case: a three-month gap between discovery and notification is within common regulatory limits but leaves affected individuals exposed longer than best practice recommends.