Heights Finance disclosed a data breach affecting 734,828 people, with reporting describing the total as nearly 750,000 customers and loan applicants. The company said it discovered an intrusion on May 7 involving a third-party hosted cloud-based platform used to store some customer data, and later notified regulators and published a breach notice. Affected individuals include people who received a loan through Heights Finance or inquired about loan products through a third party, as well as some customers tied to parent company Curo Management and related brands.
Exposed information included contact details, banking information, government identification numbers such as Social Security numbers, and personal information shared during customer service interactions. Heights Finance said its loan management systems and other internal networks were not affected, and that the compromised cloud platform has since been secured. The company also said no threat actor had claimed responsibility and that, at the time of its notice, investigators had not found the stolen data on dark web sites.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Heights Finance published a warning to customers about the breach, stating that exposed data included contact details, banking information, government identification numbers, and information shared during customer service interactions. The notice also said the compromised cloud platform had been secured and that dark web monitoring had not found the stolen data.
Heights Finance told Texas regulators that 734,828 people were affected by the breach, including loan recipients, loan applicants through third parties, and some customers of parent company Curo Management and related brands. Reporting described the impact as nearly 750,000 people.
A South Carolina breach notice disclosed the Heights Finance incident to affected residents, describing the same third-party cloud platform compromise and offering 24 months of complimentary credit monitoring and identity protection through Epiq. This state filing helped document the breach's impact beyond Texas and contributed to the later total exceeding 1.2 million affected individuals.
State breach notices showed the Heights Finance incident affected more than 1.2 million individuals in total, including 734,828 in Texas and 486,463 in South Carolina, with smaller counts in New Hampshire and Vermont. The expanded disclosures significantly increased the known scope of the breach beyond the earlier Texas-only filing.
Heights Finance said it discovered on May 7 that a hacker had gained access to a third-party hosted cloud-based platform used to store some customer data. The company stated the incident was limited to that platform and did not affect its loan management systems or other internal networks.
After discovering the unauthorized access, Heights Finance said it activated incident response procedures, brought in external cybersecurity specialists, and reported the incident to federal authorities. The company also said operations continued normally while the affected cloud platform was secured.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcesecurityweek.com
Open sourcecyberveille.ch
Open sourcetherecord.media
Open sourceheightsfinance.com
Open sourceconsumer.sc.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.