Heights Finance Data Breach Exposes 1.2 Million Users’ Info
Consumer lender Heights Finance Holdings Co. has informed over 1.2 million individuals that their personal and financial data was compromised in a cybersecurity incident.
Breach Details
Consumer lender Heights Finance Holdings Co. has informed over 1.2 million individuals that their personal and financial data was compromised in a cybersecurity incident. The breach was detected in early May when unauthorized access was identified to a third-party cloud-based platform utilized for customer data storage, according to an official statement. The company emphasized that its core loan management systems and internal networks remained unaffected, as the breach was confined to the external cloud infrastructure. Heights reported that it initiated incident response protocols immediately, engaged external cybersecurity experts for investigation, and notified federal law enforcement agencies.
Data Compromised
The attackers gained access to sensitive information, including names, residential addresses, phone numbers, Social Security numbers, government-issued identification details, driver’s license numbers, bank account information, account specifics, and dates of birth.
Affected Individuals
The company clarified that affected individuals include those who obtained loans through Heights, those who inquired about or applied for loan products (either directly or via third parties), and former borrowers of Curo Management or its affiliated brands. State-level notifications to attorney general offices indicate the breach impacted 734,828 individuals in Texas, 486,463 in South Carolina, 26 in New Hampshire, and 21 in Vermont.
Response Measures
To mitigate risks, Heights is offering affected parties 24 months of complimentary credit monitoring and identity protection services. The company stated that its dark web surveillance has not detected any dissemination of the stolen data. No specific threat actor has been identified, and no known ransomware or extortion groups have claimed responsibility for the attack.
Security Implications
The incident underscores the vulnerabilities associated with third-party cloud services and highlights the importance of continuous monitoring and response measures. Affected individuals are advised to remain vigilant against potential fraud and to utilize the provided protective services. No further details about the breach’s technical execution or the attackers’ methods have been disclosed.
The company emphasized that its core loan management systems and internal networks remained unaffected, as the breach was confined to the external cloud infrastructure.
