Heights Finance Data Breach Hits 1.2 Million Borrowers

A consumer lender's cloud storage platform was broken into, exposing Social Security numbers, bank account details and driver's licence numbers for more than 1.2 million past and present customers.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A cloud storage platform interface with financial documents and personal identification information visible, with security breach indicators and exposed data st
Share

Key points

  • Heights Finance Holdings Co. Is notifying more than 1.2 million people after hackers stole personal and financial data from a third-party cloud storage platform in early May 2025.
  • Stolen records include Social Security numbers, bank account details, government ID numbers and driver's licence numbers.
  • Texas accounts for 734,828 of those affected; South Carolina accounts for 486,463.
  • No ransomware or extortion group has publicly claimed responsibility for the breach.
  • Heights is offering affected individuals 24 months of free credit monitoring and identity protection.

Heights Finance Holdings Co., a consumer lender offering personal loans across the southern United States, is notifying more than 1.2 million customers and former loan applicants that hackers stole their data from a third-party cloud storage platform. The company discovered the intrusion in early May. Attackers copied records and were locked out before Heights says they reached its core systems.

What information was taken?

Almost everything a lender holds on a borrower. Names, home addresses and phone numbers were exposed, along with Social Security numbers, government ID numbers, driver's licence numbers, bank account details and dates of birth.

The breach covers people who only enquired about or applied for a loan, not just those who completed one. Former borrowers of Curo Management and its associated brands are included.

State People notified
Texas 734,828
South Carolina 486,463
New Hampshire 26
Vermont 21

The figures come from formal notices Heights filed with state attorneys general, as first reported by SecurityWeek. Third-party cloud breaches have been a recurring theme in our coverage: the Snowflake campaign we reported on 5 August saw one attacker drain accounts from 165 companies by exploiting systems with no second login step.

Were Heights' own systems affected?

No. The breach was contained to the third-party platform. Heights says its loan management systems and internal networks weren't touched, external cybersecurity specialists investigated, and the incident was reported to federal law enforcement.

Should affected customers be worried?

Yes, practically speaking, though Heights says dark-web monitoring has found no sign the stolen data has been sold or published. That could change.

With Social Security numbers and bank account details in criminal hands, the realistic risks are identity theft (someone opening credit accounts in your name) and account fraud. Heights is offering 24 months of free credit monitoring and identity protection to everyone affected. Take it up.

Beyond that, anyone who received a notification letter should place a free credit freeze with Equifax, Experian and TransUnion. A freeze stops lenders from opening new accounts in your name without your explicit approval. It costs nothing and can be lifted whenever you need it.

No ransomware or extortion group has claimed responsibility, and Heights hasn't named who was behind the attack. Given the volume of records taken, the absence of a public claim is the detail worth watching.

© 2026 Threat Vectr