Heights Finance Data Breach Hits 1.2 Million Borrowers

A consumer lender's cloud storage platform was broken into, exposing Social Security numbers, bank account details and driver's licence numbers for more than 1.2 million past and present customers.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Heights Finance Holdings Co. is notifying more than 1.2 million people after hackers stole personal and financial data from a third-party cloud storage platform in early May 2025.
  • Stolen records include Social Security numbers, bank account details, government ID numbers and driver's licence numbers.
  • Texas accounts for 734,828 of those affected; South Carolina accounts for 486,463.
  • No ransomware or extortion group has publicly claimed responsibility for the breach.
  • Heights is offering affected individuals 24 months of free credit monitoring and identity protection.

Heights Finance Holdings Co., a consumer lending company that offers personal loans across the southern United States, is notifying more than 1.2 million customers, former borrowers and loan applicants that their data was stolen in a breach of a third-party cloud storage platform, meaning an outside company's internet-based system used to store Heights' customer files.

The company says it discovered the intrusion in early May. Hackers broke into the cloud platform and copied records before Heights locked them out.

What information was taken?

Almost everything a lender holds on a borrower. Names, home addresses, email addresses and phone numbers were exposed, along with Social Security numbers, government ID numbers, driver's licence numbers, bank account information and dates of birth.

Heights says the breach also covers people who only enquired about or applied for a loan, not just those who completed one. Former borrowers of Curo Management, a related company, and its associated brands are included too.

State People notified
Texas 734,828
South Carolina 486,463
New Hampshire 26
Vermont 21

The figures come from formal notices Heights filed with state attorneys general, as first reported by SecurityWeek.

Were Heights' own systems affected?

Heights says no. The breach was contained to the third-party cloud platform. Its loan management systems and internal networks were not touched, the company says, and normal operations continued throughout.

External cybersecurity specialists were brought in to investigate, and the incident was reported to federal law enforcement.

Should affected customers be worried?

Yes, in a practical sense, though Heights says its dark-web monitoring has found no sign that the stolen data has been sold or published. That could change.

With Social Security numbers and bank account details in criminal hands, the realistic risks are identity theft (where someone opens credit accounts in your name) and account fraud. Heights is offering 24 months of free credit monitoring and identity protection to everyone affected. Take it up.

Beyond that, people who received a notification letter should place a free credit freeze with each of the three major US credit bureaus, Equifax, Experian and TransUnion. A credit freeze stops lenders from opening new accounts in your name without your explicit approval. It costs nothing and can be lifted whenever you need it.

No ransomware or extortion group has claimed responsibility, and Heights has not publicly named who was behind the attack.

© 2026 Threat Vectr