Heights Finance Data Breach Exposes Data of 750,000 Customers
A cloud system breach at **Heights Finance**, a prominent debt consolidation loan company, has compromised the sensitive financial and personal data of approximately 750,000 customers. The incident, discovered in May, involved unauthorized access to a third-party hosted platform, exposing a wide range of personal identifiers and banking information.
Cybercriminals successfully infiltrated the cloud-based platform utilized by **Heights Finance**, leading to a significant data breach affecting nearly three-quarters of a million individuals. The company, which operates numerous personal loan entities across several U.S. states, confirmed the breach last week and subsequently notified Texas regulators of the incident's scope.
### Extensive Data Compromised
The stolen data is comprehensive, encompassing critical personal and financial details. This includes contact information such as addresses, sensitive banking data like account and routing numbers, and government-issued identification numbers, including Social Security numbers, tax IDs, driverβs license numbers, or state IDs. Any personal information shared during customer service interactions was also compromised.
### Breach Limited to Cloud Platform
**Heights Finance** stated that the breach was identified on May 7, when an unauthorized actor gained access to a specific cloud-based platform. "This activity was limited to the cloud-based platform only β it did not affect any of our loan management systems or other computer systems or networks," the company clarified. They have since asserted that the compromised platform has been secured and that there is no ongoing security threat.
### Widespread Impact
The breach's impact extends to anyone who has either received a loan through **Heights Finance** or inquired about a loan product via a third party. This also includes certain customers associated with its parent company, **Curo Management**, and its related brands.
### Dark Web Monitoring Underway
As of now, no specific hacking group has claimed responsibility for the cyberattack. **Heights Finance** has engaged a cybersecurity firm to actively monitor the dark web for any signs of the stolen information. The Greenville, South Carolina-based company reported, "Our specialist is actively scanning dark web forums, marketplaces, and other platforms. As of this writing, they have not found any evidence that information involved in this incident is on the dark web."
### Past Regulatory Scrutiny
**Heights Finance**, which maintains over 285 offices across 11 states, has faced regulatory challenges in the past. The company was previously sued by the federal government for allegedly targeting vulnerable borrowers who were struggling to repay existing loans, coercing them into refinancing to avoid delinquency. Federal prosecutors had argued that the company generated more revenue from frequent, payment-stressed refinancers than from timely re-payers. This case was dismissed following the change in administration.