← Blog

Heights Finance Breach: 734,828 SSNs and Bank Data Exposed

Share on X

Heights Finance told Texas regulators that 734,828 people had personal and financial data exposed after an unauthorized actor reached a third-party cloud platform on 7 May 2026. The company’s own notice of data breach, dated 11 August, lists Social Security numbers, bank account and routing numbers, driver’s licenses, and customer-service notes among the fields that “may include” an individual’s record. Recorded Future News published the Texas census on 18 August.

If you took a Heights personal loan, applied or even inquired through a partner, or used a former Curo Management brand, treat this as a real identity-theft event — not a “maybe they got an email.” Canonical record: heights-finance-cloud2026.

What happened in the Heights Finance data breach

Heights Finance Holdings Co., a Greenville, South Carolina installment lender with more than 285 offices across 11 states, says it discovered the incident on 7 May. An unauthorized actor gained access to “a cloud-based platform hosted by a third party that we use to store certain customer data.” Heights says that activity stayed on the cloud platform. It did not reach loan-management systems or other company networks.

The company activated incident response, hired outside specialists, and reported the matter to federal law enforcement. By the August notice it said the cloud platform was secure again and that operations had never stopped. No ransomware group has claimed the job in public reporting, and Heights has not named the cloud vendor.

That last gap matters. Borrowers cannot tell whether the stolen store was a CRM, a document vault, a collections workspace, or a marketing lake. Heights’ own wording is “certain customer data.” The field list is what you act on. The unnamed host is what security teams will keep asking about.

The 11 August letter did not publish a headcount. The Record, citing Heights’ Texas filing on Friday 14 August, is how the 734,828 figure entered English-language coverage. BreachHistory stores that regulator-attested census. It is not an actor claim.

What data was exposed — and what was not

Heights says the specific mix varies by person, but a record “may include one or more” of:

  • Name, address, phone number, or email
  • Account details; bank name, account number, and routing number; related financial data
  • Social Security number, tax ID, driver’s license number, or state ID
  • Date of birth
  • Information “voluntarily provided” in customer-service interactions, including personal circumstances

That is a full identity kit plus live bank rails. A stolen SSN plus DOB is tax-return and credit-file fraud. A stolen routing and account number is ACH and debit-order fraud. A stolen driver’s license number is fake-KYC. Customer-service notes are the part people underestimate: hardship stories, co-signer names, workplace details, and “please call this number instead” remarks become scripts for a collections impersonator.

What Heights says was not hit: loan-management systems and other computers or networks. Read that narrowly. It means the core servicing stack, as Heights defines it, was not the entry point. It does not mean payment data never sat in the cloud copy. The notice explicitly lists bank account and routing numbers as possible cloud contents.

Heights also says a dark-web monitor had not found the stolen set for sale “as of this writing.” That is a snapshot, not a guarantee. Data from May can sit private for months. Treat “not on a forum yet” as unfinished, not as clearance.

Who is in the file

The notice is broader than “current Heights borrowers.” Your information may be involved if:

  • You received a loan through Heights
  • You inquired about or applied for a loan product, including through a third party
  • You were a former borrower of Curo Management or any of its former or current related brands

The inquiry clause is easy to miss. People who walked into a store, started an online form, or were referred by a lead generator can be in a cloud CRM even if they never signed a note. Former Curo borrowers are in scope because Heights’ parent history includes the 2021 CURO acquisition of Heights and later brand consolidation. If you paid off a Southern / Heights / Curo-family installment loan years ago, do not assume you aged out of the file.

The Record notes Heights operates personal-loan shops in Alabama, Tennessee, Georgia, Texas, and South Carolina, among other states in the 11-state footprint. Texas is where the 734,828 number was filed. Other state AGs may still post their own letters; the company notice already includes Iowa, Maryland, New York, North Carolina, Oregon, Rhode Island, and Washington, D.C. addenda.

Timeline

  1. 7 May 2026 — Heights discovers unauthorized access to the third-party cloud store.
  2. May–August — Investigation, law-enforcement report, dark-web monitoring, Epiq contract. Heights says the investigation is complete by the time of the letter.
  3. 11 August 2026 — Company notice posted at heightsfinance.com/importantinfo. Complimentary 24-month Epiq monitoring offered; enrollment deadline 9 November 2026.
  4. 14 August 2026 — Heights tells Texas regulators 734,828 people were affected, per The Record.
  5. 18 August 2026 — Recorded Future News publishes the census and field list for a national audience.

Three months from discovery to a public letter is slow for the people whose bank numbers sat in that cloud in May. It is not unusual for a third-party host investigation plus multi-state notice drafting. Do not wait for a paper envelope to freeze credit. The August letter is the start of customer action, not the start of attacker possession.

How the attack worked — what is known

Heights has not published a CVE, a phishing narrative, or a named cloud product. The confirmed path is: third-party hosted platform; unauthorized actor; view or copy of stored customer fields; containment limited to that platform.

That pattern is the consumer-finance version of a CRM or document-store breach. Lenders often park applications, ID images, and ACH details in a vendor SaaS because branches and lead partners need access. The vendor becomes the blast radius. Heights’ insistence that “loan management systems” were untouched is meant to reassure people that live loan balances were not rewritten. It does not shrink the identity file.

Unknowns that still matter:

  • Which vendor hosted the platform, and whether other CURO-legacy brands used the same tenant
  • How long the actor had access before 7 May
  • Whether access was credential stuffing, a stolen staff login, or a vendor misconfiguration
  • Whether ID document images were in the store, or only the numbers Heights listed
  • Whether the 734,828 figure is unique people or unique notice rows across brands

None of those gaps change the first-week checklist: freeze credit, watch bank accounts, treat Heights-branded calls as hostile until you originate them.

Who is at risk

Current and former Heights borrowers. If you have an active loan, assume name, SSN, and bank rails may be out. Watch for fake “your ACH failed — update routing” texts that quote a real last-four.

People who only applied or inquired. A declined or abandoned application is still a data row. You may never get a servicing email, so the first signal might be the breach letter — or a tax-refund scam that already has your SSN.

Former Curo Management / related-brand customers. Heights explicitly pulled that population into scope. If you are not sure which brand owned your 2018 installment loan, enroll in the monitoring and freeze anyway.

Co-signers, household members, and people named in service notes. The notice covers information “voluntarily provided” in customer-service interactions. A spouse’s workplace, a relative’s phone, or a hardship story can sit next to the borrower SSN.

Branch staff and lead-gen partners. An incident this size produces help-desk phishing: “IT needs you to re-auth the cloud platform.” Verify out of band.

Everyone else seeing the headline. Copycat mail will target people who never heard of Heights. If you did not borrow, apply, or get a letter, you are not automatically in the 734,828. You are still a target for generic “Heights Finance data breach — click to freeze” kits.

Why bank routing data is the urgent piece

Plenty of 2026 breaches leak SSNs. Fewer also hand over routing number plus account number in the same row. That combination lets a thief attempt ACH pulls, fake payroll deposits, and “verify your Heights payment” pages that look like they already know your bank.

Practical steps that are specific to this file:

  • Log into your bank app yourself and enable alerts for ACH, new payees, and e-statement changes
  • If Heights still auto-debits you, confirm the company-originated debit against your loan portal — do not “update bank” from SMS
  • Ask your bank about ACH blocks or positive pay if you start seeing unfamiliar company names
  • Treat a call that recites your routing last-four as proof of a leak, not proof the caller is Heights

Heights says loan-management systems were not affected. That is about Heights’ own ledgers. It is not a promise that your bank will refuse a forged ACH that uses leaked coordinates.

Credit freeze, fraud alert, and the Epiq offer

Heights is paying for 24 months of Epiq Privacy Solutions ID: one-bureau credit monitoring, dark-web monitoring of one email/phone/name/DOB/SSN, freeze assistance, NCOA watching, and identity restoration. Enrollment closes 9 November 2026.

How to enroll, per the notice: call Heights at 877-343-7785 (weekdays 9 a.m.–9 p.m. ET) for an activation code, then activate at privacysolutionsid.com. Epiq’s help line is 866-675-2006. You will get a follow-up from [email protected]. The product may not be available without established U.S. credit, a U.S. address, or a valid SSN.

A freeze at Equifax, Experian, and TransUnion is still the stronger default. Monitoring tells you after a new account appears. A freeze tries to stop the account. Do both if you can stand the extra PIN paperwork. A one-year fraud alert is the middle option if you need to keep opening credit this month.

Phishers will clone the enrollment flow. They will ask you to “confirm SSN to get your Epiq code.” Heights’ published path is: call the printed 877 number first, then the Epiq site. Do not start from a Google ad titled “Heights Finance breach checker.”

What Heights, lawyers, and regulators have said

Heights’ public voice is the August notice. It apologizes in corporate form, stresses the cloud-only scope, points at Epiq, and lists FCRA freeze language. The Record added the Texas 734,828 filing and the company’s statement that no group had claimed the incident and that dark-web scans were clean at the time of writing.

Class-action firms posted investigation pages within days of the notice. Those pages are not a census and not a regulator finding. If you want a legal path, that is separate from the freeze. This catalog row is the incident, not a lawsuit tracker.

The Record also recapped Heights’ earlier CFPB case over refinancing practices; that case was later dismissed. It is company history, not a cause of the May cloud access. Do not confuse a 2023 consumer-lending complaint with a 2026 third-party breach.

No HHS OCR filing belongs here. This is consumer-finance PII, not a HIPAA covered-entity dump. State AGs and the FTC identity-theft process are the consumer channels Heights itself lists.

Industry context: lenders, clouds, and 2026 SSN files

Installment lenders sit on exactly the fields criminals price highest: people who already need cash, plus SSNs, plus bank accounts used for repayment. A cloud CRM that also holds “personal circumstances” from hardship calls is a collections-scam factory.

Related catalog rows in the same neighborhood: AssuranceAmerica’s 6.99 million driver’s-license file, Connex Credit Union’s 172,000 members with SSNs, Frontwave Credit Union member names and SSNs via a service provider, and American Lending Center ransomware notices. TaxAct’s unverified ~2 million / 450k leak claim is a different mechanism — an API allegation, not a confirmed cloud vendor — but it is the other late-summer file where tax IDs and contact data are the prize.

Third-party storage is the repeating design. Heights, Frontwave, and a long list of 2025–2026 AG letters describe the same sentence: “a vendor we use to store customer information.” Borrowers never chose that vendor. The freeze is how you respond when the vendor is still unnamed.

Was I affected?

There is no public email-lookup portal. Signals that you are likely in the 734,828:

  • A Heights or Epiq letter / the 877-343-7785 enrollment path addressed to you
  • A Heights, Southern, or Curo-family loan or application in the years the cloud store covered (Heights has not published the oldest record date)
  • Texas or other AG notice language that matches the 11 August field list

If none of those apply, you are probably outside this extract. Still ignore “Heights Finance: confirm your routing number” mail. Attackers mix real victim lists with purchased lead files.

Do not paste an SSN or loan number into a third-party “were you breached?” form. BreachHistory does not collect that. Heights’ official page is the notice, not a search box.

What you should do

  1. Place a credit freeze at Equifax, Experian, and TransUnion. Keep the PINs offline. This is the single most useful step after an SSN leak.
  2. Add a fraud alert if you need to keep applying for credit while freezes are in place at only some bureaus.
  3. Enroll in Epiq before 9 November 2026: call 877-343-7785 for the code, then privacysolutionsid.com. Type the URL. Do not use ads.
  4. Watch bank and card accounts daily for ACH, new payees, and micro-deposits. Report unauthorized Heights-looking debits to the bank first, then Heights.
  5. File your taxes early next season and enable an IRS IP PIN if you can. SSN plus DOB is refund-fraud fuel.
  6. Assume customer-service notes are public to criminals. A caller who knows you asked for a hardship pause is still a stranger.
  7. Do not “update banking” from SMS, WhatsApp, or a QR code even if it cites your branch city.
  8. If you only inquired and never borrowed, still freeze. Application rows are in scope.
  9. Co-signers and spouses: freeze too if you were on the loan or named in service notes.
  10. Staff and partners: verify any cloud-vendor password reset out of band. This incident will be used against you.

Phishing you should expect

A scammer with this file will not send a generic “your account is locked” note. Expect:

  • “Heights: your ACH was returned — click to re-enter routing”
  • “Epiq activation: confirm SSN to release your monitoring code”
  • IRS or state-tax calls that already know last-four SSN and a Heights loan city
  • Collections impersonators who quote a real hardship note from the CRM
  • Lead-gen “you’re pre-approved” sites that reuse your leaked email and DOB

Heights will not need you to photograph your driver’s license into iMessage to finish this investigation. Epiq will not ask for a seed phrase, a Bitcoin refund, or a gift-card PIN. Open heightsfinance.com yourself if you need the notice again.

Canonical record and sources

Canonical BreachHistory page: 2026 Heights Finance — confirmed cloud-platform breach; 734,828 people (Texas AG census).

Sources: Heights Finance notice (11 August 2026), Recorded Future News / The Record.

What this is not

This is not a confirmed ransomware dump — no group has taken public credit in the reporting we indexed — and it is not a claim that Heights’ servicing app was rewritten. It is not a reason to pay a random “restoration” company that calls the same day as the news. The free Epiq window and the three-bureau freeze are the offered and recommended tools. It is also not a HIPAA story; medical details would only appear if a borrower volunteered them in a service note.

If your loan is still active

Keep paying through the channel you already used — app, mailed coupon, or branch — not a new link. A breach does not pause a legal installment contract. Scammers will tell you “Heights froze servicing until you verify.” That is the opposite of the company’s statement that operations continued. If a second debit looks like a Heights payment you did not authorize, call the bank and the 877-343-7785 center as two separate conversations.

Former Curo brands, without guessing logos

Heights’ letter names “Curo Management or any of its former or current related brands” without listing every d/b/a. If your paperwork says Curo, Southern Management, or Heights, you are in the population the company described. If you are unsure, freeze and enroll. Do not take legal-blog brand lists as Heights’ attested inventory — the attested sentence is the one on importantinfo.