2026 Heights Finance — confirmed third-party cloud breach; ~1.22M people (multi-state AG); SSNs, bank/routing, DLs
Data compromised
Per Heights: contact (name/address/phone/email); bank name, account and routing numbers and related financial data; SSN, tax ID, driver’s license or state ID; DOB; customer-service notes. Texas regulator census 734,828 (The Record). Scope includes Heights borrowers, loan inquiries/applications (incl. via third parties), and former Curo Management / related-brand borrowers. Varies by individual.
Technical writeup
Verified company notice plus multi-state AG censuses — August 2026. Heights Finance Holdings Co. (Greenville, SC installment lender) posted an 11 August notice: on 7 May 2026 an unauthorized actor accessed a third-party cloud platform storing certain customer data; loan-management systems were not affected. Fields may include contact data, bank name/account/routing, SSN/tax ID/driver’s license/state ID, DOB, and customer-service notes for borrowers, applicants (including via third parties), and former Curo Management / related-brand customers. SecurityWeek (18 August 2026) summed state filings: 734,828 (Texas), 486,463 (South Carolina), 26 (New Hampshire), 21 (Vermont) — about 1.22 million total. The Record earlier cited the Texas 734,828 figure. Dark-web monitoring had not found the set for sale as of the company notice. Complimentary 24-month Epiq monitoring; enroll by 9 November 2026 via 877-343-7785. recordsAffected 1221338 from summed AG filings cited by SecurityWeek.
Root cause
Unauthorized access on 7 May 2026 to a third-party hosted cloud platform used to store certain customer data (Heights 11 Aug notice); loan-management systems said unaffected