Hackers Expose Data of 1.2 Million Heights Finance Customers
Heights Finance is notifying over 1.2 million customers that hackers accessed a third-party cloud platform holding contact, bank and government ID data.
Heights Finance, a U.S. consumer lender, discovered unauthorized access on May 7, 2026 to a third-party cloud platform used to store customer data; its internal loan management systems and operations were not affected. Exposed data varies by person and may include contact details, financial and bank account information, government IDs and dates of birth for customers, loan applicants, inquirers, and former borrowers of Curo Management and related brands. The company is offering 24 months of free credit monitoring and identity protection; dark web monitoring found no evidence of publication and no threat actor has claimed responsibility.
- Access was limited to the third-party cloud platform; loan management systems and operations were unaffected
- Exposed data may include contact details, bank account data, government IDs and dates of birth
- 24 months of free credit monitoring offered; no evidence of data publication on the dark web
Full article352 words · extracted from securityaffairs.com · click to collapse

A Heights Finance breach exposed personal and financial data of over 1.2 million people after hackers compromised a third-party cloud platform.
Heights Finance is a U.S. consumer finance company that provides personal loans and related lending services, mainly to customers who may have limited access to traditional bank credit. It is part of Heights Finance Holdings Co.
Heights Finance Holdings is notifying more than 1.2 million people that on May 7, 2026, Heights Finance discovered unauthorized access to a third-party cloud platform storing customer data. The company launched an investigation with external cybersecurity experts and notified federal law enforcement.
“On May 7, 2026, Heights discovered that an unauthorized actor gained access to a cloud-based platform hosted by a third party that we use to store certain customer data. This activity was limited to the cloud-based platform only—it did not affect any of our loan management systems or other computer systems or networks. We immediately activated our incident response protocols, brought in outside cybersecurity specialists to investigate, and reported the incident to federal law enforcement.” reads the notice of data breach.
“We have since confirmed that the cloud-based platform is secure and that there is no ongoing security threat. Our operations were not impacted by this incident and have continued safely and securely.”
Heights said its internal systems and operations were not affected, the platform has been secured, and there is no ongoing threat.
The compromised customer information included contact details, financial and bank account data, government IDs and dates of birth. The affected data varies by person and may involve Heights Finance customers, loan applicants, people who inquired about its products, or former borrowers of Curo Management and related brands.
Heights Finance is offering affected individuals 24 months of free credit monitoring and identity protection. The company said dark web monitoring has found no evidence that the stolen data has been published.
No threat actor has claimed responsibility, and no known ransomware or extortion group has been linked to the breach so far.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Heights Finance)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/197485/data-breach/hackers-expose-data-of-1-2-million-heights-finance-customers.html