Heights Finance says third-party cloud breach exposed Social Security numbers and banking data for nearly 735,000 people

Heights Finance says hackers broke into a third-party cloud platform it used to store some customer data, exposing sensitive information for 734,828 people. The company says it discovered the intrusion on May 7, 2026 and that the affected system was limited to the external cloud-based platform, not its loan management systems. Stolen data includes addresses, bank account and routing numbers, Social Security numbers, tax IDs, driver's license or state ID numbers, and information shared during customer service interactions.
Why it matters: This is a serious identity-theft and financial-fraud risk for loan applicants and customers because the exposed data includes both banking details and government identifiers. Affected people should watch bank and credit accounts closely, consider fraud alerts or credit freezes, and treat follow-on phishing or impersonation attempts as high risk.

Sources

Heights Finance Data Breach Impacts at Least 1.2 Million Individuals
Ionut Arghire 2026.08.18 99% relevant
This is the same breach event and updates the scope from nearly 735,000 affected people to at least 1.2 million, adding state-level counts and more detail on the stolen data types and affected populations, including former Curo Management borrowers and applicants.
Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach
2026.08.17 100% relevant
This article appears to be the initial broad reporting on Heights Finance's disclosure that a third-party cloud platform breach exposed customer and applicant data on a large scale.
← Back to all stories