Heights Finance, one of the largest U.S. lenders, is at the center of a major cyberattack: the data breach, which occurred in May, affected at least 1.2 million people, whose personal and financial information was stolen from a third-party cloud storage platform. The incident highlights once again the critical risk of relying on external cloud service providers to store sensitive customer data.

According to SecurityWeek, Heights Finance Holdings Co. , a Greenville, South Carolina -based company , discovered in early May that malicious actors had gained access to a third-party cloud platform used to store customer data. The company immediately activated incident response protocols, brought in outside cybersecurity experts to investigate, and reported the incident to federal law enforcement. The public notice was issued in August after the company completed an assessment of the scope of the breach.
See also: Proton Data Breach Observatory: Notifies you when your personal data appears on the Dark Web
The incident did not impact Heights Finance’s internal loan management systems or other networks, as the breach was limited to the third-party cloud platform. However, the data exposed is highly sensitive: names, addresses, emails, phone numbers, Social Security Numbers (SSNs), government identification numbers, driver’s license numbers, bank account details, dates of birth and other information that customers had shared with the company.
Heights Finance data breach: Who is affected and how many?
Based on notifications sent to the Attorney General's Offices of various states, the total number of victims exceeds 1.2 million people. Specifically, 734,828 people were affected in Texas, 486,463 in South Carolina, 26 in New Hampshire and 21 in Vermont.
Heights Finance clarified that the data may include those who received a loan through the company, those who applied for or inquired about loan products (even through a third party), as well as former borrowers of Curo Management or any of its former or current affiliated brands. In compensation, the company is offering victims 24 months of free credit monitoring and identity protection services.
According to Heights Finance, monitoring of the dark web has not revealed any evidence that the hackers have shared or sold the stolen data. The company has not named the threat actor behind the breach, and there are no known ransomware or extortion groups that have claimed responsibility for the incident.
See also: OnTrac data breach: customer notification after network breach

Heights Finance data breach: The pattern of attacks on cloud platforms
The incident is part of a broader trend that is becoming increasingly evident in 2025-2026: attackers are increasingly targeting third-party cloud and SaaS rather than victims’ own networks. A prime example is the campaign linked to Snowflake, where stolen credentials were used to access at least 165 customer environments and extract vast amounts of data. This case has been linked to extortion and multiple secondary breaches.
Security analysts point out that third-party hosted environments often contain the most sensitive data because organizations centralize customer records there for convenience and scale. This makes them attractive targets: a single access path can expose huge data sets without necessarily triggering alarms on the victim’s main production.
Practical protection tips
For organizations that store regulated customer data in third-party cloud services, vendor access should be treated as part of their own attack surface. Key controls include: enforcing phishing-resistant MFA for all administrative and privileged accounts, regularly rotating and restricting credentials, API keys , and service tokens, monitoring cloud audit logs for unusual downloads and bulk exports, segmenting sensitive data sets and minimizing what is stored on third-party platforms, and encrypting sensitive data.
See also: FinWise Bank: Data breach affects American First Finance customers
For consumers affected by this type of breach, the most important steps are: placing a credit freeze on the three major credit bureaus, activating fraud alerts, regularly monitoring accounts, and replacing exposed government IDs if misuse is suspected. Since the exposed data includes social security numbers and banking information, the risk of identity theft remains high for an extended period of time.

In conclusion, the Heights Finance data breach is yet another high-profile example of how reliance on third-party cloud platforms can expose millions of people to serious risks. The absence of a known ransomware claiming responsibility does not diminish the seriousness of the incident — on the contrary, this silence may mean that data is being discreetly used for targeted fraud or sold on closed dark web. Businesses and consumers should remain vigilant.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
