In a significant cybersecurity incident, Heights Finance disclosed that an unauthorized party accessed its third-party cloud storage, exposing the data of hundreds of thousands of customers. The breach, detected in May 2026, included personal contact details, financial accounts, and government-issued identifiers.
- Data breach exposed names, SSNs, bank details, and more
- Impact spans Alabama, Tennessee, Georgia, Texas, and South Carolina
- Company provides credit monitoring and identity protection
What happened
On May 7, 2026, Heights Finance discovered that an unauthorized actor had accessed a cloud-based platform hosting sensitive customer data. This platform is operated by a third-party provider and is separate from the company’s primary loan management infrastructure, which remained unaffected by the breach.
The stolen data includes contact information such as names and addresses, financial details like bank account numbers and routing information, and government identifiers including Social Security numbers and driver’s license numbers. The breach affected customers who received loans or applied for financial products through Heights Finance or its affiliated brands.
Why it matters
The breach exposes a vast amount of personally identifiable information that could be exploited for identity theft, financial fraud, and other malicious activities. The inclusion of Social Security numbers and bank account details significantly raises the risk for victims, complicating recovery and fraud prevention efforts.
With over 730,000 individuals potentially impacted across multiple US states, the incident is a stark reminder of the vulnerabilities associated with cloud storage services and the importance of robust cybersecurity defenses in financial services. The breach underlines the ongoing challenges companies face in protecting sensitive data amid increasingly sophisticated cyberattacks.
What to watch next
Heights Finance has engaged external cybersecurity experts and notified regulatory authorities, continuing to investigate the full scope and methods behind the attack. Customers impacted by the breach are being offered credit monitoring and identity protection services to mitigate risks of fraud and identity theft.
Future developments to monitor include any claim of responsibility by the perpetrators, additional regulatory actions or penalties, and potential impacts on customer trust and business operations. The case also highlights the broader industry need for enhanced data security standards around cloud platforms and third-party data storage providers.