Loan company breach sees nearly 750,000 users have financial info, SSNs leaked
Heights Finance said its cloud account was compromised, and information such as bank accounts and SSNs, stolen.
Heights Finance, a US loan company, disclosed a cyberattack in early 2026 that compromised sensitive data belonging to nearly 750,000 customers. The breach occurred when an unauthorized party gained access to a third-party cloud platform used by Heights Finance for storing customer information. The stolen records contained personal details, financial information, and government identifiers such as Social Security numbers and driver’s license numbers.
Heights Finance notified relevant authorities and engaged outside cybersecurity professionals to investigate the breach. The attack did not impact the company's loan management system or other networks. According to the company, the stolen data includes contact details, financial information, and government identifiers. It emphasized that affected individuals may be customers who obtained a loan through Heights Finance, inquired about or applied for a loan, or were former borrowers of Curo Management or related brands.
The company stated that the exact number of affected individuals remains unknown but reported that more than 730,000 Texans were impacted, along with residents in Alabama, Tennessee, Georgia, Texas, and South Carolina. The affected cloud-based platform's identity remains undisclosed, and the threat actors have not claimed responsibility for the attack. In response to the incident, Heights Finance is providing affected customers with credit monitoring and identity protection services through Epiq.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.