TechNewsReel
Live

Heights Finance Breach Exposes Data of 734,828 Customers

A third-party cloud platform leak exposed Social Security numbers and banking details for nearly 750,000 loan applicants.

TechNewsReel Newsroom · August 17, 2026

Cybercriminals breached a third-party cloud-based platform used by Heights Finance in May, exposing the sensitive personal and financial information of approximately 734,828 individuals. The company discovered the intrusion on May 7 and subsequently notified regulators in Texas and the affected customers.

The stolen data is extensive, including Social Security numbers, banking account and routing numbers, tax IDs, driver's license numbers, state IDs, and home addresses. The breach affected individuals who had inquired about loan products through third parties or received loans, including some customers of the company's parent organization, Curo Management.

Infrastructure and Scope

Heights Finance, a debt consolidation and personal loan provider based in Greenville, South Carolina, maintains a significant physical footprint with over 285 offices across 11 states, including Texas, Georgia, Alabama, Tennessee, and South Carolina.

In a statement regarding the incident, Heights Finance clarified that the security failure was isolated to its external vendor. "This activity was limited to the cloud-based platform only — it did not affect any of our loan management systems or other computer systems or networks," the company stated. This distinction indicates that while the data stored on the third-party platform was compromised, the company's core internal networks remained secure.

Corporate Context

This security failure comes as Heights Finance continues to operate under the umbrella of Curo Management. The company has previously faced significant legal challenges; it was once sued by the federal government for allegedly targeting financially struggling borrowers to generate revenue through frequent refinancing fees. That specific legal action was dismissed shortly after the Trump administration took office.

Industry Implications

The breach is critical because of the nature of the leaked data. The combination of Social Security numbers and banking routing details provides bad actors with the primary components required to commit comprehensive identity theft and financial fraud. For a customer base that often seeks debt consolidation and personal loans, this exposure creates a heightened risk for a demographic that may already be financially vulnerable.

Next Steps

While the company has notified regulators and customers, the long-term risk to the affected 734,828 individuals remains high given that stolen identifiers—such as Social Security and driver's license numbers—cannot be easily changed. Affected users are typically advised to monitor credit reports and freeze accounts following the loss of such high-value personally identifiable information (PII).

Sources

Get a notification when a big story breaks. A few a day at most — no spam.