Heights Finance Holdings’ online data breach notification says an unauthorized party accessed a third-party cloud platform containing customer data, potentially exposing highly sensitive personal, banking, and identity information.
Heights Finance is a consumer lender that offers personal installment loans. Reportedly, the company filed a report with Texas regulators mentioning 734,828 affected people, though that figure should not automatically be read as a confirmed nationwide total, since Heights Finance operates dozens of personal loan companies across Alabama, Tennessee, Georgia, Texas, and South Carolina.
The company is associated with the former CURO Management business and related brands. The breach notice covers not only some Heights Finance customers, but potentially people connected to certain current or former CURO-related brands.
On May 7, Heights Finance discovered that an unauthorized party had gained access to a cloud-based platform run by a third party and used to store certain customer information. The company says its investigation found that the intruder may have viewed or copied information in that environment.
Heights says affected people may include:
- People who received a loan through Heights Finance.
- People who inquired about or applied for a loan product, including through a third party.
- Some customers of former parent company CURO Management and its present or former related brands.
What makes the incident especially concerning is the nature of the potentially exposed records, which can include the combination of information criminals need to impersonate someone, target their bank accounts, or create highly convincing phishing attempts.
Breaches happen every day. Don’t be the last to know.
Potentially exposed data includes:
- Contact information: Name, home address, phone number, and email address.
- Financial information: Account details, bank name, bank account number, routing number, and related financial information.
- Government identifiers: Social Security number (SSN), tax identification number, driver’s license number, or state ID number.
- Other personal data: Date of birth and personal circumstances voluntarily disclosed during customer service interactions.
The combination of a Social Security number, date of birth, address, and bank account details can create a much more serious risk than a breach exposing only email addresses. It can support identity fraud, financial fraud, account takeover attempts, and tailored social engineering scams.
The personal circumstances customers may have shared with support staff could also make scams more persuasive or potentially more harmful, particularly for people who discussed financial distress, repayment problems, or other sensitive subjects.
What affected customers should do
People who receive a letter from Heights Finance should follow the company’s instructions and enroll in the offered protection service. Exact instructions can be found on Heights Finance’s website.
Since people who were not actual customers could also be affected, there may be some uncertainty about whether someone’s information was included in the data breach. If you believe you fall into one of the listed groups but do not receive a notice, use contact details published by Heights Finance for inquiries. Do not use a number provided in an unexpected email, text, phone call, or even sponsored search result to ask whether your information was involved.
More general advice on what to do is available in our article Involved in a data breach? Here’s what you need to know.
What do cybercriminals know about you?
Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.




