Heights Finance Holdings Co. is notifying customers nationwide after an attacker accessed a third-party cloud platform the lender uses to store loan-related data, exposing a trove of sensitive personal and financial information.[1][5][9] Regulatory and media reports suggest the incident affected hundreds of thousands of people, with estimates ranging from roughly 734,828 individuals to more than 1.2 million.[2][6][9]
According to a breach notice posted by Heights Finance, the company discovered on May 7, 2026 that an unauthorized actor had gained access to a cloud-based platform hosted by a third-party provider that stores customer data.[1] The firm says the activity was confined to that platform and did not touch its loan management systems or broader corporate network, and that normal operations were not disrupted.[1] Heights Finance reports that it activated its incident response plan, brought in outside cybersecurity specialists, notified federal law enforcement, and has since secured the affected platform, stating there is no ongoing security threat.[1]
The data exposed in the breach varies by individual but can include names, mailing addresses, phone numbers, email addresses, dates of birth and other contact details.[1][5] More critically, the company and follow-on legal notices state that Social Security numbers, government identifiers such as driver’s license or state ID numbers, and detailed financial account information — including bank names, account numbers and routing numbers — may have been accessed.[1][5][8] Consumer protection law firm Federman & Sherwood, which is investigating the incident, warns that this combination of identifiers and financial data significantly increases the risk of identity theft, unauthorized account activity and other forms of fraud.[3]
The breach was formally disclosed to the Vermont Attorney General on August 11, 2026, with filings indicating 21 affected residents in that state but acknowledging a much larger national impact.[3][4][8] Cybersecurity reporting and threat-intelligence writeups describe the incident as compromising financial and identity data for approximately 734,828 people, while some coverage cites company communications that reference impact on at least 1.2 million individuals.[2][6][9] Heights Finance has not publicly attributed the intrusion to a specific threat actor, and there is no indication in available disclosures that a particular software vulnerability or CVE was identified as the root cause, underscoring the risks inherent in outsourcing sensitive data to third-party cloud platforms.[1][3][6]
Heights Finance says it has begun notifying affected individuals by mail and is offering complimentary credit monitoring and identity protection services, which require an activation code obtained through a dedicated call center.[1][5] Class-action specialists tracking the case advise recipients of breach letters to enroll in any free monitoring offered, closely review bank and credit card statements, and monitor credit reports for unfamiliar accounts or inquiries.[5][8] They also recommend considering fraud alerts or credit freezes with major credit bureaus and being alert to phishing emails, texts or calls that reference Heights Finance or loan information, guidance that aligns with the company’s own public advice on scam and fraud prevention.[5][8][15]
For defenders and financial institutions, the Heights Finance incident highlights the importance of strong vendor risk management, including stringent security requirements for cloud providers handling high-value data such as loan applications, Social Security numbers and bank details.[1][3] Even in the absence of a disclosed software flaw or known exploitation in the wild, the scale and sensitivity of the data involved make this type of third-party compromise particularly attractive to financially motivated threat actors and particularly damaging to victims if stolen records are sold or reused in follow-on fraud schemes.[2][3][6]
References
- Notice of Data Breach – Heights Finance
- Nearly 750k had financial info, SSNs leaked in South …
- Heights Finance Holdings Co Data Breach – Federman & Sherwood
- Heights Finance data breach (2026)
- Heights Finance Data Breach Class Action Investigation
- Cybersecurity News, Vulnerabilities and CVEs — CyberWorldOps
- Heights Finance Holdings Co Data Breach Notification Letter
- SecurityWeek: Cybersecurity News, Insights and Analysis
- Learn about Phishing Scam Protection – Heights Finance
