Heights Finance breach exposes sensitive data of hundreds of thousands of customers
US lender Heights Finance reported a May cyberattack that compromised contact, financial, and government ID data for over 730,000 Texas residents, with other states also affected.
In a data breach notification published on its website, the company said that on May 7, 2026, an unauthorized actor gained access to a cloud-based platform hosted by a third party that is used to store certain customer data. The breach was limited to that platform and did not affect its loan management system or other networks, according to the notification.
The investigation determined that the attackers stole contact details such as names, postal addresses, phone numbers and email addresses, financial information including account details, bank names, account numbers and routing numbers, and government identifiers such as Social Security numbers, tax IDs and driver’s license numbers. The company said information may be involved for anyone who received a loan through Heights, inquired about or applied for a loan product (including through a third party), or was a former borrower of Curo Management or any of its former or current related brands.
The exact number of affected individuals is not yet known. In a filing with Texas regulators, Heights Finance said more than 730,000 residents of Texas were affected, and added that residents of Alabama, Tennessee, Georgia, Texas and South Carolina were also affected.
Heights Finance notified the relevant authorities and hired outside cybersecurity help. The attackers were not named, and no group has claimed responsibility so far. The company is offering affected customers credit monitoring and identity protection services through Epiq.