Heights Finance Data Breach Exposes Financial Information of Nearly 750,000 Customers

Published:

spot_img

Cybercriminals breached the cloud system of Heights Finance, a debt consolidation loan company, in May, compromising sensitive financial information and personal data of approximately 750,000 customers. The company reported that 734,828 individuals were affected by the breach, which was disclosed to regulators in Texas last week. Heights Finance operates multiple personal loan companies across Alabama, Tennessee, Georgia, Texas, and South Carolina, and has since published a warning to its customers regarding the incident.

The stolen data includes a range of sensitive information such as contact details, banking information including account and routing numbers, and government IDs like Social Security numbers and driver’s license numbers. Additionally, any personal information shared during customer service interactions was also compromised.

The breach was detected on May 7 when a hacker accessed a cloud-based platform used by Heights Finance to store customer data. The company clarified that the breach was limited to this platform and did not impact its loan management systems or other networks. Heights Finance has since confirmed that the cloud platform is secure and that there is no ongoing security threat.

The breach affects anyone who has received a loan from Heights Finance or inquired about its loan products through third parties, including customers of its parent company, Curo Management.

As of now, no hacking group has claimed responsibility for the breach. Heights Finance has engaged a cybersecurity firm to monitor the dark web for any leaked information. The company stated, “Our specialist is actively scanning dark web forums, marketplaces, and other platforms. As of this writing, they have not found any evidence that information involved in this incident is on the dark web.”

Heights Finance operates over 285 offices across 11 states and has faced legal scrutiny in the past for its lending practices. The company was previously sued by the federal government for allegedly targeting borrowers in financial distress, which led to accusations of generating revenue through fees from borrowers who frequently refinance their loans.

For more details, visit The Record.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

spot_img

Related articles

Recent articles

Red Hat releases important security update for haproxy in RHEL 8.8

Red Hat has announced an important security update for haproxy within the Red Hat Enterprise Linux (RHEL) 8.8 Update Services for SAP Solutions and...

Irregular Faces Criticism for Vague AI Hacking Postmortem Amid Security Incidents

The company Irregular is facing significant criticism following a series of incidents where AI models compromised real-world computer systems during security evaluations. Experts have...

Snowflake GitHub Actions Vulnerability Allows Command Injection via Crafted Issues

Cybersecurity researchers at Wiz have disclosed a GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository. This vulnerability could be exploited through a...

Data Breach at France’s Tax Authority Affects Approximately 680,000 Individuals

France’s Directorate General of Public Finances (DGFiP) has disclosed a data breach impacting approximately 680,000 individuals. The breach was revealed after a threat actor...