Heights Finance Data Breach Affects 1.2 Million People
Consumer loan company Heights Finance has announced that a cyberattack on a third-party cloud platform resulted in the theft of sensitive personal and financial data of at least 1.2 million of its customers and applicants. Stolen data includes Social Security numbers and bank account information.
What Happened
Heights Finance Holdings Co., a major player in the consumer finance sector, has publicly disclosed a large-scale data breach directly affecting at least 1.2 million individuals. According to a statement from the company, the incident was discovered in early May. Attackers managed to infiltrate a third-party cloud-based platform that the company uses for storing customer data. As a result of this breach, highly sensitive personal and financial information of millions of individuals has fallen into the hands of cybercriminals.
Heights Finance stated that it activated its incident response protocols immediately upon discovering the breach. The company engaged external cybersecurity specialists to conduct a comprehensive investigation and reported the incident to federal law enforcement. It was emphasized that the breach was limited to a cloud platform it uses, rather than the company's own loan management systems or other internal networks. While this means the company's operational activities were not affected by the attack, it reveals a significant vulnerability in the security of customer data. The disclosure in August of an incident detected in May often illustrates how complex and time-consuming the investigation process for such breaches can be. Companies may avoid making notifications until they have clarified the full list of affected individuals and the scope of the stolen data.
Data Compromised
The nature of the data stolen in this breach highlights the severity of the incident. The attackers gained access to nearly all the critical information needed for identity theft and financial fraud. According to the company's notice, the types of compromised data include:
- Identity Information: Full names, home addresses, email addresses, and phone numbers.
- Official Documents: Social Security numbers (SSNs), government-issued ID numbers, and driver's license numbers.
- Financial Information: Bank account information and other account details.
- Personal Details: Dates of birth and other miscellaneous information customers shared with the company.
The theft of this data set as a whole poses an extremely high risk to the victims. The Social Security number, in particular, is considered the master key to an individual's financial identity. A fraudster armed with this information can apply for new credit cards, take out loans, file fraudulent tax returns, and even misuse medical services in the victim's name. The leak of bank account information also brings the risk of direct financial loss. Fraudsters can use this information to withdraw money from accounts or conduct illicit transfers.
How the Attack Occurred
According to Heights Finance's statement, the attack targeted a third-party cloud service provider used for data storage, not the company's own infrastructure. This is a typical example of a 'supply chain attack' in cybersecurity. No matter how well companies protect their own systems, they can remain at risk due to security weaknesses of their partners or service providers.
The company has not yet shared technical details on how the attackers breached the cloud platform. Such attacks are often carried out through methods like weak passwords, misconfigured cloud servers, zero-day vulnerabilities, or phishing attacks targeting employees of the service provider. The source of the attack and the specific methods used are being clarified as part of the ongoing investigation. The identity of the threat actor behind the attack also remains unknown. As of now, no known ransomware or cyber extortion group has claimed responsibility for the attack.
Who Is Affected
The breach affects a broad audience that has had contact with Heights Finance at any point. The company categorizes the potentially affected individuals into three main groups:
- Current and Former Customers: Anyone who has or previously had a loan from Heights Finance.
- Applicants: Individuals who applied for or inquired about a loan product from the company. This group includes those whose applications were not approved.
- Third-Party and Former Brand Customers: Those who made loan applications through a third party, or former borrowers of Curo Management and its former or current brands.
According to official notices sent by the company to various state Attorneys General, the breakdown of affected individuals by state is as follows: 734,828 in Texas, 486,463 in South Carolina, 26 in New Hampshire, and 21 in Vermont. The sum of these figures confirms that the number of affected individuals exceeds 1.2 million.
What You Can Do
If you have had a relationship with Heights Finance or received a breach notification, it is crucial to act immediately to prevent the misuse of your data. Here are the steps you can take:
- Activate the Free Credit Monitoring Service: Heights Finance is offering 24 months of free credit monitoring and identity protection services to all affected individuals. Follow the instructions in the notification sent to you to activate this service immediately. This service will alert you if a new account is opened in your name or if there is suspicious activity on your credit report.
- Freeze Your Credit Reports: One of the most effective measures is to freeze your credit reports with the three major credit bureaus (Equifax, Experian, and TransUnion). A credit freeze prevents new creditors from accessing your report unless you personally lift it, making it nearly impossible for someone to apply for new credit with your identity.
- Place a Fraud Alert: If you do not want to freeze your credit, a more flexible option is to place a fraud alert. This alert encourages lenders to take extra steps to verify your identity when an application is made in your name.
- Monitor Your Financial Accounts: Regularly check your bank and credit card statements. Report any transactions you do not recognize or find suspicious to your bank immediately.
- Be Wary of Phishing Attacks: Cybercriminals may use this stolen personal information to send you customized phishing emails or text messages (smishing). Be skeptical of messages claiming to be from Heights Finance that demand urgent action or ask you to verify your personal information.
What the Company Says
In its incident notice, Heights Finance emphasized its commitment to customer security and the steps it has taken. The company stated, "We immediately activated our incident response protocols, brought in outside cybersecurity specialists to investigate, and reported the incident to federal law enforcement." It was also noted that the breached platform is now secure and the company's main operations continue without interruption.
Furthermore, the company added that its monitoring of the dark web has not yet found any evidence of the stolen information being shared or offered for sale. However, this does not mean the data will not be used in the future. Cybercriminals often wait for a period before using or selling stolen data. The company aims to minimize these risks by offering the 24-month identity protection service to affected customers.
Source
https://www.securityweek.com/heights-finance-data-breach-impacts-at-least-1-2-million-individuals/
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.