Three months between discovery and notice
Heights Finance found the intrusion on 7 May and told 734,828 customers in August. The data includes bank accounts and social security numbers.
2 minEnterprise CyberSec
Heights Finance, a lender owned by CURO Management, has notified 734,828 customers of a breach affecting loan recipients and applicants across Alabama, Tennessee, Georgia, Texas and South Carolina.
The exposed set is close to complete for financial fraud: addresses, bank account and routing numbers, social security numbers, tax identifiers, driving licences and state identity documents, plus records of customer service interactions.
The interval is the finding
The intrusion happened in May, through a cloud platform hosted by a third party, and was discovered on 7 May. The customer warning went out around 10 August; Texas regulators were notified on 15 August. Roughly three months separate discovery from notice.
No group has claimed responsibility. The company says it hired specialists to watch dark-web forums and marketplaces and has found no evidence the data has appeared there.
That last point deserves care. Absence of evidence on monitored forums is a statement about what the monitoring covered, not about where the data is. Private sale leaves no listing to find, and it is the likelier route for a set this complete.
For anyone mapping supplier risk, the entry point matters as much as the count: a third-party cloud platform, not the lender's own systems. The customers whose social security numbers are now loose had no relationship with that vendor at all.
Retold from The Record. This is a summary in our own words; follow the link for the original reporting.