Heights Finance breach exposes SSNs and bank details

Heights Finance Holdings, a US consumer lender that sells personal installment loans, says an unauthorized party got into a cloud platform operated by a third party and used to store customer information. The company discovered the access on 7 May and says its investigation found the intruder may have viewed or copied data held in that environment. A report filed with Texas regulators cites 734,828 affected people.

Read that figure carefully. Heights Finance operates dozens of personal loan companies across Alabama, Tennessee, Georgia, Texas and South Carolina, so a number reported to one state's regulator should not automatically be treated as a confirmed nationwide total. It is the largest figure currently attached to the incident, not necessarily the final one.

Enough to become somebody else

What makes this one serious is the combination sitting in a single record. Heights Finance says the potentially exposed information includes name, home address, phone number and email address; account details, bank name, bank account number and routing number; and Social Security number, tax identification number, and driver's license or state ID number. Date of birth is in there too.

Any one of those is a nuisance. A Social Security number, a date of birth, a home address and a bank account number sitting together in the same row is the working set someone needs to open credit in a stranger's name, attempt an account takeover, or make a phone call that sounds exactly like a bank.

The part that is not a data field

The notice also covers what it calls personal circumstances that customers voluntarily disclosed during customer service interactions. That is a quietly uncomfortable category. People call a lender to explain why a payment is late, and those explanations are about job loss, illness, divorce and debt. Handed to a fraudster, that context is what turns a generic phishing email into a message that knows why you were worried in April, and it lands on people who were already under financial pressure.

You may be affected without having borrowed anything

The exposure is wider than the customer list. Heights Finance says those potentially affected may include people who received a loan, people who merely inquired about or applied for a loan product (including through a third party), and some customers of former parent company CURO Management and its present or former related brands. Plenty of people in that second and third group will not think of themselves as Heights Finance customers at all.

Enroll, and dial the number yourself

Anyone who receives a letter should follow its instructions and take up the identity protection service being offered. If you believe you fall into one of the affected groups but no letter arrives, contact the company using details published on its own website. Do not use a phone number that arrives in an unexpected email, text or call, and do not trust a sponsored search result for it either, because breach notifications reliably attract a second wave of scammers impersonating the response.

The pattern is a familiar one for consumer finance and insurance records, which sit in third-party platforms and carry government identifiers by default: last month an insurance breach exposed 6.9 million driver license numbers, and incidents of this shape now make up a steady share of what we track across the United States. The details were set out in a writeup from Malwarebytes Labs, drawing on the company's own breach notification. Three months passed between discovery and the letters. The data has had all of that time to travel.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions