Heights Finance Data Breach Investigation
Heights Finance Holdings Co. published a notice on August 11, 2026 describing a reported security incident involving a third-party cloud-based platform used to store certain customer data. According to the notice, the company discovered the activity on May 7, 2026, and said some personal and financial information may have been viewed or copied. People who received a loan, applied for one, or had prior connections to Curo Management or related brands may want to review the notice carefully. If you believe you may be affected, you can also fill out the form on this page to see whether you may qualify for a claim.
Heights Finance Holdings Co. is a South Carolina-based financial services company. According to its public notice, the reported incident may affect people who received a loan, inquired about or applied for one, or were former borrowers of Curo Management or related brands. The notice says certain customer data was stored on a third-party cloud platform.
Key Facts at a Glance
- Entity involved: Heights Finance Holdings Co.
- Reported discovery date: According to the notice, the activity was discovered on May 7, 2026.
- Notice date: The public notice is dated August 11, 2026.
- What was reported: An unauthorized actor reportedly gained access to a third-party hosted cloud-based platform used to store certain customer data.
- Who may be affected: Borrowers, loan applicants or inquiry recipients, and some former borrowers of Curo Management or related brands.
- Information that may have been involved: Name, address, phone number, email address, financial account information, Social Security number, tax ID, driver’s license or state ID number, date of birth, and other personal information.
- Credit monitoring: The notice says complimentary credit monitoring and identity protection through Epiq is being offered for 24 months to eligible individuals.
- Public listing: The incident was publicly listed through a Vermont Attorney General filing on August 11, 2026.
What Happened?
According to the company’s notice, an unauthorized actor gained access to a cloud-based platform hosted by a third party and used to store certain customer data. The notice states the activity was limited to that platform and did not affect the company’s loan management systems or other computer systems or networks. The company also says it activated incident response procedures, retained outside cybersecurity specialists, and reported the matter to federal law enforcement. The notice further states that the platform has since been secured and that there is no ongoing security threat.
What Information Was Exposed?
The notice says the exact information varies by individual. According to the notice, the information that may have been viewed or copied includes:
- Name and address
- Phone number and email address
- Bank account and related financial details
- Social Security number or tax ID
- Driver’s license number or state ID number
- Date of birth
- Other information voluntarily shared during customer service interactions
Because the potentially affected group described in the notice is broad, even former customers or people who only applied or inquired about a loan may want to take the notice seriously.
What Should You Do Next?
- Enroll in the free monitoring services. According to the notice, complimentary credit monitoring and identity protection through Epiq is available for 24 months to individuals who believe their information may have been involved.
- Review your financial accounts. Check bank accounts and other account activity for unfamiliar transactions, address changes, or notices you do not recognize.
- Check your credit reports. Look for unfamiliar accounts or hard inquiries, and consider placing a fraud alert or security freeze if you are worried about identity misuse.
- Watch out for phishing. After public incident notices, scammers often send emails, texts, or calls that appear legitimate and ask for personal information.
- Keep records. Save the notice, account statements, screenshots, and any documentation of time, expenses, or problems related to the incident.
- Ask questions if you need help. If you believe your information may have been involved, you can fill out the form on this page to contact Strauss Borrelli PLLC and learn whether you may qualify for a claim.
Your Legal Rights
Your legal rights depend on the facts, the type of information involved, and the law connected to your claim. In data-incident matters, consumers may have rights related to receiving adequate notice, learning what information may have been involved, and seeking recovery for certain losses or time spent dealing with identity-related issues.
If sensitive identifiers such as Social Security numbers, driver’s license numbers, or financial account information were involved, those facts can matter when evaluating potential claims. The fact that a third-party platform was reportedly involved does not automatically answer who may be legally responsible. A lawyer can help assess whether reasonable safeguards were used and whether any deadlines may apply. This article is general information and not individualized legal advice.
Why Hire Strauss Borrelli PLLC?
Strauss Borrelli PLLC represents consumers in data-breach and privacy-incident matters and understands how to investigate security notices, third-party vendor involvement, and the impact these events can have on affected individuals. The firm can help review what the notice says, explain possible next steps in plain English, and assess whether a claim may be worth pursuing.
If you want to discuss this reported incident, Strauss Borrelli PLLC offers a free, no-obligation case review.
If you received a breach notification letter from Heights Finance:
We would like to speak with you about your rights and potential legal remedies in response to this data breach. Please fill out the form, below, or contact us at 872.263.1100 or sam@straussborrelli.com.










