Hackers Expose Data of 1.2 Million Heights Finance Customers via Compromised Third‑Party Cloud Platform
What Happened – On May 7 2026, Heights Finance discovered that an unauthorized actor gained access to a cloud‑based platform hosted by a third‑party provider that stores customer data. The breach exposed personal, financial, and government‑ID information for more than 1.2 million current or prospective borrowers. The incident was limited to the cloud platform; internal loan‑management systems remained untouched.
Why It Matters for Compliance & Audit Readiness
- The breach illustrates a classic vendor‑risk scenario that SOC 2’s Vendor Management (CC6.1 – CC6.2) controls are designed to mitigate and evidence.
- Continuous monitoring of third‑party security posture provides the audit‑ready proof that a provider remains compliant after onboarding.
- Demonstrating due‑diligence through documented vendor assessments and real‑time alerts can turn a reactive incident response into a defensible, pre‑approved control activity.
Who Is Affected – Consumer‑finance lenders, loan‑origination platforms, and any fintech services that rely on external cloud storage for customer data.
Recommended Actions
- Map the third‑party cloud provider to SOC 2 vendor‑management controls (CC6.1 – CC6.2) and capture evidence of its security certifications.
- Implement continuous monitoring of the provider’s security posture (e.g., configuration drift, vulnerability scans) and integrate alerts into your GRC workflow.
- Update your vendor risk register with the incident details, reassess risk scores, and require remediation plans from the provider.
Source: SecurityAffairs
Technical Notes – The attack vector was unauthorized access to a third‑party cloud environment (likely via compromised credentials or mis‑configured access controls). No ransomware or extortion was reported. Exfiltrated data included names, addresses, bank account numbers, government IDs, and dates of birth. Source: same as above