Heights Finance Lender Breach Exposes 734k Customers’ Financial and Identity Data via Third‑Party Cloud Platform
What Happened – An unauthorized party accessed a third‑party cloud platform used by Heights Finance Holdings to store customer records. The intruder may have viewed or copied highly sensitive personal, banking, and government‑issued identifier data affecting an estimated 734,828 individuals.
Why It Matters for Compliance & Audit Readiness
- Demonstrates the need for SOC 2 vendor‑management controls that require continuous monitoring of third‑party environments.
- Provides a concrete example of why audit evidence (access logs, monitoring alerts, vendor due‑diligence documentation) must be collected and retained.
- Highlights the importance of a defensible incident‑response process that can be presented to regulators and auditors as proof of due care.
Who Is Affected – Consumer‑finance lenders offering personal installment loans, and related brands formerly under CURO Management.
Recommended Actions –
- Review and update third‑party risk assessments for all cloud service providers.
- Verify that contracts include security, breach‑notification, and audit‑evidence clauses.
- Implement continuous monitoring of cloud‑service access logs and integrate them into your SOC 2 evidence repository.
- Document the incident‑response workflow and ensure it aligns with SOC 2 CC6.1 (Incident Management).
Source: Malwarebytes Labs – Heights Finance data breach
Technical Notes – The breach stemmed from unauthorized access to a cloud‑based platform (likely via compromised credentials or mis‑configured access controls). Exposed data includes names, addresses, phone numbers, email, SSNs, tax IDs, driver’s licenses, dates of birth, bank account numbers, routing numbers, and other personal circumstances disclosed during support interactions. Source: same as above