HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Cloud Platform Breach Exposes Financial Data and SSNs of 750K Customers of Heights Finance

Heights Finance disclosed that a hacker accessed a third‑party cloud platform in May, stealing banking details, Social Security numbers and other personal data for roughly 750,000 customers. The breach underscores the need for robust third‑party risk controls and continuous audit evidence in SOC 2 programs.

LiveThreat™ Intelligence · 📅 August 18, 2026· 📰 therecord.media
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
therecord.media

Cloud Platform Breach Exposes Financial Data and SSNs of 750K Customers of Heights Finance

What Happened — In May, cyber‑actors accessed a third‑party cloud platform used by Heights Finance and exfiltrated personal and financial records for roughly 750,000 individuals, including bank account numbers, routing numbers, Social Security numbers, tax IDs and driver’s licenses.

Why It Matters for Compliance & Audit Readiness

  • The incident illustrates a failure in third‑party risk management – a core SOC 2 CC6.1 control that requires documented due‑diligence, ongoing monitoring, and evidence of security posture for cloud service providers.
  • Continuous evidence collection (e.g., audit logs, third‑party security attestations) is essential to demonstrate that the vendor environment remains secure and to satisfy auditors after a breach.

Who Is Affected — Consumer‑finance lenders, loan‑origination platforms, and any organization that outsources customer data storage to cloud providers.

Recommended Actions

  • Map the breach to SOC 2 CC6.1 (Vendor Management) and CC3.1 (System Operations) controls; capture logs, contracts, and security questionnaires as audit evidence.
  • Initiate a formal third‑party risk review: verify the cloud provider’s SOC 2 Type II report, enforce encryption‑at‑rest, and implement continuous monitoring alerts for anomalous access.
  • Update incident‑response playbooks to include mandatory dark‑web monitoring and customer notification timelines.

Technical Notes – The attacker gained unauthorized access to a cloud‑based data store hosted by a third‑party provider; the exact exploitation method (e.g., credential theft, misconfiguration) was not disclosed. Stolen data includes PII (SSNs, driver’s licenses) and financial account details. Source: The Record

📰 Original Source
https://therecord.media/financial-info-leak-debt-consolidator

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →