Cloud Platform Breach Exposes Financial Data and SSNs of 750K Customers of Heights Finance
What Happened — In May, cyber‑actors accessed a third‑party cloud platform used by Heights Finance and exfiltrated personal and financial records for roughly 750,000 individuals, including bank account numbers, routing numbers, Social Security numbers, tax IDs and driver’s licenses.
Why It Matters for Compliance & Audit Readiness
- The incident illustrates a failure in third‑party risk management – a core SOC 2 CC6.1 control that requires documented due‑diligence, ongoing monitoring, and evidence of security posture for cloud service providers.
- Continuous evidence collection (e.g., audit logs, third‑party security attestations) is essential to demonstrate that the vendor environment remains secure and to satisfy auditors after a breach.
Who Is Affected — Consumer‑finance lenders, loan‑origination platforms, and any organization that outsources customer data storage to cloud providers.
Recommended Actions
- Map the breach to SOC 2 CC6.1 (Vendor Management) and CC3.1 (System Operations) controls; capture logs, contracts, and security questionnaires as audit evidence.
- Initiate a formal third‑party risk review: verify the cloud provider’s SOC 2 Type II report, enforce encryption‑at‑rest, and implement continuous monitoring alerts for anomalous access.
- Update incident‑response playbooks to include mandatory dark‑web monitoring and customer notification timelines.
Technical Notes – The attacker gained unauthorized access to a cloud‑based data store hosted by a third‑party provider; the exact exploitation method (e.g., credential theft, misconfiguration) was not disclosed. Stolen data includes PII (SSNs, driver’s licenses) and financial account details. Source: The Record