Heights Finance Holdings Co., a South Carolina-based consumer lender that operates installment-loan branches under brands including Heights Finance, Southern Finance, Covington Credit and Quick Credit across roughly a dozen states, disclosed this month that hackers broke into a third-party cloud platform holding customer records. The exposed data includes Social Security numbers, tax identification numbers, driver’s license or state ID numbers, and bank account and routing numbers, along with names, addresses, phone numbers, email addresses and dates of birth. In its report to the Texas Attorney General’s office, Heights put the number of affected Texans at 734,828, and the company says the exposure reached not just people who took out a loan but also those who merely applied for or inquired about one.
What happened inside Heights Finance’s cloud platform
Heights says it discovered the intrusion on May 7, 2026, when an unauthorized actor gained access to a cloud-based platform that a third-party vendor hosts on the company’s behalf to store customer records. The company dated its consumer notice August 11, 2026, more than three months after discovery, and says the activity was confined to that platform and never reached its loan-servicing systems or other internal networks.
According to Heights’ own notice of data breach, outside cybersecurity specialists brought in to investigate have since confirmed the platform is secure, and a specialist the company hired to scan dark-web forums and marketplaces has not found the stolen data posted for sale as of this writing. Heights also reported the incident to federal law enforcement, though it has not said which agency is investigating or whether anyone has been identified as responsible.
Free retirement updates: Enrollment and claim windows come and go, and missing one can cost you real money. The free Retirement Shield newsletter keeps you ahead of the deadlines that matter. Sign up free.
Applicants and inquiries are exposed too, not just borrowers
The breach notice states plainly that the exposure is not limited to people who ever took out a loan. Heights says a person’s information may have been involved if they inquired about or applied for a loan product, including through a third party, or if they were a former borrower of Curo Management or any of its related brands. That detail widens the affected population well beyond current and former customers, to anyone who filled out an application that was later denied, walked away from, or never followed through on — people who might reasonably assume, having never actually borrowed a dollar from Heights, that their information was never on file there at all.
One state’s number, not the whole breach
The 734,828 figure is not a nationwide count. Texas law requires any company whose breach affects 250 or more state residents to report the exact number of Texans it has notified directly to the Office of the Attorney General, and that state-specific figure is what appears in Texas’s public breach registry. Heights has separately notified attorneys general in South Carolina, Massachusetts, Vermont, New Hampshire, California, Iowa, Montana, Oregon, Rhode Island and Washington, among others, and each state receives its own count of residents affected.
Those separate filings add up to a much larger breach than the Texas number alone suggests. Based on the notices Heights sent to attorney general offices in several states, a tally of the state-by-state figures puts 486,463 affected residents in South Carolina, 26 in New Hampshire and 21 in Vermont alongside the Texas count, for more than 1.2 million people combined. Heights has not published one consolidated nationwide number, so the true total could run higher still once every state’s filing is accounted for.
Free credit monitoring closes to new enrollees on November 9
Heights is paying for 24 months of credit monitoring and identity-protection services through a provider called Epiq – Privacy Solutions ID, offered at no charge to anyone who believes their information was involved in the incident. Enrolling requires calling a dedicated Heights call center for a personal activation code, then completing sign-up and identity verification at a separate enrollment site. The company’s notice sets a firm cutoff: the deadline to enroll is November 9, 2026, after which each individual’s activation code stops working and the free service closes to new enrollees.
The extra step a credit freeze does not cover
A credit freeze, which every consumer can place at Equifax, Experian and TransUnion at no charge under federal law, blocks lenders from pulling a new credit file to open an account in someone else’s name. It does nothing, however, to stop someone from using a stolen bank account and routing number to attempt a withdrawal or an unauthorized transfer against an account that already exists. For that specific risk, the recommended step is different: contact the bank directly, flag the exposure, and ask about closing the account and reopening a new one rather than waiting to see whether a fraudulent transaction shows up first.
The Federal Trade Commission’s identitytheft.gov service walks people whose bank account or routing number was exposed through that same sequence: notify the bank, close and replace the account rather than simply watching it, update any automatic payments tied to the old account number, and review statements for transactions that were never authorized. Heights’ own notice points affected borrowers and applicants toward the same federal resource, alongside the toll-free line for its dedicated call center, as the practical starting point for anyone weighing whether the call for free monitoring is worth making before November 9.
This article was produced with AI assistance and reviewed by a human editor. Figures are linked to their primary sources; where a claim could not be verified from the public record, we say so.
More Financial Reading




