
On May 7, Heights Finance identified a situation where a person accessed a cloud platform which housed their customer information. The people whose information was accessed knew about it on August 11.
There were 96 days between those two dates. During almost all of that period, there were over 1.2 million people who were exposed in a way that they did not know.
What was the problem in the Heights Finance incident? An unauthorized individual gained access to the cloud platform owned by a third party which stored the information of the customers of the consumer lender. Information like names, Social Security numbers, driver license and state ID numbers, tax IDs, bank account and routing numbers, and date of births were exposed.
Ninety-Six Days Between Discovery And Notice
Heights Finance is a consumer loan lender based in Greenville, South Carolina. It targets consumers who have trouble accessing bank credit, which defines the people who fall into this breach.
The breach was discovered by the firm on May 7. External experts were hired, and the federal law enforcement was informed, and the platform was secured. Communication efforts began on August 11.
Such delays are typical for third-party data breach notifications, and this is where things get uncomfortable. Research on third-party breaches reveals that the median time frame between the discovery and the notification is 73 days, while the average time period is closer to 117. Heights Finance is somewhere in the middle.
You Did Not Have To Be A Customer
The notification list goes much further than a live customer base.
It includes customers, former borrowers, people who applied for a loan, and people who made inquiries about a loan. Former customers of Curo Management and its brands are also included on this list.
A person who had made inquiries regarding a loan many years back and who never entered into any kind of agreement can also find himself/herself on this list. This person may not even know what company is sending him/her this letter.
This is how consumer lending works. Any inquiry creates a record, which is then retained for many years after that.
What Can Be Changed After a Breach, and What Cannot
The Data Nobody Can Rotate
Exposure categories include names, addresses, telephone numbers, email addresses, Social Security numbers, tax identification numbers, driver’s license and state identification numbers, financial account numbers including bank accounts and routing numbers, and dates of birth.
How does this compare to a password breach? The password is reset within minutes, and payment cards are reissued within days.
However, Social Security numbers are not subject to replacement. Replacement of this data is extremely uncommon and does not retire the old number. Birth dates also cannot be changed. None of the listed data categories expire, and for this reason, 24 months of credit monitoring covers merely a portion of the true exposure timeline. The sign-up period for this offer ends on November 9, 2026.
Nobody Has Claimed It
None of the ransomware gangs have claimed responsibility for the hack. There hasn’t been any extortion demand made. At the time of mid-August, there hadn’t been any sightings of the stolen documents being sold anywhere on the dark web.
One interpretation of this may be positive, but the other interpretation is more troubling.
Since extortion gangs operate using the threat model, they tend to be vocal. If there is a quiet theft of personal information that can be used in frauds, then there is some other motive involved.
The Platform Was Never Theirs
Heights Finance maintains that its systems have not been affected and that the breach has been contained to the cloud-based platform alone. This assessment is true and irrelevant for the most part.
The data was stored on infrastructure that Heights Finance did not manage itself. It does not matter which controls Heights Finance implemented on its own network because the breach occurred beyond the reach of those controls.
It’s an old trend that repeats itself. Recently, when attackers pulled patient health data and corporate secrets out of third-party cloud environments at a major biotechnology firm and left its manufacturing systems untouched. In the same vein, the perimeter was preserved while the data was outside of it.
Conclusion: The Platform Was Secured. The Identity Exposure Remains.
The defining lesson from the Heights Finance breach is that securing the system where an incident occurred does not eliminate the risk created by information that has already been accessed.
More than 1.2 million people were affected, including current customers, former borrowers, applicants, and people who had only made loan inquiries. The exposed information included Social Security numbers, tax identification numbers, driver’s license and state ID numbers, bank account and routing information, dates of birth, and contact details. Unlike a password or payment card, much of that information cannot simply be reset when a breach ends.
The initial access method to the third-party cloud platform has not been disclosed. There is no confirmed evidence here of phishing, stolen credentials, vulnerability exploitation, or malware. That uncertainty matters. What is confirmed is the downstream exposure, and that creates an identity-risk horizon that can extend far beyond the original platform.
Why This Threat Matters
- The risk can outlive the original breach. Securing the affected platform stops immediate unauthorized access, but it cannot recall information already exposed.
- Some identity data is effectively permanent. Dates of birth cannot be changed, while replacing Social Security numbers and government identifiers is difficult or incomplete.
- Historical retention expands the impact. Former customers, applicants, and even people who only made inquiries remained represented in the affected repository.
- Third-party custody does not transfer consequence. Infrastructure may belong to a provider, but the exposure still affects the people whose information was originally collected.
- No public leak does not establish safety. The absence of a ransomware claim, extortion demand, or observed sale does not establish what happened to the accessed information.
- Notification delay extends uncertainty. Ninety-six days passed between discovery and notification, leaving affected individuals unaware while investigation and notification processes continued.
Where Defensive Control Must Operate
Securing the affected platform closes one part of the incident. It does not remove the identity risk created by information that cannot easily be replaced.
Xcitium ITDR addresses that next layer, helping surface abnormal authentication, privileged access, and identity activity that may indicate subsequent account abuse. Its role here is not to explain the undisclosed initial access method, but to provide identity-side visibility as the consequences of exposed personal information extend beyond the original breach.
For durable identity data, the defensive horizon must extend beyond infrastructure recovery.
The Breach Has an End Date. The Data Does Not.
Organizations should treat data retention as part of breach risk itself. Sensitive information held by third parties should have a defined business purpose and retention period, while recovery planning should account for identity-related consequences that may emerge after the affected platform has been secured.
The infrastructure incident may be over. The value of exposed Social Security numbers, government identifiers, financial details, and other durable personal information to someone who intends to misuse them may persist for years.