Back to news
Cybersecurity Alert
August 24, 2026 by EmailMeNow IT Consulting

Was Heights Finance Breached? We Scanned Their Domain Security

Heights Finance confirmed a May 2026 third-party cloud incident. Texas OAG lists 734,828 Texans. Audits (ideal 100%): heightsfinance.com 60%. MyAccount login is cell-phone only — no YubiKey or Google Authenticator.

Source: Heights Finance · Texas OAG

NewsData BreachFinancialMFAPhishingTexasSouth CarolinaCybersecurity
Cinematic consumer-lender storefront at night with a cloud-warning overlay asking whether Heights Finance was breached

Yes — Heights Finance Holdings Co. (heightsfinance.com) was breached. The Greenville, South Carolina consumer lender posted a Notice of Data Breach dated August 11, 2026. Heights says it discovered on May 7, 2026 that an unauthorized actor reached a third-party cloud platform used to store certain customer data. The company says loan-management systems and other networks were not hit, that the cloud platform is now secure, and that it reported the incident to federal law enforcement.

This is not a duplicate of the August 14 Texas OAG week roundup or the financial-services AG tracker. Those posts list Heights as the largest Texas filing in that batch. This post is the dedicated notice, audit, MFA, website-tech, blacklist, lookalike, and CourtListener write-up.

We scanned heightsfinance.com, the loan.heightsfinance.com MyAccount host, parent attainfinance.com, legacy southernfinance.com, and the Epiq enrollment hosts. 100% is the ideal overall domain-security score. None reach it.

Snapshot

FieldDetail
OrganizationHeights Finance Holdings Co. (brands: Heights Finance, Covington Credit, Quick Credit, Southern Finance)
Parent / prior nameAttain Finance (Curo Group rebranded February 5, 2025)
Noticeheightsfinance.com/importantinfo/ · Aug 11, 2026
DiscoveredMay 7, 2026 — third-party cloud platform
Texas OAG734,828 Texans · published Aug 14, 2026
Multi-state tallySecurityWeek: TX + SC + NH + VT >1.2 million (not a Heights nationwide total)

What Heights says happened

Per the company notice and the August 11 PR Newswire release:

  • An unauthorized actor gained access to a cloud-based platform hosted by a third party.
  • Heights says activity was limited to that platform — not loan-management systems or other computers/networks.
  • The investigation is complete. Heights says the platform is secure and there is no ongoing security threat.
  • Heights has not named the cloud vendor or a threat actor. SecurityWeek reported no known ransomware crew claiming the incident.
  • Dark-web monitoring (as of the notice) found no evidence the involved data was listed there.

The notice also covers people who inquired or applied (including through a third party) and former borrowers of Curo Management or related brands. Curo rebranded to Attain Finance in 2025 and consolidated U.S. branches under Heights Finance (Attain rebrand).

Inbox lure using a Heights Finance omission lookalike next to the official importantinfo URL

Who may be involved

GroupIn scope per Heights
Heights borrowersReceived a loan through Heights
ApplicantsInquired or applied, including through a third party
Legacy brandsCovington Credit, Quick Credit, Southern Finance customers
Curo-era recordsFormer Curo Management borrowers / related brands

Data Heights says may have been viewed or copied

CategoryExamples in the notice
ContactName, address, phone, email
FinancialAccount details; bank name, account number, routing number
Government IDsSSN, tax ID, driver’s license, state ID
OtherDate of birth; circumstances shared with customer service

The Texas OAG filing (published August 14, 2026) lists the same mix for 734,828 Texans: name, address, SSN, driver’s license, government ID, financial information, other, date of birth. Notice methods: print media, company website, email, and Texas-wide broadcast.

The Record and Malwarebytes (August 18) underline the phishing risk: SSN + DOB + bank routing is enough for identity theft and tailored “your loan / your monitoring code” mail.

Published state counts

Heights has not posted a single nationwide total. SecurityWeek added four AG notices:

StateResidents (published)Source
Texas734,828Texas OAG · Aug 14, 2026
South Carolina486,463SecurityWeek citing SC AG
New Hampshire26SecurityWeek citing NH AG
Vermont21SecurityWeek citing VT AG

Treat those four rows as published AG slices, not a complete U.S. inventory. Heights operates 285+ branches across the Midwest, South, and Southeast (About).

Independent cybersecurity audits

We ran EmailMeNow domain audits on August 24, 2026. 100% is the ideal. 0 of 6 reach it. These scores are public email / transport / website posture. They do not name the cloud vendor Heights left unnamed.

OrganizationDomainOverallvs 100%
Attain Finance (parent)attainfinance.com70%−30
Epiq (monitoring vendor)epiqglobal.com68%−32
Heights Financeheightsfinance.com60%−40
MyAccount loginloan.heightsfinance.com50%−50
Epiq enrollmentprivacysolutionsid.com45%−55
Southern Finance (legacy)southernfinance.com42%−58
DomainIdentityTransportWebsite
attainfinance.com95%15%37%
epiqglobal.com50%15%92%
heightsfinance.com70%15%37%
loan.heightsfinance.com40%45%40%
privacysolutionsid.com0%15%92%
southernfinance.com25%15%37%

How to read this: heightsfinance.com is Average (60%) with the familiar 15% transport gap (no effective MTA-STS enforcement). That gap still leaves room for spoofed “enroll by November 9” mail during an active notice window. The August 14 Texas OAG week roundup listed this host at 55% in that batch; this post uses a fresh August 24 audit (60%). Parent attainfinance.com leads identity at 95% and still misses 100%. loan.heightsfinance.com is a login host — treat 40% identity as a no-MX / portal pattern, not a reason to follow a lookalike. privacysolutionsid.com has 0% identity (no MX in this pass) and a TLS leaf that Certificate Transparency shows expiring October 15, 2026before the November 9 enrollment deadline.

Audit links: heightsfinance.com · loan.heightsfinance.com · attainfinance.com · privacysolutionsid.com · epiqglobal.com · southernfinance.com

Padlocks stop short of a 100 percent finish line, illustrating domain audits that miss the ideal score

Illustration only — scores are in the tables above, not in the artwork.

Website stack note

Passive website-tech probes on August 24, 2026:

DomainStack signal
heightsfinance.comGatsby 5.13.1; Amazon Trust TLS into Jan 22, 2027
loan.heightsfinance.comStack undetected; Amazon Trust TLS into Feb 3, 2027
attainfinance.comStack undetected; Amazon Trust TLS into Feb 26, 2027
privacysolutionsid.comStack undetected; Google Trust Services TLS into Oct 15, 2026 (51d at probe)
epiqglobal.comStack undetected; Amazon Trust TLS into Feb 16, 2027
southernfinance.comFingerprinted WordPress 3.7.1 vs wordpress.org 7.1; Let’s Encrypt TLS into Oct 29, 2026

Point-in-time only. A Gatsby marketing site or a stale WordPress generator string is not proof of the May cloud incident. The Oct 15 enrollment-host cert date is worth watching because the Epiq code window runs to Nov 9.

MFA: cell phone only — no YubiKey, no Google Authenticator

Live MyAccount sign-in at loan.heightsfinance.com/sign-in (checked August 24, 2026) asks for a cell phone number and Continue. There is no password field, no security-key option, and no authenticator-app option on that screen. MyAccount instructions tell borrowers to have name, date of birth, email, and ZIP for signup — still no YubiKey or open TOTP docs.

MethodOn Heights MyAccountGrade impact
Cell phone number (login)Only field on live sign-inFail (SIM-swap class)
YubiKey / FIDO keyNot documentedNo Strong path
Google Authenticator / open TOTPNot documentedNo Pass path
PasskeysNot documentedNo Partial promote

How we grade: Fail = SMS / phone OTP (or phone-as-identity) as the documented path; Pass = open TOTP; Strong = FIDO/YubiKey. Passkeys do not promote Fail→Pass while phone remains the story. Same rule as the MFA directory.

CISA still recommends phishing-resistant MFA (More than a Password). That is guidance, not a claim that Heights already offers a consumer YubiKey.

Use these on banks and mailboxes that actually document them — not on this Heights login, which does not.

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
YubiKey 5 / 5C NFC caseKeychain protection for the keyAmazon
Proton PassPasskeys + authenticator-style TOTP vaultProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Heights MyAccount cell-phone sign-in contrasted with YubiKey and Google Authenticator, which are not offered

Blacklist, lookalikes, CourtListener

Email blacklist checks (public DoH, August 24, 2026): heightsfinance.com, loan.heightsfinance.com, attainfinance.com, privacysolutionsid.com, and epiqglobal.com were clear. southernfinance.com showed UCEPROTECT Level 3 on mail.southernfinance.comlow-signal provider noise. Do not lead as “Southern Finance is blacklisted.”

DNS lookalike scans (BEC profile, registered signals):

BrandTo reviewBEC stagingNotable hits
heightsfinance.com70heightfinance.com, heightsfinace.com, hightsfinance.com
attainfinance.com11attainfinance.io
southernfinance.com61southernfinances.com
epiqglobal.com142eepiqglobal.com, epiqgiobal.com
LookalikeTechniqueNote
heightfinance.comOmissionRegistered NS/A/MX — notice-window lure
heightsfinace.comOmissionRegistered NS/A/MX
heights-finance.comHyphenationRegistered
attainfinance.ioTLD swapBEC staging (MX)
southernfinances.comInsertionBEC staging (MX)

Type heightsfinance.com/importantinfo/ yourself. Do not call a number from unexpected SMS, sponsored search, or a lookalike “activation” page. Heights’ published call center for an Epiq activation code is 877-343-7785 (Mon–Fri 9 a.m.–9 p.m. ET). Enrollment deadline: November 9, 2026. Then activate at privacysolutionsid.com with that code.

CourtListener and weekly scan sources

RECAP re-check August 24, 2026 (afternoon):

CourtResult
Texas federal (TXSD / TXED / TXND / TXWD)0 matching Heights Finance data-breach dockets
D. South Carolina (scd)7 civil complaints naming Heights Finance Holding Co., filed Aug 19–20, 2026
SEC EDGAR Item 1.05None — Heights is a private holdings company
MERENA alerts listingNo Heights Immediate Action or Advisory
GalaxyWarden / DeXposeNo retrieved leak-site listing (this is a confirmed company notice, not an extortion dump)

D.S.C. rows (complaint PDFs not available in RECAP at re-check — treat as a litigation signal, not findings we have read):

PlaintiffDocketFiledRECAP complaint
Titus6:26-cv-03594Aug 20Not available
Huston6:26-cv-03592Aug 20Not available
Patterson6:26-cv-03579Aug 20Not available
Malone6:26-cv-03568Aug 19Not available
Smith6:26-cv-03567Aug 19Not available
Hoylman-Capecchi6:26-cv-03564Aug 19Not available
Nash6:26-cv-03563Aug 19Not available

Edelson Lechtzin announced an investigation on August 12; that is a firm press release, not a docket.

Bankruptcy captions that merely mention Heights as a creditor are out of scope.

What to do

If you had a Heights / Covington / Quick Credit / Southern Finance / Curo-era loan or application:

  1. Type heightsfinance.com/importantinfo/ — do not click a mail button.
  2. Call 877-343-7785 for an Epiq activation code, then enroll before November 9, 2026.
  3. Place a credit freeze at Equifax, Experian, and TransUnion (Heights’ notice lists freeze contacts). A freeze is stronger than 24 months of one-bureau monitoring.
  4. Watch bank accounts whose routing numbers may have been in the cloud copy. Unexpected ACH or “verify your loan payoff” mail is hostile until you confirm in-branch or via the typed MyAccount URL.
  5. Lock the mobile number on the MyAccount login (carrier PIN / port freeze). That login is the phone number.

If you run email for a lender: enforce DMARC + MTA-STS toward 100%. A 15% transport score during a 734k-Texan notice window is how spoofed enrollment mail lands.

Sources: Heights notice · PR Newswire Aug 11 · Texas OAG · SecurityWeek · The Record · Malwarebytes Aug 18 · Attain Finance rebrand · MyAccount sign-in · EmailMeNow audits, website-tech, blacklist, and cybersquat probes August 24, 2026 · CourtListener RECAP August 24, 2026 (afternoon re-check: Texas federal 0; D.S.C. 7) · MERENA / GalaxyWarden / DeXpose / SEC 8-K scanned August 24, 2026 (no Heights leak-site listing or Item 1.05)