Back to news
Cybersecurity Alert
August 24, 2026 by EmailMeNow IT Consulting

Was Heights Finance Breached? We Scanned Their Domain Security

Heights Finance confirmed a May 2026 third-party cloud incident. Texas OAG lists 734,828 Texans. Audits (ideal 100%): heightsfinance.com 60%. MyAccount login is cell-phone only — no YubiKey or Google Authenticator.

Source: Heights Finance · Texas OAG

NewsData BreachFinancialMFAPhishingTexasSouth CarolinaCybersecurity
EmailMeNow navy cover card asking whether Heights Finance was breached and showing we scanned their domain security

Yes — Heights Finance Holdings Co. (heightsfinance.com) was breached. The Greenville, South Carolina consumer lender posted a Notice of Data Breach dated August 11, 2026. Heights says it discovered on May 7, 2026 that an unauthorized actor reached a third-party cloud platform used to store certain customer data. The company says loan-management systems and other networks were not hit, that the cloud platform is now secure, and that it reported the incident to federal law enforcement.

This is not a duplicate of the August 14 Texas OAG week roundup or the financial-services AG tracker. Those posts list Heights as the largest Texas filing in that batch. This post is the dedicated notice, audit, MFA, website-tech, blacklist, lookalike, and CourtListener write-up.

We scanned heightsfinance.com, the loan.heightsfinance.com MyAccount host, parent attainfinance.com, legacy southernfinance.com, and the Epiq enrollment hosts. 100% is the ideal overall domain-security score. None reach it.

Snapshot

FieldDetail
OrganizationHeights Finance Holdings Co. (brands: Heights Finance, Covington Credit, Quick Credit, Southern Finance)
Parent / prior nameAttain Finance (Curo Group rebranded February 5, 2025)
Noticeheightsfinance.com/importantinfo/ · Aug 11, 2026
DiscoveredMay 7, 2026 — third-party cloud platform
Texas OAG734,828 Texans · published Aug 14, 2026
Multi-state tallySecurityWeek: TX + SC + NH + VT >1.2 million (not a Heights nationwide total)

What Heights says happened

Per the company notice and the August 11 PR Newswire release:

  • An unauthorized actor gained access to a cloud-based platform hosted by a third party.
  • Heights says activity was limited to that platform — not loan-management systems or other computers/networks.
  • The investigation is complete. Heights says the platform is secure and there is no ongoing security threat.
  • Heights has not named the cloud vendor or a threat actor. SecurityWeek reported no known ransomware crew claiming the incident.
  • Dark-web monitoring (as of the notice) found no evidence the involved data was listed there.

The notice also covers people who inquired or applied (including through a third party) and former borrowers of Curo Management or related brands. Curo rebranded to Attain Finance in 2025 and consolidated U.S. branches under Heights Finance (Attain rebrand).

Inbox lure using a Heights Finance omission lookalike next to the official importantinfo URL

Who may be involved

GroupIn scope per Heights
Heights borrowersReceived a loan through Heights
ApplicantsInquired or applied, including through a third party
Legacy brandsCovington Credit, Quick Credit, Southern Finance customers
Curo-era recordsFormer Curo Management borrowers / related brands

Data Heights says may have been viewed or copied

CategoryExamples in the notice
ContactName, address, phone, email
FinancialAccount details; bank name, account number, routing number
Government IDsSSN, tax ID, driver’s license, state ID
OtherDate of birth; circumstances shared with customer service

The Texas OAG filing (published August 14, 2026) lists the same mix for 734,828 Texans: name, address, SSN, driver’s license, government ID, financial information, other, date of birth. Notice methods: print media, company website, email, and Texas-wide broadcast.

The Record and Malwarebytes (August 18) underline the phishing risk: SSN + DOB + bank routing is enough for identity theft and tailored “your loan / your monitoring code” mail.

Published state counts

Heights has not posted a single nationwide total. SecurityWeek added four AG notices:

StateResidents (published)Source
Texas734,828Texas OAG · Aug 14, 2026
South Carolina486,463SecurityWeek citing SC AG
New Hampshire26SecurityWeek citing NH AG
Vermont21SecurityWeek citing VT AG

Treat those four rows as published AG slices, not a complete U.S. inventory. Heights operates 285+ branches across the Midwest, South, and Southeast (About).

Independent cybersecurity audits

We ran EmailMeNow domain audits on August 24, 2026. 100% is the ideal. 0 of 6 reach it. These scores are public email / transport / website posture. They do not name the cloud vendor Heights left unnamed.

OrganizationDomainOverallvs 100%
Attain Finance (parent)attainfinance.com70%−30
Epiq (monitoring vendor)epiqglobal.com68%−32
Heights Financeheightsfinance.com60%−40
MyAccount loginloan.heightsfinance.com50%−50
Epiq enrollmentprivacysolutionsid.com45%−55
Southern Finance (legacy)southernfinance.com42%−58
DomainIdentityTransportWebsite
attainfinance.com95%15%37%
epiqglobal.com50%15%92%
heightsfinance.com70%15%37%
loan.heightsfinance.com40%45%40%
privacysolutionsid.com0%15%92%
southernfinance.com25%15%37%

How to read this: heightsfinance.com is Average (60%) with the familiar 15% transport gap (no effective MTA-STS enforcement). That gap still leaves room for spoofed “enroll by November 9” mail during an active notice window. Parent attainfinance.com leads identity at 95% and still misses 100%. loan.heightsfinance.com is a login host — treat 40% identity as a no-MX / portal pattern, not a reason to follow a lookalike. privacysolutionsid.com has 0% identity (no MX in this pass) and a TLS leaf that Certificate Transparency shows expiring October 15, 2026before the November 9 enrollment deadline.

Audit links: heightsfinance.com · loan.heightsfinance.com · attainfinance.com · privacysolutionsid.com · epiqglobal.com · southernfinance.com

Four domain-audit bars that stop short of a 100 percent target line

Website stack note

Passive website-tech probes on August 24, 2026:

DomainStack signal
heightsfinance.comGatsby 5.13.1; Amazon Trust TLS into Jan 22, 2027
loan.heightsfinance.comStack undetected; Amazon Trust TLS into Feb 3, 2027
attainfinance.comStack undetected; Amazon Trust TLS into Feb 26, 2027
privacysolutionsid.comStack undetected; Google Trust Services TLS into Oct 15, 2026 (51d at probe)
epiqglobal.comStack undetected; Amazon Trust TLS into Feb 16, 2027
southernfinance.comFingerprinted WordPress 3.7.1 vs wordpress.org 7.1; Let’s Encrypt TLS into Oct 29, 2026

Point-in-time only. A Gatsby marketing site or a stale WordPress generator string is not proof of the May cloud incident. The Oct 15 enrollment-host cert date is worth watching because the Epiq code window runs to Nov 9.

MFA: cell phone only — no YubiKey, no Google Authenticator

Live MyAccount sign-in at loan.heightsfinance.com/sign-in (checked August 24, 2026) asks for a cell phone number and Continue. There is no password field, no security-key option, and no authenticator-app option on that screen. MyAccount instructions tell borrowers to have name, date of birth, email, and ZIP for signup — still no YubiKey or open TOTP docs.

MethodOn Heights MyAccountGrade impact
Cell phone number (login)Only field on live sign-inFail (SIM-swap class)
YubiKey / FIDO keyNot documentedNo Strong path
Google Authenticator / open TOTPNot documentedNo Pass path
PasskeysNot documentedNo Partial promote

How we grade: Fail = SMS / phone OTP (or phone-as-identity) as the documented path; Pass = open TOTP; Strong = FIDO/YubiKey. Passkeys do not promote Fail→Pass while phone remains the story. Same rule as the MFA directory.

CISA still recommends phishing-resistant MFA (More than a Password). That is guidance, not a claim that Heights already offers a consumer YubiKey.

Use these on banks and mailboxes that actually document them — not on this Heights login, which does not.

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
YubiKey 5 / 5C NFC caseKeychain protection for the keyAmazon
Proton PassPasskeys + authenticator-style TOTP vaultProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Heights MyAccount cell-phone sign-in contrasted with YubiKey and Google Authenticator, which are not offered

Blacklist, lookalikes, CourtListener

Email blacklist checks (public DoH, August 24, 2026): heightsfinance.com, loan.heightsfinance.com, attainfinance.com, privacysolutionsid.com, and epiqglobal.com were clear. southernfinance.com showed UCEPROTECT Level 3 on mail.southernfinance.comlow-signal provider noise. Do not lead as “Southern Finance is blacklisted.”

DNS lookalike scans (BEC profile, registered signals):

BrandTo reviewBEC stagingNotable hits
heightsfinance.com70heightfinance.com, heightsfinace.com, hightsfinance.com
attainfinance.com11attainfinance.io
southernfinance.com61southernfinances.com
epiqglobal.com142eepiqglobal.com, epiqgiobal.com
LookalikeTechniqueNote
heightfinance.comOmissionRegistered NS/A/MX — notice-window lure
heightsfinace.comOmissionRegistered NS/A/MX
heights-finance.comHyphenationRegistered
attainfinance.ioTLD swapBEC staging (MX)
southernfinances.comInsertionBEC staging (MX)

Type heightsfinance.com/importantinfo/ yourself. Do not call a number from unexpected SMS, sponsored search, or a lookalike “activation” page. Heights’ published call center for an Epiq activation code is 877-343-7785 (Mon–Fri 9 a.m.–9 p.m. ET). Enrollment deadline: November 9, 2026. Then activate at privacysolutionsid.com with that code.

CourtListener

RECAP search August 24, 2026:

CourtResult
Texas federal (TXSD / TXED / TXND / TXWD)0 matching Heights Finance data-breach dockets
D. South Carolina (scd)Multiple civil complaints naming Heights Finance Holding Co., filed Aug 19–20, 2026

Lead D.S.C. rows (complaint PDFs not available in RECAP at probe time): Titus, 6:26-cv-03594, Patterson, 6:26-cv-03579, plus Huston, Malone, Smith, Hoylman-Capecchi, and Nash the same week. Treat them as a litigation signal after the August 11 notice — not as findings we have read. Edelson Lechtzin announced an investigation on August 12; that is a firm press release, not a docket.

Bankruptcy captions that merely mention Heights as a creditor are out of scope.

What to do

If you had a Heights / Covington / Quick Credit / Southern Finance / Curo-era loan or application:

  1. Type heightsfinance.com/importantinfo/ — do not click a mail button.
  2. Call 877-343-7785 for an Epiq activation code, then enroll before November 9, 2026.
  3. Place a credit freeze at Equifax, Experian, and TransUnion (Heights’ notice lists freeze contacts). A freeze is stronger than 24 months of one-bureau monitoring.
  4. Watch bank accounts whose routing numbers may have been in the cloud copy. Unexpected ACH or “verify your loan payoff” mail is hostile until you confirm in-branch or via the typed MyAccount URL.
  5. Lock the mobile number on the MyAccount login (carrier PIN / port freeze). That login is the phone number.

If you run email for a lender: enforce DMARC + MTA-STS toward 100%. A 15% transport score during a 734k-Texan notice window is how spoofed enrollment mail lands.

Sources: Heights notice · PR Newswire Aug 11 · Texas OAG · SecurityWeek · The Record · Malwarebytes Aug 18 · Attain Finance rebrand · MyAccount sign-in · EmailMeNow audits, website-tech, blacklist, and cybersquat probes August 24, 2026 · CourtListener RECAP August 24, 2026