Yes — Heights Finance Holdings Co. (heightsfinance.com) was breached. The Greenville, South Carolina consumer lender posted a Notice of Data Breach dated August 11, 2026. Heights says it discovered on May 7, 2026 that an unauthorized actor reached a third-party cloud platform used to store certain customer data. The company says loan-management systems and other networks were not hit, that the cloud platform is now secure, and that it reported the incident to federal law enforcement.
This is not a duplicate of the August 14 Texas OAG week roundup or the financial-services AG tracker. Those posts list Heights as the largest Texas filing in that batch. This post is the dedicated notice, audit, MFA, website-tech, blacklist, lookalike, and CourtListener write-up.
We scanned heightsfinance.com, the loan.heightsfinance.com MyAccount host, parent attainfinance.com, legacy southernfinance.com, and the Epiq enrollment hosts. 100% is the ideal overall domain-security score. None reach it.
Snapshot
| Field | Detail |
|---|---|
| Organization | Heights Finance Holdings Co. (brands: Heights Finance, Covington Credit, Quick Credit, Southern Finance) |
| Parent / prior name | Attain Finance (Curo Group rebranded February 5, 2025) |
| Notice | heightsfinance.com/importantinfo/ · Aug 11, 2026 |
| Discovered | May 7, 2026 — third-party cloud platform |
| Texas OAG | 734,828 Texans · published Aug 14, 2026 |
| Multi-state tally | SecurityWeek: TX + SC + NH + VT >1.2 million (not a Heights nationwide total) |
What Heights says happened
Per the company notice and the August 11 PR Newswire release:
- An unauthorized actor gained access to a cloud-based platform hosted by a third party.
- Heights says activity was limited to that platform — not loan-management systems or other computers/networks.
- The investigation is complete. Heights says the platform is secure and there is no ongoing security threat.
- Heights has not named the cloud vendor or a threat actor. SecurityWeek reported no known ransomware crew claiming the incident.
- Dark-web monitoring (as of the notice) found no evidence the involved data was listed there.
The notice also covers people who inquired or applied (including through a third party) and former borrowers of Curo Management or related brands. Curo rebranded to Attain Finance in 2025 and consolidated U.S. branches under Heights Finance (Attain rebrand).

Who may be involved
| Group | In scope per Heights |
|---|---|
| Heights borrowers | Received a loan through Heights |
| Applicants | Inquired or applied, including through a third party |
| Legacy brands | Covington Credit, Quick Credit, Southern Finance customers |
| Curo-era records | Former Curo Management borrowers / related brands |
Data Heights says may have been viewed or copied
| Category | Examples in the notice |
|---|---|
| Contact | Name, address, phone, email |
| Financial | Account details; bank name, account number, routing number |
| Government IDs | SSN, tax ID, driver’s license, state ID |
| Other | Date of birth; circumstances shared with customer service |
The Texas OAG filing (published August 14, 2026) lists the same mix for 734,828 Texans: name, address, SSN, driver’s license, government ID, financial information, other, date of birth. Notice methods: print media, company website, email, and Texas-wide broadcast.
The Record and Malwarebytes (August 18) underline the phishing risk: SSN + DOB + bank routing is enough for identity theft and tailored “your loan / your monitoring code” mail.
Published state counts
Heights has not posted a single nationwide total. SecurityWeek added four AG notices:
| State | Residents (published) | Source |
|---|---|---|
| Texas | 734,828 | Texas OAG · Aug 14, 2026 |
| South Carolina | 486,463 | SecurityWeek citing SC AG |
| New Hampshire | 26 | SecurityWeek citing NH AG |
| Vermont | 21 | SecurityWeek citing VT AG |
Treat those four rows as published AG slices, not a complete U.S. inventory. Heights operates 285+ branches across the Midwest, South, and Southeast (About).
Independent cybersecurity audits
We ran EmailMeNow domain audits on August 24, 2026. 100% is the ideal. 0 of 6 reach it. These scores are public email / transport / website posture. They do not name the cloud vendor Heights left unnamed.
| Organization | Domain | Overall | vs 100% |
|---|---|---|---|
| Attain Finance (parent) | attainfinance.com | 70% | −30 |
| Epiq (monitoring vendor) | epiqglobal.com | 68% | −32 |
| Heights Finance | heightsfinance.com | 60% | −40 |
| MyAccount login | loan.heightsfinance.com | 50% | −50 |
| Epiq enrollment | privacysolutionsid.com | 45% | −55 |
| Southern Finance (legacy) | southernfinance.com | 42% | −58 |
| Domain | Identity | Transport | Website |
|---|---|---|---|
| attainfinance.com | 95% | 15% | 37% |
| epiqglobal.com | 50% | 15% | 92% |
| heightsfinance.com | 70% | 15% | 37% |
| loan.heightsfinance.com | 40% | 45% | 40% |
| privacysolutionsid.com | 0% | 15% | 92% |
| southernfinance.com | 25% | 15% | 37% |
How to read this: heightsfinance.com is Average (60%) with the familiar 15% transport gap (no effective MTA-STS enforcement). That gap still leaves room for spoofed “enroll by November 9” mail during an active notice window. Parent attainfinance.com leads identity at 95% and still misses 100%. loan.heightsfinance.com is a login host — treat 40% identity as a no-MX / portal pattern, not a reason to follow a lookalike. privacysolutionsid.com has 0% identity (no MX in this pass) and a TLS leaf that Certificate Transparency shows expiring October 15, 2026 — before the November 9 enrollment deadline.
Audit links: heightsfinance.com · loan.heightsfinance.com · attainfinance.com · privacysolutionsid.com · epiqglobal.com · southernfinance.com

Website stack note
Passive website-tech probes on August 24, 2026:
| Domain | Stack signal |
|---|---|
| heightsfinance.com | Gatsby 5.13.1; Amazon Trust TLS into Jan 22, 2027 |
| loan.heightsfinance.com | Stack undetected; Amazon Trust TLS into Feb 3, 2027 |
| attainfinance.com | Stack undetected; Amazon Trust TLS into Feb 26, 2027 |
| privacysolutionsid.com | Stack undetected; Google Trust Services TLS into Oct 15, 2026 (51d at probe) |
| epiqglobal.com | Stack undetected; Amazon Trust TLS into Feb 16, 2027 |
| southernfinance.com | Fingerprinted WordPress 3.7.1 vs wordpress.org 7.1; Let’s Encrypt TLS into Oct 29, 2026 |
Point-in-time only. A Gatsby marketing site or a stale WordPress generator string is not proof of the May cloud incident. The Oct 15 enrollment-host cert date is worth watching because the Epiq code window runs to Nov 9.
MFA: cell phone only — no YubiKey, no Google Authenticator
Live MyAccount sign-in at loan.heightsfinance.com/sign-in (checked August 24, 2026) asks for a cell phone number and Continue. There is no password field, no security-key option, and no authenticator-app option on that screen. MyAccount instructions tell borrowers to have name, date of birth, email, and ZIP for signup — still no YubiKey or open TOTP docs.
| Method | On Heights MyAccount | Grade impact |
|---|---|---|
| Cell phone number (login) | Only field on live sign-in | Fail (SIM-swap class) |
| YubiKey / FIDO key | Not documented | No Strong path |
| Google Authenticator / open TOTP | Not documented | No Pass path |
| Passkeys | Not documented | No Partial promote |
How we grade: Fail = SMS / phone OTP (or phone-as-identity) as the documented path; Pass = open TOTP; Strong = FIDO/YubiKey. Passkeys do not promote Fail→Pass while phone remains the story. Same rule as the MFA directory.
CISA still recommends phishing-resistant MFA (More than a Password). That is guidance, not a claim that Heights already offers a consumer YubiKey.
Recommended MFA tools
Use these on banks and mailboxes that actually document them — not on this Heights login, which does not.
| Product | Best for | Get it |
|---|---|---|
| YubiKey 5C NFC | USB-C laptops + NFC phones | Amazon |
| YubiKey 5 NFC | USB-A desktops + NFC phones | Amazon |
| YubiKey 5 / 5C NFC case | Keychain protection for the key | Amazon |
| Proton Pass | Passkeys + authenticator-style TOTP vault | Proton Pass |
We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Blacklist, lookalikes, CourtListener
Email blacklist checks (public DoH, August 24, 2026): heightsfinance.com, loan.heightsfinance.com, attainfinance.com, privacysolutionsid.com, and epiqglobal.com were clear. southernfinance.com showed UCEPROTECT Level 3 on mail.southernfinance.com — low-signal provider noise. Do not lead as “Southern Finance is blacklisted.”
DNS lookalike scans (BEC profile, registered signals):
| Brand | To review | BEC staging | Notable hits |
|---|---|---|---|
| heightsfinance.com | 7 | 0 | heightfinance.com, heightsfinace.com, hightsfinance.com |
| attainfinance.com | 1 | 1 | attainfinance.io |
| southernfinance.com | 6 | 1 | southernfinances.com |
| epiqglobal.com | 14 | 2 | eepiqglobal.com, epiqgiobal.com |
| Lookalike | Technique | Note |
|---|---|---|
| heightfinance.com | Omission | Registered NS/A/MX — notice-window lure |
| heightsfinace.com | Omission | Registered NS/A/MX |
| heights-finance.com | Hyphenation | Registered |
| attainfinance.io | TLD swap | BEC staging (MX) |
| southernfinances.com | Insertion | BEC staging (MX) |
Type heightsfinance.com/importantinfo/ yourself. Do not call a number from unexpected SMS, sponsored search, or a lookalike “activation” page. Heights’ published call center for an Epiq activation code is 877-343-7785 (Mon–Fri 9 a.m.–9 p.m. ET). Enrollment deadline: November 9, 2026. Then activate at privacysolutionsid.com with that code.
CourtListener
RECAP search August 24, 2026:
| Court | Result |
|---|---|
| Texas federal (TXSD / TXED / TXND / TXWD) | 0 matching Heights Finance data-breach dockets |
D. South Carolina (scd) | Multiple civil complaints naming Heights Finance Holding Co., filed Aug 19–20, 2026 |
Lead D.S.C. rows (complaint PDFs not available in RECAP at probe time): Titus, 6:26-cv-03594, Patterson, 6:26-cv-03579, plus Huston, Malone, Smith, Hoylman-Capecchi, and Nash the same week. Treat them as a litigation signal after the August 11 notice — not as findings we have read. Edelson Lechtzin announced an investigation on August 12; that is a firm press release, not a docket.
Bankruptcy captions that merely mention Heights as a creditor are out of scope.
What to do
If you had a Heights / Covington / Quick Credit / Southern Finance / Curo-era loan or application:
- Type heightsfinance.com/importantinfo/ — do not click a mail button.
- Call 877-343-7785 for an Epiq activation code, then enroll before November 9, 2026.
- Place a credit freeze at Equifax, Experian, and TransUnion (Heights’ notice lists freeze contacts). A freeze is stronger than 24 months of one-bureau monitoring.
- Watch bank accounts whose routing numbers may have been in the cloud copy. Unexpected ACH or “verify your loan payoff” mail is hostile until you confirm in-branch or via the typed MyAccount URL.
- Lock the mobile number on the MyAccount login (carrier PIN / port freeze). That login is the phone number.
If you run email for a lender: enforce DMARC + MTA-STS toward 100%. A 15% transport score during a 734k-Texan notice window is how spoofed enrollment mail lands.
Related reading
- Texas OAG breaches published August 14, 2026
- Financial services AG tracker
- Texas OAG YTD dashboard
- MFA directory — YubiKey, TOTP, passkeys
- National banks MFA scorecard
- U.S. Bank LockBit claim (unverified; bank says fourth-party)
- Cybersquat Domain Monitoring
Sources: Heights notice · PR Newswire Aug 11 · Texas OAG · SecurityWeek · The Record · Malwarebytes Aug 18 · Attain Finance rebrand · MyAccount sign-in · EmailMeNow audits, website-tech, blacklist, and cybersquat probes August 24, 2026 · CourtListener RECAP August 24, 2026