What happened
On May 7, 2026, Heights discovered unauthorised access to a cloud-based platform hosted by a third party and used to store customer data. Heights says the activity was limited to that platform, did not affect its loan-management systems or other networks, and did not interrupt operations. The company’s notice states that an unauthorised actor may have viewed or copied information and that the platform has since been secured.
On August 18, 2026, SecurityWeek reported that regulatory notifications covered at least 1.2 million individuals. The potentially involved fields include names, addresses, telephone numbers, email addresses, bank names, account and routing numbers, Social Security numbers, tax identifiers, driver’s licence or state identification numbers, dates of birth and personal circumstances shared during customer interactions. The notice says the population may include borrowers, applicants, people who made inquiries through third parties and individuals associated with former or related brands.
Attribution posture: Heights has not named an actor or the third-party cloud provider, and responsibility remains unresolved. Heights did not identify the third-party platform, the access method, the duration of unauthorised access or any forensic indicators. The public evidence therefore confirms access to a supplier-hosted data environment and potentially copied records, but it does not establish the exact number of records exfiltrated or whether the provider experienced broader tenant exposure. The cited source did not publish the specific operational detail described as The provider, access method, dwell time and technical indicators were not disclosed.
Why this matters now
The disclosure separates operational continuity from data consequence. Heights says its loan-management systems and wider network were unaffected, yet the supplier-hosted platform contained combinations of contact, identity and banking data suitable for impersonation, targeted fraud and convincing social engineering.
The affected population reportedly extends beyond current borrowers to applicants, people who inquired about loans and customers associated with former or related brands. That scope illustrates how inherited data and long retention periods can enlarge breach impact long after the original customer relationship changes.
The unnamed provider and unpublished access method limit assurance. Enterprises using cloud platforms for secondary data stores should not treat a provider’s statement that a platform is now secure as sufficient proof of tenant scope, copying, dwell time or downstream misuse.
The decision for security leaders
Direct data protection and supplier-risk teams to locate customer-data platforms that sit outside core production systems. Prioritise stores containing government identifiers, banking data or records retained for former customers, applicants and acquired brands.
Require providers to state the affected tenant, access path, access interval, logging coverage, copying evidence and containment boundary. A generic assurance that the platform is secure does not prove that data was not copied or that another tenant was outside scope.
Align legal notification, fraud monitoring and customer support around a reconciled population and data-field inventory. Where the record count remains uncertain, document the limitation and the evidence still required rather than closing the matter on the basis of uninterrupted operations.
Evidence of closure
- Provider assurance identifies the platform, access path, affected tenant and containment date.
- Reconciled data inventory matches notified populations to retained records.
- Fraud-control validation covers exposed identity and banking data.
- Approved legal record documents notification scope and unresolved limitations.
The Security.io assessment
The breach demonstrates that business interruption is an incomplete measure of cyber materiality. A secondary data platform can expose identity and banking information at substantial scale while transaction processing continues normally, leaving leadership with fraud, legal and trust consequences rather than an availability crisis.
SecurityWeek’s aggregated count is important for scale, but the company’s own wording remains more cautious about whether information was viewed or copied. The defensible position is that unauthorised access is confirmed and copying is possible; precise exfiltration volume is not established in the public notice.
Attribution posture: Heights has not named an actor or the third-party cloud provider, and responsibility remains unresolved. That uncertainty places greater weight on contractual evidence rights, provider log retention and independently reviewable tenant-scoping records.
Heights did not identify the third-party platform, the access method, the duration of unauthorised access or any forensic indicators. Enterprises should treat comparable evidence gaps in their own supplier estate as assurance limitations requiring an owner and resolution date.
Questions for the morning meeting
- Which third-party stores retain applicant data outside core transaction systems?
- Can providers prove tenant scope and data copying from forensic logs?
- Who reconciles notified populations against enterprise data inventories?
- What fraud controls cover exposed bank and government identifiers?