A lender’s cloud provider was breached—and 1.2 million people face identity-theft risk
The stolen data may include Social Security numbers, government IDs and bank-account information.
SOURCE · SecurityWeekHeights Finance says attackers obtained personal and financial information from a third-party cloud platform used to store customer data. More than 1.2 million people may be affected, including borrowers and some individuals who only applied for or asked about a loan. The records can include names, contact details, dates of birth, Social Security numbers, government ID information, bank-account details and loan history. That combination is more dangerous than a simple contact-list leak because criminals can use real financial context to pass identity checks or create highly convincing calls and messages. Heights is offering 24 months of credit monitoring, but monitoring reports suspicious activity after it occurs; it does not prevent every new account or payment attempt. Affected people should enrol only through the verified company notice, review bank and credit activity, consider a credit freeze and distrust anyone who uses genuine loan details to create urgency. Accurate personal information is evidence of exposure—not proof that the caller is legitimate.
SecBriefs adds context and practical guidance. Reporting remains credited and linked to the original publisher.
