Consumer lender Heights Finance is notifying more than 1.2 million people that their personal and financial information was stolen in a data breach, SecurityWeek reported. Names, addresses, phone numbers, Social Security numbers, government ID and driver's license numbers, bank account details, and dates of birth were all taken. State attorney general filings put the bulk of those affected in Texas (734,828) and South Carolina (486,463), with smaller numbers in New Hampshire and Vermont.
The detail that matters most is in the second paragraph of Heights' own incident notice: in early May, hackers accessed a third-party, cloud-based platform the company used for customer data storage. Heights says the incident was limited to that platform and did not affect its loan management systems or other computer systems or networks. The lender's own infrastructure, by its own account, was never the point of failure.
That's the structural problem with third-party risk in one sentence: an institution can run a genuinely well-secured internal environment and still be the one sending 1.2 million breach notifications, because the vulnerable system was never its own to secure. Heights' loan management systems held up. The cloud storage vendor sitting alongside them didn't, and the customers whose data it held have no relationship with that vendor at all, no way to have chosen it, and no visibility into how well it was ever assessed.
Heights' own notice makes a second critical point: affected individuals include anyone who received a loan through Heights, anyone who inquired about or applied for a loan product including through a third party, and anyone who was a former borrower of Curo Management or any of its former or current related brands. That's data flowing in through third-party origination channels and data inherited through a corporate history of mergers and rebrands, all sitting in the same exposed system, none of it freshly reviewed at the point this breach occurred.
A periodic compliance check, run annually or at onboarding, has no mechanism for catching this. It confirms what was true at the last checkpoint, not what's true today, and it was never designed to track risk that accumulates through M&A history and third-party channels years after the fact.
None of this required a sophisticated attack on Heights itself. It required one third-party, several steps removed from the lender's own security team, to be the weaker link, and a population of customers with no way to have known that third-party was even in the chain. That's precisely the gap continuous assessment is built to close: verifying not just whether a third-party was secure when it was onboarded, but whether it still is, on an ongoing basis, including the sub-processors and legacy data holdings that accumulate over time and never get re-examined until something goes wrong.
See how the Invela Network applies standardized accreditation and continuous risk monitoring to every participant holding customer data, including the third-party platforms sitting a step removed from the financial institution.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place. Open finance, covered.
Invela is the infrastructure layer that makes open finance trustworthy - accrediting who's in the network, monitoring risk in real time, and ensuring liability lands in the right place.