Security News

Heights Finance Data Breach Exposes Details of 1.2 Million People

Security Week · 18 Aug 2026
Key Takeaway Regularly review the security practices of any third-party vendors handling your customers' sensitive data, since their breaches can become your business's problem too.

Heights Finance has disclosed a data breach affecting at least 1.2 million individuals after hackers accessed a third-party platform used by the company. The stolen data reportedly includes names, addresses, phone numbers, Social Security numbers, and financial information — details that could be used for identity theft or targeted scams.

The incident highlights a growing risk for businesses of all sizes: breaches don't always start within your own systems. When a vendor or third-party service provider is compromised, sensitive customer data can be exposed even if your own network defences are strong. For small businesses that rely on external platforms for payments, data storage, or customer management, this case is a reminder to understand exactly what data your partners hold and how they protect it.

Affected individuals should watch for phishing attempts, unexpected account activity, or unauthorised credit inquiries in the wake of this breach. Businesses that work with third-party vendors handling sensitive customer information should review those vendors' security practices and ensure contracts include clear data protection obligations.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.