Data Breaches

Nearly 1 Million User Records Compromised in Figure Data Breach

The blockchain-based lender has confirmed a data breach after ShinyHunters leaked over 2GB of data allegedly stolen from the company.

Data breach

Nearly 1 million user records have been compromised in a data breach at blockchain-powered lender Figure Technology Solutions.

The company confirmed to TechCrunch that it suffered a data breach after an employee fell victim to a social engineering attack, saying the attackers obtained a limited number of files. 

The ShinyHunters hacker group took credit for the attack on Figure. On its Tor-based leak website the cybercrime group made available more than 2.4GB of archive files allegedly containing data stolen from the company.

The data breach notification service Have I Been Pwned has analyzed the leaked data and identified roughly 967,000 Figure user records.

The exposed information includes names, dates of birth, email addresses, postal addresses, and phone numbers. 

Figure Technology Solutions is a Nasdaq-listed fintech firm specializing in blockchain-based home equity lending and mortgage services.

ShinyHunters told TechCrunch that Figure is one of the many victims of the recent Okta campaign, which involved voice phishing to target single sign-on (SSO) accounts that the hackers could leverage to access sensitive data.  

Advertisement. Scroll to continue reading.

The list of victims also includes Betterment, Crunchbase, and Panera Bread

Related: ShinyHunters-Branded Extortion Activity Expands, Escalates

Related: Hackers Offer to Sell Millions of Eurail User Records

Related: Dior, Louis Vuitton, Tiffany Fined $25 Million in South Korea After Data Breaches

Related: Dutch Carrier Odido Discloses Data Breach Impacting 6 Million

Related Content

Data Breaches

The cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision.

Data Breaches

The data breach was initially believed to affect roughly 350,000 people, but the HHS breach tracker shows a far bigger impact.

Data Breaches

Hackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform.

Data Breaches

Hackers used compromised credentials to access enterprise and personal tax-related data.

Data Breaches

Hackers exploited a vulnerability in the order-tracking function of a plugin to access SafePal customer information.

Cloud Security

A threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations.

Data Breaches

The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers.

Data Breaches

The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version