Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Nearly 1 Million User Records Compromised in Figure Data Breach

The blockchain-based lender has confirmed a data breach after ShinyHunters leaked over 2GB of data allegedly stolen from the company.

Data breach

Nearly 1 million user records have been compromised in a data breach at blockchain-powered lender Figure Technology Solutions.

The company confirmed to TechCrunch that it suffered a data breach after an employee fell victim to a social engineering attack, saying the attackers obtained a limited number of files. 

The ShinyHunters hacker group took credit for the attack on Figure. On its Tor-based leak website the cybercrime group made available more than 2.4GB of archive files allegedly containing data stolen from the company.

The data breach notification service Have I Been Pwned has analyzed the leaked data and identified roughly 967,000 Figure user records.

The exposed information includes names, dates of birth, email addresses, postal addresses, and phone numbers. 

Figure Technology Solutions is a Nasdaq-listed fintech firm specializing in blockchain-based home equity lending and mortgage services.

ShinyHunters told TechCrunch that Figure is one of the many victims of the recent Okta campaign, which involved voice phishing to target single sign-on (SSO) accounts that the hackers could leverage to access sensitive data.  

Advertisement. Scroll to continue reading.

The list of victims also includes Betterment, Crunchbase, and Panera Bread

Related: ShinyHunters-Branded Extortion Activity Expands, Escalates

Related: Hackers Offer to Sell Millions of Eurail User Records

Related: Dior, Louis Vuitton, Tiffany Fined $25 Million in South Korea After Data Breaches

Related: Dutch Carrier Odido Discloses Data Breach Impacting 6 Million

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.