{"id":43754,"date":"2026-02-18T22:58:14","date_gmt":"2026-02-18T14:58:14","guid":{"rendered":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/02\/18\/data-breach-at-fintech-firm-figure-affects-nearly-1-million-accounts\/"},"modified":"2026-02-18T22:58:14","modified_gmt":"2026-02-18T14:58:14","slug":"data-breach-at-fintech-firm-figure-affects-nearly-1-million-accounts","status":"publish","type":"post","link":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/02\/18\/data-breach-at-fintech-firm-figure-affects-nearly-1-million-accounts\/","title":{"rendered":"Data breach at fintech firm Figure affects nearly 1 million accounts"},"content":{"rendered":"\n<p style=\"text-align:center\"><img loading=\"lazy\" decoding=\"async\" height=\"900\" src=\"https:\/\/www.bleepstatic.com\/content\/hl-images\/2026\/02\/18\/Figure_headpic.jpg\" width=\"1600\" alt=\"Data breach at fintech firm Figure affects nearly 1 million accounts\"><\/p>\n<p>Hackers have stolen the personal and contact information of nearly 1 million accounts after breaching the systems of Figure Technology Solutions, a self-described blockchain-native financial technology company.<\/p>\n<p>Founded in 2018, Figure uses the Provenance blockchain for lending, borrowing, and securities trading, and has unlocked over $22 billion in home equity with over 250 partners, including banks, credit unions, fintechs, and home improvement companies.<\/p>\n<p>While the blockchain lender didn&#8217;t publicly disclose the incident, a Figure spokesperson <a href=\"https:\/\/techcrunch.com\/2026\/02\/13\/fintech-lending-giant-figure-confirms-data-breach\/\" target=\"_blank\" rel=\"nofollow noopener\">told TechCrunch<\/a> on Friday that the attackers stole &#8220;a limited number of files&#8221; in a social engineering attack.<\/p>\n<div align=\"center\" style=\"width:98%; margin:0 auto; text-align:center; padding:4px; background:#f0f0f0; border:1px solid #ccc; border-radius:6px;\">  <a href=\"https:\/\/www.wiz.io\/lp\/secure-images-101-a-visual-guide?utm_source=bleepingcomputer&amp;utm_medium=display&amp;utm_campaign=FY26Q4_INB_FORM_Hardened-Images-101-Digital-Poster&amp;sfcid=701Py00000WFCeLIAX&amp;utm_term=FY27-bleepingcomputer-article-970x250&amp;utm_content=Secured-Images-101\" rel=\"nofollow noopener\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/c\/w\/Secured-Images-970x250.png\" style=\"margin-top: 0px;\" alt=\"Data breach at fintech firm Figure affects nearly 1 million accounts\"><\/a> <\/div>\n<p>BleepingComputer has also reached out to Figure with further questions about the breach, but a response was not immediately available.<\/p>\n<p>Although the company has yet to share how many individuals were affected <span style=\"box-sizing:border-box; margin:0px; padding:0px\">by the data breach, notification service Have I Been Pwned <a href=\"https:\/\/haveibeenpwned.com\/Breach\/Figure\" target=\"_blank\" rel=\"nofollow noopener\">has now revealed the extent of the incident<\/a>, reporting that data from<\/span> 967,200 accounts was stolen in the attack.<\/p>\n<p>&#8220;In February 2026, data obtained from the fintech lending platform Figure was publicly posted online,&#8221; Have I Been Pwned said on Wednesday.<\/p>\n<p>&#8220;The exposed data, dating back to January 2026, contained over 900k unique email addresses along with names, phone numbers, physical addresses and dates of birth. Figure confirmed the incident and attributed it to a social engineering attack in which an employee was tricked into providing access.&#8221;<\/p>\n<p>The ShinyHunters extortion group claimed responsibility for the breach and added the company to its dark web leak site, leaking 2.5GB of data allegedly stolen from thousands of loan applicants.<\/p>\n<div style=\"text-align:center\">\n<figure style=\"display:inline-block\"><img loading=\"lazy\" decoding=\"async\" height=\"241\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1109292\/2026\/Figure%20Technology%20Solutions%20ShinyHunters.png\" width=\"700\" alt=\"Data breach at fintech firm Figure affects nearly 1 million accounts\"><figcaption><em>CaptionFigure Technology on ShinyHunters leak site (BleepingComputer)<\/em><\/figcaption><\/figure>\n<\/div>\n<p>In recent weeks, ShinyHunters claimed similar breaches at <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/canada-goose-investigating-as-hackers-leak-600k-customer-records\/\" target=\"_blank\" rel=\"nofollow noopener\">Canada Goose<\/a>, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/panera-bread-data-breach-impacts-51-million-accounts-not-14-million-customers\/\" target=\"_blank\" rel=\"nofollow noopener\">Panera Bread<\/a>, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/data-breach-at-fintech-firm-betterment-exposes-14-million-accounts\/\" target=\"_blank\" rel=\"nofollow noopener\">Betterment<\/a>, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/have-i-been-pwned-soundcloud-data-breach-impacts-298-million-accounts\/\" target=\"_blank\" rel=\"nofollow noopener\">SoundCloud<\/a>, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/pornhub-extorted-after-hackers-steal-premium-member-activity-data\/\" target=\"_blank\" rel=\"nofollow noopener\">PornHub<\/a>, and <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/crowdstrike-catches-insider-feeding-information-to-hackers\/\" target=\"_blank\" rel=\"nofollow noopener\">CrowdStrike<\/a>.<\/p>\n<p>While not all of them are part of the same campaign, some of these victims were breached in a voice phishing (vishing) campaign <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/shinyhunters-claim-to-be-behind-sso-account-data-theft-attacks\/\" target=\"_blank\" rel=\"nofollow noopener\">targeting single sign-on (SSO) accounts<\/a> at Okta, Microsoft, and Google across <a href=\"http:\/\/www.silentpush.com\/blog\/slsh-alert\/\" target=\"_blank\" rel=\"nofollow noopener\">more than 100 high-profile organizations<\/a>.<\/p>\n<p>The attackers are impersonating IT support, calling their targets&#8217; employees and tricking them into entering credentials and multi-factor authentication (MFA) codes on phishing sites that impersonate their companies&#8217; login portals.<\/p>\n<p>Once in, they gain access to the victim&#8217;s SSO account, which provides them with access to other connected enterprise applications and services, including Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Zendesk, Dropbox, Adobe, Atlassian, and many others.<\/p>\n<p>As part of this campaign, ShinyHunters also <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match\/\" target=\"_blank\" rel=\"nofollow noopener\">breached online dating giant Match Group<\/a>, which owns multiple popular dating services, including Tinder, Hinge, Meetic, Match.com, and OkCupid.<\/p>\n<style> .ia_ad {     background-color: #f0f6ff;     width: 95%;     max-width: 800px;     margin: 15px auto;     border-radius: 8px;     border: 1px solid #d6ddee;     display: flex;     align-items: stretch;     padding: 0;     overflow: hidden; }  .ia_lef {     flex: 1;     max-width: 200px;     height: auto;     display: flex;     align-items: stretch; }  .ia_lef a {     display: flex;     width: 100%;     height: 100%; }   .ia_lef a img {     width: 100%;     height: 100%;          border-radius: 8px 0 0 8px;     margin: 0;     display: block; }  .ia_rig {     flex: 2;     padding: 10px;     display: flex;     flex-direction: column;     justify-content: center; }  .ia_rig h2 {     font-size: 17px !important;     font-weight: 700;     color: #333;     line-height: 1.4;     font-family: Georgia, \"Times New Roman\", Times, serif;     margin: 0 0 14px 0; }  .ia_rig p {     font-weight: bold;     font-size: 14px;     margin: 0 0 clamp(6px, 2vw, 14px) 0; }  .ia_button {     background-color: #FFF;     border: 1px solid #3b59aa;     color: black;     text-align: center;     text-decoration: none;     border-radius: 8px;     display: inline-block;     font-size: 16px;     font-weight: bold;     cursor: pointer;     padding: 10px 20px;     width: fit-content; }  .ia_button a {     text-decoration: none;     color: inherit;     display: block; }  @media (max-width: 600px) {     .ia_ad {         flex-direction: column;         align-items: center;     }      .ia_lef {         max-width: 100%;     }      .ia_lef a img {         border-radius: 8px 8px 0 0;     }       .ia_rig {         padding: 15px;         width: 100%;     }      .ia_button {         width: 100%; \tmargin: 0px auto;     } } <\/style>\n<div>\n<div>         <a href=\"https:\/\/www.tines.com\/access\/guide\/the-future-of-it-infrastructure\/?utm_source=BleepingComputer&amp;utm_medium=paid_media&amp;utm_content=ROS-inarticlebanner-0102\" target=\"_blank\" rel=\"noopener sponsored\">             <img decoding=\"async\" src=\"https:\/\/www.bleepingcomputer.com\/news\/security\/data-breach-at-fintech-firm-figure-affects-nearly-1-million-accounts\/data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" data-src=\"https:\/\/www.bleepstatic.com\/c\/t\/tines-in-art-square.jpg\" alt=\"Data breach at fintech firm Figure affects nearly 1 million accounts\"><\/a>     <\/div>\n<div>\n<h2><a href=\"https:\/\/www.tines.com\/access\/guide\/the-future-of-it-infrastructure\/?utm_source=BleepingComputer&amp;utm_medium=paid_media&amp;utm_content=ROS-inarticlebanner-0102\" target=\"_blank\" rel=\"noopener sponsored\">The future of IT infrastructure is here<\/a><\/h2>\n<p>Modern IT infrastructure moves faster than manual workflows can handle.<\/p>\n<p>In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.<\/p>\n<p>          <button><a href=\"https:\/\/www.tines.com\/access\/guide\/the-future-of-it-infrastructure\/?utm_source=BleepingComputer&amp;utm_medium=paid_media&amp;utm_content=ROS-inarticlebanner-0102\" target=\"_blank\" rel=\"noopener sponsored\">Get the guide<\/a><\/button>     <\/div>\n<\/p><\/div>\n<div>\n<h3>Related Articles:<\/h3>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/panera-bread-data-breach-impacts-51-million-accounts-not-14-million-customers\/\">Panera Bread breach impacts 5.1 million accounts, not 14 million customers <\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match\/\">Match Group breach exposes data from Hinge, Tinder, OkCupid, and Match<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hacker-admits-to-leaking-stolen-supreme-court-data-on-instagram\/\">Hacker admits to leaking stolen Supreme Court data on Instagram<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/nordvpn-denies-breach-claims-says-attackers-have-dummy-data\/\">NordVPN denies breach claims, says attackers have &#8220;dummy data&#8221;<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/canada-goose-investigating-as-hackers-leak-600k-customer-records\/\">Canada Goose investigating as hackers leak 600K customer records<\/a><\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Hackers have stolen the personal and contact informatio [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[28],"tags":[],"class_list":["post-43754","post","type-post","status-publish","format-standard","hentry","category--bleepingcomputer"],"_links":{"self":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/43754","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/comments?post=43754"}],"version-history":[{"count":0,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/43754\/revisions"}],"wp:attachment":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/media?parent=43754"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/categories?post=43754"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/tags?post=43754"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}