Blockchain Lending Platform Figure Hit By Data Breach – Details

bitcoinistPublished on 2026-02-16Last updated on 2026-02-16

Abstract

Figure Technology, a blockchain lending platform, suffered a data breach after an employee fell victim to a social engineering attack. The breach resulted in the theft of approximately 2.5GB of customer data, including full names, home addresses, dates of birth, and phone numbers. The hacker group ShinyHunters claimed responsibility and publicly released the data after alleged failed ransom negotiations. The company confirmed that its core blockchain systems and financial services remained secure, emphasizing the incident was due to human error, not a technical flaw. Figure is offering free credit monitoring to affected customers and has launched an internal review. The exact number of impacted individuals has not been disclosed.

Figure Technology confirmed that some customer files were stolen after an employee was tricked, according to reports. The company says the intrusion happened when an internal account was used to download a limited batch of records. The breach did not stem from a flaw in its blockchain system, but from human error.

Reports say the stolen material was later posted online by a hacker collective that claimed responsibility. The group is said to have released about 2.5GB of data after alleging that ransom talks broke down. That public dump quickly drew attention across the crypto and fintech space.

Customer Names, Contact Details Among Items Exposed

Based on reports that reviewed samples of the leaked files, the exposed data includes full names, home addresses, dates of birth, and phone numbers. These are the kinds of details often used in identity fraud or targeted scams.

The exact number of affected customers has not been shared publicly. That missing figure leaves uncertainty about how large the fallout could be.

Security researchers warn that even when bank accounts or crypto wallets are untouched, personal data alone can create serious risk. Phishing calls, fake loan offers, and account takeover attempts often follow this type of leak.

Total crypto market cap at $2.34 trillion on the daily chart: TradingView

Figure Hit By Social Engineering Attack

According to coverage of the incident, attackers used a social engineering method to gain access to an employee’s credentials or active session. Instead of breaking through code, they relied on deception. Once inside, files were downloaded through that employee’s access rights.

The company said it detected suspicious activity and moved to block it. Outside forensic specialists were brought in to review system logs and determine what was accessed. A broader internal review is also under way.

Image: CybersecAsia

ShinyHunters claimed responsibility for the breach on its leak site. The group has been linked to prior data exposures involving tech and finance firms. In this case, the data was made public after payment demands were reportedly rejected.

Figure said it will notify customers whose information was involved. Free credit monitoring services are being offered to those who receive formal notice. Impacted individuals are being advised to watch for unusual activity and unsolicited messages.

Funds And Core Services Secure

Reports note that lending operations and on-chain systems were not breached. The platform’s core financial infrastructure was not described as affected. Still, the exposure of personal records carries its own weight.

Financial companies remain frequent targets because they hold detailed customer files. A single employee account, if misused, can open a door wider than expected. That lesson has surfaced again here.

Regulators may seek further details in the coming weeks. Customers will be waiting for clearer numbers. The long-term cost, both financial and reputational, will depend on how widely the data spreads and how quickly protective steps are taken.

Featured image from Yahoo Finance, chart from TradingView

Related Questions

QWhat was the cause of the data breach at Figure Technology?

AThe data breach was caused by human error, specifically a social engineering attack where an employee was tricked, leading to the misuse of an internal account to download customer records.

QWhat type of customer data was exposed in the Figure breach?

AThe exposed data includes full names, home addresses, dates of birth, and phone numbers of customers.

QWhich hacker group claimed responsibility for the data breach?

AThe hacker collective ShinyHunters claimed responsibility for the breach and later posted the stolen data online.

QWere Figure's core financial systems or blockchain infrastructure compromised in the attack?

ANo, the company confirmed that its lending operations, on-chain systems, and core financial infrastructure were not breached in the attack.

QWhat steps is Figure taking to help affected customers?

AFigure is notifying affected customers, offering free credit monitoring services, and advising them to watch for unusual activity and unsolicited messages.

Related Reads

Understanding CPO (Co-Packaged Optics) in One Article: Why Nvidia Is Willing to Spend $3.2 Billion on a Fiber?

NVIDIA and Corning announced a multi-year strategic partnership on May 6, 2026, with NVIDIA committing up to $3.2 billion to support Corning's U.S. expansion. This investment will triple Corning's manufacturing plants and significantly boost its optical fiber and communications production capacity. The core driver behind this massive investment is the fundamental shift from copper to optical interconnect technology within AI data centers. As GPU clusters scale, copper wires face critical limitations: severe signal attenuation over distance, high energy consumption for signal integrity, and excessive heat generation. Optical fiber, transmitting light instead of electrical signals, solves these issues with minimal loss, near-light speed, and lower power needs. The article outlines a three-stage evolution of data center interconnect: 1. **Traditional Copper Interconnects:** The mainstream solution of the 2010s, now being phased out due to scaling bottlenecks. 2. **Pluggable Optical Modules:** The current mainstream, where modules convert electrical signals to light externally. This process still introduces energy loss and latency. 3. **CPO (Co-Packaged Optics):** The next-generation technology where the optical engine is integrated directly with the GPU chip package. This drastically reduces the electrical signal travel distance to mere millimeters, slashing power consumption and latency while boosting data density. NVIDIA CEO Jensen Huang has identified CPO as an essential core technology for AI infrastructure. NVIDIA's investment signifies a strategic shift from being a buyer to actively controlling its supply chain for critical components. With demand for specialized optical fiber far outstripping supply—evidenced by soaring prices—securing long-term manufacturing capacity has become a competitive necessity. While Corning's expansion may pressure some suppliers, a projected global fiber supply gap of 5-15% over the next few years creates a significant opportunity window, particularly for Chinese manufacturers competitive in optical preforms, chips, and modules. Ultimately, NVIDIA's move is not about chasing a trend but an engineering imperative. The transition to light-based interconnects like CPO is driven by the physical limits of copper, marking a definitive step in the ongoing AI computing revolution.

marsbit6m ago

Understanding CPO (Co-Packaged Optics) in One Article: Why Nvidia Is Willing to Spend $3.2 Billion on a Fiber?

marsbit6m ago

KOL's Perspective: Why Is SOL Set to Rise from This Point?

**Summary: Why SOL is Positioned for Growth at This Level** The article argues that SOL is poised for an upward move from its current price point, citing several key factors. Primarily, SOL has just broken out of a 4-month consolidation phase. This breakout signals a return of risk appetite to the broader crypto market, as SOL is seen as a key indicator of overall crypto health. The token's ownership has reportedly shifted from short-term traders and tourists to long-term accumulators, leading to low volume. Any meaningful increase in trading activity could thus trigger significant upward momentum. Fundamental strengths include strong institutional adoption, integration with DeFi and RWAs (Real-World Assets), and the potential benefits from the Clarity Act. Despite its high volatility—having dropped 70% from its all-time high but still up 12x from its bear market low—SOL is highlighted as one of the few tokens from the last cycle to reach new highs. It boasts a robust ecosystem of applications, users, and protocols. Future catalysts include the expected influx of AI developers following the Miami Accelerate conference, which focused on AI on Solana. Furthermore, Solana is positioned as the premier chain for memecoin activity, a trend expected to continue and drive network usage and fees. The article concludes that recent price action reflects a healthy transfer to long-term holders, setting the stage for growth.

marsbit56m ago

KOL's Perspective: Why Is SOL Set to Rise from This Point?

marsbit56m ago

Those Pre-Bitcoin PoW Protocols Have Recently Been Reimplemented

This article details a recent surge in replicating pre-Bitcoin Proof-of-Work (PoW) protocols, specifically focusing on Hal Finney's 2004 RPOW (Reusable Proofs of Work). Within five days in May 2026, multiple independent builders in the Bitcoin/cypherpunk community launched projects inspired by this early electronic cash proposal. The initiative began with Fred Krueger's `rpow2.com`, a centralized but auditable system that replaced RPOW's original IBM 4758 hardware with Ed25519 signatures. Initially a faithful replica, it later adopted Bitcoin-like features (21M supply cap, difficulty adjustment) and a controversial 5.24% founder allocation. This sparked rapid forks, including `rpow4.com` which incorporated full Bitcoin parameters, a prediction market (`rpowmarket.com`), and a DEX (`rpow2swap.com`). Concurrently, Mike In Space created a prototype of Wei Dai's 1998 b-money proposal (`b-money.replit.app`), pushing the historical exploration even further back. The article contrasts these centralized, server-dependent experiments with Bitcoin's core innovation of decentralized, trustless consensus. It also highlights a parallel development: the `HASH` project on Ethereum, which uses smart contract hooks to enable a purely fair-launch, browser-mineable PoW token with 0% allocations to team or VCs. The collective activity is framed as a meme-driven, educational exploration of cypherpunk history rather than a serious financial movement, with all projects heavily disclaiming any investment value.

marsbit1h ago

Those Pre-Bitcoin PoW Protocols Have Recently Been Reimplemented

marsbit1h ago

South Korean Exchanges 'Battle' Regulators, Challenging the Boundaries of Enforcement and Legislation

South Korea's cryptocurrency industry is engaged in a rare, direct confrontation with regulators. The Financial Intelligence Unit (FIU), the primary anti-money laundering (AML) watchdog, has recently imposed heavy penalties on major exchanges like Upbit and Bithumb for alleged violations involving unregistered overseas VASPs and AML procedures. However, exchanges are now actively challenging these actions in court and through industry associations. In a significant shift, the Seoul Administrative Court ruled in favor of Upbit's operator, Dunamu, overturning part of an FIU-ordered business suspension. The court found the FIU's penalty criteria and justification insufficiently clear. Similarly, the court suspended the enforcement of a six-month business suspension against Bithumb pending a final ruling, citing potential irreversible harm to the exchange. Beyond legal battles, the industry is contesting proposed legislative amendments. The Digital Asset eXchange Alliance (DAXA) strongly opposes a draft rule that would mandate Suspicious Transaction Reports (STRs) for all crypto transfers over 10 million KRW (~$6,800). DAXA argues this "poison pill" clause violates legal principles and would overwhelm the STR system, increasing reports from 63,000 to an estimated 5.45 million annually for major exchanges, thereby crippling effective AML monitoring. This conflict highlights a structural tension in South Korea's crypto governance: comprehensive digital asset laws are still developing, while regulators rely heavily on AML enforcement. The industry's move from passive compliance to active legal and legislative challenges signifies a new phase, pressing for clearer rules and more proportionate enforcement. While short-term disputes may intensify, this clash could ultimately lead to a more mature and sustainable regulatory framework for South Korea's vibrant crypto market.

marsbit1h ago

South Korean Exchanges 'Battle' Regulators, Challenging the Boundaries of Enforcement and Legislation

marsbit1h ago

Trading

Spot
Futures
活动图片