Figure Technology Confirms Customer Data Breach After Social Engineering Attack

TheNewsCryptoPublié le 2026-02-14Dernière mise à jour le 2026-02-14

Résumé

Figure Technology, a blockchain-based lending firm, has confirmed a data breach resulting from a social engineering attack. Hackers tricked an employee into providing access, leading to the theft of approximately 2.5 GB of customer data, including names, addresses, birth dates, and phone numbers. The group ShinyHunters claimed responsibility and released the data after the company refused to pay a ransom. No financial information or passwords were confirmed to be compromised. The company has launched an investigation, notified affected customers, and is offering free credit monitoring. Cybersecurity experts emphasize that such attacks target human vulnerabilities rather than technical flaws.

Figure Technology, a publicly traded blockchain-based lender company, has confirmed that hackers gained access to customer information by tricking an employee through a social engineering scheme. As per the report from TechCrunch, attackers claimed that they had released 2.5 gigabytes of stolen data after the company refused to pay a ransom.

How did the hack happen?

One of the staff members was manipulated by an outside actor, which allowed the attacker to download the files using the employee’s legitimate account. According to the company, the suspicious activity was blocked quickly, and forensic investigations have been launched. A report from TechCrunch said that the stolen files may include full names, home addresses, dates of birth, and phone numbers. Still, there is no confirmation that the passwords or financial assets were accessed.

The cybercrime group ShinyHunters claims responsibility, and one alleged member said that the breach is part of the wider campaign targeting organizations that use the identity and login provider Okta. The group alleged that it had released about 2.5 GB of data after the company refused the ransom demands. The company says that it is now notifying affected individuals and offering free credit monitoring with strong internal security controls.

Expert’s Advice

Cybersecurity experts warn that social engineering attacks don’t break the software; instead, they trick humans, and criminals may pretend to be IT staff and send fake approval requests with some urgent messages to pressure the victims. Once the access is granted, they operate as legitimate users. Right now, investigators are still working to confirm which file has been stolen and how many people are affected. So further updates are expected once the forensic review is complete.

Highlighted Crypto News:

KuCoin Institutional Premiere 2026 Highlights Long-Term Growth and Market Resilience

TagsCrypto ScamCryptocurrency

Questions liées

QWhat type of attack did Figure Technology experience that led to the customer data breach?

AFigure Technology experienced a social engineering attack where hackers tricked an employee to gain access to customer information.

QWhich cybercrime group claimed responsibility for the attack on Figure Technology?

AThe cybercrime group ShinyHunters claimed responsibility for the attack.

QWhat specific customer information was potentially exposed in the data breach according to the TechCrunch report?

AAccording to the TechCrunch report, the stolen files may include full names, home addresses, dates of birth, and phone numbers.

QWhat action did the attackers take after the company refused to pay the ransom?

AAfter the company refused to pay the ransom, the attackers claimed to have released about 2.5 gigabytes of stolen data.

QWhat is the company doing to assist the affected individuals following the breach?

AThe company is notifying affected individuals and offering them free credit monitoring.

Lectures associées

Liste des altcoins les plus populaires selon les recherches des dernières heures publiée !

La plateforme CoinGecko a publié une liste des cryptomonnaies les plus recherchées par les utilisateurs au cours des dernières heures. Le jeton Pudgy Penguins ($PENGU) est en tête, suivi de Catecoin (CATE) et de Bless ($BLESS). Sur les 24 dernières heures, CATE a enregistré une hausse de prix impressionnante de 126,2%, tandis que $BLESS a augmenté de 86,1% et $PENGU de 3,9%. What IF (IF) a également progressé de 41,9%. Le classement complet des actifs les plus consultés sur CoinGecko, avec leur capitalisation boursière, est le suivant : 1. Pudgy Penguins ($PENGU) – 389,13 millions de dollars 2. Catecoin (CATE) – 19,62 millions de dollars 3. Bless ($BLESS) – 32,72 millions de dollars 4. Aerodrome Finance (AERO) – 385,03 millions de dollars 5. Hyperliquid (HYPE) – 11,43 milliards de dollars 6. Ethereum (ETH) – 224,17 milliards de dollars 7. Chainlink (LINK) – 6,17 milliards de dollars 8. Aave (AAVE) – 1,42 milliard de dollars 9. What IF (IF) – 31,24 millions de dollars 10. Polkadot (DOT) – 1,34 milliard de dollars 11. Bitcoin (BTC) – 1,27 trillion de dollars 12. Virtual Protocol (VIRTUAL) – 366,19 millions de dollars 13. Algorand (ALGO) – 758,15 millions de dollars 14. Cash Cat (CASHCAT) – 41,81 millions de dollars 15. Solana (SOL) – 42,38 milliards de dollars. *Ceci ne constitue pas un conseil en investissement.

cryptonews.ruIl y a 1 h

Liste des altcoins les plus populaires selon les recherches des dernières heures publiée !

cryptonews.ruIl y a 1 h

Les retraits de Bitcoin se poursuivent : 8 ans de stockage en portefeuille froid Coldcard se sont terminés par un solde nul

Le portefeuille matériel Coldcard a été compromis, entraînant une nouvelle vague de retraits depuis les appareils vulnérables. Selon Galaxy Research, environ 1 367,05 BTC (88,6 millions de dollars) ont été dérobés à partir de 4 585 adresses. Le problème ne réside pas dans le firmware, qui a été corrigé, mais dans les phrases seed générées entre mars 2021 et les mises à jour correctives. Ces phrases, créées en raison d'une erreur de programmation ayant conduit à l'utilisation d'un générateur de nombres aléatoires logiciel (Yasmarang) au lieu du générateur matériel STM32, sont prévisibles et vulnérables à une attaque par force brute hors ligne. Les propriétaires concernés doivent impérativement générer une nouvelle phrase seed sur un firmware corrigé et transférer leurs actifs, sous peine de rester exposés. L'histoire d'un investisseur de 39 ans illustre l'impact dévastateur : après avoir accumulé 2 BTC (130 000 dollars) sur huit ans via un travail physique, en les conservant comme protection contre l'hyperinflation dans son pays, il a tout perdu en quelques minutes. Son cas montre que même les stratégies de conservation à long terme les plus prudentes ("cold storage") ne sont pas infaillibles. D'un point de vue historique, cet incident rappelle les faiblesses passées des générateurs de nombres aléatoires dans la cryptographie. Il remet en question l'idée reçue selon laquelle le stockage hors ligne garantit automatiquement une sécurité absolue. La communauté espère que le fabricant pourra aider à récupérer les fonds volés.

cryptonews.ruIl y a 3 h

Les retraits de Bitcoin se poursuivent : 8 ans de stockage en portefeuille froid Coldcard se sont terminés par un solde nul

cryptonews.ruIl y a 3 h

Trading

Spot
活动图片