Blockchain Lending Platform Figure Hit By Data Breach – Details

bitcoinist2026-02-16 tarihinde yayınlandı2026-02-16 tarihinde güncellendi

Özet

Figure Technology, a blockchain lending platform, suffered a data breach after an employee fell victim to a social engineering attack. The breach resulted in the theft of approximately 2.5GB of customer data, including full names, home addresses, dates of birth, and phone numbers. The hacker group ShinyHunters claimed responsibility and publicly released the data after alleged failed ransom negotiations. The company confirmed that its core blockchain systems and financial services remained secure, emphasizing the incident was due to human error, not a technical flaw. Figure is offering free credit monitoring to affected customers and has launched an internal review. The exact number of impacted individuals has not been disclosed.

Figure Technology confirmed that some customer files were stolen after an employee was tricked, according to reports. The company says the intrusion happened when an internal account was used to download a limited batch of records. The breach did not stem from a flaw in its blockchain system, but from human error.

Reports say the stolen material was later posted online by a hacker collective that claimed responsibility. The group is said to have released about 2.5GB of data after alleging that ransom talks broke down. That public dump quickly drew attention across the crypto and fintech space.

Customer Names, Contact Details Among Items Exposed

Based on reports that reviewed samples of the leaked files, the exposed data includes full names, home addresses, dates of birth, and phone numbers. These are the kinds of details often used in identity fraud or targeted scams.

The exact number of affected customers has not been shared publicly. That missing figure leaves uncertainty about how large the fallout could be.

Security researchers warn that even when bank accounts or crypto wallets are untouched, personal data alone can create serious risk. Phishing calls, fake loan offers, and account takeover attempts often follow this type of leak.

Total crypto market cap at $2.34 trillion on the daily chart: TradingView

Figure Hit By Social Engineering Attack

According to coverage of the incident, attackers used a social engineering method to gain access to an employee’s credentials or active session. Instead of breaking through code, they relied on deception. Once inside, files were downloaded through that employee’s access rights.

The company said it detected suspicious activity and moved to block it. Outside forensic specialists were brought in to review system logs and determine what was accessed. A broader internal review is also under way.

Image: CybersecAsia

ShinyHunters claimed responsibility for the breach on its leak site. The group has been linked to prior data exposures involving tech and finance firms. In this case, the data was made public after payment demands were reportedly rejected.

Figure said it will notify customers whose information was involved. Free credit monitoring services are being offered to those who receive formal notice. Impacted individuals are being advised to watch for unusual activity and unsolicited messages.

Funds And Core Services Secure

Reports note that lending operations and on-chain systems were not breached. The platform’s core financial infrastructure was not described as affected. Still, the exposure of personal records carries its own weight.

Financial companies remain frequent targets because they hold detailed customer files. A single employee account, if misused, can open a door wider than expected. That lesson has surfaced again here.

Regulators may seek further details in the coming weeks. Customers will be waiting for clearer numbers. The long-term cost, both financial and reputational, will depend on how widely the data spreads and how quickly protective steps are taken.

Featured image from Yahoo Finance, chart from TradingView

İlgili Sorular

QWhat was the cause of the data breach at Figure Technology?

AThe data breach was caused by human error, specifically a social engineering attack where an employee was tricked, leading to the misuse of an internal account to download customer records.

QWhat type of customer data was exposed in the Figure breach?

AThe exposed data includes full names, home addresses, dates of birth, and phone numbers of customers.

QWhich hacker group claimed responsibility for the data breach?

AThe hacker collective ShinyHunters claimed responsibility for the breach and later posted the stolen data online.

QWere Figure's core financial systems or blockchain infrastructure compromised in the attack?

ANo, the company confirmed that its lending operations, on-chain systems, and core financial infrastructure were not breached in the attack.

QWhat steps is Figure taking to help affected customers?

AFigure is notifying affected customers, offering free credit monitoring services, and advising them to watch for unusual activity and unsolicited messages.

İlgili Okumalar

Thanks to Dice Rolls, Bitcoin Keys Are Stored Offline, But Not Everyone Will Do It

The article discusses using dice rolls to generate secure Bitcoin wallet seeds, providing entropy independent of potentially flawed hardware random number generators. It explains that each fair dice roll offers about 2.585 bits of entropy, with around 50 rolls needed for a standard 12-word seed phrase and 99+ recommended for higher security. This method gained attention after a vulnerability was revealed in some Coldcard hardware wallets, where a faulty firmware RNG (dating back to 2021) compromised generated keys. The analysis notes that while a dice-generated main seed was safe from this specific flaw, other Coldcard functions (like creating paper wallets, backup keys, or passwords) could still be vulnerable if they used the defective RNG. The piece argues that while dice-based entropy is technically robust, the manual process is error-prone, tedious, and unrealistic for most new users, who might make mistakes in recording or inputting rolls. It concludes that while manual entropy generation should remain an option for advanced users, the long-term goal is to develop reliable, user-friendly hardware and software that securely generates randomness without requiring specialized knowledge. Coldcard users are advised to check their firmware version and replace any secondary secrets (like paper wallet keys) created with vulnerable devices, while also considering multi-signature setups with devices from different manufacturers for added security.

cryptonews.ru4 saat önce

Thanks to Dice Rolls, Bitcoin Keys Are Stored Offline, But Not Everyone Will Do It

cryptonews.ru4 saat önce

İşlemler

Spot
活动图片