julho 29, 2026

Fintech Giant Figure Confirms Dark Web Data Leak

0
figure-technology-logo-times-squware

Blockchain-based lending giant Figure Technology confirmed on Friday that it suffered a data breach after a social engineering attack tricked an employee into compromising corporate files.

How the Figure Technology Breach Unfolded

According to Figure spokesperson Alethea Jadick, the security incident originated when an employee fell victim to a targeted social engineering scheme. This unauthorized access allowed the cybercriminals to exfiltrate what the company characterizes as “a limited number of files.”

In response to the exposure, Figure is currently communicating with affected partners and individuals. The fintech firm has committed to offering free credit monitoring services to all individuals who receive an official breach notification. However, Figure’s spokesperson declined to provide answers to specific questions regarding the technical details or the exact scale of the breach.

ShinyHunters Leak Stolen Data on the Dark Web

The cybercriminal syndicate known as ShinyHunters has claimed responsibility for the attack. Writing on their official dark web leak portal, the group disclosed that Figure refused to pay an extortion ransom. In retaliation, the hackers published 2.5 gigabytes of data allegedly stolen from the company’s servers.

A review of a portion of the leaked dataset confirmed the exposure of highly sensitive customer details. The compromised files contain personally identifiable information (PII), including customers’ full names, home addresses, dates of birth, and phone numbers.

Linked to a Broader Campaign Targeting Okta Users

A member of the ShinyHunters group stated that Figure was compromised as part of a wider hacking campaign. This malicious initiative specifically targets enterprise customers utilizing the single sign-on (SSO) identity provider Okta. Other notable institutions compromised in this same campaign include Harvard University and the University of Pennsylvania (UPenn).

Deixe um comentário

O seu endereço de e-mail não será publicado. Campos obrigatórios são marcados com *