Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
mass-credential-exposureunderground-data-leakbreach-disclosure-notificationfinancial-sector-threat

Figure Technology Solutions Data Breach via Social Engineering

Updated 3mo agoFirst seen Feb 18, 20265 sources

Figure Technology Solutions suffered a data breach in which attackers obtained and later publicly posted customer data. Reporting indicates the exposed dataset (dating back to January 2026) included roughly 967,200 accounts / 900k+ unique email addresses, along with names, phone numbers, physical addresses, and dates of birth. Figure confirmed the incident and attributed initial access to social engineering, stating an employee was tricked into providing access and that attackers stole a “limited number of files.”

The ShinyHunters extortion group claimed responsibility and listed Figure on its leak site, alleging the leak included about 2.5GB of data tied to loan applicants. The breach’s scale was corroborated by Have I Been Pwned’s publication of the incident details, while broader coverage noted Figure had not proactively disclosed the incident publicly at the time of reporting and that additional details (e.g., full scope and notification posture) were still emerging.

Share:
Figure Technology Solutions Data Breach via Social Engineering
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 26, 20264mo ago

Have I Been Pwned adds the Figure breach

On February 26, 2026, Have I Been Pwned published the Figure breach, stating that data from more than 900,000 unique email addresses had been publicly posted online in February 2026. The breach entry said Figure confirmed the incident resulted from an employee-targeted social engineering attack.

Feb 18, 20264mo ago

Researchers determine breach exposed 967,200 Figure accounts

On February 18, 2026, reporting citing analysis by security researcher Troy Hunt said the exposed dataset contained data from 967,200 accounts, including more than 900,000 unique email addresses as well as names, phone numbers, physical addresses, and dates of birth. This provided a fuller picture of the breach's scale than Figure's initial description.

Figure confirms breach and begins notifying affected parties

By February 18, 2026, Figure confirmed the breach, said only a limited number of files were taken, attributed the incident to social engineering, and stated it was notifying affected individuals and partners. The company also offered free credit monitoring while its investigation continued.

Feb 1, 20265mo ago

ShinyHunters claims Figure breach and leaks 2.5 GB of data

In February 2026, the ShinyHunters extortion group claimed responsibility for the Figure incident, listed the company on its leak site, and published about 2.5 GB of allegedly stolen data after an apparent extortion attempt. Reports said the leaked material included customer personal and contact information.

Jan 1, 20266mo ago

Employee social engineering attack compromises Figure systems

In January 2026, Figure said an employee was deceived in a social engineering attack that granted attackers unauthorized access to company systems. The intrusion led to theft of customer-related files and data dating back to that month.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

34 LINKEDOpen in app
Threat actors
1 linked
Affected products
4 linked
TinderZendeskDropboxDropbox
Organizations
29 linked
Have I Been PwnedBettermentOkcupidTinderCrowdStrikeSoundcloudHingeMatch GroupOktaMicrosoft CorporationGoogleMeeticTechCrunchPornhubMatch.comPanera BreadCanada GooseSalesforceZendeskAtlassianBleepingComputerSAPDropboxHubspotAdobeSlack TechnologiesFigureMercer AdvisorsBeacon Pointe Advisors
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.