HomeMore StoriesBlockchain-based Lending Firm Confirms Customer Data Breach

Blockchain-based Lending Firm Confirms Customer Data Breach

- Advertisement -

Blockchain-based lending firm Figure Technology confirmed on Friday, February 13, 2026, that it experienced a customer data breach following a social engineering attack targeting one of its employees.

The hacking group ShinyHunters claimed responsibility, alleging it released approximately 2.5 gigabytes of stolen data after the company declined to pay a ransom.

The incident adds to a broader wave of credential-based intrusions affecting organizations using third-party authentication systems.

How the Breach Occurred

According to company statements, the breach began when an employee was manipulated into granting unauthorized access. The attacker was able to download a “limited number of files” through the compromised account.

Figure spokesperson Alethea Jadick said the suspicious activity was detected and blocked shortly after it began. The company engaged a forensic investigation firm to assess the scope of the exposure and identify precisely which files were accessed.

The leaked materials reviewed by investigators and media outlets reportedly include sensitive personal data such as:

  • Full names
  • Home addresses
  • Dates of birth
  • Phone numbers

The extent of financial data exposure has not been publicly detailed.

Broader Campaign Linked to Okta Users

A member of ShinyHunters claimed the incident is part of a larger campaign targeting organizations that use Okta single sign-on services.

Other institutions reportedly affected in the same campaign include Harvard University and University of Pennsylvania. While the specific technical vectors may vary by organization, the pattern suggests attackers are exploiting credential access workflows rather than breaching core infrastructure directly.

Company Response and Mitigation

Figure stated that it has initiated direct outreach to partners and individuals potentially impacted by the breach. The company is offering free credit monitoring services to anyone who receives a formal notification.

Additionally, the firm has engaged cybersecurity specialists to strengthen internal safeguards and evaluate system vulnerabilities exposed during the incident.

Structural Implications

The attack underscores the persistent risk posed by social engineering, particularly in organizations handling sensitive financial data. Even when core systems remain uncompromised, employee-level credential access can create meaningful exposure.

As investigations continue, the primary focus will remain on containment, customer notification, and reinforcing authentication protocols to prevent similar incidents in the future.

Disclaimer: ETHNews does not endorse and is not responsible for or liable for any content, accuracy, quality, advertising, products, or other materials on this page. Readers should do their own research before taking any actions related to cryptocurrencies. ETHNews is not responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods, or services mentioned.
Toheeb Kolade
Toheeb Kolade
Toheeb is an insightful blockchain reporter with deep knowledge of cryptocurrencies. With years of experience in financial journalism, Toheeb covers the latest developments in blockchain technology, cryptocurrency trends, decentralized finance (DeFi), and regulatory updates. Known for breaking news and in-depth analysis, Toheeb brings new angles on how blockchain is transforming industries and changing the global economy. From uncovering market movements to providing expert commentary on new technologies, Toheeb is dedicated to keeping readers informed about the developments in blockchain-related topics.
RELATED ARTICLES

LATEST ARTICLES