Security News

Cybersecurity news aggregator

⚔️
MEDIUM Attacks SecurityWeek

Nearly 1 Million User Records Compromised in Figure Data Breach

  • What: Figure Technology Solutions, a blockchain-based lender, suffered a data breach after an employee fell victim to a social engineering attack.
  • Impact: Nearly 1 million user records were compromised after the ShinyHunters hacker group leaked over 2GB of data allegedly stolen from the company.
Read Full Article →

DATA BREACHES Nearly 1 Million User Records Compromised in Figure Data Breach The blockchain-based lender has confirmed a data breach after ShinyHunters leaked over 2GB of data allegedly stolen from the company. By Eduard Kovacs | February 19, 2026 (8:19 AM ET) Flipboard Reddit Whatsapp Email Nearly 1 million user records have been compromised in a data breach at blockchain-powered lender Figure Technology Solutions. The company confirmed to TechCrunch that it suffered a data breach after an employee fell victim to a social engineering attack, saying the attackers obtained a limited number of files. The ShinyHunters hacker group took credit for the attack on Figure. On its Tor-based leak website the cybercrime group made available more than 2.4GB of archive files allegedly containing data stolen from the company. The data breach notification service Have I Been Pwned has analyzed the leaked data and identified roughly 967,000 Figure user records. The exposed information includes names, dates of birth, email addresses, postal addresses, and phone numbers. Figure Technology Solutions is a Nasdaq-listed fintech firm specializing in blockchain-based home equity lending and mortgage services. ADVERTISEMENT. SCROLL TO CONTINUE READING. ShinyHunters told TechCrunch that Figure is one of the many victims of the recent Okta campaign, which involved voice phishing to target single sign-on (SSO) accounts that the hackers could leverage to access sensitive data. The list of victims also includes Betterment, Crunchbase, and Panera Bread. Related: ShinyHunters-Branded Extortion Activity Expands, Escalates Related: Hackers Offer to Sell Millions of Eurail User Records Related: Dior, Louis Vuitton, Tiffany Fined $25 Million in South Korea After Data Breaches Related: Dutch Carrier Odido Discloses Data Breach Impacting 6 Million WRITTEN BY Eduard Kovacs Eduard Kovacs (@EduardKovacs) is the managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. More from Eduard Kovacs Palo Alto Networks to Acquire Koi in Reported $400 Million Transaction Dell RecoverPoint Zero-Day Exploited by Chinese Cyberespionage Group Hackers Offer to Sell Millions of Eurail User Records Man Linked to Phobos Ransomware Arrested in Poland 3 Threat Groups Started Targeting ICS/OT in 2025: Dragos Password Managers Vulnerable to Vault Compromise Under Malicious Server Dior, Louis Vuitton, Tiffany Fined $25 Million in South Korea After Data Breaches Android 17 Beta Strengthens Secure-by-Default Design for Privacy and App Security Latest News Venice Security Emerges From Stealth With $33M Funding for Privileged Access Management Ivanti Exploitation Surges as Zero-Day Attacks Traced Back to July 2025 OpenClaw Security Issues Continue as SecureClaw Open Source Tool Debuts German Rail Giant Deutsche Bahn Hit by Large-Scale DDoS Attack New Keenadu Android Malware Found on Thousands of Devices Cogent Security Raises $42 Million for AI-Driven Vulnerability Management Vulnerabilities in Popular PDF Platforms Allowed Account Takeover, Data Exfiltration CISA: Hackers Exploiting Vulnerability in Product of Taiwan Security Firm TeamT5 TRENDING Password Managers Vulnerable to Vault Compromise Under Malicious Server Vulnerabilities in Popular PDF Platforms Allowed Account Takeover, Data Exfiltration Dell RecoverPoint Zero-Day Exploited by Chinese Cyberespionage Group Apple Patches iOS Zero-Day Exploited in ‘Extremely Sophisticated Attack’ Dior, Louis Vuitton, Tiffany Fined $25 Million in South Korea After Data Breaches Over 300 Malicious Chrome Extensions Caught Leaking or Stealing User Data New Keenadu Android Malware Found on Thousands of Devices CISA Navigates DHS Shutdown With Reduced Staff Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Identity Under Attack: Why Every Business Must Respond Now February 11, 2026 Attendees will walk away with guidance for how to build robust identity defenses, unify them under a consistent security model, and ensure business operations move quickly without compromise. Register Virtual Event: Ransomware Resilience & Recovery 2026 Summit February 25, 2026 SecurityWeek’s 2026 Ransomware Summit will discuss a roadmap for defending the enterprise, from mitigating root causes to mastering recovery, giving security teams the critical insights needed to navigate and neutralize today’s ransomware extortion threats. Submit PEOPLE ON THE MOVE Cyera has appointed Brandon Sweeney as President, Shira Azran as Chief Legal Officer and Joseph Iantosca as Chief Financial Officer. Robert Carvajal has been appointed as CISO of BayCare Health System. KnowBe4 announced the appointment of Kelly Morgan as Chief Customer Officer. More People On The Move EXPERT INSIGHTS How to Eliminate the Technical Debt of Insecure AI-Assisted Software Development Developers must view AI as a collaborator to be closely monitored, rather than an autonomous entity to be unleashed. Without such a mindset, crippling tech debt is inevitable. (Matias Madou) Security in the Dark: Recognizing the Signs of Hidden Information Security failures don’t always start with attackers, sometimes they start with missing truth. (Joshua Goldfarb) Living off the AI: The Next Evolution of Attacker Tradecraft Living off the AI isn’t a hypothetical but a natural continuation of the tradecraft we’ve all been defending against, now mapped onto assistants, agents, and MCP. (Etay Maor) Why We Can’t Let AI Take the Wheel of Cyber Defense The fastest way to squander the promise of AI is to mistake automation for assurance, and novelty for resilience. (Steve Durbin) The Upside Down is Real: What Stranger Things Teaches Us About Modern Cybersecurity To all those who are fighting the good fight in the world of cyber, keep collaborating to ensure our world never succumbs to the chaos of the Upside Down. (Nadir Izrael) Flipboard Reddit Whatsapp Email

Share this article