Applying for a loan today often happens entirely online. That convenience also concentrates large amounts of identity data inside a single platform. A recent Figure data breach shows how quickly attackers can exploit that reality after gaining employee access.

Hackers infiltrated the fintech lender through a social engineering scheme and later published stolen records. Investigators linked the incident to the ShinyHunters extortion group, which has increasingly targeted financial companies.

What Figure is and why it matters

Figure Technology Solutions operates a US fintech platform focused on home equity lending. The service uses digital identity verification and automated approval workflows. Customers submit sensitive personal details during the process, including contact data and birth dates.

Financial services platforms keep more verified information than social networks or retail apps. That makes a single compromise valuable for identity fraud operations.

Scope of the exposure

Public disclosures show attackers accessed about 967,000 accounts during the intrusion. The stolen dataset reportedly included:

  • Full names
  • Email addresses
  • Phone numbers
  • Home addresses
  • Dates of birth

Criminals can combine those fields to impersonate victims or pass identity checks.

Attackers also leaked internal company files after ransom negotiations failed. The publication significantly increases long-term fraud risk because the information now circulates publicly.

How attackers got access

The intrusion did not start with malware or a software flaw. Instead, attackers targeted an employee and convinced them to reveal login credentials during a social engineering call.

Researchers associate the method with ongoing voice phishing campaigns against single sign-on systems. One compromised authentication account can unlock multiple internal tools at once. That dramatically lowers the effort needed to reach customer databases.

The approach shows why modern breaches often bypass technical defenses entirely and focus on human trust.

Why the stolen data is dangerous

Unlike many breaches, this dataset contains verified identity information. Criminals can use it to:

  • Apply for loans under a victim’s name
  • Reset financial accounts
  • Conduct targeted phone scams
  • Build convincing phishing messages

Fraud attempts may not appear immediately. Attackers often wait months before using personal records.

ShinyHunters activity pattern

The ShinyHunters group has shifted toward financial organizations in recent campaigns. Instead of only stealing login credentials, the group now targets companies storing verified identity profiles.

This strategy produces higher-value data and increases extortion pressure on victims.

Company response

Figure confirmed the incident and began notifying affected users. The company also offered credit monitoring services. While helpful, monitoring mainly detects damage after misuse begins.

Users must remain alert for suspicious financial activity long after the breach notification.

What affected users should do

Anyone who used the platform should take precautionary steps:

  • Enable credit freeze or alerts
  • Change financial passwords
  • Ignore unexpected verification requests
  • Monitor bank and loan statements
  • Treat unknown callers as suspicious

Preventive action reduces long-term fraud impact.

Conclusion

Large data breaches increasingly start with simple human manipulation instead of complex exploits. The Figure data breach demonstrates how one compromised employee account can expose massive identity datasets.

Financial platforms concentrate verified personal records in one place, which amplifies the consequences of access failures. Both companies and customers must treat authentication requests carefully, because modern attacks rely more on persuasion than hacking tools.


0 responses to “Figure data breach exposes nearly 1M accounts”