Data breach
Figure Technology Solutions
- Records
- 1,004,503
- Breach date
- 14 February 2026Estimated
- Added
- 16 February 2026
What was exposed
5 types of data · 1 more reported
- Dates of birth1
- Email addresses1
- Names1
- Home addresses1
- Phone numbers1
- Social security numbersReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Figure Technology Solutions, the blockchain-based fintech lender, confirmed in February 2026 that hackers stole personal information belonging to roughly a million customers and applicants. According to our investigation team, the listing covers 1,004,503 records, with an estimated attack date of February 14, 2026. The company said an employee was tricked in a social engineering attack, which allowed intruders to download a limited number of files from systems storing loan and loan inquiry data. The cybercrime group ShinyHunters claimed responsibility, saying Figure refused to pay a ransom, and published 2.5 gigabytes of stolen data on its leak site.
Breach Timeline
January 28, 2026: Figure identified evidence that data containing personal information was obtained through queries on company databases, according to its breach notification filed with the Massachusetts Attorney General.
February 13, 2026: ShinyHunters published 2.5 gigabytes of allegedly stolen data after the company did not pay a ransom, and Figure confirmed the breach to TechCrunch.
February 24, 2026: Figure began mailing written breach notifications, offering two years of complimentary credit monitoring and identity restoration services through TransUnion.
What Information Was Compromised?
Our analysis found the following data types in this breach: names, home addresses, phone numbers, email addresses, and dates of birth. TechCrunch reported that the leaked data contained roughly 967,200 unique email addresses associated with Figure customers.
Figure's written notice to affected individuals, filed with the Massachusetts Attorney General, lists additional fields: Social Security numbers, loan account numbers, and loan information. The notice states there was no evidence of unauthorized access to customer accounts or funds.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The exposed records combine identity documents with financial details. A name, date of birth, address, and Social Security number together are enough for criminals to open accounts, file fraudulent tax returns, or apply for loans in someone else's name. Loan account numbers and loan details can support convincing phishing calls or emails that impersonate a lender. Because the data is now public on a criminal leak site, the risk is not limited to a single round of scams; stolen identity records circulate for years.
What Is Figure Technology Solutions Doing in Response?
Figure said it acted quickly to stop the activity, retained a forensic firm, and reported the incident to law enforcement. In its notice, the company said it implemented enhanced security and monitoring controls, established a dedicated call center at 1-855-522-6935, and is offering two years of complimentary credit monitoring and identity restoration through TransUnion. Individuals who receive a notice must enroll by May 31, 2026.
The company has not publicly disputed independent estimates of the scale of the breach. A law firm, Schubert Jonckheer & Kolbe, announced an investigation into whether Figure's notification timeline complied with state and federal law, noting the breach occurred in January but notices went out February 24.
What Should You Do If You Were Affected?
Enroll in the free credit monitoring if you received a notice, before the May 31, 2026 deadline.
Place a free fraud alert or security freeze with Equifax, Experian, and TransUnion. A freeze blocks most new credit from being opened in your name.
Watch your bank, credit card, and loan statements for activity you do not recognize.
Be wary of calls or emails claiming to be from Figure, its partners, or IT support. Never share login codes or passwords, even with someone who sounds official.
If you use the same password on Figure as elsewhere, change it, and turn on multi-factor authentication wherever it is offered.
In the news
- TechCrunch: Fintech lending giant Figure confirms data breachtechcrunch.com (opens in a new tab)
- TechCrunch: Data breach at fintech giant Figure affects close to a million customerstechcrunch.com (opens in a new tab)
- Massachusetts Attorney General: Notice of Data Breach, Figure Lending Corpmass.gov (opens in a new tab)
- PR Newswire: Schubert Jonckheer & Kolbe investigation announcementprnewswire.com (opens in a new tab)
