In an increasingly digital era, cybersecurity represents a crucial challenge for companies that manage sensitive data. Even the most cutting-edge organizations can fall victim to sophisticated attacks, as demonstrated by the recent case of Figure Technology Solutions, Inc., a company specializing in blockchain-based lending solutions.
On February 13, 2026, Figure Technology publicly revealed that it had been the victim of a data breach. The attack, according to the company’s report, was carried out using social engineering and phishing techniques targeting an employee. The hackers managed to access a limited number of files, totaling approximately 2.5 GB of data, containing personally identifiable information (PII) of customers, including names, addresses, dates of birth, and phone numbers.
The hacker group known as ShinyHunters claimed responsibility for the attack, which appears to be part of a broader campaign targeting users of the Okta platform. In response to the incident, Figure Technology has initiated notifications to the individuals involved and offered a free credit monitoring service to help protect customers from potential fraud.
This type of breach is particularly concerning because it demonstrates how even companies operating in the blockchain sector, traditionally considered secure, can be vulnerable to tactics that exploit the human element. The stolen personal information could be used for fraud attempts, identity theft, or further targeted attacks.
For companies, this incident underscores the importance of implementing robust security training programs for employees, with particular attention to recognizing phishing and social engineering attempts. It is essential to adopt multi-factor authentication and develop clear protocols for managing access to sensitive data.
Figure Technology customers, and more generally all users of digital services, should remain vigilant by regularly checking their bank accounts and credit reports for suspicious activity. It is advisable to periodically change passwords and activate, where possible, two-factor authentication for all online services used.
Key points to remember:
- Even technologically advanced companies are vulnerable to social engineering attacks that target employees
- Personal information exposed in data breaches can be used for fraud and identity theft
- Continuous staff training and implementation of multi-layered security measures are essential to reduce the risks of similar breaches
Sources:
https://techcrunch.com/2026/02/13/fintech-lending-giant-figure-confirms-data-breach/
https://www.kucoin.com/news/flash/figure-technology-confirms-data-breach-via-social-engineering-attack
https://www.mexc.com/news/712318
Source: Security Affairs