Blockchain-based lending firm Figure Technology confirmed on Friday, February 13, 2026, that it experienced a customer data breach following a social engineeringBlockchain-based lending firm Figure Technology confirmed on Friday, February 13, 2026, that it experienced a customer data breach following a social engineering

Blockchain-based Lending Firm Confirms Customer Data Breach

2026/02/14 20:52
2 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Blockchain-based lending firm Figure Technology confirmed on Friday, February 13, 2026, that it experienced a customer data breach following a social engineering attack targeting one of its employees.

The hacking group ShinyHunters claimed responsibility, alleging it released approximately 2.5 gigabytes of stolen data after the company declined to pay a ransom.

The incident adds to a broader wave of credential-based intrusions affecting organizations using third-party authentication systems.

How the Breach Occurred

According to company statements, the breach began when an employee was manipulated into granting unauthorized access. The attacker was able to download a “limited number of files” through the compromised account.

Figure spokesperson Alethea Jadick said the suspicious activity was detected and blocked shortly after it began. The company engaged a forensic investigation firm to assess the scope of the exposure and identify precisely which files were accessed.

The leaked materials reviewed by investigators and media outlets reportedly include sensitive personal data such as:

  • Full names
  • Home addresses
  • Dates of birth
  • Phone numbers

The extent of financial data exposure has not been publicly detailed.

Trump-Linked Truth Social Files for Two Crypto ETFs

Broader Campaign Linked to Okta Users

A member of ShinyHunters claimed the incident is part of a larger campaign targeting organizations that use Okta single sign-on services.

Other institutions reportedly affected in the same campaign include Harvard University and University of Pennsylvania. While the specific technical vectors may vary by organization, the pattern suggests attackers are exploiting credential access workflows rather than breaching core infrastructure directly.

Company Response and Mitigation

Figure stated that it has initiated direct outreach to partners and individuals potentially impacted by the breach. The company is offering free credit monitoring services to anyone who receives a formal notification.

Additionally, the firm has engaged cybersecurity specialists to strengthen internal safeguards and evaluate system vulnerabilities exposed during the incident.

Structural Implications

The attack underscores the persistent risk posed by social engineering, particularly in organizations handling sensitive financial data. Even when core systems remain uncompromised, employee-level credential access can create meaningful exposure.

As investigations continue, the primary focus will remain on containment, customer notification, and reinforcing authentication protocols to prevent similar incidents in the future.

The post Blockchain-based Lending Firm Confirms Customer Data Breach appeared first on ETHNews.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Shocking OpenVPP Partnership Claim Draws Urgent Scrutiny

Shocking OpenVPP Partnership Claim Draws Urgent Scrutiny

The post Shocking OpenVPP Partnership Claim Draws Urgent Scrutiny appeared on BitcoinEthereumNews.com. The cryptocurrency world is buzzing with a recent controversy surrounding a bold OpenVPP partnership claim. This week, OpenVPP (OVPP) announced what it presented as a significant collaboration with the U.S. government in the innovative field of energy tokenization. However, this claim quickly drew the sharp eye of on-chain analyst ZachXBT, who highlighted a swift and official rebuttal that has sent ripples through the digital asset community. What Sparked the OpenVPP Partnership Claim Controversy? The core of the issue revolves around OpenVPP’s assertion of a U.S. government partnership. This kind of collaboration would typically be a monumental endorsement for any private cryptocurrency project, especially given the current regulatory climate. Such a partnership could signify a new era of mainstream adoption and legitimacy for energy tokenization initiatives. OpenVPP initially claimed cooperation with the U.S. government. This alleged partnership was said to be in the domain of energy tokenization. The announcement generated considerable interest and discussion online. ZachXBT, known for his diligent on-chain investigations, was quick to flag the development. He brought attention to the fact that U.S. Securities and Exchange Commission (SEC) Commissioner Hester Peirce had directly addressed the OpenVPP partnership claim. Her response, delivered within hours, was unequivocal and starkly contradicted OpenVPP’s narrative. How Did Regulatory Authorities Respond to the OpenVPP Partnership Claim? Commissioner Hester Peirce’s statement was a crucial turning point in this unfolding story. She clearly stated that the SEC, as an agency, does not engage in partnerships with private cryptocurrency projects. This response effectively dismantled the credibility of OpenVPP’s initial announcement regarding their supposed government collaboration. Peirce’s swift clarification underscores a fundamental principle of regulatory bodies: maintaining impartiality and avoiding endorsements of private entities. Her statement serves as a vital reminder to the crypto community about the official stance of government agencies concerning private ventures. Moreover, ZachXBT’s analysis…
Share
BitcoinEthereumNews2025/09/18 02:13
South Korea Orders Crypto Custody Overhaul After Police Lose Seized BTC

South Korea Orders Crypto Custody Overhaul After Police Lose Seized BTC

TLDR South Korea introduced new custody rules after police lost seized Bitcoin worth $1.4 million. The Finance Minister confirmed a full inspection of digital asset
Share
Coincentral2026/03/03 01:00
Trump Justice Department’s motion to take Michigan voter rolls misspelled 'United States'

Trump Justice Department’s motion to take Michigan voter rolls misspelled 'United States'

The Justice Department filed an emergency motion at the Sixth Circuit Court of Appeals on Monday against the state of Michigan over its refusal to share voter rolls
Share
Alternet2026/03/03 01:25