Figure Technology confirmed a data breach after an employee was tricked by hackers into giving access to company files.Figure Technology confirmed a data breach after an employee was tricked by hackers into giving access to company files.

Figure Technology confirmed a data breach after an employee was tricked by hackers into giving access to company files

2026/02/14 13:48
4 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Figure Technology, a prominent blockchain-based fintech company, has acknowledged a security incident involving unauthorized access to its data.

In a statement, Alethea Jadick, a spokesperson for Figure Technology, said the breach occurred when an employee fell for a social engineering scam, allowing hackers to gain access to a few files.

The firm confirmed that it is communicating with partners and affected parties regarding the breach. Moreover, it pointed out that complimentary credit monitoring is available to all recipients of this notice. Nonetheless, reporters claimed that Figure’s spokesperson failed to address certain questions concerning the breach details.

Breach incidents in the tech industry remain a key concern

The figure’s breach incident has sparked security concerns among individuals, igniting heated discussions in the industry. In this scenario, reports stressed that ShinyHunters, a notorious black-hat criminal hacking and extortion group, took credit for the breach on its dark web portal. According to the hackers, the company refused to meet their demands, prompting them to leak 2.5 gigabytes of allegedly stolen data.

In response to this action, Figure stated that,  “We recently found out that an employee was manipulated into giving access, which let someone download a limited number of files through their account. We took immediate action to stop the activity and hired a forensic firm to investigate which files were impacted.”  

Following this statement, sources declared that the approach applied in this case was Social engineering, a psychological manipulation of people into performing actions such as granting unauthorized access or divulging confidential information, acting as a form of “human hacking”.

Meanwhile, to demonstrate the intensity of the situation, Chainalysis shared a report last month noting that scammers stole an estimated $17 billion in cryptocurrency last year, using AI to enhance impersonation and social engineering.

Their report showed that data breaches remained a key concern in the tech industry last year, further heightening tensions this year.  This was after a report from the Privacy Rights Clearinghouse, dated December 2025, revealed that regulators recorded more than 8,000 filings covering more than 4,000 distinct scenarios that significantly affected at least 374 million people.

While Figure’s spokesperson provided limited details about the firm’s breach, an anonymous individual from the ShinyHunters group informed a reliable source that the breach was part of a broader campaign targeting companies that use the Okta single sign-on service. In the meantime, sources mentioned that other alleged victims were the University of Pennsylvania and Harvard University.

Step Finance encounters a breach in its operation 

As breach incidents continue to be a significant challenge in the industry, Step Finance, a prominent DeFi platform particularly within the Solana blockchain ecosystem, announced that several of its treasury and fee wallets were compromised, prompting an investigation into the breach.

Following its announcement, onchain data revealed that hackers unstaked about 261,854 SOL and moved them to an unknown address. At the moment, the blockchain security company CertiK claimed that the price of SOL was around $110, implying that these transfers accounted for almost $29 million in value.

Meanwhile, in attempts to calm down the tension among its clients, Step Finance shared an X post, highlighting that, “We experienced a security breach in some of our treasury wallets a few hours ago, and we are currently looking into it… We will share more details later.” The platform also disclosed that it engaged cybersecurity experts to assist with the investigation.

Nonetheless, Step Finance failed to mention the primary cause of the breach. This sparked speculation in the ecosystem, with some alleging it stemmed from a smart contract flaw and others claiming it was due to an access control issue. The main question raised at the moment was whether user funds outside the treasury were affected. 

These concerns prompted reporters to reach out to Step Finance for clarity on the speculations and questions raised, but it declined to respond. 

Earn 8% CASHBACK in USDC when you pay with COCA. Order your FREE card.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Shocking OpenVPP Partnership Claim Draws Urgent Scrutiny

Shocking OpenVPP Partnership Claim Draws Urgent Scrutiny

The post Shocking OpenVPP Partnership Claim Draws Urgent Scrutiny appeared on BitcoinEthereumNews.com. The cryptocurrency world is buzzing with a recent controversy surrounding a bold OpenVPP partnership claim. This week, OpenVPP (OVPP) announced what it presented as a significant collaboration with the U.S. government in the innovative field of energy tokenization. However, this claim quickly drew the sharp eye of on-chain analyst ZachXBT, who highlighted a swift and official rebuttal that has sent ripples through the digital asset community. What Sparked the OpenVPP Partnership Claim Controversy? The core of the issue revolves around OpenVPP’s assertion of a U.S. government partnership. This kind of collaboration would typically be a monumental endorsement for any private cryptocurrency project, especially given the current regulatory climate. Such a partnership could signify a new era of mainstream adoption and legitimacy for energy tokenization initiatives. OpenVPP initially claimed cooperation with the U.S. government. This alleged partnership was said to be in the domain of energy tokenization. The announcement generated considerable interest and discussion online. ZachXBT, known for his diligent on-chain investigations, was quick to flag the development. He brought attention to the fact that U.S. Securities and Exchange Commission (SEC) Commissioner Hester Peirce had directly addressed the OpenVPP partnership claim. Her response, delivered within hours, was unequivocal and starkly contradicted OpenVPP’s narrative. How Did Regulatory Authorities Respond to the OpenVPP Partnership Claim? Commissioner Hester Peirce’s statement was a crucial turning point in this unfolding story. She clearly stated that the SEC, as an agency, does not engage in partnerships with private cryptocurrency projects. This response effectively dismantled the credibility of OpenVPP’s initial announcement regarding their supposed government collaboration. Peirce’s swift clarification underscores a fundamental principle of regulatory bodies: maintaining impartiality and avoiding endorsements of private entities. Her statement serves as a vital reminder to the crypto community about the official stance of government agencies concerning private ventures. Moreover, ZachXBT’s analysis…
Share
BitcoinEthereumNews2025/09/18 02:13
South Korea Orders Crypto Custody Overhaul After Police Lose Seized BTC

South Korea Orders Crypto Custody Overhaul After Police Lose Seized BTC

TLDR South Korea introduced new custody rules after police lost seized Bitcoin worth $1.4 million. The Finance Minister confirmed a full inspection of digital asset
Share
Coincentral2026/03/03 01:00
Trump Justice Department’s motion to take Michigan voter rolls misspelled 'United States'

Trump Justice Department’s motion to take Michigan voter rolls misspelled 'United States'

The Justice Department filed an emergency motion at the Sixth Circuit Court of Appeals on Monday against the state of Michigan over its refusal to share voter rolls
Share
Alternet2026/03/03 01:25