{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-figure-technology-loses-967-000-customer-records-after-employee-falls-fo"},"incident":{"slug":"2026-figure-technology-loses-967-000-customer-records-after-employee-falls-fo","title":"Figure Technology loses ~967,000 customer records after employee falls for SSO vishing","date":"2026-02-19","date_precision":"day","year":2026,"victim_org":"Figure Technology Solutions","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Data Breach","Credential Theft","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":967000,"threat_actor":"ShinyHunters","summary":"Nasdaq-listed fintech Figure Technology Solutions, which runs blockchain-based home equity lending, disclosed that an employee was compromised in a voice-phishing attack on the company's single sign-on accounts, part of a wider ShinyHunters campaign against Okta-protected tenants. Figure confirmed to TechCrunch that the attackers obtained a limited number of files. Roughly 967,000 user records were exposed, containing names, dates of birth, email addresses, postal addresses and phone numbers. ShinyHunters posted more than 2.4 GB of alleged company data on its Tor leak site, and the incident was reported on 19 February 2026.","how_it_worked":"The attackers telephoned Figure staff posing as internal IT or help desk personnel and used the pretext of an urgent account or access problem to walk the employee through a sign-in flow. The employee entered corporate SSO credentials and relayed the multi-factor code, which the callers used immediately against the real identity provider, giving them an authenticated session under a trusted staff identity. The trust signal abused was the familiarity of an internal IT support call plus the employee's own working single sign-on screen; the pressure applied was time-critical framing that discouraged the employee from calling back through a known internal number.","lessons":"Hardware-bound phishing-resistant MFA plus a mandatory call-back to a directory-listed internal number before any credential or code is provided would have broken the live relay this attack depends on.","confidence":"Reported","sources":[{"title":"Nearly 1 Million User Records Compromised in Figure Data Breach","url":"https://www.securityweek.com/nearly-1-million-user-records-compromised-in-figure-data-breach/","publisher":"SecurityWeek"},{"title":"Nearly 1 million Figure customer accounts exposed in breach linked to ShinyHunters","url":"https://cybernews.com/security/figure-data-breach-nearly-1-million-accounts-shiny-hunters/","publisher":"Cybernews"},{"title":"Data Breach at Fintech Company Figure Technology Solutions Impacts Nearly 1 Million People","url":"https://www.cpomagazine.com/cyber-security/data-breach-at-fintech-company-figure-technology-solutions-impacts-nearly-1-million-people/","publisher":"CPO Magazine"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-figure-technology-loses-967-000-customer-records-after-employee-falls-fo"}}