Data breach at fintech firm Figure affects nearly 1 million accounts
嗯,用户让我帮忙总结一篇文章的内容,控制在一百个字以内,而且不需要特定的开头。首先,我需要仔细阅读文章,理解其主要内容。 文章讲的是Figure Technology Solutions公司被黑客入侵,导致近100万账户的信息被盗。这是一家自称基于区块链的金融科技公司。黑客通过社会工程攻击,诱骗员工泄露了访问权限。泄露的数据包括电子邮件、姓名、电话号码、地址和出生日期。此外,ShinyHunters勒索集团声称对此负责,并在暗网上泄露了数据。 接下来,我需要将这些信息浓缩到100字以内。要抓住关键点:公司名称、事件性质(数据泄露)、受影响账户数量、攻击手段(社会工程)、泄露的数据类型以及责任方。 然后,组织语言,确保简洁明了。可能的结构是:公司名称 + 事件 + 账户数量 + 攻击手段 + 泄露数据 + 责任方。 最后,检查字数是否符合要求,并确保没有使用任何开头模板。 </think> 区块链金融科技公司Figure Technology Solutions遭遇黑客攻击,近100万账户的个人信息被盗。攻击者通过社会工程手段诱骗员工提供访问权限,泄露数据包括电子邮件、姓名、电话号码、地址和出生日期。ShinyHunters勒索团伙声称对此负责,并将数据发布在其暗网站点上。 2026-2-18 14:15:36 Author: www.bleepingcomputer.com(查看原文) 阅读量:2 收藏

Figure

Hackers have stolen the personal and contact information of nearly 1 million accounts after breaching the systems of Figure Technology Solutions, a self-described blockchain-native financial technology company.

Founded in 2018, Figure uses the Provenance blockchain for lending, borrowing, and securities trading, and has unlocked over $22 billion in home equity with over 250 partners, including banks, credit unions, fintechs, and home improvement companies.

While the blockchain lender didn't publicly disclose the incident, a Figure spokesperson told TechCrunch on Friday that the attackers stole "a limited number of files" in a social engineering attack.

Wiz

BleepingComputer has also reached out to Figure with further questions about the breach, but a response was not immediately available.

Although the company has yet to share how many individuals were affected by the data breach, notification service Have I Been Pwned has now revealed the extent of the incident, reporting that data from 967,200 accounts was stolen in the attack.

"In February 2026, data obtained from the fintech lending platform Figure was publicly posted online," Have I Been Pwned said on Wednesday.

"The exposed data, dating back to January 2026, contained over 900k unique email addresses along with names, phone numbers, physical addresses and dates of birth. Figure confirmed the incident and attributed it to a social engineering attack in which an employee was tricked into providing access."

The ShinyHunters extortion group claimed responsibility for the breach and added the company to its dark web leak site, leaking 2.5GB of data allegedly stolen from thousands of loan applicants.

Figure Technology on ShinyHunters leak site
CaptionFigure Technology on ShinyHunters leak site (BleepingComputer)

In recent weeks, ShinyHunters claimed similar breaches at Canada Goose, Panera Bread, Betterment, SoundCloud, PornHub, and CrowdStrike.

While not all of them are part of the same campaign, some of these victims were breached in a voice phishing (vishing) campaign targeting single sign-on (SSO) accounts at Okta, Microsoft, and Google across more than 100 high-profile organizations.

The attackers are impersonating IT support, calling their targets' employees and tricking them into entering credentials and multi-factor authentication (MFA) codes on phishing sites that impersonate their companies' login portals.

Once in, they gain access to the victim's SSO account, which provides them with access to other connected enterprise applications and services, including Salesforce, Microsoft 365, Google Workspace, SAP, Slack, Zendesk, Dropbox, Adobe, Atlassian, and many others.

As part of this campaign, ShinyHunters also breached online dating giant Match Group, which owns multiple popular dating services, including Tinder, Hinge, Meetic, Match.com, and OkCupid.

tines

The future of IT infrastructure is here

Modern IT infrastructure moves faster than manual workflows can handle.

In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.


文章来源: https://www.bleepingcomputer.com/news/security/data-breach-at-fintech-firm-figure-affects-nearly-1-million-accounts/
如有侵权请联系:admin#unsafe.sh