TL;DR: Blockchain lending company Figure Technology confirmed on February 13, 2026 that hackers breached their systems through a social engineering attack on an employee. ShinyHunters claimed responsibility and dumped 2.5GB of stolen customer data after Figure refused to pay ransom. The leaked files include customer names, home addresses, dates of birth, and phone numbers. This is the same crew that hit Harvard (115,000 records), Match Group (10 million records), and University of Pennsylvania using voice phishing to steal Okta SSO credentials. If you're a Figure customer, assume your data is exposed.

What Figure Lost

Figure Technology (a fintech company that handles home loans through blockchain) admitted an employee got tricked into giving up access.[1]

"An employee was socially engineered, and that allowed an actor to download a limited number of files through their account," a Figure spokesperson told TechCrunch.[1]

ShinyHunters thought "limited" was underselling it. They published 2.5 gigabytes of data on their dark web leak site after Figure refused to pay up.[2]

Samples reviewed by TechCrunch include:[1]

  • Full customer names
  • Home addresses
  • Dates of birth
  • Phone numbers

This is identity theft starter pack material. Enough to open credit cards, file fake tax returns, or target victims with convincing phishing calls.

The Okta Playbook Strikes Again

ShinyHunters told TechCrunch this breach was part of a larger campaign targeting companies that rely on Okta for single sign-on.[1]

Here's how the attack works:[3]

  1. The phone call: Attackers pose as IT staff. They call employees claiming the company needs to update MFA settings or verify credentials.
  2. The fake portal: The caller directs the employee to a convincing phishing page that looks exactly like their company's Okta login. Complete with proper branding and SSL certificates.
  3. The credential grab: Employee enters their username, password, and MFA code. Attackers capture everything in real time.
  4. The device registration: With those credentials and the MFA code, attackers register their own device as a trusted authenticator. They're now a "legitimate" user.
  5. The download: Once inside, they have whatever access that employee had. They start grabbing files.

This technique, called vishing (voice phishing), bypasses even strong MFA setups. Doesn't matter if you have hardware keys or authenticator apps. If someone tricks an employee into entering credentials on a fake site while the attacker relays them to the real site, they're in.

The Body Count So Far

Figure isn't special. They're just the latest victim in a coordinated campaign that's been running since at least January 2026.[3][4]

Harvard University

115,000 records from Alumni Affairs and Development. Names, addresses, donation histories, employment info. ShinyHunters published the data after Harvard refused ransom.[4]

University of Pennsylvania

Breached using the same Okta social engineering technique. Data published on ShinyHunters leak site.[4]

Match Group

Over 10 million records claimed from Hinge, OkCupid, and Match.com. Dating profiles, messages, potentially payment info. Attackers used vishing to grab Okta credentials.[5]

Security researchers at Silent Push link ShinyHunters to a "malicious supergroup" called SLSH: a predatory alliance between Scattered Spider, LAPSUS$, and ShinyHunters. They've identified over 100 organizations in the crosshairs.[3]

Why Okta Keeps Getting Targeted

Okta is everywhere. Over 15,000 companies use it for single sign-on, including 70% of Fortune 500 companies. That makes it a skeleton key.

Compromise one Okta account at a company and you often get access to:

  • Salesforce (customer data)
  • Slack (internal communications)
  • GitHub (source code)
  • Google Workspace (emails, documents)
  • AWS consoles (cloud infrastructure)

Attackers don't need to hack the fortress. They just need to convince one employee to hand over the key. And humans are easier to hack than servers.

What Figure Is Doing

Figure says they "acted quickly to block the activity" and hired a forensic firm to investigate.[1]

For affected customers:

  • Breach notification letters coming via mail
  • Free credit monitoring for those who receive notifications

That's the standard playbook. Minimum legal requirements. Nothing more.

What You Should Do

If you've ever used Figure for a loan, home equity line, or any financial product, assume your data is in that 2.5GB dump.

Freeze Your Credit

Not a fraud alert, a full freeze. Free at all three bureaus: Equifax, Experian, TransUnion.

Get an IRS Identity Protection PIN

Stops fraudulent tax returns in your name. Takes 10 minutes at irs.gov/get-an-identity-protection-pin.

Watch for Targeted Phishing

Attackers now have your real address and phone number. Expect convincing calls and texts. Verify everything through official channels, don't click links.

Monitor Financial Accounts

Set up alerts for new accounts and transactions. Check your credit reports at annualcreditreport.com.

The SSO Problem

Figure's breach shows why single sign-on is both a security feature and a liability. Centralize authentication and you reduce password sprawl. But you also create a single point of failure.

The technical controls exist to stop these attacks: phishing-resistant MFA with hardware keys, strict session monitoring, impossible travel detection. Most companies just haven't implemented them.

Until they do, ShinyHunters will keep calling.

References

  1. TechCrunch - Fintech lending giant Figure confirms data breach
  2. FinanceFeeds - Figure Technology Data Breach: Hackers Leak 2.5GB After Social Engineering Attack
  3. Silent Push - SLSH Malicious Supergroup Targeting 100+ Organizations via Live Phishing Panels
  4. TechCrunch - Hackers publish personal information stolen during Harvard, UPenn data breaches
  5. UpGuard - Match Group Suffers Alleged Breach According to Dark Web Reports