In February 2026, Figure Technology Solutions, Inc., a fintech lending company, suffered a data breach. The incident, disclosed and reported starting mid-February 2026, was a result of a social engineering (vishing) attack conducted by the ShinyHunters ransomware group. Figure Technology Solutions confirmed the breach, indicating that hackers gained access to an employee’s account and downloaded a limited number of files. The company took immediate steps to block malicious activity, engaged a forensic firm, and is in the process of notifying affected individuals. The data was publicly posted by ShinyHunters on February 13, 2026.
The breach compromised full names, email addresses, phone numbers, physical addresses, and dates of birth for approximately 967,200 unique user accounts. It has been confirmed that no Social Security numbers, financial account details, loan information, or medical data were involved in this incident. While the company is notifying affected individuals and offering complimentary credit monitoring, specific details on affected states have not yet been disclosed.
Details about the full impact are still emerging, and notification delays are possible. Figure Technology Solutions, Inc. is actively managing the situation and providing credit monitoring to those affected.