Figure Technology Hit by Data Breach: ShinyHunters Exploit Social Engineering
cybercrime

Figure Technology Hit by Data Breach: ShinyHunters Exploit Social Engineering

WebMag WriterFebruary 14, 20267 min read

Key Takeaways

  • 1.Figure Technology confirmed a data breach resulting from a social engineering attack on an employee.
  • 2.Notorious hacking group ShinyHunters claimed responsibility and leaked 2.5GB of data after a ransom refusal.
  • 3.The incident is part of a broader campaign targeting Okta support systems, affecting other institutions like Harvard and UPenn.
  • 4.Exposed data includes full names, dates of birth, home addresses, and phone numbers, posing significant identity theft risks.

In the rapidly evolving landscape of financial technology, security remains the paramount concern. On Friday, blockchain-based lending giant Figure Technology confirmed that it has become the latest victim of a significant cybersecurity incident. The breach, which exposed the sensitive personal information of customers, highlights the persistent vulnerabilities facing even the most tech-forward financial institutions.

The attack has been claimed by the notorious cybercriminal collective known as ShinyHunters, a group with a prolific history of targeting digital platforms. This incident serves as a stark reminder of the sophisticated methods hackers are employing to bypass traditional security perimeters, specifically through the manipulation of human targets.

The Anatomy of the Breach: Social Engineering

According to a statement provided to TechCrunch, Figure Technology acknowledged that the unauthorized access was not the result of a brute-force attack on their encryption, but rather a successful social engineering campaign. A spokesperson for the company, Alethea Jadick, revealed that an employee was "tricked" into facilitating access for the attackers.

What is Social Engineering?

Social engineering relies heavily on psychological manipulation rather than technical hacking to trick users into making security mistakes or giving away sensitive information. In this instance, the attackers likely impersonated a trusted entity—such as IT support or a vendor—to persuade the Figure employee to hand over credentials or approve a login request.

The Cybersecurity and Infrastructure Security Agency (CISA) notes that these types of attacks are increasingly common because it is often easier to exploit human error than to find a zero-day vulnerability in software code. Once the attackers bypassed the human firewall, they were able to exfiltrate files from Figure's systems.

The Scale of Stolen Data: Company vs. Hackers

As is common in the immediate aftermath of a data breach, there are conflicting narratives regarding the severity of the data loss between the victim company and the perpetrators.

Figure Technology's Stance: The company has characterized the incident as involving a "limited number of files." They have stated they are actively communicating with partners and impacted individuals and are offering free credit monitoring services to those notified.

The ShinyHunters Claim: Contradicting the company's conservative estimate, ShinyHunters posted on their official dark web leak site that they had successfully stolen 2.5 gigabytes of data. The group claimed that Figure Technology refused to pay a demanded ransom, prompting the hackers to publish the stolen dataset publicly.

Upon review of a portion of the leaked data, it was confirmed that the files contained highly sensitive Personally Identifiable Information (PII), including:

  • Full legal names
  • Home addresses
  • Dates of birth
  • Phone numbers

While financial account numbers or social security numbers were not explicitly mentioned in the initial analysis of the sample, the combination of names, addresses, and birth dates is often sufficient for bad actors to commit synthetic identity fraud.

The Okta Connection: A Broader Campaign

This breach appears to be part of a much larger, coordinated offensive rather than an isolated incident. A representative from ShinyHunters indicated that Figure Technology was targeted as part of a campaign exploiting the single sign-on (SSO) provider, Okta.

Targeting the Supply Chain

Okta is a ubiquitous tool used by thousands of organizations to manage employee access. By targeting the support systems or customer service portals associated with Okta, hackers can gain a foothold into multiple downstream organizations. This method, often referred to as supply chain attacks, allows threat actors to scale their operations significantly.

According to threat intelligence reports, this specific campaign has also claimed other high-profile victims, including prestigious educational institutions like Harvard University and the University of Pennsylvania (UPenn). The Google Cloud Threat Intelligence team has previously documented the expansion of ShinyHunters' tactics into SaaS (Software as a Service) data theft, noting their proficiency in navigating cloud environments once initial access is gained.

Who Are ShinyHunters?

ShinyHunters is a threat actor group that emerged around 2020 and quickly gained infamy for selling vast databases of stolen user records on dark web forums. Unlike ransomware gangs that lock up systems and demand payment for a decryption key, ShinyHunters typically focus on data theft and extortion.

Their modus operandi involves:

  1. Infiltration: Often through stolen credentials or cloud misconfigurations.
  2. Exfiltration: Copying large volumes of customer databases.
  3. Extortion: Threatening to leak the data unless a ransom is paid.
  4. Leakage: If the ransom is refused—as was the case with Figure—they publish the data to damage the company's reputation and prove the validity of their threats to future victims.

Implications for Fintech and Consumers

The breach at Figure Technology is particularly concerning given the nature of the business. As a company that leverages blockchain for lending, Figure handles sensitive financial profiles. While blockchain architecture is immutable and secure regarding transaction ledgers, the centralized access points—like employee login portals—remain a critical point of failure.

What Should Affected Customers Do?

If you are a customer of Figure Technology, or if you suspect your data may have been involved in this breach, immediate action is required. The exposure of dates of birth and home addresses creates a long-term risk profile that goes beyond simple credit card fraud.

  1. Freeze Your Credit: This is the most effective way to prevent new accounts from being opened in your name. You must contact Equifax, Experian, and TransUnion individually.
  2. Monitor Accounts: Watch for small, unauthorized transactions on existing accounts.
  3. Be Wary of Phishing: With your phone number and email potentially exposed, expect an increase in targeted phishing attempts (smishing and vishing) pretending to be from banks or service providers.
  4. Utilize Provided Monitoring: Take advantage of the free credit monitoring Figure is offering.

For a comprehensive guide on recovering from data exposure, the Federal Trade Commission (FTC) Identity Theft recovery site provides step-by-step instructions customized to the type of data that was lost.

Conclusion

The Figure Technology breach serves as a sobering case study in modern cybersecurity. It demonstrates that even sophisticated blockchain fintechs are susceptible to the oldest trick in the book: human manipulation. As ShinyHunters continue their aggressive campaign targeting Okta-linked organizations, both companies and consumers must remain in a state of heightened vigilance. While Figure attempts to contain the fallout, the leaked data is now in the wild, underscoring the critical need for robust personal cybersecurity hygiene.

Frequently Asked Questions (FAQs)

1. What data was stolen in the Figure Technology breach?

The hackers claim to have stolen 2.5GB of data. Verified samples of the leak include customers' full names, home addresses, dates of birth, and phone numbers.

2. Who is responsible for the hack?

The hacking group ShinyHunters has claimed responsibility. They are a well-known cybercriminal group with a history of targeting digital platforms and selling data on the dark web.

3. How did the hackers get into Figure's system?

The breach occurred through a social engineering attack where an employee was tricked into facilitating access for the attackers. It was not a technical flaw in the blockchain technology itself.

4. Is this related to the Okta hacks?

Yes. ShinyHunters stated that Figure was compromised as part of a wider hacking campaign that targets customers relying on Okta's identity management software. This campaign also affected Harvard and UPenn.

5. What should I do if I am a Figure customer?

You should freeze your credit reports immediately, monitor your financial statements for irregularities, and sign up for the free credit monitoring services offered by Figure. Be extremely cautious of unsolicited calls or texts, as scammers may use your stolen info to make their attacks look legitimate.

-- Keep Reading --