Short answer
Figure Technology Solutions confirmed in February 2026 that hackers stole a limited number of files after breaking into an employee account through social engineering. As TechCrunch reported, ShinyHunters claimed responsibility and published allegedly stolen data. A follow-up TechCrunch report said Have I Been Pwned analysis found the breach affected nearly one million customer email addresses. The lesson is very human: even advanced financial platforms can be compromised through trust, deception, and one employee account.
What happened?
Figure Technology Solutions, a fintech company known for blockchain-based lending and financial services, confirmed a data breach in February 2026. The company said hackers downloaded a limited number of files after gaining access to an employee’s account through a social engineering attack.
According to TechCrunch, the hacking group ShinyHunters claimed responsibility and published 2.5GB of allegedly stolen data. TechCrunch reviewed a portion of the data and reported that it included customer names, home addresses, dates of birth, and phone numbers.
A few days later, TechCrunch reported that Troy Hunt, creator of Have I Been Pwned, analyzed the leaked data and found 967,200 unique email addresses associated with Figure customers. Cybernews also reported that the breach affected nearly one million accounts and tied the initial access to an employee tricked by social engineering.
Figure said it was communicating with impacted individuals and offering free credit monitoring to those receiving notices.
The details are familiar, but that is exactly why they matter. This was not a story about blockchain code failing. It was a story about a trusted person, a trusted account, and a deception that opened the door.
Why should leaders care?
Fintech companies ask customers for some of the most sensitive information they have: names, addresses, dates of birth, financial details, loan information, identity records, and contact information. When that data is exposed, the risk does not end with the breach notification. It can fuel identity theft, loan fraud, targeted scams, vishing, and highly personalized phishing.
The Figure breach also shows a pattern that applies far beyond fintech. Many organizations invest heavily in platforms, encryption, infrastructure, identity providers, and security tools, but attackers still look for the human shortcut. They do not always need to break the strongest system. They need to compromise an account that already has permission to use it.
That is why social engineering remains so powerful. It targets the place where technology, process, and human judgment meet. A message, call, login prompt, fake support request, or impersonation attempt can turn into access if the person on the receiving end does not have the training, confidence, or process support to challenge it.
In financial services, that trust gap is especially costly. Customers assume their financial data is handled with extreme care. Attackers assume employees are busy, helpful, and human. Unfortunately, both assumptions can be true.
The human risk behind employee account compromise
Employee account compromise is rarely just one bad click. It usually sits inside a chain of conditions.
Maybe the attacker knew enough about the company to sound credible. Maybe the request felt urgent. Maybe the employee had access they did not use every day but still retained. Maybe MFA was vulnerable to push fatigue or social manipulation. Maybe the help process was unclear. Maybe the employee did not feel comfortable slowing things down.
Human risk management looks at the whole chain, not just the moment someone was tricked.
That matters because social engineering exploits culture. If people are rewarded only for speed, they may rush. If they fear blame, they may delay reporting. If procedures are unclear, they may improvise. If challenging authority feels risky, they may comply. If security training is generic, they may not recognize a targeted attack until after the fact.
A strong cyber culture gives people the practical skills and social permission to pause. It makes verification normal. It makes escalation easy. It treats reporting as a success, not an admission of failure.
That is how organizations reduce the chance that one employee account becomes a customer-data incident.
What organizations should do now
Organizations should review which employee accounts can access customer data, financial records, sensitive files, operational systems, and third-party platforms. Access should be limited, monitored, and removed when no longer needed. High-risk systems should use strong MFA, phishing-resistant authentication where possible, and alerts for unusual access patterns.
Social-engineering training should be role-specific. Fintech employees, customer-support teams, finance teams, IT administrators, legal teams, and executives face different lures. They need examples that reflect real workflows: account resets, vendor calls, urgent access requests, suspicious MFA prompts, fake identity checks, and requests for files.
Companies should also prepare for follow-on customer scams. If names, addresses, dates of birth, phone numbers, or email addresses are exposed, attackers can use that data to make future contact sound more legitimate. Customer communications should explain what happened, what the company will never ask for, and how customers can verify legitimate outreach.
Finally, leaders should measure human risk rather than assuming annual training has handled it. Do employees know how to verify identity? Are they comfortable refusing unusual requests? Do they report quickly? Do managers support cautious behavior? Do high-risk teams understand the specific ways they may be targeted?
Those questions are not soft. They are controls with a pulse.
The Cybermaniacs take
The Figure breach is a human risk management story because it shows how customer trust can be exposed through one manipulated employee account.
Cyber culture matters when employees receive unusual requests, approve access, handle sensitive files, respond to MFA prompts, or decide whether to report something suspicious. It also matters after the incident, when customers need clear guidance and teams need to recover without blame or confusion.
For Cybermaniacs, this is why modern human risk management has to connect identity, behavior, culture, and business impact. Social engineering is not just an awareness problem. It is an operating-model problem. It touches access governance, customer trust, employee confidence, escalation habits, and leadership assurance.
The blockchain may be advanced. The attack path was deeply human.
FAQ
What happened in the Figure breach?
Figure confirmed that hackers stole a limited number of files after gaining access to an employee account through social engineering. ShinyHunters claimed responsibility and published allegedly stolen data.
How many people were affected?
TechCrunch reported that Have I Been Pwned analysis found 967,200 unique email addresses associated with Figure customers in the leaked data.
What information was exposed?
Public reporting said the exposed data included customer names, home addresses, dates of birth, phone numbers, and email addresses.
Why is this a human risk management issue?
The breach began with social engineering against an employee account. Human risk management helps organizations build the training, culture, verification habits, and escalation processes needed to resist deception.
How can companies reduce this risk?
Use least privilege, phishing-resistant MFA, access monitoring, role-specific social-engineering training, fast reporting channels, customer scam warnings, and a culture where employees feel supported when they pause and verify.