Figure Technology, a blockchain-based lending company, has admitted that a data breach has occurred.
On Friday, Figure spokesperson Alethea Jadick told TechCrunch that the breach resulted from an employee being tricked into a social engineering attack that allowed hackers to steal a “limited number of files.”
In a statement, the company said it was “working with our partners and affected individuals” to provide free credit monitoring “to all individuals who receive a notification.”
A spokesperson for Mr. Figures did not respond to a series of specific questions about the breach.
Hacking group ShinyHunters took responsibility for the hack on the company's official dark web leak website, announcing that the company refused to pay the ransom and released 2.5 gigabytes of allegedly stolen data.
TechCrunch viewed some of the data, including customers' names, home addresses, dates of birth, and phone numbers.
Members of ShinyHunters told TechCrunch that Figure was one of the victims of a hacking campaign targeting customers who rely on single sign-on provider Okta. Other victims of this campaign include Harvard University and the University of Pennsylvania (UPenn).
tech crunch event
Boston, Massachusetts | June 23, 2026

