Markets & Business
Figure Technology confirms data breach after social engineering attack
Figure Technology confirmed a data breach involving stolen files after a social engineering attack, with hackers publishing 2.5 gigabytes of allegedly stolen data.
Figure Technology, a blockchain-based lending company, has confirmed that it experienced a data breach. The incident was disclosed on Friday, when Figure spokesperson Alethea Jadick told TechCrunch in a statement that the breach originated when an employee was tricked with a social engineering attack. Social engineering is a manipulation technique used to gain unauthorized access to systems by tricking individuals. According to Jadick, who serves as a spokesperson for Figure, this attack allowed the hackers to steal “a limited number of files.” In response to the incident, the statement noted that Figure is communicating with partners and those who are impacted by the breach. Additionally, the company is offering free credit monitoring to all individuals who receive a notice regarding the compromise of their files, as part of its response to the incident.
Following the breach, the hacking group ShinyHunters took responsibility for the hack, posting about the incident on its dark web leak website. The group claimed that Figure refused to pay a ransom. Following this refusal, ShinyHunters subsequently published 2.5 gigabytes of allegedly stolen data online. Figure’s spokesperson did not respond to a series of specific questions about the breach, leaving details about the files unconfirmed. However, the publication of the data highlights the operational risks faced by technology firms when ransom demands are rejected and data is leaked.
The breach at Figure appears to be part of a wider campaign. ShinyHunters reported that Figure was among the victims of a hacking campaign that targeted customers relying on Okta, a single sign-on provider. Single sign-on is a centralized authentication method used by organizations to manage user access across applications. By targeting this centralized point of entry, the hacking campaign was able to compromise multiple organizations that rely on the provider for access management. According to the hacking group, other victims of this campaign include Harvard University and the University of Pennsylvania, demonstrating that the campaign targeted both technology firms and universities that rely on the same authentication provider.
Why it matters
The breach highlights the persistent vulnerability of fintech firms to social engineering and the cascading security risks associated with centralized single sign-on providers.