Policy & Regulation
Figure confirms data breach affecting nearly a million customers
Blockchain lender Figure confirmed a data breach that exposed the personal information of nearly a million customers, with the cybercrime group ShinyHunters claiming responsibility.
The blockchain-based lending company Figure confirmed last week that a data breach allowed hackers to access its systems and steal “a limited number of files.” At the time of its initial confirmation, the company did not provide specifics regarding the types of data that were stolen, nor did it disclose how many of its customers were affected by the incident. However, subsequent independent analysis of the compromised files indicates that the scope of the breach is significantly larger than initially reported, affecting nearly a million customers. According to the security researcher who analyzed the stolen data, the breach has had a far wider impact than the company’s initial statements suggested, exposing a vast amount of customer information.
On Wednesday, Troy Hunt, a security researcher and the creator of Have I Been Pwned, a data breach notification site, analyzed the data allegedly taken from Figure. Have I Been Pwned is a website that allows users to check if their personal data has been compromised by data breaches. Hunt’s analysis of the leaked files revealed that the stolen dataset contained 967,200 unique email addresses associated with Figure customers. In addition to the unique email addresses, the analyzed data also included other personal customer information, specifically customer names, dates of birth, physical addresses, and phone numbers. Figure did not respond to a request for comment regarding the breach. Additionally, the company did not respond to inquiries about whether it disputes Hunt’s findings, providing no official statement on the security researcher’s analysis of the stolen data.
The cybercrime group ShinyHunters claimed responsibility for the cyberattack targeting Figure, telling TechCrunch last week that it was to blame for the breach. The hackers subsequently published 2.5 gigabytes of data allegedly stolen from Figure on their leak website. This website is used by the hackers to shame their victims and publish stolen data if they fail to extort the hacked companies. The publication of this data on the leak website serves as a public shaming mechanism, which the hackers employ when they fail to extort the hacked companies they target.
Why it matters
The breach at a blockchain-based lending platform highlights the persistent vulnerability of fintech firms to large-scale data theft, as cybercrime groups increasingly target financial data for extortion.