Figure Data Breach (2026): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
On 28 January 2026, Figure disclosed a data breach affecting 967,000 individuals whose names, email and physical addresses, phone numbers, and dates of birth were exposed. If you have an account or relationship with Figure, review the company’s notice and consider changing passwords, enabling multi-factor authentication, and monitoring your accounts for unusual activity.
What happened
Public posting of the data occurred in February 2026. Figure confirmed the incident and attributed it to a social engineering attack in which an employee was tricked into providing access. The company has not released further technical details about the method or the timeline of the intrusion itself. The number of people affected is given as 967,000, with more than 900,000 unique email addresses present in the posted material.
How a breach like this happens
Social engineering incidents of this type usually begin with an attacker contacting an employee through channels that appear legitimate, such as email, messaging platforms or phone calls. The goal is to obtain credentials, session tokens or direct access rather than to exploit a software vulnerability. Once initial access is granted, data can be located and copied with standard internal tools. Organisations that store large volumes of customer records are frequent targets because the same set of contact details can support repeated follow-on activity.
Who is Figure?
Figure operates as a fintech lending platform. Companies in this sector collect and retain customer information required for loan applications, identity verification and account servicing. The data typically includes the categories of personal identifiers that were posted in this case. Because lending platforms maintain records that link names and contact details to financial histories, any confirmed exposure draws attention from both customers and regulators.
The information in question
The posted material contains dates of birth, email addresses, names, phone numbers and physical addresses. No other data categories have been named in public statements about the incident.
The real-world impact
Names combined with addresses, phone numbers and dates of birth can be used to construct more convincing impersonation attempts or to cross-reference records held elsewhere. Email addresses and phone numbers increase the volume of potential contact points for unsolicited messages. For the organisation, the incident adds to the record of confirmed exposures in the lending sector and may prompt reviews of employee access controls and verification procedures.
What to do if you're exposed
Individuals can begin by monitoring statements from financial accounts and credit files for activity that does not match their own records. Changing passwords on any accounts that reuse the exposed email address reduces the chance of credential stuffing. Calls or messages that reference the exposed details should be treated as unverified until independently confirmed through official channels.
- Review recent account activity at banks and lenders
- Enable available multi-factor authentication on email and financial services
- Watch for unsolicited contact that uses the exposed phone number or address
- Run a free exposure scan of your email address against known breach data sets
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Moody Bible Institute Data Breach (2026)Sysco Data Breach (2026)American Tower Data Breach (2026)JCPenney Data Breach (2026)Latest breaches
Read GalaxyWarden’s full analysis of the Figure Data Breach (2026) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.