Back Mezha Figure Technology Data Breach Confirmed After Social Engineering Attack
Figure Technology, a blockchain-based lending company, has officially confirmed a data breach.
On Friday, the company’s spokesperson Aleteya Jadik told TechCrunch in a statement that the breach occurred due to social engineering of an employee, which allowed attackers to steal “a limited number of files”.
“a limited number of files.”
The statement also said that the company, together with partners and those affected, is working to resolve the situation and offers free credit monitoring to “all individuals who receive notifications”.
The Figure spokesperson did not respond to a number of specific questions the breach. The hacker group ShinyHunters claimed responsibility for the breach on its official dark web site, stating that the company refused to pay the ransom, and published 2.5 gigabytes of allegedly stolen data.
TechCrunch reviewed part of the data, which included customers’ full names, addresses, dates of birth, and phone numbers. A member of ShinyHunters told TechCrunch that Figure was among the victims of a campaign targeting customers who use the Okta single sign-on provider. Other victims of the campaign included Harvard University and the University of Pennsylvania (UPenn).
“to all individuals who will receive notifications.”
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
