SecuritySeptember 5, 20267 min read

What to Do After the Figure Data Breach

PT

By PrivacyOn Team

Privacy Research & Removal Operations

SharePostFacebookEmail
What to Do After the Figure Data Breach

Worried you're exposed? Find out in 60 seconds with a free exposure scan.

Figure Technology Solutions confirmed a breach affecting roughly 967,000 customer records. Exposed data includes names, dates of birth, email addresses, postal addresses and phone numbers, with Social Security numbers and loan account details also potentially compromised. Freeze your credit at all three bureaus today — that is the single most important step.

What Happened

Figure Technology Solutions is a Nasdaq-listed fintech specializing in blockchain-based home equity lending and mortgage services. In late January 2026, the hacking group ShinyHunters targeted Figure employees with voice phishing — calling staff and impersonating internal IT to talk them into handing over access. One employee fell for it, and the attackers obtained a set of internal files.

Figure did not pay the ransom the group demanded. On February 13, 2026, ShinyHunters published 2.5 gigabytes of compressed files taken in the attack. The breach notification service Have I Been Pwned subsequently indexed approximately 967,000 Figure user records from the leaked data. Law firms began announcing class action investigations into Figure Lending in March 2026.

What Data Was Exposed

Based on Figure's disclosures and analysis of the leaked files, the exposed information includes:

  • Full names and dates of birth
  • Email addresses
  • Postal addresses
  • Phone numbers
  • Social Security numbers (potentially affected)
  • Loan account numbers and loan information (potentially affected)

This is a lender breach, which raises the stakes

A leaked email address is a nuisance. A leaked name, date of birth, address and Social Security number together are enough to open credit in your name. Because Figure is a lending company, the exposed dataset skews toward exactly the identity elements used in loan fraud — and unlike a password, none of it can be changed.

Step 1: Freeze Your Credit at All Three Bureaus

Do this first, before anything else. A credit freeze blocks new accounts from being opened in your name, and it is the only measure that directly stops the fraud this dataset enables. Freezes are free by law, do not affect your credit score, and can be lifted temporarily whenever you legitimately apply for credit.

You must freeze separately at Equifax, Experian, and TransUnion — freezing one does nothing at the other two. Each takes a few minutes online.

Step 2: Check Whether You Were Affected

Search your email address on Have I Been Pwned, which has indexed the Figure records. Check every email address you might have used with Figure, including old ones. If you took out a home equity loan or HELOC through Figure, or applied for one, assume you are in the dataset even if a search comes back clean — breach indexes are rarely complete.

Is your data already out there?

Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.

Run a free scan

★★★★★ 4.8/5 · Trusted by thousands of families

Step 3: Watch for Loan Fraud Specifically

Because loan account numbers and loan information were exposed, the fraud risk here is more targeted than a generic breach. Pull your free credit reports at annualcreditreport.com and review them for:

  • Credit inquiries you did not authorize
  • New loan or credit accounts you did not open
  • Changes to the balance or terms of your existing Figure loan
  • Address changes you did not request

Stagger your reports — pull one bureau every four months rather than all three at once — so you have continuous visibility through the year.

Step 4: Expect Targeted Phishing and Vishing

The attackers reached Figure through voice phishing, and the same technique is now being used against Figure's customers. Someone holding your name, address, phone number and loan account number can call you, recite those details, and sound entirely legitimate.

Assume any unexpected contact referencing your Figure loan is fraudulent until proven otherwise:

  • Never act on an inbound call or email about your loan. Hang up and call the number on your official statement.
  • Knowing your details proves nothing. Those details are in a public leak. A real lender never needs you to confirm your full SSN over the phone.
  • Refuse urgency. "Your account will be suspended today" is a pressure tactic, not a real policy.
  • Watch for payoff and wire-transfer scams, which target home equity borrowers specifically and are unrecoverable once sent.

Step 5: Add an Identity Theft Protection PIN

Because Social Security numbers may be exposed, request an Identity Protection PIN from the IRS. It blocks anyone from filing a fraudulent tax return in your name — a common follow-on to any breach involving SSNs, and one that typically only surfaces months later when your legitimate return is rejected. You can also lock your Social Security number through the Social Security Administration's my Social Security portal.

Step 6: Reduce What an Attacker Can Add to the Leak

Breached data becomes far more dangerous when it is combined with information that is already public. Data brokers and people-search sites publish your current address, phone numbers, relatives, and address history — the exact context that turns a leaked record into a convincing impersonation or a successful account takeover.

Removing yourself from those sites will not undo the Figure breach, but it removes the fresh, cross-referenced detail that makes leaked data actionable years after the fact.

Shrink Your Exposure with PrivacyOn

PrivacyOn removes your personal information from 100+ data brokers and people-search sites and keeps monitoring 24/7, automatically re-removing your data when it reappears. Dark web monitoring alerts you if your details surface in this or any other breach dump, and family plans cover up to 5 people from $8.33 per month. Start with a free scan to see what is exposed right now.

Frequently Asked Questions

Was I affected by the Figure data breach?

Search your email address on Have I Been Pwned, which indexed roughly 967,000 Figure records from the leaked files. If you applied for or held a home equity loan or HELOC through Figure, assume you were affected even if a search returns nothing — breach indexes are often incomplete.

What information was exposed in the Figure breach?

Names, dates of birth, email addresses, postal addresses and phone numbers were exposed. Social Security numbers, loan account numbers and loan information were also potentially compromised, which is what makes this breach higher risk than a typical credential leak.

How did the Figure breach happen?

The ShinyHunters group used voice phishing against Figure employees around January 28, 2026, impersonating internal staff to obtain access. After Figure declined to pay a ransom, the group published 2.5 gigabytes of compressed stolen files on February 13, 2026.

Should I freeze my credit after the Figure breach?

Yes, and it should be your first action. With names, dates of birth, addresses and potentially Social Security numbers exposed, a credit freeze is the only step that directly prevents new accounts being opened in your name. Freezes are free, do not affect your score, and must be placed separately at Equifax, Experian and TransUnion.

Is there a class action lawsuit over the Figure data breach?

Law firms announced investigations into Figure Lending in March 2026 over the breach of nearly one million user records. If a suit is certified, affected customers are typically notified — but do not wait on litigation to protect yourself. Freezing your credit today matters far more than any eventual settlement.

How long am I at risk after a breach like this?

Indefinitely. Passwords can be changed; your name, date of birth and Social Security number cannot. Leaked identity data circulates for years and is regularly recombined with newer information from data brokers. Ongoing monitoring and keeping your current details off people-search sites are what reduce the long-term risk.

SharePostFacebookEmail
PT
PrivacyOn Team

Privacy Research & Removal Operations

Operates removal across 100+ data broker sitesGuides verified against live opt-out processesContent reviewed and updated continuously

The team that operates PrivacyOn's data-removal service — publishing opt-out guides and privacy research based on handling real removal requests every day.

Find out what's already exposed

A free 60-second scan shows your breaches and broker exposure. PrivacyOn removes it and monitors 24/7 so it stays gone.

★★★★★ 4.8/5 · Trusted by thousands of families