Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Impact
Personal data obtained from databases used for loan and loan-inquiry information; the affected fields varied by individual. [2][3][5]
Documented data types include:
- Contact information — The Massachusetts sample includes address, phone number, and email; the California sample includes address. [2][3]
- Names — The affected fields varied by person; both inspected individual-notice samples include names. [2][3]
- Financial account information — The California individual-notice sample includes a bank account number and routing number; fields varied by affected person. [2][3]
- Loan information — The Massachusetts individual-notice sample includes a loan account number and loan information; fields varied by affected person. [2][3]
- Social Security numbers — Affected-person-specific: the Massachusetts notice sample includes a Social Security number, while the California sample explicitly says the recipient’s Social Security number was not affected. [2][3]
- Dates of birth — Included in the Massachusetts individual-notice sample; fields varied by affected person. [2][3]
A cited record reports 146 individuals (Massachusetts residents listed in incident record 2026-267; this is not a national total; as of 2026-02-23). [2][3][5]
Personal information was obtained through queries against company databases that stored loan and loan-inquiry data. [3]
Timeline
Documented event
Known date on which personal data was obtained through database queries; the sources do not establish the full unauthorized-access window.
[4]Public disclosure
Publication date of the California Attorney General incident-notification record.
[4]Documented event
Date printed on the Massachusetts affected-individual notice sample.
[3]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
Figure reported no evidence of unauthorized access to customer accounts or funds and said business operations continued uninterrupted. [2]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
Figure reported stopping the activity, engaging a cybersecurity firm, notifying law enforcement, enhancing security and monitoring controls, and offering two years of credit monitoring and identity restoration. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [3]
