Figure Lending database-query data incident

Unauthorized activity on Figure systems that included personal data being obtained through queries against loan and loan-inquiry databases. Personal data obtained from databases used for loan and loan-inquiry information; the affected fields varied by individual.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Unauthorized activity on Figure systems included personal data being obtained through queries against loan and loan-inquiry databases. [2]

Impact

Personal data obtained from databases used for loan and loan-inquiry information; the affected fields varied by individual. [2][3][5]

Documented data types include:

  • Contact information — The Massachusetts sample includes address, phone number, and email; the California sample includes address. [2][3]
  • Names — The affected fields varied by person; both inspected individual-notice samples include names. [2][3]
  • Financial account information — The California individual-notice sample includes a bank account number and routing number; fields varied by affected person. [2][3]
  • Loan information — The Massachusetts individual-notice sample includes a loan account number and loan information; fields varied by affected person. [2][3]
  • Social Security numbers — Affected-person-specific: the Massachusetts notice sample includes a Social Security number, while the California sample explicitly says the recipient’s Social Security number was not affected. [2][3]
  • Dates of birth — Included in the Massachusetts individual-notice sample; fields varied by affected person. [2][3]

A cited record reports 146 individuals (Massachusetts residents listed in incident record 2026-267; this is not a national total; as of 2026-02-23). [2][3][5]

Personal information was obtained through queries against company databases that stored loan and loan-inquiry data. [3]

Timeline

  1. Documented event

    Known date on which personal data was obtained through database queries; the sources do not establish the full unauthorized-access window.

    [4]
  2. Public disclosure

    Publication date of the California Attorney General incident-notification record.

    [4]
  3. Documented event

    Date printed on the Massachusetts affected-individual notice sample.

    [3]
  4. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

Figure reported no evidence of unauthorized access to customer accounts or funds and said business operations continued uninterrupted. [2]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

Figure reported stopping the activity, engaging a cybersecurity firm, notifying law enforcement, enhancing security and monitoring controls, and offering two years of credit monitoring and identity restoration. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [3]