---
title: "Figure Lending database-query data incident"
description: "Evidence-backed account of Figure Lending database-query data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/figure-lending-database-query-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/figure-lending-database-query-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/figure-lending-database-query-data-incident-2026/stix.json"
---

# Figure Lending database-query data incident

Unauthorized activity on Figure systems that included personal data being obtained through queries against loan and loan-inquiry databases. Personal data obtained from databases used for loan and loan-inquiry information; the affected fields varied by individual.

Last modified Aug 9, 2026 · 5 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Unauthorized activity on [Figure](https://www.figure.com/lending/) systems included personal data being obtained through queries against loan and loan-inquiry databases. [2](#source-2)

## Impact

Personal data obtained from databases used for loan and loan-inquiry information; the affected fields varied by individual. [2](#source-2) [3](#source-3) [5](#source-5)

Documented data types include:

- Contact information — The Massachusetts sample includes address, phone number, and email; the California sample includes address. [2](#source-2) [3](#source-3)
- Names — The affected fields varied by person; both inspected individual-notice samples include names. [2](#source-2) [3](#source-3)
- Financial account information — The California individual-notice sample includes a bank account number and routing number; fields varied by affected person. [2](#source-2) [3](#source-3)
- Loan information — The Massachusetts individual-notice sample includes a loan account number and loan information; fields varied by affected person. [2](#source-2) [3](#source-3)
- Social Security numbers — Affected-person-specific: the Massachusetts notice sample includes a Social Security number, while the California sample explicitly says the recipient's Social Security number was not affected. [2](#source-2) [3](#source-3)
- Dates of birth — Included in the Massachusetts individual-notice sample; fields varied by affected person. [2](#source-2) [3](#source-3)

A cited record reports 146 individuals (Massachusetts residents listed in incident record 2026-267; this is not a national total; as of 2026-02-23). [2](#source-2) [3](#source-3) [5](#source-5)

Personal information was obtained through queries against company databases that stored loan and loan-inquiry data. [3](#source-3)

## Timeline

### January 28, 2026 — Documented event

Known date on which personal data was obtained through database queries; the sources do not establish the full unauthorized-access window. [4](#source-4)

### February 23, 2026 — Public disclosure

Publication date of the California Attorney General incident-notification record. [4](#source-4)

### February 24, 2026 — Documented event

Date printed on the Massachusetts affected-individual notice sample. [3](#source-3)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

Figure reported no evidence of unauthorized access to customer accounts or funds and said business operations continued uninterrupted. [2](#source-2)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

Figure reported stopping the activity, engaging a cybersecurity firm, notifying law enforcement, enhancing security and monitoring controls, and offering two years of credit monitoring and identity restoration. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [3](#source-3)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/figure-lending-database-query-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Annual Report on Form 10-K for the year ended December 31, 2025

official · Figure Technology Solutions, Inc.

<https://www.sec.gov/Archives/edgar/data/2064124/000206412426000009/figr-20251231.htm>

<a id="source-2"></a>

### Notice of Data Breach — California individual notice sample

official · Figure Lending Corp.

<https://oag.ca.gov/system/files/L03_Figure%20Invididual%20Notification.pdf>

<a id="source-3"></a>

### Notice of Data Breach — Massachusetts individual notice sample

official · Figure Lending Corp.

<https://www.mass.gov/doc/2026-267-figure-technology-solutions-inc/download>

<a id="source-4"></a>

### Submitted Breach Notification Sample — Figure Technology Solutions

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/ecrime/databreach/reports/sb24-619176>

<a id="source-5"></a>

### 2026 Data Breach Notification Report

regulatory · Massachusetts Office of Consumer Affairs and Business Regulation

<https://www.mass.gov/doc/data-breach-report-2026/download>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   January 2026 Figure lending-platform compromise: Figure reported no evidence of unauthorized access to customer accounts or funds and said business operations continued uninterrupted.
2. **Subsidiary Of · 100% confidence · current**  
   Figure Lending Corp.: Figure Technology Solutions, Inc.
3. **Resulted In · 100% confidence · current**  
   January 2026 Figure lending-platform compromise: Figure affected-individual notification
4. **Exposed Data Category · 100% confidence · current**  
   Figure loan and loan-inquiry data exposure: Contact information
5. **Subsidiary Of · 100% confidence · current**  
   Figure Lending LLC: Figure Lending Corp.
6. **Occurred At · 100% confidence · current**  
   Personal data obtained through Figure database queries: 2026-01-28
7. **Resulted In · 100% confidence · current**  
   January 2026 Figure lending-platform compromise: Figure reported stopping the activity, engaging a cybersecurity firm, notifying law enforcement, enhancing security and monitoring controls, and offering two years of credit monitoring and identity restoration.
8. **Affected Organization · 100% confidence · current**  
   January 2026 Figure lending-platform compromise: Figure Lending LLC
9. **Exposed Data Category · 100% confidence · current**  
   Figure loan and loan-inquiry data exposure: Names
10. **Affected Individual Count · 100% confidence · current**  
   Figure loan and loan-inquiry data exposure: 146 individual
11. **Resulted In · 100% confidence · current**  
   Personal data obtained through Figure database queries: Figure loan and loan-inquiry data exposure
12. **Subsidiary Of · 100% confidence · current**  
   Figure Payments Corporation: Figure Lending Corp.
13. **Resulted In · 100% confidence · current**  
   January 2026 Figure lending-platform compromise: Personal data obtained through Figure database queries
14. **Subsidiary Of · 100% confidence · current**  
   Figure Markets Credit LLC: Figure Lending Corp.
15. **Affected Organization · 100% confidence · current**  
   January 2026 Figure lending-platform compromise: Figure Lending Corp.
16. **Affected Organization · 100% confidence · current**  
   January 2026 Figure lending-platform compromise: Figure Payments Corporation
17. **Exposed Data Category · 100% confidence · current**  
   Figure loan and loan-inquiry data exposure: Financial account information
18. **Occurred At · 100% confidence · current**  
   Figure affected-individual notification: 2026-02-24
19. **Exposed Data Category · 100% confidence · current**  
   Figure loan and loan-inquiry data exposure: Loan information
20. **Disclosed At · 100% confidence · current**  
   January 2026 Figure lending-platform compromise: 2026-02-23
21. **Exposed Data Category · 100% confidence · current**  
   Figure loan and loan-inquiry data exposure: Social Security numbers
22. **Resulted In · 100% confidence · current**  
   Figure loan and loan-inquiry data exposure: Personal information was obtained through queries against company databases that stored loan and loan-inquiry data.
23. **Exposed Data Category · 100% confidence · current**  
   Figure loan and loan-inquiry data exposure: Dates of birth
24. **Affected Organization · 100% confidence · current**  
   January 2026 Figure lending-platform compromise: Figure Markets Credit LLC

</details>
