Ransomware victim disclosure
← All victimsFigure Technology Solutions, Inc.
Claimed by Shinyhunters · listed 4 months ago
Status timeline
- ListedFeb 24, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Feb 24, 2026
- Data size
- 2.5 GB
About the victim
AI dossier — public-source company profileFigure Technology Solutions, Inc. is a U.S.-based financial technology company associated with the Figure group of companies, known for offering blockchain-based financial products including home equity lines of credit (HELOCs), mortgage refinancing, and related lending services. The company leverages the Provenance Blockchain to facilitate loan origination and servicing. It operates nationally across the United States.
- Industry
- Financial Technology (Fintech)
Attack summary
Severity: critical — Figure Technology Solutions operates in fintech/lending, meaning exfiltrated data almost certainly contains regulated financial PII (loan applications, SSNs, banking details, credit information) at scale. Data has been confirmed published (disclosed status: data_published), representing actual exposure of likely sensitive financial consumer data.ShinyHunters claims to have exfiltrated approximately 2.5 GB of compressed data from Figure Technology Solutions, Inc. after the company allegedly refused to pay a ransom; the data has been published following non-payment.
Data the group says was taken
AI dossier — extracted from the leak post- Exfiltrated company data (2.5 GB compressed)
- Potentially customer financial records
- Potentially loan origination data
- Potentially internal business documents
What the group claims
Size: 2.5GB (compressed) | Updated: 13 Feb 2026 | Note: Pay or be humiliated. | They were given multiple chances to pay the ransom, but they decided to waste time and hide instead.
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

