Observed Signal · Feb 18, 2026 · Data Breach · Source: techcrunch · Impact: 3/5 · Sentiment: Negative
Figure Data Breach Exposes Nearly One Million Customers
Figure, a blockchain-based lending company, confirmed a data breach after hackers stole what the firm described as "a limited number of files." Security researcher Troy Hunt, creator of the breach-notification site Have I Been Pwned, analyzed the allegedly leaked dataset and found 967,200 unique email addresses tied to Figure customers. The exposed records reportedly include customer names, dates of birth, physical addresses and phone numbers. Cybercriminal group ShinyHunters claimed responsibility and published roughly 2.5 GB of data on its leak site. Figure has not publicly detailed the scope or specific types of data stolen beyond its initial statement and did not respond to inquiries about Hunt’s analysis. The incident raises privacy, fraud and regulatory risks for affected customers and data holders.
Large-scale exposure of customer identity data (names, DOB, addresses, phones, emails) creates privacy, fraud and regulatory risk; relevant to firms handling customer data and identity infrastructure.
Track Getty Images Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Figure confirmed a data breach allowing hackers to steal "a limited number of files."
- Security researcher Troy Hunt analyzed the leaked data and identified 967,200 unique Figure customer email addresses.
- The allegedly exposed dataset included customer names, dates of birth, physical addresses and phone numbers.
- Cybercrime group ShinyHunters claimed responsibility and published about 2.5 GB of data on its leak site.
- Figure did not provide detailed disclosures about the breach contents or publicly respond to questions about Hunt’s findings.
Connected Companies & Entities
2 Entities mappedRelated Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Instructure Breach: ShinyHunters Steal Student Data
Instructure confirmed a data breach that exposed students' private information after the hacking gang ShinyHunters claimed responsibility. TechCrunch reviewed a sample of allegedly stolen records that included student and staff names, personal email addresses, messages between teachers and students, and some phone numbers from two U.S. schools (one in Massachusetts and one in Tennessee). The sample did not contain passwords. ShinyHunters posted a list of roughly 8,800 schools it says were affected and claimed the breach impacts about 275 million people; the group told TechCrunch the unique emails in the dataset number about 231 million. Instructure says it has more than 8,000 institutional customers and is publishing incident updates on its status site, and some products such as Canvas have been restored after maintenance.
Framework notifies all customers of data breach
Framework, a maker of modular repairable computers, notified all customers that hackers accessed personal information — including names, email addresses, phone numbers and physical addresses — after an upstream cyberattack at business-intelligence provider Metabase. Framework said payment information was not included. Metabase disclosed it was hacked via an unknown security flaw (a zero-day) that allowed attackers access to customers' databases stored on its cloud servers. Framework's spokesperson Eric Schumacher confirmed the breach affected "all customers" but did not provide a precise number.
Hugging Face confirms breach of datasets and credentials
Hugging Face disclosed a security breach on July 20, 2026, saying attackers exploited a malicious dataset to run code on its servers, escalate privileges, and access internal datasets and service credentials. The company revoked and rotated compromised credentials, fixed the exploited vulnerability, and urged users to rotate any keys stored on the platform. Hugging Face attributed the attack to an external AI agent that operated across many short-lived sandboxes with self-migrating command-and-control, and said its anomaly detection and a locally hosted LLM helped analyze server logs after a commercial provider’s guardrails blocked analysis. The company has engaged forensic specialists and law enforcement and continues investigating whether customer or partner data was stolen.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
