Figure Data Breach: How SMBs Should Protect Caller Data
TL;DR
- A social-engineering attack exposed data on nearly 1 million Figure customers. Here is what small businesses should do to protect caller data.
Fintech lender Figure Technology Solutions confirmed a data breach that exposed personal information on close to a million customers after attackers used social engineering to gain access, according to TechCrunch's February 18, 2026 report. Security researcher Troy Hunt independently verified 967,200 unique email addresses tied to the stolen data, which also included names, dates of birth, physical addresses and phone numbers. The cybercrime group ShinyHunters claimed responsibility and published roughly 2.5 gigabytes of the stolen data on a leak site. For any small business that collects customer information over the phone, the lesson isn't about blockchain lending. It's that social engineering, tricking a real employee into handing over access, keeps working even against companies with real security budgets.
Key Takeaways
- Fintech lender Figure Technology Solutions confirmed a data breach that exposed personal information on close to a million customers after attackers used social engineering to gain access (TechCrunch, February 18, 2026).
- Security researcher Troy Hunt independently verified 967,200 unique email addresses tied to the stolen data, which also included names, dates of birth, physical addresses and phone numbers.
- The group ShinyHunters claimed responsibility and published roughly 2.5 gigabytes of the stolen data on a leak site.
- The FTC's small business guidance recommends knowing what personal information you hold, keeping only what you need, restricting access, and training employees to recognize social engineering attempts.
- Any vendor handling caller data should be able to confirm encryption at rest and in transit and a current SOC 2 Type II audit.
What Happened at Figure
According to TechCrunch, attackers socially engineered an employee to gain account access and download a limited set of files. Troy Hunt's independent analysis of the leaked data found it contained personal details, names, birth dates, addresses, phone numbers and email addresses, for roughly 967,200 people. Figure confirmed the breach but gave few specifics publicly, and did not dispute Hunt's findings when TechCrunch asked for comment.
Social engineering, as opposed to a technical hack, means the attacker didn't need to break through a firewall. They convinced a person to help them, whether through a phishing message, a fake support call, or impersonation. That's the same category of attack small businesses face every day on their own phone lines, just aimed at a much larger target.
Why This Matters for a Small Business's Phone Line
A small business collects caller data constantly: names, phone numbers, addresses, sometimes payment or health information, all given verbally to whoever answers the phone. If that data sits in an unsecured spreadsheet, an unencrypted voicemail system, or a shared inbox anyone can access, a single social engineering attempt (a caller impersonating a vendor, a fake "IT support" call, a phishing email to your office manager) can expose it just as easily as it exposed Figure's data, just at smaller scale.
The Federal Trade Commission's guidance for small businesses lays out the same basic discipline that large companies too often skip: know what personal information you actually hold, keep only what you need, restrict who can access it, and have a plan for when something goes wrong (FTC, "Protecting Personal Information: A Guide for Business"). The FTC specifically recommends training employees to recognize social engineering attempts and giving them a clear way to report anything suspicious, exactly the gap that Figure's attackers exploited.
What to Check in Your Own Business
Ask three things about however your business currently handles caller data: Who can access it, and is that list as short as it can be? Is it encrypted, both while it's being collected and while it's stored? And does your team know what a social engineering attempt sounds like, whether it's a caller pretending to be a vendor or an email pretending to be your own IT department?
If you use any AI system to help answer calls or take messages, ask the same questions of that vendor. Data encrypted at rest and in transit, and a SOC 2 Type II audit specifically, are the baseline a small business should expect from any vendor handling caller information.
What This Means for Small Businesses
You don't control whether a fintech giant gets breached, but you do control how your own business handles the names, numbers and details callers give you every day. Write down who has access to that data today, cut the list to only the people who need it, and make sure whatever system stores it, whether that's your own CRM or a phone-answering vendor, is encrypted and independently audited. A SOC 2 Type II report is a specific, checkable claim; "we take security seriously" is not.
How This Guide Was Sourced
Written by the Voksha team (https://voksha.com/). Breach facts are drawn from TechCrunch's February 18, 2026 report, which includes independent verification from security researcher Troy Hunt. Small business security guidance is drawn directly from the FTC's published small business data security resources. No Voksha call data is used in this guide.
Sources
- Data breach at fintech giant Figure affects close to a million customers, TechCrunch, February 18, 2026
- Protecting Personal Information: A Guide for Business, Federal Trade Commission
- Recognize Data Privacy Day by protecting your small business from cybercriminals, Federal Trade Commission, January 2026
Published by the Voksha team. Voksha builds AI receptionists for small businesses.
Frequently Asked Questions
What is social engineering, in plain terms?
It's an attack that targets a person instead of a computer system, tricking an employee into granting access, sharing a password, or sending files, usually by impersonating someone trustworthy like a vendor, executive or IT support.
What should I ask any vendor that handles my customers' data?
Ask whether data is encrypted at rest and in transit, whether the company has a current SOC 2 Type II report, and what happens to your data if you cancel. A vendor that can answer all three specifically is a safer bet than one that offers general reassurance.
If you're comparing AI phone vendors and want to see what a checkable security standard looks like, see the security features Voksha publishes, including SOC 2 Type II compliance and encryption details, or read 5 Critical Security Features to Look for in Any AI Phone System.