Figure Lending Corp
bd_16047971769a6e51 · schema v1 · pii pii-v1
Full breach record for Figure Lending Corp →Figure Lending Corp disclosed a security incident where unauthorized activity on its systems led to the exfiltration of personal information via database queries on January 28, 2026. Affected data includes names, SSNs, addresses, phone numbers, emails, dates of birth, and loan account numbers. The company contained the incident, engaged a cybersecurity firm, notified law enforcement, and is offering two years of credit monitoring through TransUnion. No evidence of unauthorized access to customer accounts or funds was found.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 28, 2026
Begins
Feb 23, 2026
Filed
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- California State AGbd_296cbbf7363298af2026-02-23Verified
- Nebraska State AGbd_7b52ff5445d950f12026-02-24 · +1dVerified
- California State AGbd_04d4edb44be7c3652026-02-27 · +4dCandidate
- Washington State AGbd_e5eff25ef061db852026-02-27 · +4dVerified
Show 3 more filings ↓Show fewer ↑up to 11d gap
- Nebraska State AGbd_e98dfc28a35687cb2026-02-27 · +4dVerified
- Massachusetts State AGbd_0e4a9ec64e5867df2026-03-03 · +8dVerified
- New Hampshire State AGbd_983f209181acda622026-03-06 · +11dVerified
Filing propagation · 8 filings · 5 states
View merged incident ↗Pattern: first filing Feb 23 (CA), last Mar 6 (NH) — a 11-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.