INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Attackers Use MFA to Gain Access via Social Engineering

| 2026-04-09 14:02 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
In February 2026, a financial services company Figure exposed nearly 967,200 email records in a data breach. The attackers are believed to be behind the incident, but no specific attribution has been made. These exposed email addresses were operational inputs that adversaries ran through multiple parallel workflows simultaneously within hours of becoming available. The first workflow is credential stuffing, where success rates against fresh email lists typically range from two to three percent, resulting in 19,000 to 29,000 valid credential pairs. Targeted phishing campaigns can also be generated using AI-assisted tooling in minutes, with personalized messages referencing the organization by name and impersonating internal communications. The breach created conditions under which access becomes achievable through authentication systems itself, bypassing technical vulnerabilities entirely.
Technical Mitigations AI-generated
• User Training (ATT&CK mitigation for Social Engineering): Reduces success of phishing/vishing/impersonation and modern “human interface” lures. • Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate. • Password Policies (ATT&CK mitigation for Credential Stuffing): Refer to NIST guidelines when creating password policies. • User Account Management (ATT&CK mitigation for Credential Stuffing): Proactively reset accounts that are known to be part of breached credentials either immediately, or after detecting bruteforce attempts. • Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

to•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope financefinance
Incident Timeline
‎February 2026
Threat actors used targeted phishing to impersonate employees and gain access to 967,000 records containing 29,000 valid credential pairs.
infrastructure Microsoft 365
data_breach 967,000 records
data_breach 29,000 valid credential pairs
‎2026/04/09
Figure, a financial services company, exposed nearly 967,200 email records in a data breach without any reported exploit.
data_breach 967,200 email records
Tactical Metrics
Metrics
data_breach
967,200
Email Records
Metrics
infrastructure
‎Microsoft 365
Affected Product
Metrics
data_breach
967,000
Records
Metrics
data_breach
29,000
Valid Credential Pairs
Intelligence Sources