INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Attackers Use MFA to Gain Access via Social Engineering
| 2026-04-09 14:02 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
In February 2026, a financial services company Figure exposed nearly 967,200 email records in a data breach. The attackers are believed to be behind the incident, but no specific attribution has been made. These exposed email addresses were operational inputs that adversaries ran through multiple parallel workflows simultaneously within hours of becoming available. The first workflow is credential stuffing, where success rates against fresh email lists typically range from two to three percent, resulting in 19,000 to 29,000 valid credential pairs. Targeted phishing campaigns can also be generated using AI-assisted tooling in minutes, with personalized messages referencing the organization by name and impersonating internal communications. The breach created conditions under which access becomes achievable through authentication systems itself, bypassing technical vulnerabilities entirely.
Technical Mitigations AI-generated
• User Training (ATT&CK mitigation for Social Engineering): Reduces success of phishing/vishing/impersonation and modern “human interface” lures.
• Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate.
• Password Policies (ATT&CK mitigation for Credential Stuffing): Refer to NIST guidelines when creating password policies.
• User Account Management (ATT&CK mitigation for Credential Stuffing): Proactively reset accounts that are known to be part of breached credentials either immediately, or after detecting bruteforce attempts.
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
to•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
financefinance
Incident Timeline
February 2026
Threat actors used targeted phishing to impersonate employees and gain access to 967,000 records containing 29,000 valid credential pairs.
Click on any entity below to view its context and source!
infrastructure
Microsoft 365
Adversaries combine the exposed addresses with breach databases from prior incidents — LinkedIn, Dropbox, RockYou2024 — and test the resulting pairs against enterprise portals, VPN gateways, Microsoft 365, Okta, and identity providers at scale.
data_breach
967,000 records
On 967,000 records, that is 19,000 to 29,000 valid credential pairs.
data_breach
29,000 valid credential pairs
On 967,000 records, that is 19,000 to 29,000 valid credential pairs.
2026/04/09
Figure, a financial services company, exposed nearly 967,200 email records in a data breach without any reported exploit.
Click on any entity below to view its context and source!
data_breach
967,200 email records
In February 2026, TechRepublic reported that Figure, a financial services company, exposed nearly 967,200 email records in a newly disclosed data breach.
The Figure breach exposed 967,200 email records without a single exploit.
Tactical Metrics
Metrics
data_breach
967,200
Email Records
Click for context!
In February 2026, TechRepublic reported that Figure, a financial services company, exposed nearly 967,200 email records in a newly disclosed data breach.
The Figure breach exposed 967,200 email records without a single exploit.
Metrics
infrastructure
Microsoft 365
Affected Product
Adversaries combine the exposed addresses with breach databases from prior incidents — LinkedIn, Dropbox, RockYou2024 — and test the resulting pairs against enterprise portals, VPN gateways, Microsoft 365, Okta, and identity providers at scale.
Metrics
data_breach
967,000
Records
On 967,000 records, that is 19,000 to 29,000 valid credential pairs.
Metrics
data_breach
29,000
Valid Credential Pairs
On 967,000 records, that is 19,000 to 29,000 valid credential pairs.
Intelligence Sources
BleepingComputer
2026-04-09
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T11:11
Comprehensive Tactical Telemetry
Highly Correlated Entities
18x
organisation
Identified Entity
TechRepublic
entity
5x
tactic
Cyber Operation Type
Data Breach
tactic
3x
tactic
MITRE ATT&CK Technique
T1566 - Phishing
technique
Contextual Telemetry
Context Block
7 METRICS
timeline
Temporal Reference
February 2026
date
data breach
Email Records
967,200
email records
infrastructure
Affected Product
Microsoft 365
software
general metric
Microsoft
365
microsoft
general metric
Exposed Email Addresses
967,000
exposed email addresses
data breach
Records
967,000
records
data breach
Valid Credential Pairs
29,000
valid credential pairs
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.