John Abbamondi had orders to let the CEO of Ticketmaster down easy.
Technology
Figure data breach exposes nearly 1M accounts
Cyber expert shares tips to avoid AI phishing scams
Kurt ‘The CyberGuy’ Knutsson shares practical ways to avoid falling victim to AI-generated phishing scams and discusses a report that North Korean agents are posing as I.T. workers to funnel money into the country’s nuclear program.
NEWYou can now listen to Fox News articles!
If you have applied for a loan online, you probably shared more than you realized. Your name. Your email. Your date of birth. Maybe even your home address and phone number. Now imagine all of that sitting on a dark web forum.
That is the reality for nearly 1 million people after hackers breached Figure Technology Solutions, a blockchain-focused fintech lender.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.
What happened in the Figure data breach
Figure Technology Solutions, founded in 2018, uses the Provenance blockchain for lending, borrowing and securities trading. The company says it has unlocked more than $22 billion in home equity through partnerships with banks, credit unions, fintechs and home improvement companies. However, behind the scenes, attackers were working on a very different angle.
GOOGLE DROPPED DARK WEB MONITORING: SHOULD YOU CARE?
Nearly 1 million accounts were exposed after hackers breached fintech lender Figure Technology Solutions in a social engineering attack. (Felix Zahn/Photothek via Getty Images)
According to breach notification data shared by Have I Been Pwned, information from 967,200 accounts was exposed. The leaked data included more than 900,000 unique email addresses along with names, phone numbers, physical addresses and dates of birth. That is a gold mine for identity thieves. Figure says the incident stemmed from a social engineering attack. What that means in simple terms is that someone inside the company was tricked into handing over access.
“We recently identified that an employee was socially engineered, and that allowed an actor to download a limited number of files through their account,” a Figure Technology Solutions spokesperson told CyberGuy in a statement. “We acted quickly to block the activity and retained a forensic firm to investigate what files were affected. We understand the importance of these matters and are communicating with partners and those impacted as appropriate. We are also implementing additional safeguards and training to further strengthen our defenses. We are offering complimentary credit monitoring to all individuals who receive a notice. We continuously monitor accounts and have strong safeguards in place to protect customers’ funds and accounts.”
Social engineering is the real weapon
When people hear the word blockchain, they think secure and untouchable. But attackers did not break cryptography. They targeted a human being. Groups like ShinyHunters specialize in this playbook. They reportedly claimed responsibility for the breach and, according to BleepingComputer, posted 2.5GB of data allegedly tied to thousands of loan applicants.
In recent weeks, the same group has claimed breaches involving companies like Canada Goose, Panera Bread and SoundCloud. Not every case is connected. Still, security researchers have observed a troubling pattern. Attackers impersonate IT support. They call employees. They create urgency. Then they direct victims to fake login portals that look nearly identical to real ones.
Once employees enter credentials and even multi-factor authentication codes, attackers gain access to single sign-on systems tied to major platforms like Microsoft and Google. From there, one compromised account can unlock a web of connected tools and internal systems.
PANERA BREAD DATA BREACH EXPOSES 5.1M CUSTOMERS
Security researchers say the Figure data leak underscores how social engineering bypasses even blockchain-based platforms. (Maxim Konankov/NurPhoto via Getty Images)
Why this matters to you
If your information was part of the Figure data breach, criminals now have enough detail to craft convincing phishing emails or phone scams. They can reference your real name. They can cite your address. They can pretend to be a lender or bank calling about your application.
Even if you never applied for a loan with Figure, this incident highlights something bigger. No platform is immune to human error. And social engineering works because it targets trust, not technology.
The bigger lesson about blockchain and trust
Figure markets itself as blockchain native. Blockchain can provide transparency and strong cryptographic security. However, none of that protects against a well-crafted phone call.
Security failures often happen at the human layer. That is where attackers focus their energy. As more financial services move online, the attack surface grows. Loan applications, identity verification tools and cloud-based systems create convenience. They also create new targets.
How to protect yourself after the Figure data breach
You cannot control how companies secure their systems. You can control how you respond. Start by checking whether your email address appears in the exposed dataset, then take the steps below to lock down your accounts.
SUBSTACK DATA BREACH EXPOSES EMAILS AND PHONE NUMBERS
Figure says an employee was tricked into granting access, allowing attackers to download sensitive customer data. (Luke MacGregor/Bloomberg via Getty Images)
Check if your email was exposed
To see if your email address was affected, visit https://haveibeenpwned.com/. Enter your email address to find out whether your information appears in the leak. When finished, return here and begin Step 1 below.
Take these steps immediately
- Change any exposed passwords right away. Do not leave a known leaked password in place. Update it everywhere you used it. Use a password manager to create strong, unique passwords for every account. Check out the best expert-reviewed password managers of 2026 at Cyberguy.com
- Turn on multi-factor authentication wherever possible.
- Never share login codes with anyone, even if they claim to be IT support.
- Install strong antivirus software to help block phishing links, malicious downloads and ransomware that often follow major breaches. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.
- Consider a data removal service to reduce your personal information on data broker sites, which scammers often combine with breached data. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.
- Place a free fraud alert or credit freeze with the major credit bureaus.
- Monitor your bank and credit card statements weekly for suspicious activity.
Also, be cautious of unexpected calls about your accounts. If someone pressures you to act immediately, hang up and call the company directly using a number from its official website.
Kurt’s key takeaways
The Figure data breach is a reminder that technology alone cannot protect sensitive information. A single employee tricked into revealing credentials can expose hundreds of thousands of people. That is not a blockchain failure. It is a trust failure. If your data was involved, take action now. Even if it was not, treat this as a wake-up call. Your personal information has value. Criminals know it. Companies should know it too.
If one phone call can unlock nearly a million records, are companies investing enough in training people, or are they still betting everything on technology alone? Let us know by writing to us at Cyberguy.com
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Did Live Nation punish a venue by taking Billie Eilish away?
In April 2021, Abbamondi was the CEO of BSE Global, the company that ran Brooklyn arena the Barclays Center. BSE Global’s existing Ticketmaster contract would expire at the end of September, and Abbamondi and his team had evaluated proposals from SeatGeek, AXS, and Ticketmaster. The economics of Ticketmaster offer, according to Abbamondi, “was nowhere near as good as the other two.” SeatGeek’s technology was “superior” to Ticketmaster’s on balance, on top of better financial terms including an equity stake in the company, the arena decided. It clinched their decision to go with a newer, smaller player in the field.
When Abbamondi called to break the news to Michael Rapino, the Live Nation Entertainment CEO, the meeting became tense — and a recording of it came back to haunt Rapino in this month’s Live Nation-Ticketmaster monopoly trial. Abbamondi was one of two witnesses who took the stand Wednesday, alongside Mitch Helgerson, the chief revenue officer for the Minnesota Wild hockey team. Both men said that when they considered switching their venues’ ticketing platform from Ticketmaster, executives there threatened them with the loss of vital Live Nation-promoted concerts. It’s the behavior, the Justice Department and 40 state and district attorneys general say, of a monopolist — a charge Live Nation-Ticketmaster denies.
Abbamondi, identifying the voices on the 2021 call to a Manhattan jury Wednesday, said that “the nervous guy was me and the angry guy was Michael.” The few minutes played in court captures an exchange that went “sideways,” as Abbamondi put it, when he tried to thread a delicate needle: rejecting Ticketmaster’s services while trying to hold its parent company Live Nation to a separate contract promising to fill Barclays Center with concerts. At one point, Rapino dropped an F-bomb while discussing his frustration over a contractual dispute. He told Abbamondi he believed they were never planning to renew with Ticketmaster in the first place.
Rapino reminded Abbamondi about the new UBS Arena in Queens, which could draw more Live Nation-promoted shows away from Barclays. Though Ticketmaster theoretically operates separately from Live Nation, Abbamondi took this as a “not-so-veiled” threat — cut off the left arm, and the right arm would swing back. Abbamondi hung up feeling like he’d failed to “do my job there, which was to land the plane smoothly.”
The venue “saw a dramatic decline in Live Nation shows that were booked at the arena”
Abbamondi still signed the deal with SeatGeek, which began in October 2021. Then, he testified, the venue “saw a dramatic decline in Live Nation shows that were booked at the arena.” Artists were just beginning to fill stadiums again after the start of the covid pandemic, including Billie Eilish, who’d had to cancel shows in New York venues including Barclays in 2020. Normally, Abbamondi would have expected Live Nation to rebook her show there next time she was on tour. But when she began touring again in 2021, she booked at the new venue Rapino had warned about — the UBS Arena. When Barclays asked about it, they were told it was the “artist’s decision.” Other promoters, he said, hadn’t reduced their bookings at Barclays by nearly as much.
In 2022, mere months into the SeatGeek contract, Abbamondi was fired. Less than a year later, Barclays announced it was going back to Ticketmaster.
Ticketmaster, in the witnesses’ telling, wasn’t the best option for a ticketing vendor, but Live Nation’s power as a concert promoter forced their hand. In the case of the Minnesota Wild, which played at the then-Xcel Energy Center in St. Paul, Helgerson said the fear of losing Live Nation shows was a large driver behind its decision to stick with Ticketmaster — even though it found it would make $1 million a year more switching to SeatGeek.
The arena was already engaged in tight competition for concerts with the Target Center across the river in Minneapolis, a similarly-sized venue. So when the Wild kicked off negotiations over renewing its contract with Ticketmaster in 2018, the ticketing service knew how to hit them where it would hurt. When the Wild staff mentioned they were planning to consider a proposal from SeatGeek too, a Ticketmaster executive told them that Live Nation could move all of their shows to the Target Center if they switched ticketing vendors, Helgerson testified. “We took it as a credible threat,” he said. “Losing those shows would be almost catastrophic to our organization.”
“We took it as a credible threat”
To ease the risk, SeatGeek offered what it called “Live Nation retaliation insurance” — a promise to compensate the arena for concerts booked at the Target Center on dates Xcel had open. SeatGeek offered the arena a higher upfront bonus and fee share that overall would make the venue an additional $1 million a year compared to Ticketmaster’s offer. But even retaliation insurance couldn’t make up for the loss of the “vibrance of the venue” and the impact on its own employees should Live Nation pull its shows. Ticketmaster’s alleged threat created an “insurmountable challenge.” The venue signed another contract with Ticketmaster.
There were complicating factors in both these cases, which Live Nation pointed out on cross-examination. It was both risky and a lot of work to move to a new ticketing platform. Like switching any enterprise software, it would take a while for staff to get up to speed, and Abbamondi admitted that while SeatGeek’s technology gave them more options over things like how to price individual seats, it was less user-friendly. An executive whom Helgerson worked with worried that SeatGeek’s lack of an interface for concert promoters at the time would be an obstacle to getting them to bring shows to the arena. Abbamondi also said he’s personal friends with SeatGeek’s co-founder, and he testified he wasn’t fired because of the SeatGeek deal — he was given two other reasons.
SeatGeek offered what it called “Live Nation retaliation insurance”
There was also a separate legal dispute between the Barclays Center and Ticketmaster, which appeared to be at least part of the reason that the call between Abbamondi and Rapino broke down. Barclays believed their contract with Ticketmaster would expire at the end of September 2021, as originally stated. But Ticketmaster believed that because the Covid pandemic shortened the regular NBA season, a clause in the contract had been triggered to extend that contract another year. On top of that, in an earlier, unrecorded call between Abbamondi and Rapino, the Ticketmaster CEO suggested that they should be given the chance to counter any offer Barclays received. Abbamondi said he tried his best to respond in a “noncommittal” way, but the implication was that Rapino might have seen it differently.
The jury will have to decide whether the threats Abbamondi and Helgerson described were really as menacing as they believe, one of many factors that will determine whether Live Nation-Ticketmaster should face penalties — including the possibility of a breakup.
In one text exchange, Live Nation executive Patti Kim, a friend of Abbamondi’s, wrote that he should “think about the bigger relationship” with Live Nation, not just who’s writing the bigger check. She added a winky face. “That was my friend saying, ‘you know what I mean,’” Abbamondi said. This week, the jury is expected to get the chance to hear from the rival allegedly offering those bigger checks: SeatGeek CEO Jack Groetzinger.
Technology
Scams that aren’t illegal (but should be)
NEWYou can now listen to Fox News articles!
Every year during National Consumer Protection Week, you hear warnings about phishing emails, fake IRS calls and identity theft. Those threats are real, but there is another risk that gets far less attention, and it is completely legal.
Right now, hundreds of companies collect, package and sell personal information, including your home address, phone number, family members, income estimates and even your daily habits. They are not targeting you because you did anything wrong. Instead, they profit simply because your data is valuable.
Unlike traditional scams, this does not happen in the shadows. It happens out in the open, every single day. As a result, most people only realize it is happening after someone uses their personal information against them.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.
Data brokers build detailed profiles using information pulled from public records, apps and online activity. (Kurt “CyberGuy” Knutsson)
Your personal information is a product
Data brokers are companies most people have never heard of, but they know a surprising amount about you. They collect information from public records, online activity, retail purchases, app usage and hundreds of other sources.
Then they build detailed profiles and sell them to advertisers, marketers and anyone else willing to pay. A typical profile may include:
- Full names, ages and phone numbers
- Home addresses
- Names of relatives and household members
- Estimated income, home value and net worth
- Shopping habits and interests
- Political, health and lifestyle indicators
This information often appears on people-search sites, where anyone can look you up in seconds. Scammers use these same databases to find and target victims. But even legitimate companies use them in ways most consumers never knowingly agreed to.
People-search sites expose more data than you realize
Search your own name online, and you may find pages listing your address, relatives’ names and contact details. These sites present themselves as “background check tools” or “public records directories.” But their business model depends on making personal information easy to find.
- That creates real-world risks. Criminals use these sites to:
- Impersonate banks, government agencies, or delivery services
- Convince victims they already “know” them
- Locate elderly or vulnerable individuals
- Target family members using shared address history.
Even strangers can learn where you live, who your relatives are and how to contact you. No hacking required.
CRIMINALS ARE USING ZILLOW TO PLAN BREAK-INS. HERE’S HOW TO REMOVE YOUR HOME IN 10 MINUTES
People-search websites make your address, phone number and even family connections easy to find in seconds. (Serene Lee/SOPA Images/LightRocket via Getty Images)
Your browsing history is being tracked and sold
Many websites and apps track what you click, read and buy. Incogni’s research found that popular apps like TikTok, Alibaba, Temu and Shein collect numerous personally identifiable data points and share them with third parties, like advertising networks and data brokers.
Even web extensions track what you do online. Popular Chrome extensions like the AI-powered Grammarly or Quillbotinvade your privacy, require extensive permissions and collect sensitive data.
Over time, this data collection builds a behavioral profile. It can reveal:
- Financial stress or debt concerns
- Health interests or medical conditions
- Major life events like moving, retirement, or the loss of a spouse
- Online purchases and brand preferences.
This is why you may suddenly receive highly specific emails, calls, or ads that feel uncomfortably personal. Someone already knew what to say.
AI is accelerating data collection
AI makes personal data more valuable and easier to collect than ever before. These systems scrape public websites, social media profiles, images and videos to pull identifying details. They also connect scattered pieces of information into a single, detailed identity profile, which can include:
- Photos connected to your name
- Voice recordings from public videos
- Employment history
- Locations you’ve lived at or visited.
Once collected, this information can circulate indefinitely. You can delete a social media post, but copies of that data may already exist elsewhere.
5 SIMPLE TECH TIPS TO IMPROVE DIGITAL PRIVACY
The more accessible your personal data is, the easier it becomes for scammers to target you with convincing, personalized attacks. (Kurt “CyberGuy” Knutsson)
Most AI companies collect data by default, unless you opt out
Are you using ChatGPT, Gemini, or even LinkedIn? Then your data is automatically collected from your chatbot conversations, posts, and more. They collect user interactions like prompts, voice recordings, uploaded photos and behavioral data to improve the AI system.
In some cases, you have to manually disable this in settings, but it’s buried in countless opt-out guides or obscure labels. For example, to opt out of LinkedIn data collection, you need to:
- Go to Settings and find the Privacy tab.
- Find the toggle named ‘Data for Generative AI Improvement.’
- Review other default data sharing options.
- Disable everything from personal demographic information to social, economic and workplace research.
AI-powered apps and services continuously switch it up and make it harder for you to opt out. Why? Your data is fueling their business model. The more data points they have, the better they can train their AI and the more money they make.
Why this matters for your safety, not just your privacy
Most people think data collection is just about targeted ads. But the same information can be used to make scams far more convincing. Instead of sending generic phishing emails, scammers can reference your real address or recent activities.
For example: “Hi, Mr. Smith, this is your bank. We noticed unusual activity on your bank account, ending in 0123. Please confirm your information.”
Because the details are accurate, the message feels legitimate. This dramatically increases the chances someone will respond. In many cases, the information came from data broker databases that were legally purchased or accessed.
Consumer protection starts with reducing your digital footprint
National Consumer Protection Week is meant to empower people to protect themselves. That protection shouldn’t stop at obvious scams. It should include limiting how easily your personal information can be found in the first place.
A data removal service helps remove your personal data from data brokers and people-search sites that collect and sell it. Instead of submitting dozens or hundreds of manual requests yourself, they automate the process and continue removing your data as it reappears.
Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.
Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.
Kurt’s key takeaways
When most people think about scams, they imagine criminals hiding in the shadows. But some of the biggest threats to your personal information are operating out in the open. Data brokers legally collect and sell detailed profiles about you. People-search sites make your address, phone number and even relatives easy to find in seconds. Your browsing activity is tracked, packaged and monetized. And now AI is speeding up how quickly that information can be gathered, connected and reused. This is not just about annoying ads. The more accessible your personal data is, the easier it becomes for scammers to sound convincing and target you with precision. Real consumer protection is not only about avoiding suspicious links. It is about limiting where your information lives and who can access it. The less strangers know about you, the harder it is to use your own data against you.
Have you ever searched for your name online and been surprised by what you found? Let us know by writing to us at Cyberguy.com.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
MacBook Neo versus an old MacBook Air: good luck
My first thought when Apple announced the MacBook Neo today was “okay, but why not just get an older Air?” If you’re thinking that too, you might be right. If you can find one.
The Neo starts at $599 with an A18 Pro processor, 8GB of memory, and 256GB storage, and ends at $699 with the same specs plus TouchID and 512GB of storage. It has two USB-C (not Thunderbolt) ports, a pretty basic-looking screen, a mechanical trackpad instead of haptic, and various other cost-saving measures. It’s the cheapest new MacBook you can get now.
The new M5 MacBook Air starts at $1,099 with 16GB of memory and 512GB of much faster storage, a bigger and brighter screen, a better webcam, better Wi-Fi and Bluetooth, more speakers, Thunderbolt 4, a faster charger, and so forth. It’s $100 more than last year’s model, probably because of the Neo. Or you can get an M4 MacBook Air for $1000, with a slightly slower processor than the M5 (but still faster than the Air), and otherwise pretty much the same specs.
If you could still get a new M1 Air from Walmart for $700, it’d be a pretty tough call between that and the Neo. That machine came out in 2020, but is still better in most respects. Unfortunately, they’ve been out of stock since last month — probably because of the Neo — so that’s the end of that. You can probably find a refurb one. Same with the M3 and M4: if you can find one for around the same price as the Neo, especially with 16GB of RAM, you should get one of those. But they’re pretty thin on the ground, and I’d expect them to become thinner. (Keep an eye on Apple’s refurb site, though — a refurb M4 Air for $750 is pretty dang good.)
The modern Air is unquestionably a better computer. The thing about $1,000 is it’s a lot more money than $600. $600 is already more than most non-Mac people want to spend on a laptop, but it’s a lot less than an Air, and the gap between the two is big enough that it’s harder to justify the jump unless you know you’re gonna need more than 8GB of RAM, if you’re ever gonna use Thunderbolt, and so forth. I wouldn’t buy the Neo for myself.
The Neo isn’t meant to compete with the Air, though. It’s aiming for the first-time MacBook buyer. It’s Apple trying to pick up the cheap Windows laptop crowd who are annoyed by Windows. With its $499 price for education, it’s also an attempt to break the Chromebook’s stranglehold on the K-12 market, to turn iPad kids into MacBook Neo teens into Air adults. Heck, when it’s time for my kids to turn in their school-issued Chromebooks, and I have to choose between a Chromebook, a Windows laptop, and a MacBook Neo for them? That’ll be interesting.
And that’s how they get you!
I honestly don’t think the Neo vs Air debate is going to be that hard for most people, just because most people aren’t spending a thousand bucks on a laptop in the first place. The processor’s probably going to feel about the same as an M1 Air’s, which is to say fast enough for most things. The toughest parts are going to be figuring out if you’re satisfied with 8GB of RAM (rough!), if you ever really need Thunderbolt (maybe not?), and if you care about that fancy webcam (eh). If you already know the answer, you already know the answer. And you should probably grab that refurb Air while you can.
A cynical part of me thinks this is Apple trying to get MacBooks onto the same upgrade cycle as its phones. If you bought the cheapest MacBook Air six years ago, it’s probably still fine. If you buy the cheapest MacBook Neo today, is it going to feel fine in six years? Maybe! Or maybe you’ll decide you need to spring for an Air next time. And up the funnel you go.
-
World1 week agoExclusive: DeepSeek withholds latest AI model from US chipmakers including Nvidia, sources say
-
Massachusetts1 week agoMother and daughter injured in Taunton house explosion
-
Wisconsin3 days agoSetting sail on iceboats across a frozen lake in Wisconsin
-
Maryland4 days agoAM showers Sunday in Maryland
-
Florida4 days agoFlorida man rescued after being stuck in shoulder-deep mud for days
-
Denver, CO1 week ago10 acres charred, 5 injured in Thornton grass fire, evacuation orders lifted
-
Massachusetts2 days agoMassachusetts man awaits word from family in Iran after attacks
-
Oregon6 days ago2026 OSAA Oregon Wrestling State Championship Results And Brackets – FloWrestling