Technology
Figure data breach exposes nearly 1M accounts
Cyber expert shares tips to avoid AI phishing scams
Kurt ‘The CyberGuy’ Knutsson shares practical ways to avoid falling victim to AI-generated phishing scams and discusses a report that North Korean agents are posing as I.T. workers to funnel money into the country’s nuclear program.
NEWYou can now listen to Fox News articles!
If you have applied for a loan online, you probably shared more than you realized. Your name. Your email. Your date of birth. Maybe even your home address and phone number. Now imagine all of that sitting on a dark web forum.
That is the reality for nearly 1 million people after hackers breached Figure Technology Solutions, a blockchain-focused fintech lender.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.
What happened in the Figure data breach
Figure Technology Solutions, founded in 2018, uses the Provenance blockchain for lending, borrowing and securities trading. The company says it has unlocked more than $22 billion in home equity through partnerships with banks, credit unions, fintechs and home improvement companies. However, behind the scenes, attackers were working on a very different angle.
GOOGLE DROPPED DARK WEB MONITORING: SHOULD YOU CARE?
Nearly 1 million accounts were exposed after hackers breached fintech lender Figure Technology Solutions in a social engineering attack. (Felix Zahn/Photothek via Getty Images)
According to breach notification data shared by Have I Been Pwned, information from 967,200 accounts was exposed. The leaked data included more than 900,000 unique email addresses along with names, phone numbers, physical addresses and dates of birth. That is a gold mine for identity thieves. Figure says the incident stemmed from a social engineering attack. What that means in simple terms is that someone inside the company was tricked into handing over access.
“We recently identified that an employee was socially engineered, and that allowed an actor to download a limited number of files through their account,” a Figure Technology Solutions spokesperson told CyberGuy in a statement. “We acted quickly to block the activity and retained a forensic firm to investigate what files were affected. We understand the importance of these matters and are communicating with partners and those impacted as appropriate. We are also implementing additional safeguards and training to further strengthen our defenses. We are offering complimentary credit monitoring to all individuals who receive a notice. We continuously monitor accounts and have strong safeguards in place to protect customers’ funds and accounts.”
Social engineering is the real weapon
When people hear the word blockchain, they think secure and untouchable. But attackers did not break cryptography. They targeted a human being. Groups like ShinyHunters specialize in this playbook. They reportedly claimed responsibility for the breach and, according to BleepingComputer, posted 2.5GB of data allegedly tied to thousands of loan applicants.
In recent weeks, the same group has claimed breaches involving companies like Canada Goose, Panera Bread and SoundCloud. Not every case is connected. Still, security researchers have observed a troubling pattern. Attackers impersonate IT support. They call employees. They create urgency. Then they direct victims to fake login portals that look nearly identical to real ones.
Once employees enter credentials and even multi-factor authentication codes, attackers gain access to single sign-on systems tied to major platforms like Microsoft and Google. From there, one compromised account can unlock a web of connected tools and internal systems.
PANERA BREAD DATA BREACH EXPOSES 5.1M CUSTOMERS
Security researchers say the Figure data leak underscores how social engineering bypasses even blockchain-based platforms. (Maxim Konankov/NurPhoto via Getty Images)
Why this matters to you
If your information was part of the Figure data breach, criminals now have enough detail to craft convincing phishing emails or phone scams. They can reference your real name. They can cite your address. They can pretend to be a lender or bank calling about your application.
Even if you never applied for a loan with Figure, this incident highlights something bigger. No platform is immune to human error. And social engineering works because it targets trust, not technology.
The bigger lesson about blockchain and trust
Figure markets itself as blockchain native. Blockchain can provide transparency and strong cryptographic security. However, none of that protects against a well-crafted phone call.
Security failures often happen at the human layer. That is where attackers focus their energy. As more financial services move online, the attack surface grows. Loan applications, identity verification tools and cloud-based systems create convenience. They also create new targets.
How to protect yourself after the Figure data breach
You cannot control how companies secure their systems. You can control how you respond. Start by checking whether your email address appears in the exposed dataset, then take the steps below to lock down your accounts.
SUBSTACK DATA BREACH EXPOSES EMAILS AND PHONE NUMBERS
Figure says an employee was tricked into granting access, allowing attackers to download sensitive customer data. (Luke MacGregor/Bloomberg via Getty Images)
Check if your email was exposed
To see if your email address was affected, visit https://haveibeenpwned.com/. Enter your email address to find out whether your information appears in the leak. When finished, return here and begin Step 1 below.
Take these steps immediately
- Change any exposed passwords right away. Do not leave a known leaked password in place. Update it everywhere you used it. Use a password manager to create strong, unique passwords for every account. Check out the best expert-reviewed password managers of 2026 at Cyberguy.com
- Turn on multi-factor authentication wherever possible.
- Never share login codes with anyone, even if they claim to be IT support.
- Install strong antivirus software to help block phishing links, malicious downloads and ransomware that often follow major breaches. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.
- Consider a data removal service to reduce your personal information on data broker sites, which scammers often combine with breached data. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.
- Place a free fraud alert or credit freeze with the major credit bureaus.
- Monitor your bank and credit card statements weekly for suspicious activity.
Also, be cautious of unexpected calls about your accounts. If someone pressures you to act immediately, hang up and call the company directly using a number from its official website.
Kurt’s key takeaways
The Figure data breach is a reminder that technology alone cannot protect sensitive information. A single employee tricked into revealing credentials can expose hundreds of thousands of people. That is not a blockchain failure. It is a trust failure. If your data was involved, take action now. Even if it was not, treat this as a wake-up call. Your personal information has value. Criminals know it. Companies should know it too.
If one phone call can unlock nearly a million records, are companies investing enough in training people, or are they still betting everything on technology alone? Let us know by writing to us at Cyberguy.com
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Snap, YouTube, and TikTok settle suit over harm to students
Snap, YouTube, and TikTok have settled the first lawsuit of its kind, alleging that social media addiction has cost public schools massive amounts of money, according to Bloomberg. The suit, filed by the Breathitt County School District in Kentucky, claims that social media has disrupted learning and created a mental health crisis, straining budgets. The terms of the settlement have not been revealed yet, and Meta is still facing a trial in the same suit, which is viewed as a bellwether for over 1,000 similar lawsuits across the country
This follows an earlier case, settled by Snap and TikTok, in which a 19-year-old plaintiff claimed significant personal injury due to addictive social media apps. Google and Meta did not agree to a settlement in that suit, and it eventually went to trial, where a jury awarded the plaintiff $6 million. Meta also recently lost a suit brought by New Mexico’s Attorney General, to the tune of $375 million.
Beyond monetary awards, many, including New Mexico, are pushing for significant changes to social media apps to limit their harm to minors. And this is just the start of what’s shaping up to be a busy year for social media lawsuits. According to Bloomberg, lawyers representing school districts said their “focus remains on pursuing justice for the remaining 1,200 school districts who have filed cases.”
Technology
Missed voicemails with no calls? It could be a scam
NEWYou can now listen to Fox News articles!
It starts quietly. Your phone buzzes. You see a voicemail notification. But your phone never rang. Then it happens again. And again. Before long, your voicemail inbox looks like it’s under attack.
That’s exactly what Mike from Westport, CT, is dealing with right now. He wrote to us saying,
“I am so upset. Every 20 to 30 minutes, I am getting voicemails, but what’s weird is my phone never rings. After blocking the number, it just rolls over to a new source number. When I go to play the message, there is no audio. Is this a scammer just trying to get me to call them back? Not sure what the endgame is here. What can I do to stop this from happening? I really appreciate your help.”
What he is describing is something we’re seeing more often. It may feel random, but there’s a clear pattern behind this voicemail scam and here’s what you need to know to stay safe.
RECEIVING UNEXPECTED INTERNATIONAL CALLS? WHAT YOU NEED TO KNOW
Silent voicemail scams can flood a phone with blank messages even when the device never rings. (Getty Images)
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
What the silent voicemail scam actually is
This tactic is often called a silent voicemail scam or ringless voicemail spam. Here’s how it works in plain terms:
- Scammers drop voicemail messages directly into your inbox
- Your phone never rings, so it feels strange and urgent
- The message is blank, garbled or extremely short
- The number changes constantly to avoid blocks
At first glance, it looks like a glitch. That confusion is the point.
What’s really happening behind the scenes
This pattern almost always points to automated robocall systems using caller ID spoofing, not real people manually calling you.
Here’s what’s likely happening:
- Automated dialing systems are repeatedly hitting your number
- They use spoofed or constantly changing caller IDs, which is why blocking one number doesn’t stop it
- Some calls connect briefly, then drop, leaving behind a silent or very short voicemail
- In some cases, the system is “pinging” your number to confirm it’s active
Once a number is confirmed as active, it can be shared across spam networks and used in future campaigns.
Why scammers leave empty voicemails
It seems pointless, but there’s a strategy behind it.
1) They want you to call back
Curiosity does the work for them. Many people return the call just to figure out what happened. When you call back, you may:
- Reach a premium-rate number that charges per minute
- Get routed into a scam call center
- Confirm your number is active and monitored
2) They test if your number is real
Even if you never call back, your voicemail confirms your number is in use. That makes it more valuable for future scams.
3) They try to bypass spam filters
Because your phone never rings, traditional call filters may not catch it. That lets more of these messages slip through.
Why do the numbers keep changing
You block one number, and another appears minutes later. That’s usually a sign of caller ID spoofing and number cycling. Scammers use software to falsify the number that shows up on your phone and rotate through large batches of numbers to stay ahead of blocks and spam filters. Some of those numbers may be completely fabricated, while others may belong to real people whose caller ID information is being misused. Many of those numbers are:
- Fake
- Reassigned or temporarily used
- Tied to real people who have no idea their number is being spoofed
Blocking a single number can still be worth doing, but it usually will not stop the campaign by itself because the caller can keep switching numbers.
GOOGLE SEARCH LED TO A COSTLY SCAM CALL
Scammers may use ringless voicemail spam and caller ID spoofing to test whether a phone number is active. (Getty Images)
Is your phone being hacked?
This is one of the first things many people worry about. In most cases, no. These silent voicemails are more likely to be part of a scam call or robocall campaign than a sign that your phone has been hacked. Scammers can use tactics such as caller ID spoofing and ringless voicemail to reach you without making the call feel normal.
The bigger risk isn’t your phone itself. It’s how the scam tries to get you to respond. Calling back, pressing prompts or engaging with the message can confirm that your number is active and may expose you to more scam attempts. The FTC specifically advises people to hang up or delete the voicemail and not call back unknown numbers.
How to stop silent voicemail scams
You don’t have to just put up with it. There are ways to reduce or stop these messages.
1) Do not call back unknown numbers
Even if it feels harmless, skip it. If it’s important, the caller will leave a real message.
2) Enable spam call filtering
On iPhone and Android, turn on built-in call filtering and silence unknown callers. This helps reduce future attempts.
How to enable spam call filtering
On iPhone (latest iOS)
Apple now gives you two strong options: Silence Unknown Callers and Call Screening.
Option 1: Silence unknown callers
- Open Settings
- Tap Apps
- Tap Phone
- Scroll down and turn on Unknown Callers
This sends calls from numbers not in your contacts straight to voicemail without ringing.
Option 2: Turn on Call Screening (recommended)
- Open Settings
- Tap Apps
- Tap Phone
- Scroll down and under Screen Unknown Callers, select Ask Reason for Calling
This feature prompts unknown callers to say who they are before your phone rings, which filters out many spam calls automatically.
Optional: Enable spam identification
- Go to Settings
- Tap Apps
- Tap Phone
- Tap Call Blocking & Identification
- Tap Business Call Identification
- Make sure it is set to ON
This allows your iPhone to show verified business names and logos for legitimate callers when available.
On Samsung
Samsung combines spam protection with AI call screening.
Settings and feature names may vary depending on your Samsung model, carrier and software version.
Option 1: Turn on spam protection
- Open the Phone app
- Tap the three-dot menu (top right)
- Tap Settings
- Tap Caller ID and spam protection
- Toggle it ON
This flags suspected spam calls before you answer.
Option 2: Block unknown callers
- Open the Phone app
- Tap the three-dot menu (top right)
- Tap Settings
- Tap Block numbers
- Turn on Block calls from unknown numbers
This stops hidden or unidentified numbers from ringing your phone.
Option 3: Enable Call Screen (best option)
- Open the Phone app
- Tap the three-dot menu (top right)
- Tap Settings
- Tap Bixby Text Call or just Text Call
- Toggle it ON
This lets your phone answer unknown calls with AI and show you what the caller says in real time.
One important reality check: Even with these turned on, some calls may still go to voicemail. That’s because voicemail is controlled by your carrier, not your phone.
HOW TO STOP SPAM MAIL, POLITICAL TEXTS AND EMAIL SPAM FOR GOOD
Unknown voicemail messages that contain no audio may be part of an automated robocall campaign. (Kurt “CyberGuy” Knutsson)
3) Use a call-blocking app
Apps can spot patterns faster than manual blocking and stop repeat offenders. Many of these apps can also identify known scam numbers and automatically block high-risk calls, helping reduce how often your phone gets hit.
4) Contact your carrier
Many carriers offer network-level spam blocking. Ask about tools that block ringless voicemail or robocalls.
5) Use a data removal service
If your number keeps getting hit, it may already be circulating on marketing lists or data broker sites. These data removal services scan for your personal information and help remove it from databases that scammers often tap into. Cutting down where your number appears can reduce how often you get targeted over time. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com
6) Report the activity
You can report unwanted calls and voicemails to the Federal Trade Commission at reportfraud.ftc.gov or by calling 1-877-FTC-HELP (1-877-382-4357). Reports help track and shut down large scam campaigns.
7) Protect your number going forward
Avoid posting your phone number publicly. The less exposure it has, the harder it is for scammers to target you.
8) Register your phone number on the National Do Not Call Registry at donotcall.gov/
This can help reduce telemarketing calls from legitimate businesses, but it unfortunately won’t stop scammers, illegal robocalls, or exempt organizations (like charities and political groups) from calling you. Scammers often ignore the registry and use tactics like number spoofing to bypass it. Want to know more about why your phone still won’t stop ringing and what you can do about it? Check out our article on the ‘Do Not Call’ list loophole.
Kurt’s key takeaways
Silent voicemails are designed to mess with your instincts. They rely on curiosity and confusion, not sophisticated hacking. The best move is simple. Don’t engage. Let them hit a dead end. Over time, that tells the system your number isn’t worth the effort.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
So here’s the real question: If scammers are counting on curiosity to hook you, how often do you think that instinct is working on other people right now? Let us know by writing to us at Cyberguy.com
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Xbox is now XBOX
Xbox just allcapsmaxxed: Meet XBOX. This isn’t a joke; Microsoft appears to be actually rebranding Xbox to XBOX. Asha Sharma, Xbox CEO, ran a poll on X earlier this week, asking fans whether Microsoft should use Xbox or XBOX. The results were in favor of XBOX, and the company has now renamed its X account.
Curiously, the Threads and Bluesky accounts for Xbox haven’t been renamed yet, but if Microsoft is going ahead with a rebranding then I expect those will change soon. I asked Microsoft to comment on this potential Xbox rebranding and the company simply referred me to Sharma’s post.
The use of all caps for Xbox is a return to original form, though. Microsoft’s first Xbox logo for its console was all caps, and the company has favored using similar capped versions for the Xbox 360, Xbox One, and Xbox Series X / S console logos.
The apparent rebranding comes just a few weeks after Sharma scrapped Microsoft Gaming and renamed Microsoft’s gaming division back to Xbox. It’s part of Sharma’s continued promise of a “return of Xbox,” which has involved fan-focused console updates, a new Xbox logo, Game Pass pricing changes, and lots more in recent weeks.
-
Ohio2 minutes agoOhio Highway Patrol investigating fatal head-on crash on U.S. Route 62
-
Oklahoma8 minutes agoOklahoma ‘Getting Gritty’ After SEC Tournament Loss
-
Oregon14 minutes agoRecall issued for organic ice cream sold in Oregon over metal concerns
-
Pennsylvania20 minutes agoSen. McCormick tours NSF-funded AI-powered biotech labs at Penn
-
Rhode Island26 minutes agoWhat to expect at Roger Wheeler and Misquamicut beaches this summer
-
South-Carolina32 minutes agoSouth Carolina lands commitment from big transfer portal offensive lineman
-
South Dakota38 minutes agoFact brief: Was an east-west split of Dakota Territory considered?
-
Tennessee44 minutes agoTennessee man arrested after kidnapping his two grandchildren