[News](/news)

Crunchbase Suffers Breach According to Dark Web Reports

[Blog](/blog)[Breaches](/breaches)[Resources](/resources)[News](/news)

# Crunchbase Suffers Breach According to Dark Web Reports

##### [UpGuard Team](/team/upguard)

January 26, 2026

### Key facts: Crunchbase data breach

* **Date reported**: January 24, 2026 (confirmed January 26, 2026).
* **Threat actor**: ShinyHunters (attributed to the "Scattered LAPSUS$ Hunters" collective).
* **Records exposed**: Over 2 million records.
* **Data volume**: Approximately 402MB of compressed files.
* **Data types**: Personally Identifiable Information (PII), signed corporate contracts, internal documents, and corporate data.
* **Attack method**: Voice phishing (vishing) targeting Okta single sign-on (SSO) credentials to bypass multi-factor authentication.
* **Status**: Data was leaked on a Tor-based site after a failed ransom extortion attempt.

### What happened in the Crunchbase data breach?

Crunchbase (crunchbase.com) was the subject of a security incident reported on January 24, 2026, and officially [confirmed by the company on January 26](https://www.securityweek.com/crunchbase-confirms-data-breach-after-hacking-claims/). The incident was part of a larger campaign by the notorious cybercrime group ShinyHunters, which also targeted other major platforms like SoundCloud and Betterment.

The hackers reportedly gained initial access to Crunchbase’s corporate network through a sophisticated social engineering attack known as voice phishing. By impersonating IT support, the attackers tricked employees into providing their Okta SSO credentials via a real-time phishing kit, allowing the group to bypass standard security controls. Once inside, they exfiltrated approximately 400MB of sensitive data. After Crunchbase refused to pay a ransom demand, ShinyHunters published the stolen archives on their data leak site.

### Who is behind the incident?

The threat actor group ShinyHunters has claimed responsibility for this incident. Operating as the public-facing entity for a collective known as Scattered LAPSUS$ Hunters, this group is infamous for targeting high-value technology and financial organizations. Their recent 2026 campaign has focused on identity-based attacks, leveraging custom phishing kits and voice-based social engineering to compromise organizations that use centralized identity providers like Okta, Microsoft Entra, and Google.

### Impact and risks for Crunchbase customers

The exposure of over 2 million records poses several risks to Crunchbase users and corporate partners. The stolen data includes personally identifiable information (PII) such as names and email addresses, as well as highly sensitive corporate documents and signed contracts.

Typical outcomes of such data exposures include targeted phishing and business email compromise (BEC). Because the leak includes internal business details and contracts, malicious actors could craft extremely convincing fraudulent communications to target Crunchbase’s partners or employees. While Crunchbase stated that business operations were not disrupted, the public availability of these documents necessitates long-term vigilance regarding corporate identity and data privacy.

## Frequently asked questions

### What happened in the Crunchbase security breach?

In January 2026, the ShinyHunters group breached Crunchbase (crunchbase.com) by using voice phishing to steal employee SSO credentials. After the company refused to pay an extortion demand, the hackers leaked a 400MB archive containing over 2 million records, including internal contracts and personal user data.

### When did the Crunchbase breach occur?

While the data leak was publicly identified on January 24, 2026, the intrusion is believed to be part of a broader social engineering campaign that targeted Okta environments throughout December 2025 and early January 2026.

### What data was exposed?

The types of data involved in the Crunchbase incident include names, email addresses, and other personal identifiers. Crucially, the leak also contained sensitive corporate information, such as signed business contracts and internal documents exfiltrated from the company’s corporate network.

### Is my personal information at risk?

If you have a Crunchbase account or your company has entered into contracts with the platform, your data may have been included in the leak. Given the nature of the stolen documents, there is a risk of highly targeted phishing. You should remain vigilant and watch for official notifications from Crunchbase regarding your specific data status.

### How can I protect myself after the Crunchbase data breach?

* Update your Crunchbase password and any other accounts that share the same credentials.
* Enable multi-factor authentication (MFA) on all sensitive accounts, preferably using phishing-resistant methods like hardware keys.
* Monitor your bank statements and credit reports for any unauthorized transactions.
* Be cautious of unsolicited emails or phone calls, especially those appearing to come from IT support or corporate partners.
* Use a data breach monitoring service to track potential exposures of your information.

### What steps should companies take after being impacted by the Crunchbase data breach?

Organizations should respond by securing their systems, rotating compromised credentials, and notifying affected individuals as required by law. Crunchbase has engaged cybersecurity experts and federal law enforcement to investigate the scope of the exfiltration. If the breach is proven to be of more significant severity, the company should release a statement with recommended response actions.

## How secure is Crunchbase?

Crunchbase operates a business intelligence platform that provides data and insights on private and public companies, funding rounds, investments, and market activity. The platform aggregates information on organizations, investors, and industry trends to support business development, sales prospecting, and investment research.

* View our free preliminary report on Crunchbase’s security posture
* 13 risk factors, including email security, SSL, DNS health, open ports and common vulnerabilities

[View Crunchbase's score](/security-report/crunchbase-com)

[View score](/security-report/crunchbase-com)

[https://www.crunchbase.com](/security-report/crunchbase-com)

### Sign up for our newsletter

UpGuard's monthly newsletter cuts through the noise and brings you what matters most: our breaking research, in-depth analysis of emerging threats, and actionable strategic insights.

## Latest news

Stay up-to-date with the latest news in cybersecurity.

[](/news/hugging-face-data-breach-2026-07-20)

#### [Hugging Face data breach: key facts and what we know so far](/news/hugging-face-data-breach-2026-07-20)

A data breach involving Hugging Face was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [UpGuard Team](/team/upguard)

July 20, 2026

[](/news/ey-data-breach-2026-07-19)

#### [EY data breach: what happened and what's at risk](/news/ey-data-breach-2026-07-19)

A data breach involving EY was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [UpGuard Team](/team/upguard)

July 15, 2026

[](/news/south-florida-injury-convenient-care-data-breach-2026-07-16)

#### [South Florida Injury & Convenient Care data breach exposes names and Social Security numbers](/news/south-florida-injury-convenient-care-data-breach-2026-07-16)

A data breach involving South Florida Injury & Convenient Care was reported in July 2026. See incident details, impact on customers, and security measures.

##### [UpGuard Team](/team/upguard)

July 15, 2026

[](/news/park-west-psychology-data-breach-2026-07-16)

#### [Park West Psychology data breach: what happened and what's at risk](/news/park-west-psychology-data-breach-2026-07-16)

A data breach involving Park West Psychology was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [UpGuard Team](/team/upguard)

July 15, 2026

[](/news/fall-river-municipal-credit-union-data-breach-2026-07-16)

#### [Fall River Municipal Credit Union data breach: what happened and what's at risk](/news/fall-river-municipal-credit-union-data-breach-2026-07-16)

A data breach involving Fall River Municipal Credit Union was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [](#)

July 14, 2026

[](/news/npcil-data-breach-2026-07-16)

#### [NPCIL data breach: World Leaks claims exposure of Kudankulam Nuclear Power Plant files](/news/npcil-data-breach-2026-07-16)

A data breach involving NPCIL was reported in July 2026. See incident details, impact on customers, and recommended security measures.

##### [UpGuard Team](/team/upguard)

July 14, 2026

[View all news](/news)

## Protect your organization

Get in touch or book a free demo.

[Contact sales](/demo)

[Free demo](/demo)

##### Free instant security score

## How secure is your organization?

Request a free cybersecurity report to discover key risks on your website, email, network, and brand.

* Instant insights you can act on immediately
* Hundreds of risk factors including email security, SSL, DNS health, open ports and common vulnerabilities

[Free score](/instant-security-score)
