← Crunchbase

2026 Social engineering breach — 2M+ records

2026 2.0M records affected Share on X

Data compromised

Names, email addresses, job titles, contracts, executive contacts, partner lists

Technical writeup

Crunchbase confirmed a data breach in January 2026. Attackers used voice phishing (vishing) to trick employees into providing SSO credentials. Part of coordinated campaign targeting Okta/Microsoft Entra/Google customers. ShinyHunters leaked ~400MB of data after ransom refused. Exposed: PII, signed contracts, executive contacts, partner lists.

Root cause

Voice phishing (vishing); social engineering; SSO credential compromise.

References