2026 Social engineering breach — 2M+ records
Data compromised
Names, email addresses, job titles, contracts, executive contacts, partner lists
Technical writeup
Crunchbase confirmed a data breach in January 2026. Attackers used voice phishing (vishing) to trick employees into providing SSO credentials. Part of coordinated campaign targeting Okta/Microsoft Entra/Google customers. ShinyHunters leaked ~400MB of data after ransom refused. Exposed: PII, signed contracts, executive contacts, partner lists.
Root cause
Voice phishing (vishing); social engineering; SSO credential compromise.