2025 Database intrusion — 17.6M records
Data compromised
Names, SSNs, dates of birth, addresses, email, government IDs, employment data, income, bank account numbers, driver's license numbers, tax information
Technical writeup
Unauthorized access to Prosper's databases between June and August 2025. Attackers issued unauthorized queries to extract customer data in a 'quiet database intrusion' that did not disrupt customer-facing services. Data compromised included SSNs, bank account numbers, driver's license numbers, and tax information. Prosper offered two years of credit monitoring through Experian.
Root cause
Unauthorized database access; direct data extraction via queries.