
AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.
Crunchbase says a threat actor exfiltrated documents from its corporate network. ShinyHunters claims over 2 million records and published an archive after an extortion demand went unpaid.
What happened
Crunchbase, the company-data platform, confirmed on 26 January 2026 that "a threat actor exfiltrated certain documents from our corporate network". It said business operations were not disrupted, the incident was contained, and it had brought in outside cybersecurity experts and contacted US federal law enforcement. It is reviewing the affected information to decide what notifications the law requires.
The confirmation came after ShinyHunters, a financially motivated extortion group active since 2020, posted Crunchbase files on its leak site.
Confirmed vs. claimed
Confirmed by Crunchbase: documents were taken from its corporate network. It has not said how many people are affected or which data types were involved.
Claimed by ShinyHunters: more than 2 million records containing personal information, released as a compressed archive of roughly 400 MB after Crunchbase did not pay. According to SecurityWeek, threat intelligence firm Hudson Rock found the files included personal information, contracts and corporate data. Hudson Rock also said ShinyHunters claims to be behind a voice-phishing campaign against Okta single sign-on (SSO) accounts at the companies involved; Crunchbase has not said how the attacker got in.
Who is affected
People whose details appear in Crunchbase's internal documents and contracts, such as customers, partners and staff. SoundCloud and Betterment disclosed separate incidents around the same time that SecurityWeek grouped with this campaign.
What to do
- If you have a commercial relationship with Crunchbase, watch for its notification and for invoice or contract fraud using real details.
- If you receive an extortion email referencing this data, do not reply or pay; read our guide to ShinyHunters extortion emails.
- Security teams: help desks and staff should never approve MFA (multi-factor authentication) prompts or SSO changes requested by phone; verify callers through a known number.
Sources
More breaches in United States
- IDScan.net — 01 Sep 2026
- Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) — 27 Aug 2026
- Boston Scientific — 26 Aug 2026
- Aesto Health — 14 Aug 2026
- DentaQuest — 17 Jul 2026