Crunchbase Confirms Breach After ShinyHunters Publishes Stolen Files

Voice phishing campaigns targeting single sign-on accounts can bypass typical security controls and expose corporate data.

Illustration: Crunchbase Confirms Breach After ShinyHunters Publishes Stolen Files
AI-generated illustration · Sylvaris

Data Posted After Failed Extortion

On January 26, 2026, Crunchbase confirmed a cybersecurity incident after the ShinyHunters crime group published approximately 400 MB of compressed files on its dark web site. The group claimed to have stolen more than 2 million records, including personally identifiable information, signed contracts, and internal corporate documents.

Crunchbase told SecurityWeek that it detected the incident, engaged cybersecurity experts, and contacted federal law enforcement. The company said business operations were not disrupted and that it is reviewing the data to determine notification requirements under applicable laws.

Voice Phishing and SSO Compromise

Researchers at Hudson Rock and other threat intelligence firms linked the attack to a broader ShinyHunters campaign targeting Okta single sign-on credentials through voice phishing, also known as vishing. The technique involves impersonating IT support to trick employees into providing login credentials and bypassing multi-factor authentication.

The same campaign reportedly affected SoundCloud, which disclosed a breach in mid-December affecting roughly 20 percent of users, and investment firm Betterment, which said attackers used social engineering to send scam messages to customers. Okta issued a private warning to customers and published guidance on phishing kits designed for vishing attacks.

ShinyHunters Track Record

ShinyHunters has operated since around 2020 and is known for large-scale data theft followed by extortion or public leaks. The group has been linked to breaches involving major organizations and often refuses to negotiate, instead publishing stolen data when ransom demands are not met.

For organizations relying on single sign-on systems, the incident underscores the risk that credential theft through social engineering can provide access to corporate networks even when other security controls are in place. Experts recommend phishing-resistant authentication methods, including hardware security keys and passkeys, as stronger alternatives to SMS-based or app-based one-time passwords.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.