Crunchbase Confirms Breach After ShinyHunters Publishes Stolen Files
Voice phishing campaigns targeting single sign-on accounts can bypass typical security controls and expose corporate data.
Data Posted After Failed Extortion
On January 26, 2026, Crunchbase confirmed a cybersecurity incident after the ShinyHunters crime group published approximately 400 MB of compressed files on its dark web site. The group claimed to have stolen more than 2 million records, including personally identifiable information, signed contracts, and internal corporate documents.
Crunchbase told SecurityWeek that it detected the incident, engaged cybersecurity experts, and contacted federal law enforcement. The company said business operations were not disrupted and that it is reviewing the data to determine notification requirements under applicable laws.
Voice Phishing and SSO Compromise
Researchers at Hudson Rock and other threat intelligence firms linked the attack to a broader ShinyHunters campaign targeting Okta single sign-on credentials through voice phishing, also known as vishing. The technique involves impersonating IT support to trick employees into providing login credentials and bypassing multi-factor authentication.
The same campaign reportedly affected SoundCloud, which disclosed a breach in mid-December affecting roughly 20 percent of users, and investment firm Betterment, which said attackers used social engineering to send scam messages to customers. Okta issued a private warning to customers and published guidance on phishing kits designed for vishing attacks.
ShinyHunters Track Record
ShinyHunters has operated since around 2020 and is known for large-scale data theft followed by extortion or public leaks. The group has been linked to breaches involving major organizations and often refuses to negotiate, instead publishing stolen data when ransom demands are not met.
For organizations relying on single sign-on systems, the incident underscores the risk that credential theft through social engineering can provide access to corporate networks even when other security controls are in place. Experts recommend phishing-resistant authentication methods, including hardware security keys and passkeys, as stronger alternatives to SMS-based or app-based one-time passwords.