If you had a Crunchbase account, act now: change your Crunchbase password and any password you reused elsewhere, enable 2FA on your email and work accounts, watch for targeted phishing referencing your job title and company, treat any "investor outreach" or "partnership" email with extreme suspicion, and remove your personal information from data broker sites so attackers can't combine the leak with your home address and phone number.
What Happened in the Crunchbase Breach
Crunchbase confirmed a data breach in 2026 after the cybercrime group ShinyHunters published a 402 MB archive containing more than 2 million records claimed to have been stolen from Crunchbase. The dump appeared on the group's Tor leak site after an alleged extortion attempt failed.
According to samples reviewed by security researchers, the leaked data includes:
- Full names
- Contact information (email addresses, phone numbers)
- Physical addresses
- Job data — role, company, industry
- Business contracts between Crunchbase and partner firms
- Internal documents detailing business operations
Crunchbase notified federal authorities and states that operations weren't affected and the breach is contained. That doesn't help users whose data is already in the wild.
Why This Breach Is Different
Most consumer breaches leak email/password combos. The Crunchbase dump is a professional Rolodex: names, job titles, employers, contact info, and business relationships. That's the exact ammunition needed for high-quality spear-phishing, BEC (business email compromise), and impersonation scams targeting investors, founders, and executives.
Who's Most at Risk
Because Crunchbase's user base skews toward VCs, founders, sales professionals, journalists, and corporate researchers, the highest-risk targets are:
- Startup founders and executives
- Venture capital and private equity investors
- Sales and business development professionals
- Journalists and analysts covering tech/finance
- Anyone with a public Crunchbase profile linked to a business
Step 1: Change Your Crunchbase Password
Log in to Crunchbase and change your password immediately. Use a strong, unique password generated by a password manager (1Password, Bitwarden, or your browser's built-in manager). If Crunchbase forces a password reset via email, verify the reset link goes to a real crunchbase.com URL before clicking.
Step 2: Change Any Reused Passwords
If you used your Crunchbase password anywhere else — your work email, LinkedIn, Salesforce, HubSpot, Slack, banking apps — change those too. Password reuse is how one breach becomes ten.
Step 3: Enable Two-Factor Authentication
Turn on 2FA on every important account, especially:
- Your work email
- Your personal email
- Salesforce, HubSpot, and any CRM tied to your Crunchbase login
- Slack, Microsoft 365, and Google Workspace
- Banking and investment accounts
Prefer authenticator apps or hardware keys (YubiKey) over SMS 2FA, which is vulnerable to SIM-swap attacks made easier by the leaked contact data.
Step 4: Watch for Targeted Phishing and BEC
Attackers use professional data to craft convincing spear-phishing. Expect emails and LinkedIn messages that:
- Reference your job title, company, and recent funding rounds
- Impersonate real investors, portfolio companies, or partners
- Pose as "Crunchbase Security" and ask you to verify your account
- Offer "partnership opportunities" with malicious PDF attachments
- Ask for wire transfers using CFO or founder impersonation
Verify any unusual financial request via a second channel — call the person on a known number, not the number in the email.
Is your data already out there?
Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.
Run a free scan★★★★★ 4.8/5 · Trusted by thousands of families
Step 5: Review Your Public Crunchbase Profile
Log in to Crunchbase and audit what's visible on your profile. Consider removing or hiding:
- Your personal phone number
- Your personal email (use a work-only alias instead)
- Your home city if it's more specific than "San Francisco Bay Area"
- Any board seats, angel investments, or affiliations you'd rather not have targeted
Step 6: Monitor Financial Accounts
Review the last 90 days of transactions on personal and business accounts. Look for small "test" charges, new payees, unfamiliar ACH transfers, and any activity you didn't authorize. For business accounts, verify that your accounting or payments team hasn't changed any vendor payment details without an out-of-band confirmation.
The Cross-Reference Attack
Attackers combine the Crunchbase leak with public data broker profiles — your home address, personal phone, relatives, past addresses — to build convincing pretexts for social engineering. Removing your personal data from broker sites breaks that chain and dramatically reduces attack quality.
Step 7: Remove Your Data From Broker Sites
People-search sites and data brokers publish your home address, personal cell, age, and family members. Combined with a leaked Crunchbase profile, an attacker has everything needed for a convincing pretext call, SIM swap, or physical stalking.
PrivacyOn removes your personal information from 100+ data broker and people-search sites and keeps it removed with continuous 24/7 monitoring. Run a free PrivacyOn scan to see exactly which brokers are exposing your info right now — no credit card required.
Step 8: Report and Document
If you receive obvious phishing tied to the breach, report it:
- Forward suspicious emails to reportphishing@apwg.org
- Report BEC attempts to the FBI's IC3 at ic3.gov
- Alert your company's security team so they can update filters and warn colleagues
The Bottom Line
The Crunchbase breach isn't a typical consumer credentials dump — it's a targeting kit for professional social engineering. If your data was in it, treat every unsolicited email, LinkedIn message, and phone call with extra scrutiny for the next 12–18 months. And take away the raw material scammers rely on: start a free PrivacyOn scan to remove your personal information from the data broker sites attackers use to build convincing pretexts.
Frequently Asked Questions
How do I know if my Crunchbase data was in the ShinyHunters leak?
ShinyHunters posted the archive on their Tor leak site, and security researchers have added the exposure to breach-tracking databases. Check haveibeenpwned.com with the email you used for Crunchbase. If you had an active Crunchbase account before the disclosure, assume your information could be in the sample and act accordingly.
What data was leaked in the Crunchbase breach?
The 402 MB archive included full names, contact information, physical addresses, job data (role, company, industry), business contracts between Crunchbase and partner firms, and internal documents about business operations. Over 2 million records were involved.
Should I delete my Crunchbase account after the breach?
You can, but the leaked data is already public — deleting the account now won't remove it from the ShinyHunters archive. Deletion prevents future breaches from adding to what's exposed. At minimum, audit your public profile and remove personal contact details.
Who is ShinyHunters?
ShinyHunters is a financially motivated cybercrime group active since 2020. They specialize in stealing large volumes of personal and corporate data from major companies, then selling or leaking it on underground forums when extortion demands aren't met. Recent victims include SoundCloud, Betterment, and now Crunchbase.
How do I stop scammers from combining the Crunchbase leak with my other info?
Remove your personal information from data broker and people-search sites — that's where attackers get your home address, personal phone, and relatives to build convincing pretexts. PrivacyOn's free scan shows exactly which brokers are exposing your info and can remove them automatically. It's the fastest way to disarm cross-reference attacks.
Am I at higher risk if I'm a founder or investor?
Yes. Professional targeting is the whole point of a breach like this one. Founders, investors, and executives are prime targets for spear-phishing, BEC scams, and impersonation. Enable hardware-key 2FA, verify any financial request out-of-band, and reduce your public data footprint immediately.