LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Crunchbase, Inc. Listed by shinyhunters Ransomware Group

HIGH severityUnverified claimHow we verify

Crunchbase, Inc. Listed by shinyhunters Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 20, 2025
Crunchbase, Inc. Listed by shinyhunters Ransomware Group

Reported September 20, 2025.

HIGH
Severity
September 20, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Crunchbase, Inc. has been listed by the shinyhunters ransomware group, with internal files reported as exfiltrated. The incident was disclosed on 20 September 2025; an undisclosed number of individuals may be affected, and readers should check any notifications or account alerts and follow guidance from Crunchbase.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People whose professional or personal details appear in business databases may now face the possibility that internal files from Crunchbase, Inc. have been taken and listed for exposure. Public reporting indicates the company was named by the shinyhunters ransomware group, with claims of roughly two million records among 1.3 GB of compressed data. The number of individuals actually affected remains unknown, and the precise contents of those files have not been independently confirmed. For anyone who has used Crunchbase or whose information appears in company profiles, investor lists, or related records, the practical stakes are straightforward: stolen internal material can enable targeted phishing, identity misuse, or competitive harm once it circulates.

The listing itself is a claim made by the group rather than a verified confirmation from the company or independent investigators. Still, the reported scale and the nature of the data make the incident worth understanding calmly and factually so that people can judge their own exposure and take sensible steps.

What happened

According to available public reporting, Crunchbase, Inc. was listed by the shinyhunters ransomware group on or around 20 September 2025. The group claims to have exfiltrated internal files in a ransomware attack. The reported summary associated with the listing states a compressed size of 1.3 GB containing 2 million records, with an update noted on 23 January 2026. No further technical details about the method of intrusion, the exact date of the intrusion itself, or any ransom demand have been disclosed in the facts available. The number of people affected is listed as unknown. Because the information originates from a threat-actor leak-site claim, independent verification of the full scope has not been established in the public record.

The group behind it: shinyhunters

Shinyhunters is a well-documented cybercrime group known for large-scale data theft and for posting stolen material on leak sites or underground forums. Public reporting over several years has associated the group with breaches involving customer databases, corporate files, and credentials from companies across technology, retail, and other sectors. Their typical pattern involves gaining access, exfiltrating data, and then advertising the haul—sometimes after ransomware encryption, sometimes as pure data extortion—to pressure victims or to sell the material. They have been linked to multiple high-profile incidents in which large volumes of records were later confirmed or partially confirmed by the affected organisations or by security researchers. In this case the group claims Crunchbase files were taken; that claim should be treated as an assertion by the actors until corroborated by other sources. No additional statements by shinyhunters specifically about Crunchbase beyond the listing details have been provided in the available facts.

Who is Crunchbase, Inc.?

Crunchbase, Inc. operates a widely used online platform that aggregates business information, startup funding data, company profiles, investor details, and related professional records. Organisations and individuals rely on it for market research, competitive intelligence, fundraising, and networking. Because of that role, the company typically holds structured data about companies, founders, executives, funding rounds, and contact or professional information that users and partners contribute or that is compiled from public and proprietary sources. A breach involving internal files from such a platform is consequential precisely because the data often describes real people and real commercial relationships. Even when the exact files remain unconfirmed, the potential for misuse of business-contact or professional records is clear.

The information in question

The facts state that internal files were exfiltrated in a ransomware attack and that the listing reports 1.3 GB of compressed data containing 2 million records. No more granular breakdown of data types—such as names, email addresses, financial figures, or authentication credentials—has been disclosed. Organisations of this kind commonly maintain databases of company profiles, personnel information, funding histories, and internal operational documents. Whether those categories, or others, appear in the claimed files cannot be confirmed from the public facts. Readers should therefore treat the precise contents as unconfirmed while recognising that any large set of internal business records can include personally identifiable or commercially sensitive material.

Why it matters

For individuals whose details may be present, the concrete risks include phishing emails that appear more credible because they reference real company or funding information, attempts to impersonate them in business settings, or the quiet sale of contact data for further fraud. For the organisation, the exposure of internal files can damage trust among users and partners, create regulatory or contractual obligations, and require costly investigation and remediation. Because the number of people affected is unknown and the exact data types remain unconfirmed, the full extent of harm cannot yet be measured. The combination of a claimed multi-million-record haul and the business-intelligence nature of Crunchbase’s work means the incident carries both personal and commercial weight even while many details stay limited.

What to do if you're exposed

If you have an account with Crunchbase, appear in its public profiles, or have shared professional information that might reside in internal systems, treat the listing as a prompt for caution rather than panic. Change passwords on related accounts, enable multi-factor authentication where available, and watch for unexpected messages that reference your business affiliations or funding history. Monitor financial and professional accounts for unusual activity. You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. Keep records of any suspicious contact and report clear fraud to the appropriate authorities. Public detail on this incident remains limited, so stay alert to official statements from Crunchbase itself for any confirmed guidance.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyCrunchbase, Inc. security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Crunchbase, Inc.’s full breach history →

More recent breaches

Edmunds.com, Inc. Listed by shinyhunters Ransomware GroupSeptember 30, 2025Red Hat, Inc. Listed by shinyhunters Ransomware GroupSeptember 13, 2025Cisco Listed by shinyhunters Ransomware GroupJuly 23, 2025Google Adsense Listed by shinyhunters Ransomware GroupJune 30, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Crunchbase, Inc. Listed by shinyhunters Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by shinyhunters — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram