Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Prosper Data Breach Impacts 17.6 Million Accounts

Hackers stole names, addresses, dates of birth, email addresses, Social Security numbers, government IDs, and other information.

Data breach

More than 17 million individuals were likely impacted by a data breach at peer-to-peer lending marketplace Prosper, data breach notification service Have I Been Pwned warns.

Prosper disclosed the incident last month, noting that hackers accessed its network and stole confidential, proprietary, and personal information from its systems.

According to the US-based company, the attackers queried its database containing customer information and applicant data to exfiltrate the information, but did not access user accounts.

“There is no evidence of unauthorized access to customer accounts and funds, and our customer-facing operations continue uninterrupted,” Prosper said.

The company said it had contained the incident and no unauthorized activity was observed since September 2. Law enforcement was notified of the attack.

While Prosper did not specify the type of personal information that was compromised, only noting that Social Security numbers were stolen, Have I Been Pwned has added the stolen information to its database, so that individuals can check if they have been affected.

Advertisement. Scroll to continue reading.

The database, the breach notification service says, contains information pertaining to 17.6 million Prosper accounts, including names, addresses, IP addresses, email addresses, dates of birth, government IDs, employment statuses, income levels, credit statuses, and browser user agent details.

Prosper says it is still investigating the incident, noting it takes time to analyze the compromised information, determine who it belongs to, and coordinate notifications.

“We will be offering free credit monitoring as appropriate after we determine what data was affected. We continuously monitor accounts and have strong safeguards in place to protect customers’ funds,” Prosper said.

SecurityWeek has emailed Prosper for a statement on the compromised information and will update this article if the company responds.

UPDATE: Prosper has provided SecurityWeek the following statement:

We’re aware of the statement by [Troy Hunt of Have I Been Pwned] but we are not able to validate his claim. The investigation to determine what data was affected and to whom it belongs remains ongoing.  We will be offering free credit monitoring as appropriate after we determine what data was affected. Resolving this incident is our top priority and we are committed to sharing additional information with our customers as appropriate.

Related: Customer Service Firm 5CA Denies Responsibility for Discord Data Breach

Related: SimonMed Imaging Data Breach Impacts 1.2 Million

Related: 1.2 Million Impacted by WestJet Data Breach

Related: 766,000 Impacted by Data Breach at Dealership Software Provider Motility

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter

CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.

Quantum Secure Encryption has named Michael Massing as Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.