HomeSecurityHave I Been Pwned: Prosper breach affects 17.6 million people

Have I Been Pwned: Prosper breach affects 17.6 million people

One of the largest data breaches in the financial services space occurred this year, as cybercriminals stole personal information from more than 17.6 million people from the systems of Prosper, an American peer-to-peer lending platform. The incident, detected on September 2, 2025, has already caused turmoil in the industry and raised serious questions about data security at fintech companies.

Have I Been Pwned Prosper breach

A platform with a huge customer base

Founded in 2005, Prosper operates as a peer-to-peer lending marketplace, facilitating direct transactions between lenders and borrowers without the intermediary of banks. To date, it has helped over 2 million customers secure loans worth over $30 billion, making it one of the most important players in the US fintech ecosystem.

Its rapid growth, however, seems to have made it an attractive target for cyberattacks.

See also: MANGO reveals customer data breach

What happened and how was the breach detected?

The company said in a statement that the breach was discovered on September 2 , but there is no evidence that the hackers accessed any active accounts or customer funds. However, the attackers appear to have stolen sensitive personal data belonging to customers and loan applicants.

In a special update page, Prosper states that through unauthorized searches of internal databases, information such as Social Security Numbers (SSN) and other “confidential and proprietary information” was obtained.

The company emphasizes that it has informed the relevant authorities and is cooperating with law enforcement agencies to investigate the case, while stating that the protection of its customers is "the top priority."

Have I Been Pwned: Prosper breach affects 17.6 million people

The revelation from “Have I Been Pwned”

Although Prosper did not officially disclose the scope of the breach, the well-known data breach notification platform “Have I Been Pwned” published that the attack affected 17.6 million unique email addresses.

See also: US DHS: Chinese gangs stole $1 billion from SMS scams

According to the same sources, the leaked data includes:

  • Full names and dates of birth
  • Social Security numbers and government identification
  • Employment, income and credit status information
  • Physical addresses and IP addresses
  • Browser usage information

The combination of this data makes those affected particularly vulnerable to identity theft, phishing or financial fraud.

Prosper's reaction

In a statement to BleepingComputer, a company spokesperson said that Prosper is “aware of the Have I Been Pwned report, but is unable to confirm it.” An internal investigation, she added, is underway to determine what data was exposed and who owns it.

The company has committed to offering free monitoring and identity protection services creditonce the incident mapping is complete.

At the same time, Prosper emphasizes that the breach did not affect operations that directly concern customers, assuring that the transaction systems remain secure.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Why Fintech platforms are in the spotlight

Fintech companies have become prime targets for cybercriminals. The reason is simple: they handle huge volumes of sensitive personal and financial data, which can yield high profits on the black market.

See also: Phishing campaign misuses LastPass name – Company denies breach

The very nature of peer-to-peer lending services, which rely on online trust and connectivity, creates additional security challenges. Even a small breach can undermine user trust and cause significant financial damage.

Have I Been Pwned: Prosper breach affects 17.6 million people

What users can do now

Users who had an account with Prosper are invited to:

  1. change passwords their and avoid reusing the same passwords on other platforms.
  2. Activate the credit profile monitoring that the company will offer.
  3. Avoid suspicious emails or SMS, especially those that ask for personal information.
  4. They closely monitor their bank and financial accounts for suspicious activity.

The message of the times

The Prosper incident is another reminder that no company, no matter how much they invest in security, is invulnerable. Attacks are now targeting not just big banks but also fast-growing fintech platforms that support millions of users.

The day ahead for Prosper – and the industry as a whole – will depend on how quickly and transparently they restore their customers’ trust.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS