Skip to main content
Breach Signal

Breach report

Financial Services

Prosper Marketplace

Have I Been Pwned: Prosper data breach impacts 17.6 million accounts

Attackers ran unauthorized queries against Prosper's customer and applicant databases, exposing Social Security numbers, income and employment details tied to roughly 17.6 million email addresses at the peer-to-peer lender.

Reported by BleepingComputer

Records exposed

17.6M

About 17.6 million unique email addresses

Scale vs. largest on file

When
2025
How they got in
Unauthorized database queries
Sector
Financial Services

In September 2025, San Francisco-based Prosper Marketplace, one of the oldest peer-to-peer lending platforms in the United States, disclosed that it had detected suspicious activity on its systems. The company said an attacker had made unauthorized queries against databases storing information on customers and loan applicants, and that it had contained the activity by September 2, 2025. Prosper initially did not say how many people were affected.

The scale became clearer in October, when breach notification service Have I Been Pwned added the stolen dataset and reported it contained 17.6 million unique email addresses. Because Prosper collects data from people who apply for loans as well as those who borrow or invest, many of those affected may never have completed a transaction. Prosper said it could not validate the figure and that its own review was ongoing.

The exposed fields were extensive and closely tied to lending decisions. According to the breach data, they included names, Social Security numbers, government-issued ID details, dates of birth and physical addresses, as well as employment status, credit status and income levels. IP addresses and browser user agent strings, technical data captured when people visit a website, were also present. This combination gives criminals much of what they need to open fraudulent accounts or craft convincing lending scams.

Prosper said it had no evidence that attackers accessed customer accounts or funds, and that its customer-facing operations continued without interruption. It reported the incident to law enforcement and said it would offer free credit monitoring once it determined what data had been affected. The company did not publicly describe how the attackers obtained the ability to query its databases or whether a ransom demand was made. Class-action lawsuits followed in the weeks after the breach became public.

The Prosper incident illustrates a persistent problem in online lending: platforms gather detailed financial profiles from applicants and often retain that information long after a loan decision. Consumers who applied for credit years earlier can find themselves exposed. For fintech lenders, the case reinforces the importance of monitoring unusual database query patterns, limiting retention of applicant data and encrypting the most sensitive fields.

More from the wire

More in Financial Services.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.