[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5mw7f6joxj4w":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":12,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":13,"affectedCountUnit":22,"hasEnglishDescription":4,"contentLocale":23,"availableLocales":24,"translations":26,"severity":29,"dataClasses":30,"description":49,"seoTitle":50,"seoDescription":51,"logoUrl":52,"isVerified":4,"isSensitive":53,"isSpamList":53,"isMalware":53,"company":54},"6a452308a20f867c8ba8e707","Prosper","Prosper Data Breach","prosper","prosper.com","2025-09-01T00:00:00.000Z","2025-10-16T00:03:21.000Z",null,"2026-07-19T23:38:43.786Z","Database intrusion","https:\u002F\u002Fwww.prosper.com\u002Flegal\u002Fincident-response",[16,18,19],"https:\u002F\u002Fwww.prosper.com\u002Fblog\u002Fprosper-notice-of-data-breach","https:\u002F\u002Fwww.securityweek.com\u002Fprosper-data-breach-impacts-17-6-million-accounts\u002F",17605276,"known","unknown","en",[23,25],"tr",{"en":27,"tr":28},{"slug":9},{"slug":9},"Critical",[31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48],"Account numbers","Bank account numbers","Browser user agent details","Credit status information","Dates of birth","Driver's license numbers","Email addresses","Employment statuses","Financial information","Government issued IDs","Income levels","IP addresses","Names","Passport numbers","Payment card information","Physical addresses","Social security numbers","Tax information","\u003Cp>The 2025 Prosper data breach affected 17,605,276 unique email addresses and exposed highly sensitive identity and financial data.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The confirmed scope includes names, email and physical addresses, dates of birth, IP addresses, browser user-agent details, employment status, income levels and credit-status information. Prosper’s completed review also confirmed Social Security or national identification numbers, bank account numbers, Prosper account numbers, driver’s license and passport numbers, marriage or birth certificates, tax information, payment card numbers and other financial or credit-application data. Not every person had every field exposed; individual notices define the exact scope. The reviewed dataset contained \u003Cstrong>17,605,276 unique email addresses\u003C\u002Fstrong>, but Prosper has not described that figure as the unique total of people it notified. Passwords are not among the confirmed data classes. The combination of identity numbers, birth dates and financial information creates critical, long-lived risk of identity theft, fraudulent credit applications, account-recovery fraud and highly targeted phishing.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>Prosper detected unauthorized activity in its systems on 1 September 2025 and responded to stop the access, strengthen security controls and investigate the event. The completed analysis found that an outside criminal actor queried company databases holding customer and applicant data between June and August 2025 and obtained personal information. Prosper reported no new activity after 2 September, said it was not ransomware and notified law enforcement. The first incident page appeared on 17 September, review concluded on 26 November and notifications began on 9 December. The listed 1 September date is the discovery date because the exact days of data extraction within the June-to-August period have not been made public. The company reported no evidence of unauthorized access to customer accounts or funds and said customer-facing operations continued without interruption.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The affected population may include both Prosper customers and people who applied for credit or another product; it is not limited to active account holders. Individuals whose Social Security number, national ID, driver’s license, passport, bank account, payment card or tax information was involved face the greatest long-term risk. These details are difficult or impossible to change and can be reused years later for new-account fraud, credit applications, tax fraud or identity-verification attacks. \u003Cstrong>There is no evidence that customer accounts or funds were accessed\u003C\u002Fstrong>, but that statement does not prevent stolen identity data being abused at another organization. People affected only through email, IP address or browser details may face less direct financial risk, yet personalized phishing and device impersonation remain possible.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>Review the fields in your Prosper notice and consider the complimentary credit-monitoring and identity-restoration services through the official channel. Check reports from all three nationwide credit bureaus and dispute any unfamiliar account, inquiry, address or debt promptly. If a Social Security or other government identifier was affected, consider placing a security freeze or fraud alert on your credit files. When a bank account or payment card appears in your notice, contact the financial institution directly, review transactions and ask what replacement or monitoring steps are appropriate. Enable multi-factor authentication on your email account and review active sessions and forwarding rules. Do not follow links in messages offering Prosper compensation, credit monitoring, account verification or fund protection; navigate to the official site independently and never share a one-time code.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>This event creates persistent identity and financial-data risk rather than a conventional password-exposure problem, so changing a password alone is insufficient. Monitor credit reports, bank and card activity, tax accounts and new-account alerts at regular intervals. Unique passwords and multi-factor authentication on every service add protection when stolen identity fields are combined with account-recovery attempts. \u003Cstrong>Treat immutable identification numbers as permanent risk signals\u003C\u002Fstrong> and avoid reusing a birth date, address or other easily researched fact as an answer to security questions. If you receive an unexpected credit denial, tax notice, new card, bank verification request or address-change alert, verify it independently using the institution’s official contact details and preserve records of your response.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Use the secure search field on this page to check every current and historical email address used for a Prosper account or application. A match means the address is one of the 17,605,276 unique emails in the verified dataset; it does not reveal which financial or identity fields were present in your specific record. Rely on the individual notice from Prosper for that exact scope. If you receive a match, assess credit reports, financial activity and identity-use alerts rather than reviewing only the Prosper account. No result is an absolute guarantee because a differently written address, a record outside this dataset or another breach may still exist. Never enter a Social Security number, bank account, payment card, password or authentication code into a breach search. Rechecking older addresses periodically can alert you when additional verified records are published.\u003C\u002Fp>","Prosper Data Breach (17.6 Million Reported Records)","Prosper Data Breach. 17.6 Million reported records are reported. Reported data: Account numbers, Bank account numbers, Browser user agent details. Review the…","\u002Fuploads\u002Flogo\u002Fprosper_com.webp",false,{"name":55,"sector":56,"country":57,"website":10,"websiteArchiveUrl":58,"websiteStatus":58,"websiteCheckedAt":13},"Prosper Marketplace, Inc.","Financial technology and consumer lending","United States",""]