VC giant Insight Partners confirms investor data stolen in breach



Venture capital firm Insight Partners has confirmed that sensitive data for employees and limited partners was stolen in a January 2025 cyberattack.

Insight Partners is a prominent global venture capital and private equity firm specializing in high-growth technology, software, and internet companies, managing over $90 billion in regulatory assets.

The company has significant investments in more than 800 companies worldwide, including Twitter, HelloFresh, and Veeam Software.

On February 18, 2025, Insight Partners released a statement informing of a cybersecurity incident that occurred on January 16, 2025, where an unauthorized actor accessed certain IT systems after carrying out a “sophisticated social engineering attack.”

Insight Partners assured that the incident was isolated and its duration was contained to a single day, resulting in no disruptions to its business operations. However, an investigation into its full scope was still underway.

In an update published earlier this week, the company says it has verified a data breach with the help of experts at an eDiscovery vendor and is now working on determining who is impacted.

The data that has been exposed varies per individual and investor, and may include:

  • Fund information
  • Management company information
  • Portfolio company information
  • Banking information
  • Tax information
  • Personal information of current and former employees
  • Information related to Limited Partners

Individuals confirmed to have had their information exposed will be notified, but Insight Partners says this will occur in waves, starting in the next few days.

In the meantime, potentially impacted persons are recommended to change their personal and enterprise passwords and activate two-factor authentication (2FA) on all financial accounts.

Additionally, it is recommended to closely monitor financial statements and credit reports, and consider placing a fraud alert or freeze.

Insight Partners has not yet been listed on any ransomware sites and extortion portals, so the type of attack and the perpetrators responsible for it are still unknown.

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.


Source link


Leave a Reply

Your email address will not be published. Required fields are marked *