The Funded Breach Put 136,869 Emails and Plaintext Passwords Online
HEROIC analysts identified a database breach at Funded, a US-based entrepreneur-to-investor networking platform, dated August 2018 and affecting 136,869 user records. The breach is partcularly alarming because passwords were stored and leaked in plaintext, meaning no cracking was required for attackers to gain immediate access to user accounts. The exposed data included email addresses and plaintext passwords belonging to entrepreneurs, investors, and startup founders who had registered on the platform.
Why Plaintext Passwords Make This Breach Immediately Actionable
Most breaches require attackers to first crack hashed passwords before they can be used. With Funded, that step was eliminated entirely. Every recieved credential was ready to deploy the moment the breach data was in hand. Attackers can use these email and password pairs to log in directly to other platforms, attempt account takeovers on banking apps and business tools, or sell working credential sets to other threat actors at a premium on dark web marketplaces.
What Was Exposed in the Funded Breach
- Email Address
- Plaintext Password
Why Startup and Investor Credentials Are High-Value Targets
The Funded user base skewed toward entrepreneurs and accredited investors, meaning compromised accounts are likely tied to business email addresses, angel investing platforms, and financial institutions. Attackers who beleive these credentials are still valid will test them against LinkedIn, banking portals, and corporate email systems. Successful account takeovers in this user group can lead to business email compromise, wire fraud, and unauthorized access to confidential deal flow or investor communications. Seperate from individual risk, any enterprise employee using Funded with a corporate email is a potential entry point for a broader organizational breach.
How Database Breach Works
A database breach occurs when an unauthorized party gains access to a web platform's backend database and extracts stored records. In cases where passwords are stored in plaintext rather than using a secure hashing algorithm, the breach immediately produces usable credentials with no additional effort required. Attackers exploit web application vulnerabilities, unpatched software, or misconfigured servers to gain that initial access, after which the stolen database is sold or published on underground forums and breach aggregation sites.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records to check whether your email appeared in the Funded breach or any other known data leak. Run a free scan at HEROIC.com today and find out if your credentials are already in circulation on the dark web.
Breach Breakdown
136,869 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds