Skip to content
NetarxImpact Database
Spear Phishing (Email)No AI reportedReported

Sequoia Capital investor data exposed after employee falls for phishing email

Sequoia Capital · Financial Services · United States · February 2021

What happened

Sequoia Capital told its limited partners in February 2021 that some of their personal and financial information may have been accessed by a third party after an employee's email account was compromised in a successful phishing attack. Reporting described an accompanying business email compromise attempt that failed. Sequoia is one of the best-known venture firms and holds sensitive investor data on individuals and institutions.

How the deception worked

An employee at the firm received and acted on a phishing email, handing over credentials that gave the attacker access to their corporate mailbox. The intruder used that mailbox to read stored correspondence containing investor personal and financial details, and attempted to leverage the account for fraudulent payment instructions in the style of a business email compromise, which was not successful. Sequoia notified affected limited partners, engaged outside investigators and law enforcement, and offered credit monitoring. No malware deployment or wider network intrusion was reported.

AI involvement · No AI reported

No AI element reported.

The control that would have caught it· our reading, not a claim from the sources

Phishing-resistant MFA on cloud mailboxes plus alerting on anomalous mailbox rules and sign-in locations catches this pattern in hours rather than weeks.

Sources (3)

  1. Scoop: Sequoia Capital says it was hacked
    Axios·axios.comOpen ↗
  2. VC Giant Sequoia Capital Informs Investors of Data Breach
    SecurityWeek·securityweek.comOpen ↗
  3. VC giant Sequoia Capital discloses data breach after failed BEC attack
    BleepingComputer·bleepingcomputer.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.