What happened
New York venture capital firm Insight Partners, which manages tens of billions of dollars, confirmed that it suffered a cyber incident in January 2025 that began with a social engineering attack. The firm later notified employees, limited partners and portfolio-company contacts that personal, banking and tax information, fund data and transaction details had been taken. Investigators found the intruders had been inside the environment for a period before discovery.
How the deception worked
Insight Partners stated publicly that the intrusion was the result of a social engineering attack rather than an exploited vulnerability. Investment firms are a high-value pretext environment: staff routinely exchange documents and wire instructions with founders, co-investors, lawyers and limited partners they have never met in person, so an approach from an unfamiliar sender referencing a live deal reads as normal. The attackers used that trust to obtain access to internal systems, then spent time collecting fund-level financial data, banking and tax details for individuals, and transaction records, before the activity was detected and remediated.
The control that would have caught it· our reading, not a claim from the sources
For deal-driven firms, phishing-resistant MFA plus verified out-of-band confirmation for any document or credential request from outside the firm is the control that matters.
Sources (2)
- Statement from Insight Partners on Cyber IncidentInsight Partners·insightpartners.comOpen ↗
- VC giant Insight Partners notifies staff and limited partners after data breachTechCrunch·techcrunch.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.