Prosper Marketplace, a peer-to-peer lending platform, reported a breach potentially affecting more than 10 million customers — the largest incident in the financial sector recorded in 2025.
A Lender Holds Far More Applicants Than Borrowers
The population in a lending platform’s database is dominated by people who applied and did not proceed: declined, withdrawn, or approved on terms they refused.
Every one of them completed a credit application — the single densest identity document an ordinary person produces. Full legal name, date of birth, national identifier, address history, employment, stated income, and consent to a credit check that pulls the rest.
A person who was declined in 2019 and has not thought about the company since is in that dataset, with a full identity profile, and no relationship through which they would expect to hear anything.
The Desk Has Filed This Before
At 26-0702 this desk recorded declined applicants as a category the remediation framework does not reach: they are not customers, they may not recognise the company’s name, and notification depends on contact details supplied years earlier that were never maintained because there was no ongoing relationship to maintain them for.
Prosper is that finding at eight figures. And the retention question is sharper here than in most files — a declined application has a defensible retention period for regulatory and fair-lending purposes, and no obvious justification for indefinite storage of the full submitted document.
On "Potentially Affected"
The qualifier is doing real work and this desk does not treat it as evasion. Early figures in a breach of this size routinely describe the population whose records were reachable rather than the population whose records were taken, and the two can differ substantially.
Graded medium accordingly: the scale is well reported, the confirmed exposure is not. This is the counting problem set out at 26-0512.
Compiled from public reporting, listed below. The figure is as reported and described as potential rather than confirmed. The intrusion route is not established in the material we reviewed. Corrections: corrections@forensicpost.com.
- The seven largest banking data breaches of 2025American Banker
- Largest financial sector data breaches 2025Statista