The Brazilian crowdfunding platform APOIA.se suffered a significant data breach that exposed users' personal information, with more than 450,000 email addresses added today to the data breach notification service Have I Been Pwned (HIBP).Â
The company acknowledged the incident in January 2026, a month after a database containing user records was posted on a popular online hacking forum.
The December 2025 APOIA.se data breach exposed a substantial dataset. Technical details of the breach and the number of affected individuals have not yet been disclosed. According to HIBP, the leak includes the platform's backers and creators:
Reports last month also suggested unique identifiers may have been exposed. These do not directly reveal which campaigns users supported or their interests or preferences without access to our protected internal systems, the company reportedly said in sent breach notification emails.
The company allegedly emphasized that sensitive information, such as payment data, was not exposed because partners with international security certification (PCI-DSS) processed the purchases.Â
The Brazilian crowdfunding platform breach highlights how these sites have become attractive targets for cybercriminals due to the valuable personal and financial data they store.Â
As crowdfunding continues to grow in popularity, platforms must prioritize implementing advanced security measures to protect user data from unauthorized access and prevent similar large-scale breaches in the future.