Skip to main content
Jump to a category page

A single phone scam gave criminals a way into employee accounts at venture capital firm Bessemer Venture Partners on August 3, 2026. The firm says names and Social Security numbers stored in its cloud platforms were affected, but it did not send letters until September 30.

What Happened at Bessemer Venture Partners

Bessemer Venture Partners (BVP) is a venture capital firm. Its registered investment adviser, Deer Management Co. LLC, filed the breach notice with Massachusetts regulators on September 30, 2026.

According to the firm’s notice letter, BVP “was the target of a voice phishing incident” on August 3, 2026. The attack gave criminals “temporary unauthorized access to certain BVP employee accounts.” BVP says it contained the incident, notified law enforcement and hired a forensic firm. That firm found the incident was fully contained by August 4.

The investigation found that the incident affected records stored in certain cloud-hosted platforms that BVP uses.

How a Phone Call Opened the Door

Voice phishing, or “vishing,” is a scam carried out by phone. A caller pretends to be someone trusted, such as an IT help desk or a coworker, and talks an employee into sharing a password, a login code or other access. No hacking tools are needed when an employee hands over the keys.

BVP’s letter does not say how the call worked or which employees were targeted.

58 Days From Attack to Letter

The dates in the letter show a long gap between the attack and the notice:

  • August 3: the voice phishing attack
  • August 4: the incident was contained, according to BVP’s forensic firm
  • September 30: notice letters dated, 58 days after the attack

BVP has not explained why notice took nearly two months after the incident was contained.

What Information Was Exposed?

According to the Massachusetts data breach report, the information involved includes:

  • Name
  • Social Security number

The letter itself fills in the exposed information for each person, so recipients should check their own letter. BVP says it has no indication that the data has been published on the dark web or used for identity theft.

How Many People Were Affected?

BVP has not disclosed a total. Massachusetts lists 82 of its residents as affected, according to the state’s data breach report. That count reflects only one state and is not a measure of the total.

The letter does not say who the affected people are. It does tell recipients to review their “BVP account statements,” which suggests that some recipients hold accounts with the firm.

What Is Bessemer Venture Partners Offering?

BVP is offering two years of credit monitoring and identity protection through IDX at no cost. The services include:

  • Credit monitoring
  • Dark web monitoring
  • Identity restoration help

People enroll at app.idx.us/account-creation/protect, or by scanning the QR code, using the enrollment code at the top of their letter. The enrollment deadline is December 30, 2026. Questions go to 1-833-788-9712, Monday through Friday, 9 a.m. to 9 p.m. Eastern Time.

Your Information Is at Risk

A name and Social Security number together are enough for a criminal to open credit, file a false tax return or claim benefits in someone else’s name. A Social Security number usually cannot be changed, so the risk can last for years. Because this attack started with a phone scam, affected individuals may also be targeted by follow-up calls, emails or texts that use their personal details to seem real.

Do You Have Legal Options?

Investment firms that collect Social Security numbers from investors, employees and others have a duty to protect them, including by training staff to resist phone scams, and to notify people promptly when that information is exposed. When that obligation is not met, affected individuals may have legal rights and remedies worth discussing with an attorney. Emery | Reddy is investigating this incident on behalf of people who received a notice letter.

Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review. No Fee Unless We Recover. 

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

Frequently Asked Questions

Did Bessemer Venture Partners have a data breach?

Yes. BVP says a voice phishing attack on August 3, 2026 gave unauthorized access to certain employee accounts and affected records in its cloud platforms. Letters are dated September 30, 2026.

Who is Deer Management Co. LLC?

Deer Management Co. LLC is the investment adviser for Bessemer Venture Partners. The Massachusetts breach filing is under that name, while the letter itself comes from BVP.

How many people were affected?

BVP has not said. Massachusetts lists 82 of its residents. The national total has not been disclosed.

What information was exposed?

According to the Massachusetts filing:

  • Name
  • Social Security number

Check your own letter, since the information listed can vary by person.

Why did it take 58 days to get a letter?

The attack happened August 3 and was contained August 4, according to BVP. Letters are dated September 30. BVP has not explained the gap.

How do I protect myself from scams that mention the breach?

This breach started with a phone scam, so be cautious with any call, email or text that mentions BVP or the breach. Do not share personal information, passwords or codes with anyone who contacts you. Use only the phone number and website printed on your letter.

What should I do if I received a letter?

Take these steps:

  • Enroll in the IDX monitoring by December 30, 2026
  • Place a free credit freeze with Equifax, Experian and TransUnion
  • Review your credit reports and your BVP account statements for activity you do not recognize
  • Be wary of calls, texts or emails that mention the breach
  • Keep your letter

Do I have a legal claim?

You may. Firms that collect Social Security numbers have a duty to protect them and to notify people promptly when they are exposed. If you received a Notice of Data Breach letter from Bessemer Venture Partners, contact Emery | Reddy at 916.995.5968 or visit emeryreddy.com for a Free Case Review to see what you may qualify for. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now