NEW YORK — Online fund-raising site Kickstarter says hackers got some of its users’ data.
Cofounder Yancey Strickler said in a blog post that hackers accessed names, e-mail addresses, phone numbers, and passwords. The passwords are encrypted, but the company said it’s possible for a hacker to guess a weak or obvious password. It recommended that users change their passwords.
Hackers did not get credit card information, said New York-based Kickstarter, but two accounts saw unauthorized transactions.
Kickstarter is one of dozens of crowdfunding websites that let people raise money from donors for projects.
Kickstarter campaigns have included Zach Braff and Spike Lee movies, a brewery, arts projects, and business startups.
The breach was disclosed Saturday on the Kickstarter blog. The company said it learned about the problem from law enforcement on Wednesday and closed the breach immediately.
‘‘We’re incredibly sorry that this happened,’’ Strickler wrote. ‘‘We set a very high bar for how we serve our community, and this incident is frustrating and upsetting. We have since improved our security procedures and systems in numerous ways.” Strickler said the company is ‘‘working closely with law enforcement.’’
Kickstarter, founded five years ago, has collected $982 million for more than 56,000 projects, according to its website. It says it has collected pledges from more than 5.6 million people.
The breach comes after discount retailer Target Corp. said it believes hackers infiltrated the computers of one of its vendors and installed malicious software in Target’s checkout system for its 1,800 US stores.
Experts believe the thieves gained access during the busy holiday season to about 40 million credit and debit card numbers from Target customers.
They also got the personal information — including names, e-mail addresses, phone numbers, and home addresses — of as many as 70 million customers.