Data Breach Ledger
The breaches spilling your data
A breach isn't a place on a map -- its victims are everywhere its customers are. So this is a ledger, not a map: every breach we can source that spilled personal records. The focus is on what's newest, but it reaches back years, because a Social Security number stolen in 2017 or a passport leaked in 2018 still works against you today. Led by the number that matters most, tagged by exactly what leaked. The throughline: as age-verification and KYC laws force more people to upload driver's licenses and passports, those are the very documents turning up in the spills.
people's records exposed in 2026
across 54 breaches disclosed in 2026
records exposed, all time
summed across every tracked breach -- most people appear in more than one
breaches in the ledger
tracked back to 2007, and still counting
exposed driver's licenses or passports
the same IDs age-verification laws demand
Been caught in a breach? Jump to what to do ↓
People affected per year
Records exposed each year across the breaches in this ledger. A single mega-breach can tower over an entire year, and people caught in more than one are counted each time.
Sum of disclosed victim counts per year across tracked breaches; breaches with an undisclosed scale aren't included, and people hit by more than one breach are counted each time. 2026 is only a partial year. Bar color runs yellow for lighter years through orange to red for the worst on record.
2026, month by month
Each cell is a month -- darker means more breaches disclosed. Tap a month to filter the ledger to it.
What was exposed
How often each kind of personal data turned up across the 180 breaches.
The largest on record
The biggest breaches in the ledger by people affected. Many are years old -- and still fuel identity theft today, because a stolen SSN, passport, or fingerprint can't be reset.
The ledger
Every tracked breach, grouped by year, newest first. Open a year to read its breaches. Filter by region, what was exposed, or sector -- matches open automatically.
2026
Suno 55.3M Jul 2026
55.3M AI-music accounts exposed, users never individually notified
The November 2025 breach of AI music platform Suno finally got a number on July 20, 2026, when Have I Been Pwned ingested the stolen dataset: 55.3 million unique accounts. Exposed data includes email addresses, phone numbers used as logins, names, physical addresses, purchase records, and partial payment-card details from tens of thousands of Stripe records -- card type, expiry, and last four digits. Suno had decided individual customer notifications were not required, so for most of its users the HIBP listing eight months later is the first practical way to learn they were in the dump. The case is becoming a reference point for how AI startups handle disclosure: a consumer platform with tens of millions of accounts, a breach it acknowledged only generally, and a notification standard outsourced to a volunteer-run lookup site.
Hugging Face n/a Jul 2026
first breach executed by an autonomous AI agent
Hugging Face, the platform hosting much of the world's open AI models, disclosed a high-severity breach on July 20, 2026 with a first for this ledger: the intrusion was carried out by an autonomous AI agent system exploiting vulnerabilities in production infrastructure. Entering through the data-processing pipeline, the attacker's agent stole cloud and cluster credentials, moved laterally across internal clusters, and took internal datasets before Hugging Face closed the holes, evicted the actor, and rebuilt compromised nodes. The inevitable milestone, arrived: AI attacking the AI supply chain, at machine speed, against the company whose job is distributing AI.
Eurail 309K Jul 2026
300,000+ rail travelers' passport and ID details exposed
A breach at Eurail, which sells Interrail and Eurail passes, exposed the personal data of more than 300,000 travelers, including names, contact details, dates of birth, and passport or ID details, with some IBANs or health-related information. Some travelers were advised to replace their passports.
DHS Homeland Security Information Network (HSIN) n/a Jul 2026
intelligence-sharing platform breached
The Department of Homeland Security confirmed on July 1, 2026 that an unknown attacker had breached HSIN, the sensitive-but-unclassified network that federal, state, local, tribal, and private-sector partners use to share intelligence, coordinate security for major events, and respond to incidents. First reported by Nextgov, the intrusion is believed to have happened between late May and early June and also hit an associated SharePoint system; DHS said it isolated the affected systems and that classified networks were not impacted, while it stayed unclear whether any data was taken. Sen. Mark Warner, vice chair of the Senate Intelligence Committee, called for a DHS and DOJ investigation, noting HSIN was supporting security for the World Cup underway in the US.
Medtronic 9M+ Jul 2026
SSNs and health data of ~9M claimed stolen; listing quietly removed
Medical-device giant Medtronic began notifying customers in July 2026 of a breach detected in April, in which attackers accessed names, contact details, dates of birth, Social Security numbers, and health-related information. The ShinyHunters extortion group claimed more than 9 million records -- and then the listing vanished from the group's leak site, a removal that in extortion economics usually means one thing: the victim likely paid. For patients whose cardiac devices, insulin pumps, and health profiles run through Medtronic systems, the combination of SSN plus health data is the full identity-theft kit, and the quiet delisting means the records' fate is unverifiable either way.
NAIC n/a Jul 2026
US insurance regulators breached via Oracle PeopleSoft zero-day
The National Association of Insurance Commissioners -- the standard-setting body for US insurance regulators -- was breached by ShinyHunters through a zero-day in an Oracle PeopleSoft server. The group claimed 3.1 TB across roughly 105,000 files, including regulatory filings from 2017-2024, customer, order, and payment records, and credentials for production environments; NAIC's response was that only publicly available data, outdated logs, and configuration files were taken. The gap between those two descriptions is the story, and either way a regulator that holds filings from every US insurer was reachable through one unpatched enterprise server -- the same PeopleSoft vector ShinyHunters has been running against universities and agencies all year. Scale update: by mid-July the same PeopleSoft zero-day campaign had breached more than 100 organizations -- including Nissan's employee records across four countries -- before Oracle had even published an advisory.
Novo Nordisk n/a Jun 2026
attackers copy personal data from internal systems
The Danish maker of Ozempic and Wegovy disclosed on June 11, 2026 that attackers had reached a limited number of internal IT systems and copied non-public data, including personal data. The group claiming responsibility said it got in months earlier through an exposed high-privilege developer credential; healthcare-professional records were directly identifying, while clinical-trial patient data was pseudonymized.
Texas 3M+ Jun 2026
3M+ hunting/fishing license holders' IDs stolen from state agency
The Texas Parks and Wildlife Department said a breach may have exposed the driver's license and passport numbers of more than 3 million people who bought hunting and fishing licenses. The theft of state-held government ID numbers underscores the risk created as age-verification and KYC systems push more people to hand over identity documents.
AssuranceAmerica 7M Jun 2026
6.99M people's driver's licenses exposed by auto insurer
Auto insurer AssuranceAmerica told customers that hackers who breached its systems (discovered March 17, 2026) stole names, contact information, and driver's license numbers, along with policy, vehicle, and claims details. The company said the attackers targeted an employee and it disabled the compromised credentials. Regulatory filings to the Maine and Indiana attorneys general put the total at about 6.99 million people. Update, July 8, 2026: filings with the Indiana and Maine attorneys general put the toll at 6.99 million people, with notification letters going out July 10 -- among the largest driver's-license spills in the year's run of identity-document breaches. TechCrunch noted Maine's own breach-disclosure portal was offline at the time, under review after someone published a fraudulent breach notice on it.
DentaQuest 2.6M Jun 2026
2.6M dental-benefits accounts with IDs and health data leaked
After a May 2026 extortion campaign, the ShinyHunters group published a 234GB archive from dental-benefits administrator DentaQuest. Have I Been Pwned verified 2.6 million unique email addresses alongside names, phone numbers, addresses, dates of birth, government-issued IDs, and health-insurance information.
University of Nottingham 455K+ Jun 2026
455K students' and alumni records, including passports, leaked
ShinyHunters leaked files from the University of Nottingham's student records system. Have I Been Pwned found roughly 455,000 unique email addresses along with names, addresses, phone numbers, passport numbers, and sensitive fields such as ethnicity, disability, citizenship status, and fee-payment data for current students and alumni.
France 73K Jun 2026
Tchap government messaging platform breach hits 73K accounts
France's interministerial digital directorate DINUM disclosed a breach of Tchap, the government's sovereign messaging platform, after an account-hijacking incident on June 7, 2026. Officials said 73,467 accounts were affected; an actor using the name 'misere' claimed to have taken 13.5GB of messages and user data, a larger claim officials had not verified.
KDDI 14.2M+ Jun 2026
14.2M email accounts exposed across six Japanese ISPs
Japanese carrier KDDI disclosed a breach of an email platform it provides to six ISPs (STNet, KDDI Web Communications, JCOM, Chubu Telecommunications, Nifty, and Biglobe). Up to 14.22 million email addresses and passwords may have been exposed after attackers exploited a third-party software vulnerability; the company urged users to change passwords.
Kodak 2.2M+ Jun 2026
2.2M customer and corporate records claimed stolen
Kodak confirmed a June 2026 breach after ShinyHunters claimed it stole 2.2 million customer and corporate records and listed the company on its leak site. Kodak said an unauthorized third party temporarily accessed a limited amount of data but had not verified the record count or full scope.
Amazon One Medical n/a Jun 2026
legacy senior-patient records accessed
Amazon-owned One Medical disclosed that a third-party file-storage platform holding archived records for legacy Iora Health and One Medical Seniors patients was accessed in June 2026. Affected files included demographic and clinical data across nine metro areas; ShinyHunters claimed 8.8TB of data, which One Medical had not confirmed.
iRhythm n/a Jun 2026
cardiac-monitoring patient data stolen
Cardiac-monitoring company iRhythm disclosed a June 2026 cyberattack after detecting unauthorized activity in third-party-hosted applications. An actor claimed to have stolen patients' protected health information and other personal data and demanded payment; iRhythm confirmed some data was stolen but had not confirmed the number of people affected.
Madison Square Garden 26M+ Jun 2026
26M+ records with facial-recognition and biometric data exposed
ShinyHunters used a voice-phishing call to breach Madison Square Garden Entertainment and published a trove the group said covered up to 26 million people. The leaked data reportedly included MSG's facial-recognition entry-surveillance logs, biometric data, background-check reports, and threat-assessment profiles built on visitors and celebrities, plus attendee contact details. MSG had not confirmed the scope; multiple class actions followed.
Aflac 4.4M Jun 2026
insurer breach exposes personal and bank-account data
US supplemental-insurance giant Aflac disclosed a 2026 breach after attackers compromised its Japan subsidiary, stealing personal information and bank account details for about 4.38 million customers, along with policy and coverage data.
Age-verification vendor 985K+ Jun 2026
985,000 passports and licenses left on the open web
A security researcher found roughly 985,000 passport and driver's-license photos from an identity-verification company sitting on public web servers -- no password, no encryption, reachable by anyone with the URL, for months. The firm had collected the documents to perform age and identity checks, exactly the kind of KYC and age-verification screening that laws are pushing onto more of the internet, then stored the resulting ID scans as if they were disposable public images.
LastPass n/a Jun 2026
customer contact and support data stolen via the Klue supply-chain hack
LastPass disclosed on June 24, 2026 that attackers reached customer data in its Salesforce environment after the Icarus extortion group compromised Klue, a market-intelligence vendor, and stole the OAuth tokens Klue held for many of its customers. Exposed data was limited to names, email addresses, phone numbers, physical addresses, and customer support-case records; LastPass said its products, infrastructure, and encrypted password vaults were not affected. The same Klue supply-chain attack hit more than a dozen firms including Recorded Future, Tanium, and Jamf.
University of Oxford n/a Jun 2026
students' and alumni data exposed in a careers-platform breach
The University of Oxford disclosed in early June 2026 that its CareerConnect careers platform, run by third-party provider Group GTI, had been breached on May 28. Attackers accessed the first names, last names, and email addresses of students, alumni, research staff, and recruiters, plus encrypted passwords for users who logged in with a local password rather than Oxford's single sign-on. Oxford said the attack appeared aimed at harvesting credentials for phishing; no financial or course data was involved. It was Oxford's second third-party breach of 2026.
Nintendo of America n/a Jun 2026
employee survey data stolen from a third-party HR tool
A hacker using the handle SHADOWBYT3$ claimed on June 13, 2026 to have stolen about 859 MB of data from TinyPulse, a third-party employee-survey service used by Nintendo of America, and demanded a $2 million ransom. Nintendo confirmed the incident but said it was limited to internal survey content for a small subset of employees, that its own systems were not compromised, and that no customer or financial data was involved -- disputing the attacker's claim that bank statements and W-9 tax forms were included. Most of the data reportedly dated back several years.
24 billion stolen credential records found exposed in a giant online compilation n/a Jun 2026
Researchers at Cybernews found a publicly exposed database of more than 8.3 terabytes holding about 24 billion credential records -- usernames, passwords, and other account data -- reportedly drawn from 36 sources including Telegram channels, earlier breach compilations, and infostealer logs, with some datasets apparently exported directly from live servers. The trove was taken offline soon after discovery, so the number of duplicate records could not be confirmed.
Council of Europe n/a Jun 2026
staff payslips, personnel files, and CVs claimed stolen
The Council of Europe, the continent's oldest intergovernmental body, said in June 2026 that it was investigating a data-breach claim by the ShinyHunters extortion group. The attackers claimed to have taken more than 409,000 payslips covering over 10,000 staff from 2011 to 2026, along with thousands of personnel files and CVs, said to include names, dates of birth, home addresses, phone numbers, employee IDs, salaries, bank-account and tax details, and some medical records.
Mediaworks Hungary n/a May 2026
15 million files leaked from the country's largest media group
Mediaworks, Hungary's largest media group, disclosed on May 4, 2026 that it had suffered a serious cyberattack on April 30. Hungary's data protection authority later said the attackers had unlawfully obtained nearly 15 million files, about 8.5 terabytes, and published them on the dark web, including names, addresses, bank-account details, internal records, and public-interest documents. The company said its investigation was ongoing and warned readers about phishing abuse.
Instructure/Canvas 30M+ May 2026
30M+ students' and staff data stolen
ShinyHunters breached the Canvas learning-management system run by Instructure twice within two weeks in April-May 2026, claiming data from nearly 9,000 institutions (including Harvard and Princeton). Personal information of more than 30 million students and staff was taken -- names, emails, student IDs and private messages -- and the attackers defaced Canvas login screens during finals. Instructure paid a ransom.
Blank Rome n/a May 2026
law-firm breach exposes clients' IDs and health data
Law firm Blank Rome disclosed a May 2026 breach in which an attacker posed as IT over the phone and tricked an attorney into uploading files to an external account. The exposed client information may have included Social Security numbers, driver's license, state ID and passport numbers, other government IDs, financial account and payment-card data, and medical and health-insurance information.
Tabiq 1M+ May 2026
1 million hotel guests' passports and licenses left on the open web
Tabiq, a Japanese hotel check-in platform run by startup Reqrea, left an Amazon S3 storage bucket public, exposing more than 1 million guests' passports, driver's licenses, and facial-verification selfies to anyone who knew the bucket name. Files spanned early 2020 to May 2026 and covered travelers from many countries. A researcher found it and TechCrunch alerted the company and Japan's JPCERT, after which it was locked down; the exposure window and whether others accessed it remain unknown.
France 11.7M+ Apr 2026
national ID portal (ants.gouv.fr) breach hits 11.7M accounts
France Titres, which runs the government identity portal ants.gouv.fr, confirmed a breach exposing about 11.7 million accounts (a threat actor advertised up to 19 million). Exposed fields included login IDs, names, email addresses, dates of birth and unique account IDs, and sometimes postal addresses, birthplaces and phone numbers. A 15-year-old suspect was detained on April 25, 2026.
FBI n/a Apr 2026
China-linked breach of a wiretap surveillance system
The FBI told Congress that a suspected China-linked intrusion into an unclassified network holding pen-register and trap-and-trace surveillance data (the DCS-3000 'Red Hook' collection system) was a 'major incident' under FISMA. First detected Feb 17, 2026 and reportedly reached through a commercial ISP's vendor infrastructure, the breach is believed to have exposed the phone numbers of people under active FBI surveillance.
Charter/Spectrum 4.9M+ Apr 2026
vishing call exposes millions of customer records
One of the largest U.S. broadband providers was compromised on April 1, 2026 when the ShinyHunters group used a voice-phishing call to obtain an employee's Microsoft Entra credentials and reach Charter's Salesforce environment. Charter said only sales tools were affected, but breach monitoring tied the published data to about 4.9 million people (the group claimed 42 million records): names, emails, phone numbers and home addresses.
Medtronic 9M+ Apr 2026
medical-device maker breach exposes SSNs and health data
Medical-device company Medtronic began notifying customers of a breach detected in April 2026 that exposed names, contact details, dates of birth, Social Security numbers, and health-related information. The ShinyHunters group claimed more than 9 million records; the listing was later removed, suggesting a ransom was paid.
Carnival 6M+ Apr 2026
cruise operator breach exposes 6M passengers' passport and license numbers
Carnival, the world's largest cruise operator, disclosed that a social-engineering attack on a single employee account (identified April 14, 2026) let an attacker copy personal data on about 6 million people, including names, addresses, dates of birth, and government-issued ID numbers such as driver's license and passport numbers.
Kubota n/a Apr 2026
breach exposes SSNs of customers and dependents
Equipment maker Kubota disclosed a breach that took place between March and April 2026, which may have exposed full names -- including those of dependents -- and Social Security numbers, among other personal details. The company had not confirmed the number of people affected.
Duc money-transfer app n/a Apr 2026
KYC passports, licenses and selfies left on open server
A misconfigured, password-free Amazon server run by the money-transfer app Duc left hundreds of thousands of files reachable to anyone, dating back to 2020 -- government-issued IDs such as driver's licenses and passports, know-your-customer selfies, and spreadsheets of names, addresses, and transactions. Another example of KYC identity checks becoming the leak.
Citizens and Frost banks 3.7M+ Apr 2026
3.6 million exposed through a shared vendor
In April 2026 the Everest ransomware group claimed data from two major US banks breached through a shared third-party vendor rather than the banks themselves -- about 3.4 million records from Citizens and over 250,000 Social Security numbers and tax IDs from Frost Bank -- a textbook case of shared-vendor risk cascading across financial institutions.
McGraw-Hill 13.5M Apr 2026
13.5 million accounts exposed in Salesforce data theft
Education publisher McGraw-Hill was caught in the 2026 wave of Salesforce-related thefts by ShinyHunters; Have I Been Pwned confirmed 13.5 million unique email addresses in the leaked data, alongside names, phone numbers, and physical addresses -- a broad spear-phishing risk across its student and educator base.
ADT 5.5M Apr 2026
5.5 million customers' data stolen
Home-security company ADT confirmed an April 2026 intrusion after ShinyHunters claimed the theft; Have I Been Pwned measured about 5.5 million people in the exposed dataset. Stolen data was mostly names, phone numbers, and addresses, with dates of birth and the last four digits of Social Security or tax IDs included for a smaller share.
Hallmark Cards 2.8M Mar 2026
2.8 million accounts leaked after extortion
In March 2026 ShinyHunters claimed records from Hallmark Cards' Salesforce environment and, after an unmet extortion deadline, leaked more than 2.8 million unique accounts -- customer names, phone numbers, physical and email addresses, and dates of birth.
Aura 1.5M Mar 2026
1.5 million exposed at an identity-protection company
In March 2026 identity-protection company Aura confirmed a breach after an employee fell for a voice-phishing (vishing) attack, giving ShinyHunters access through a marketing tool. More than 1.5 million records of customer names, addresses, phone numbers, and email addresses were exposed -- a pointed irony for a firm that sells identity protection.
Lloyds Banking Group 500K+ Mar 2026
500,000 customers' bank and National Insurance data exposed
A March 2026 software glitch at Lloyds Banking Group let around half a million UK customers of Lloyds, Halifax, and Bank of Scotland view other people's sensitive data -- transactions, sort codes, account numbers, and even National Insurance numbers -- and in some cases data belonging to customers of other banks.
NYC Health + Hospitals 1.8M+ Feb 2026
1.8M patients' records, IDs and biometrics taken
The largest public health system in the U.S. said an attacker reached its network through a third-party vendor from late November 2025 through February 2026 and copied files on at least 1.8 million people -- medical records, Social Security numbers, driver's licenses and passports, and biometric fingerprints and palm prints -- one of the largest healthcare breaches reported to HHS in 2026.
Odido (T-Mobile Netherlands) 6.4M Feb 2026
6.2 million customers, with passport and license numbers
In February 2026 attackers broke into a customer-contact system at Odido, the largest mobile operator in the Netherlands (formerly T-Mobile NL), and downloaded data on about 6.39 million people -- roughly one in three Dutch residents. The haul included names, addresses, phone numbers, dates of birth, bank account (IBAN) numbers, and, for many, passport or driver's-license numbers, a near-complete identity-theft toolkit.
Figure Lending 3M+ Feb 2026
3 million records with SSNs stolen
US fintech lender Figure Lending confirmed a February 2026 breach after an employee was socially engineered into giving ShinyHunters access via the company's Okta single-sign-on. More than 3 million records were exposed, including names, dates of birth, addresses, phone numbers, email addresses, passwords, and Social Security numbers.
Senegal (DAF) n/a Feb 2026
national biometric, passport and voter database hit
Senegal's Directorate of File Automation (DAF), the agency that manages national ID cards, biometric records, passports, and electoral data, was hit by a February 2026 cyberattack that compromised about 139 terabytes -- the citizen database, biometric records, and immigration files -- and halted document production for days. The number of individuals was not quantified, but it reaches much of the country.
TriZetto Provider Solutions 3.4M Feb 2026
3.4M affected in healthcare billing vendor breach
TriZetto Provider Solutions, a Cognizant-owned revenue-cycle vendor that processes billions of US healthcare transactions a year, reported a breach to the HHS Office for Civil Rights in February 2026 affecting about 3,433,965 people -- the largest single healthcare breach reported to OCR in the first half of 2026. An unauthorized party had accessed insurance eligibility-verification records, with access beginning around November 2024.
Match Group 10M+ Jan 2026
10M+ records claimed stolen from Hinge, Match, and OkCupid
ShinyHunters claimed in late January 2026 to have stolen more than 10 million records tied to Match Group's dating apps -- Hinge, Match, and OkCupid -- via a social-engineering attack on Okta SSO access. The data reportedly included user IDs, IP addresses, Hinge subscription transaction IDs and amounts paid, and internal employee emails. Match Group said it was investigating.
Basic-Fit 1M+ 2026
1 million gym members' bank details exposed
European gym chain Basic-Fit confirmed a 2026 breach affecting around 1 million members, exposing bank account details, names, dates of birth, and other contact information -- the account numbers being the standout risk for direct-debit fraud.
Navia Benefit Solutions 2.7M Jan 2026
2.7 million people's SSNs and licenses stolen
Benefits administrator Navia disclosed a breach spanning late December 2025 into January 2026 that hit about 2.7 million people, exposing names, dates of birth, Social Security numbers, driver's-license information, phone numbers, email addresses, and details of their benefits accounts.
Hyundai 2.7M+ 2026
2.7 million owners' SSNs and driver's licenses exposed
Automaker Hyundai suffered a 2026 breach compromising the personal data of up to 2.7 million owners, with the stolen records including Social Security numbers and driver's-license details.
Nissan n/a 2026
employees' SSNs and national IDs stolen via Oracle zero-day
Nissan warned current and former employees of a 2026 breach after attackers exploited an Oracle PeopleSoft vulnerability, part of a wider extortion campaign. Exposed data could include contact and banking information, Social Security numbers, Social Insurance Numbers, national identification numbers, and tax and beneficiary details.
Illinois and Minnesota human-services agencies 1M+ Jan 2026
~1 million exposed
System failures at the Illinois and Minnesota human-services departments exposed the personal data of nearly a million people in early 2026. In Illinois sensitive case information sat publicly visible for years; in Minnesota excessive internal access led to improper disclosure. Exposed fields included names, addresses, dates of birth, Medicaid IDs, and the first digits of Social Security numbers.
7-Eleven 185K+ 2026
185,000 people's SSNs and licenses in franchise-document leak
A 2026 breach tied to 7-Eleven's franchisee-document systems exposed roughly 185,000 people; filings reportedly referenced Social Security numbers and driver's-license numbers, and the company offered identity-protection services to those affected.
Xsolis 1.4M Jan 2026
1.4 million patients' SSNs and health data stolen
Tennessee healthtech firm Xsolis disclosed a January 2026 breach, blamed on a phishing attack, that affected roughly 1.4 million people. Social Security numbers and health-insurance information were among the data believed stolen.
2025
Petco n/a Dec 2025
customers' SSNs and driver's licenses left accessible by a software setting
Petco disclosed in December 2025 that a misconfigured setting in one of its applications had left customer files accessible online, exposing names, Social Security numbers, driver's license numbers, financial account and card numbers, and dates of birth. Discovered during a July 2025 security review, the retailer notified customers months later and filed breach reports in Texas, California, Massachusetts, and Montana. Petco, which serves over 24 million customers a year, did not disclose the total number affected.
F5 n/a Oct 2025
nation-state actor lived in BIG-IP source code for a year
F5 disclosed on October 15, 2025 that a nation-state actor -- linked by Bloomberg to China's BRICKSTORM/UNC5221 cluster -- had persistent access to the development environment of BIG-IP, the load balancers and gateways that sit in front of a huge share of the world's networks, for at least twelve months. Stolen: portions of BIG-IP source code, F5's internal notes on undisclosed vulnerabilities, some customer configurations, and employee data. Detection came August 9; disclosure waited until October at the Justice Department's direction. CISA issued an emergency directive the same day -- its language was that the actor posed an imminent threat capable of full compromise of targeted systems -- ordering every federal civilian agency to patch or disconnect, with roughly 680,000 F5 devices visible on the open internet. Nobody's personal data was the product here; the product was the master key to everyone else's.
Discord 70K+ Oct 2025
70,000 government-ID photos stolen from an age-verification vendor
Discord said in October 2025 that hackers breached a third-party support vendor and stole data from users who had filed age-related appeals, including about 70,000 photos of government IDs (driver's licenses and passports) taken as selfies to prove their age. Also exposed were names, usernames, emails, support-chat transcripts, limited billing metadata including the last four digits of cards, and IP addresses. The attackers claimed a far larger haul of up to 2.1 million ID images, which Discord disputed as an extortion tactic.
SSA 300M+ Aug 2025
live copy of every American's Social Security file moved to a cloud only DOGE could see
The Social Security Administration's own chief data officer, Charles Borges, filed a whistleblower complaint with the Office of Special Counsel and Congress on August 26, 2025: DOGE staffers had copied NUMIDENT -- the master file of every Social Security number ever issued, over 548 million records with names, birth dates, parents' names, citizenship, and ethnicity for 300M+ living Americans -- into a cloud environment only DOGE personnel could access, with no security oversight and no logging of who touched it. Career security officials had refused the request; a DOGE-affiliated official approved it with one word. Borges, who was never consulted, warned that a compromise could mean reissuing every American a new SSN. No exfiltration was proven -- that is precisely the problem: with no tracking, no one can say. Filed here as an exposure, not a confirmed theft, and as the ledger's largest single concentration of identity data placed outside normal controls.
TransUnion 4.4M Aug 2025
4.4 million people's SSNs exposed at a credit bureau
Credit bureau TransUnion disclosed in August 2025 that attackers reached a third-party Salesforce environment and took data on more than 4.4 million US individuals, including names, addresses, dates of birth, and unredacted Social Security numbers. TransUnion said its core credit database was not affected.
Salesloft Drift supply-chain campaign n/a Aug 2025
Salesforce data siphoned from hundreds of companies
Between roughly August 8 and 18, 2025, the threat actor tracked as UNC6395 used OAuth tokens stolen from Salesloft's Drift chat integration to reach the Salesforce environments of around 760 organizations, exporting an estimated 1.5 billion records. The exposed data was mostly business contact details (names, email addresses, phone numbers, job titles) and customer support-case content; investigators found the attackers combed the data for embedded secrets such as AWS keys and passwords to pivot into other systems. Confirmed victims included Cloudflare, Palo Alto Networks, Zscaler, Proofpoint, Tenable, and a small number of Google Workspace accounts.
Farmers Insurance 1.1M Aug 2025
1.11M customers' licenses taken in the Salesforce wave
Farmers Insurance notified 1,111,386 customers in August 2025 that names, addresses, birth dates, driver's license numbers, and partial Social Security numbers were stolen from a third-party vendor's database on May 29 -- one hit among dozens in the year's ShinyHunters/UNC6040 Salesforce campaign, in which voice-phishing calls talked employees into linking a malicious OAuth app to their Salesforce instance, after which the attackers simply downloaded the CRM and extorted the owner. The Farmers entry earns its place as the wave's insurance-sector exemplar: a company serving 10 million households, breached through a vendor it wouldn't name, in a campaign whose victims routinely say third-party CRM rather than the word Salesforce.
Qantas 5.7M Jul 2025
5.7 million customers' data taken via a call-center vendor
Qantas confirmed that a June-July 2025 attack on a third-party call-center platform, attributed to the Scattered Spider group, exposed data on 5.7 million customers -- names, email addresses, phone numbers, dates of birth, addresses, and frequent-flyer details. The data was later leaked after the airline refused an extortion demand.
Allianz Life 1.4M+ Jul 2025
most of 1.4 million customers' data stolen
Allianz Life disclosed a July 2025 breach, tied to the Salesforce-targeting extortion wave, that reached a majority of its roughly 1.4 million customers along with financial professionals and some employees, exposing personal data including Social Security numbers. The company said it contained the intrusion within a day.
Tea 72K+ Jul 2025
72,000 images including women's verification IDs leaked on 4chan
Tea, a women-only dating-safety app that required a selfie and government ID to join, left a legacy Firebase storage bucket unsecured, exposing about 72,000 images in July 2025 -- roughly 13,000 verification selfies and government IDs (driver's licenses and passports) plus 59,000 images from posts and messages. A second flaw exposed more than a million private messages. The verification photos were downloaded and reposted on 4chan, putting the app's users at risk.
City of St. Paul, Minnesota 12K Jul 2025
residents' and staff data leaked in the Interlock ransomware attack
The Interlock ransomware group attacked the City of St. Paul in late July 2025, prompting a full network shutdown, a local state of emergency, and activation of the Minnesota National Guard. After the city refused to pay, the gang leaked about 43 GB taken from a Parks and Recreation network drive. The city confirmed the exposed data covered 12,484 people -- current and former employees, interns, volunteers, and program participants -- including names, addresses, phone numbers, dates of birth, and Social Security numbers.
Episource 5.4M Jun 2025
5.4 million patients' health data exposed
Episource, an Optum-owned medical billing and risk-adjustment firm, detected unauthorized network access in early 2025 and disclosed in June that the breach affected more than 5.4 million people across the health systems it serves, exposing health and personal information.
AT&T 86M+ Jun 2025
86 million records re-leaked in 2025 with SSNs decrypted
In May-June 2025 a threat actor posted a repackaged AT&T customer database on a Russian cybercrime forum -- about 86 million unique records including full names, addresses, phone numbers, and nearly 44 million Social Security numbers. Crucially, SSNs and birthdates that were encrypted in the earlier 2021/2024 thefts were now circulating fully decrypted in plaintext, turning old stolen data into ready-to-use identity-theft kits.
McHire (Paradox.ai) 64M+ Jun 2025
64 million McDonald's job applicants exposed by a '123456' password
Security researchers found that McHire, the McDonald's hiring chatbot built by Paradox.ai, protected an admin account with the password '123456' and had an insecure API (IDOR) that together exposed up to 64 million job applicants' names, emails, phone numbers, IP addresses, some home addresses, and chat transcripts. Disclosed on June 30, 2025 and fixed within a day, no Social Security numbers or financial data were involved. Paradox.ai said only the researchers accessed the data and that no records were leaked publicly.
Coinbase 69K May 2025
69,000 customers' data leaked by bribed support agents
Cybercriminals bribed overseas support contractors at vendor TaskUs to pull data on 69,461 Coinbase customers, an intrusion that began in December 2024 and was discovered in May 2025. The stolen records included names, addresses, phone numbers, email addresses, masked Social Security and bank-account numbers, and images of government-issued IDs submitted for identity verification. No passwords, private keys, or funds were taken. Coinbase refused a $20 million ransom and offered a matching bounty instead.
UK Legal Aid Agency 2.1M+ May 2025
2.1 million applicants' sensitive records stolen
The UK's Legal Aid Agency, part of the Ministry of Justice, was hit by a cyberattack detected on April 23, 2025 and disclosed on May 19. Attackers downloaded a large amount of data on people who applied for legal aid through its online service going back to 2007 -- contact details, addresses, dates of birth, national ID numbers, criminal history, employment status, and financial data such as debts and payments. The group claimed about 2.1 million records, and the MoJ admitted the agency's systems had been known to be vulnerable for years.
Kettering Health 1.7M May 2025
1.7 million patients' records stolen in the Interlock ransomware attack
Interlock ransomware operators breached the 14-hospital Ohio health system Kettering Health, holding access from April 9 to May 20, 2025, when they deployed ransomware and triggered a system-wide outage that forced staff back to paper records. The gang exfiltrated roughly 941 GB of data and published it after Kettering refused to pay. Confirmed at 1,695,382 individuals, the stolen data included names, Social Security numbers, driver's license and passport numbers, financial account numbers, medical and treatment information, health insurance and billing records, and account usernames and passwords.
TeleMessage n/a May 2025
the Signal clone archiving officials' texts, cracked in 20 minutes
After a Reuters photo caught national security adviser Mike Waltz using TM SGNL -- a modified Signal that archives messages for compliance -- a hacker breached its maker TeleMessage in what they described as 15-20 minutes of effort. The clone kept plaintext copies of supposedly end-to-end-encrypted messages on its archive servers; the haul included message contents and metadata tied to Customs and Border Protection, Coinbase, Scotiabank, and, per a Reuters review of the later 410GB DDoSecrets release, more than 60 government users -- disaster responders, diplomats, Secret Service members, a White House staffer. Cabinet-level chats weren't in the stolen set, but the architecture was the story: every agency that bolted an archiving middleman onto Signal had quietly traded away the encryption itself. Smarsh suspended the service; CBP disabled it immediately.
DaVita 2.7M Apr 2025
2.7 million dialysis patients' SSNs and health data stolen
The Interlock ransomware group attacked kidney-dialysis giant DaVita in April 2025, exfiltrating and encrypting data on about 2.7 million patients from a lab database -- names, dates of birth, addresses, Social Security numbers, dialysis and health-insurance records, and even images of checks.
Hertz n/a Apr 2025
customers' driver's licenses stolen via Cleo file-transfer flaw
Hertz, including its Dollar and Thrifty brands, confirmed in April 2025 that customer data had been stolen after attackers exploited zero-day flaws in Cleo's file-transfer software in late 2024. Exposed data included names, contact details, dates of birth, credit-card and driver's license information; a smaller group also had Social Security or other government-ID numbers, passport data, or Medicare/Medicaid IDs taken. Hertz gave no total but said it would be inaccurate to call it millions. The Clop ransomware gang was behind the wider Cleo campaign.
Co-op 6.5M Apr 2025
all 6.5 million members' personal data stolen
UK retailer Co-op confirmed that a late-April 2025 cyberattack by Scattered Spider affiliates stole the personal data of all 6.5 million of its members -- names, addresses, email addresses, phone numbers, and dates of birth. No financial, transaction, or password data was taken. The attack forced Co-op to shut down systems, emptying some store shelves, but early isolation stopped the DragonForce ransomware from being deployed. Four suspects aged 17-20 were later arrested.
SK Telecom 23.2M Apr 2025
23.2M subscribers' SIM keys stolen; record $97M fine
South Korea's biggest carrier disclosed in April 2025 that attackers had reached its Home Subscriber Server and siphoned 25 categories of data on 23.2 million people -- phone numbers, IMSI subscriber identities, and the USIM authentication keys that make SIM cloning possible. The regulator's autopsy was brutal: internet-facing, management, and internal networks linked on one system, management servers needlessly connected to the subscriber core, 26.1 million SIM authentication keys stored unencrypted, and, in the privacy commission chairperson's words, a company in a vulnerable state for a long time that kept missing its chances. SKT replaced every subscriber's SIM card and spent about $812M on remediation and compensation; the PIPC still levied a record 134.8 billion won (~$97M) fine -- the largest in Korean history -- which SKT sued to overturn in January 2026, arguing no user suffered financial loss.
Yale New Haven Health 5.5M+ Mar 2025
5.5 million patients' data stolen
Yale New Haven Health, Connecticut's largest health system, disclosed a March 2025 hack in which attackers stole the personal data of about 5.5 million patients, including names, dates of birth, contact details, Social Security numbers, and medical-record information. Patient care was not disrupted.
Absolute Dental 1.2M Feb 2025
1.2 million patients exposed after a managed-services account was abused
Absolute Dental, a Nevada practice with more than 50 locations, was breached between February 19 and March 5, 2025 after attackers ran a malicious version of a legitimate software tool through an account tied to its third-party managed-services provider. A file review concluded on July 28, 2025 confirmed 1,223,635 people affected. Exposed data included names, contact details, dates of birth, Social Security numbers, driver's license or state-ID information, passport or other government-ID information, and health information; a smaller subset also had financial-account or payment-card data exposed.
Conduent 62.2M+ 2025
62 million people's SSNs and health data exposed
Business-services and government-contracting giant Conduent disclosed a ransomware breach in an April 2025 SEC filing; attackers had been in its systems from October 2024 to January 2025 and took more than 8TB of data. Notifications expanded through 2026 as states reported millions of residents affected, and healthcare-breach reporting ultimately placed the total above 62 million people, with Social Security numbers and medical information among the exposed data.
PowerSchool 62M+ Jan 2025
62 million students' records, including SSNs, stolen
A single stolen contractor login let attackers into PowerSchool's K-12 student-information system in January 2025; reporting placed the reach at more than 62 million students and 9.5 million teachers across North America. Exposed data included grades, medical information, and Social Security numbers. PowerSchool paid a ransom but data still surfaced.
Blue Shield of California 4.7M 2025
4.7 million members' health data shared with Google Ads
Blue Shield of California disclosed in 2025 that a misconfigured Google Analytics setup had, from 2021 to 2024, shared the protected health information of about 4.7 million members with Google's advertising system -- names, insurance plan details, medical claims data, and doctor-search activity -- potentially fueling targeted ad campaigns. A textbook case of ad-tech tracking quietly leaking medical data.
2024
Salt Typhoon n/a Oct 2024
China inside US phone networks, through the wiretap door
Chinese state hackers spent years inside at least nine major US carriers -- AT&T, Verizon, T-Mobile, Lumen, Charter and more -- in what Sen. Mark Warner called the worst telecom hack in the nation's history and the FBI called gigantic and seemingly indiscriminate: over a million call records, who called whom, when, and from where, with the ability to geolocate millions and record calls at will, sparing no one, not even children. The entry that should haunt every lawful-access debate: Salt Typhoon compromised the CALEA wiretap portals that carriers are legally required to build for court-ordered surveillance -- the mandated backdoor became the foreign intelligence service's front door. Targets included the phones of both 2024 presidential campaigns. By August 2025 the FBI counted 200+ victim companies across 80 countries; one carrier had hosted the intruders for three years before detection. No breach notification letters, no credit monitoring -- the people affected are simply everyone with a phone.
National Public Data 1.3B+ 2024
1.3 billion people's SSNs exposed by a data broker
Background-check data broker National Public Data exposed roughly 2.9 billion records covering about 1.3 billion people through a misconfigured database -- full names, addresses, dates of birth, Social Security numbers, phone numbers, and emails. The fallout pushed NPD into bankruptcy.
Change Healthcare 193M+ 2024
190 million people in the largest US health breach
A ransomware attack on UnitedHealth's Change Healthcare -- which processes a huge share of US medical claims -- exposed the data of roughly 193 million people (a tally that nearly doubled UnitedHealth's initial estimate), including health records, Social Security numbers, and financial information, making it the largest healthcare breach in US history.
AT&T 73M+ 2024
73 million account records exposed, plus near-total call logs
AT&T disclosed in 2024 that data on about 73 million current and former account holders -- including Social Security numbers -- had leaked online, and separately that call and text metadata for nearly all its wireless customers had been downloaded from a third-party cloud platform.
El Salvador 5.1M 2024
national ID and facial photos of 80% of citizens leaked
In April 2024 a threat actor dumped 144GB of data on more than 5.1 million Salvadorans -- over 80% of the population -- including a high-definition headshot of each person labeled with their national ID (DUI) number, plus names, birthdates, phone numbers, emails, and addresses. It is among the first breaches to expose the biometric data of nearly an entire country.
Ticketmaster 560M+ 2024
560 million customers exposed in the Snowflake wave
As part of the 2024 Snowflake campaign -- in which stolen logins gave attackers access to about 165 companies' cloud data because multi-factor authentication was not enforced -- an alleged 560 million Ticketmaster customer records were taken, including names, contact details, and partial payment information.
Advance Auto Parts 2.3M 2024
job applicants' SSNs exposed via Snowflake
Advance Auto Parts was among the Snowflake-wave victims in 2024; the breach exposed sensitive data on more than 2.3 million people, largely job applicants, including Social Security numbers and other personal details.
Kaiser Permanente 13.4M 2024
13.4 million members' health data sent to ad trackers
Kaiser Permanente disclosed in 2024 that tracking technologies on its websites and apps had transmitted the personal and health-related data of about 13.4 million members to third-party advertisers including Google, Microsoft Bing, and X -- names, IP addresses, and details of how members used its health sites. It was the largest confirmed US health breach of 2024 and a stark example of surveillance-style ad tracking spilling medical data.
Indonesia (KPU) 252M+ 2024
252 million voter records, including passport data, put up for sale
Ahead of Indonesia's 2024 election, a threat actor calling themselves 'Jimbo' advertised a breach of the General Elections Commission (KPU) system totaling about 252 million voter entries -- national identity (NIK) numbers, names, birthplaces and dates, addresses, and reportedly passport details -- for roughly two bitcoin, in a country of about 274 million people.
Dell 49M+ 2024
49 million customer records scraped
Dell disclosed a 2024 breach in which an attacker abused a partner portal to scrape a database of about 49 million customer records, including names, physical addresses, and order and hardware information.
2023
23andMe 6.9M+ 2023
6.9 million people's genetic and ancestry data exposed
A credential-stuffing attack on 23andMe in 2023 reached about 6.9 million people's profiles, exposing ancestry, relationship, and in some cases health-related genetic data -- information that, once out, can never be changed.
MOVEit / Clop 95M+ 2023
95 million+ people hit across thousands of organizations
The Clop ransomware group exploited a zero-day in the widely used MOVEit file-transfer tool in 2023, cascading through thousands of companies and government agencies and ultimately exposing the data of more than 95 million people -- a defining supply-chain breach.
Latitude Financial 14M+ 2023
14 million people's licenses and passports stolen
A 2023 breach of Australian lender Latitude Financial, begun with stolen employee credentials, affected about 14 million people across Australia and New Zealand -- including roughly 7.9 million driver's license numbers and 53,000 passport numbers, some records dating back to 2005. Latitude offered to reimburse customers who replaced stolen ID documents.
India (ICMR) 815M+ 2023
815 million citizens' Aadhaar and passport data leaked
In late 2023 a threat actor put the personal data of more than 800 million Indian citizens up for sale, drawn from records held by the Indian Council of Medical Research, including names, addresses, passport numbers, and Aadhaar national-ID numbers -- one of the largest exposures of government-ID data ever.
HCA Healthcare 11M+ 2023
11 million patients' data stolen and posted for sale
Hospital giant HCA Healthcare disclosed in 2023 that an external storage location was accessed and data on about 11 million patients was stolen and offered for sale, including names, contact details, dates of birth, and appointment information. It was the largest US health-data breach reported that year until Change Healthcare.
Comcast Xfinity 35.8M 2023
35.8 million customers exposed via Citrix Bleed
Attackers exploited the Citrix Bleed vulnerability in October 2023 to reach Comcast Xfinity's internal systems, exposing usernames and hashed passwords for about 35.8 million customers -- essentially the entire base -- and, for many, names, contact details, the last four digits of Social Security numbers, dates of birth, and security questions. Comcast later settled for $117.5 million.
Mr. Cooper 14.7M+ 2023
14.7 million mortgage customers' data stolen
Mortgage servicing giant Mr. Cooper disclosed a late-2023 cyberattack that exposed the data of about 14.7 million current and former customers, including names, addresses, dates of birth, Social Security numbers, and bank account numbers tied to their home loans.
Bangladesh 50M+ 2023
50 million citizens' national ID data exposed by a government site
In mid-2023 a researcher found a Bangladeshi government website leaking the personal data of tens of millions of citizens -- names, contact details, and national ID card numbers drawn from the country's birth-and-death registration system -- reachable without authentication. Reporting placed the exposure at around 50 million people.
UK Electoral Commission 40M+ 2023
up to 40 million voters' registers accessed
The UK Electoral Commission disclosed in 2023 that hackers had sat undetected in its systems for over a year, gaining access to electoral registers holding the names and addresses of up to 40 million voters, including many not otherwise on public rolls. The intrusion was discovered 14 months after it began.
Indonesia 34.9M 2023
34.9 million passport holders' data leaked from Immigration
In July 2023 the hacker 'Bjorka' leaked data on 34.9 million Indonesian passport holders taken from the Immigration Directorate General -- full names, passport numbers, issue and expiry dates, dates of birth, and gender -- and offered it for sale, spanning documents issued from 2009 to 2020.
2022
Optus 9.8M+ 2022
9.8 million Australians' passports and licenses exposed
A 2022 breach of Australian telecom Optus, traced to an exposed, unauthenticated API, exposed the data of about 9.8 million current and former customers -- roughly a third of Australia's population -- including names, dates of birth, addresses, and passport, driver's license, and Medicare numbers. Optus reserved A$140 million partly to replace compromised identity documents.
Medibank 9.7M+ 2022
9.7 million health-insurance customers' records leaked
A 2022 breach of Australian health insurer Medibank, entered via stolen admin credentials, exposed data on about 9.7 million current and former customers -- names, dates of birth, Medicare and passport numbers, and highly sensitive health-claims data including diagnoses and procedures. When Medibank refused a US$10M ransom, the data was published on the dark web.
Shanghai police 1B+ 2022
1 billion residents' IDs and surveillance records exposed
In 2022 a hacker offered a 23TB dump from the Shanghai National Police database -- roughly one billion Chinese residents -- exposing names, addresses, national ID numbers, phone numbers, and photos of ID cards, passports, and driver's licenses, alongside detailed police and criminal-case records. Files included movement tracking and reports of people punished for using a VPN to post critical remarks, laying bare a state surveillance apparatus. Likely left exposed by a misconfigured, password-free dashboard.
Twitter 5.4M 2022
5.4 million accounts exposed via an API flaw
A now-patched Twitter API flaw let attackers match email addresses and phone numbers to accounts, and in 2022 a dataset of about 5.4 million users built this way was put up for sale.
Neopets 69M 2022
69 million players breached
The children's virtual-pet game Neopets was breached in 2022 after attackers spent 18 months inside its systems, stealing data on about 69 million current and former users -- names, emails, birth dates, gender, PINs, and hashed passwords -- plus source code.
Cash App 8.2M 2022
8.2 million users' financial data taken by an ex-employee
Block disclosed in 2022 that a former employee had downloaded internal reports covering about 8.2 million Cash App Investing users, exposing names, brokerage account numbers, portfolio holdings, and trading activity.
Shields Health Care 2M+ 2022
2 million patients' SSNs and health data stolen
Massachusetts medical provider Shields Health Care Group disclosed a 2022 breach affecting more than 2 million people across 56 facilities, exposing Social Security numbers, diagnoses, medical records, billing information, and other personal data.
Los Angeles Unified School District n/a 2022
students' IDs and records leaked
The Vice Society ransomware group leaked about 500GB of data from the Los Angeles Unified School District, the second-largest US school district, in 2022 -- including students' passport and Social Security details, health information, and psychological assessments -- after the district refused to pay.
2021
LinkedIn 700M+ 2021
700 million users' profile data scraped and sold
Data associated with about 700 million LinkedIn users -- roughly 90% of its base -- was scraped and offered for sale in 2021, including names, email addresses, phone numbers, geolocation, and professional details usable for targeted phishing and social engineering.
Facebook 533M+ 2021
533 million users' phone numbers leaked
The phone numbers and profile details of about 533 million Facebook users across 106 countries were posted online for free in 2021, tied to a vulnerability abused before 2019. Phone numbers cannot be changed as easily as passwords, keeping the data useful to scammers for years.
T-Mobile 76.6M+ 2021
76.6 million customers' SSNs and licenses exposed
T-Mobile confirmed in 2021 that a breach exposed the personal data of about 76.6 million current, former, and prospective customers, including names, dates of birth, Social Security numbers, and driver's license or ID information.
Argentina (RENAPER) 45M+ 2021
national ID data for the entire population stolen
In 2021 a hacker obtained the contents of RENAPER, Argentina's National Registry of Persons, which issues national ID cards to every citizen -- exposing the ID-card data, including photos, of essentially the country's entire population of about 45 million. The government suspected an insider; the data was offered for sale on hacking forums.
Air India 4.5M 2021
4.5 million passengers, with passport data
Air India disclosed a 2021 breach, stemming from a compromise at IT provider SITA, that affected about 4.5 million passengers worldwide and exposed names, birth dates, contact details, passport information, and some payment card data.
EssilorLuxottica 77M+ 2021
77 million records exposed
Eyewear giant EssilorLuxottica had about 77 million records exposed tied to a 2021 breach, including names, contact details, and health-related eyecare information.
2020
MGM Resorts 142M+ 2020
142 million hotel guests' details posted online
Details of MGM Resorts hotel guests -- names, addresses, phone numbers, dates of birth, and emails -- were posted on hacker forums. First reported in early 2020 as 10.6 million guests, the exposed set was later found being sold at about 142 million records. MGM said no passwords or payment card data were included.
Wattpad 270M+ 2020
270 million records leaked
The storytelling platform Wattpad suffered a 2020 breach exposing roughly 270 million records -- names, email addresses, hashed passwords, dates of birth, and other profile data. The database, tied to the ShinyHunters group, was first sold privately and later dumped for free on hacker forums.
easyJet 9M 2020
9 million travelers' data stolen
UK low-cost airline easyJet disclosed a 2020 breach that exposed the email addresses, names, and travel records of about 9 million customers, and the full credit card details (including CVV) of roughly 2,200 of them. The airline was criticized for waiting months to notify customers.
Marriott 5.2M 2020
5.2 million guests hit in a second breach
In March 2020 Marriott disclosed a fresh breach -- distinct from its 2018 Starwood incident -- after attackers used two employees' login credentials to siphon data on about 5.2 million guests over roughly a month, including names, contact details, dates of birth, gender, and loyalty account information. No payment data was taken.
Broadvoice 350M+ 2020
350 million records, including voicemail transcripts
A researcher found unsecured databases from VoIP provider Broadvoice exposing more than 350 million records -- caller names, phone numbers, and locations -- along with hundreds of thousands of transcribed voicemails, some revealing sensitive medical and financial details.
Weibo 538M+ 2020
538 million users' data offered for sale
Data on about 538 million users of the Chinese microblogging platform Weibo surfaced for sale in 2020 -- real names, site usernames, gender, and location, with phone numbers for roughly 172 million of them. No passwords or payment data were reported in the set.
Antheus Tecnologia n/a 2020
76,000 fingerprints exposed by a biometrics firm
Researchers found an unsecured server run by Brazilian biometrics company Antheus Tecnologia holding about 76,000 fingerprint records -- stored as binary data that could be reverse-engineered back into usable fingerprints -- alongside some 81.5 million records with employee and administrator details. Unlike a password, a leaked fingerprint can never be changed.
2019
First American Financial 885M+ 2019
885 million mortgage records exposed
A website design flaw (an insecure direct object reference) left roughly 885 million First American Financial mortgage and title documents publicly accessible without authentication, including Social Security numbers, driver's licenses, bank account details, and images of sensitive financial records going back years.
Capital One 106M+ 2019
106 million applicants' data stolen
A misconfigured web application firewall let an attacker access Capital One data on about 106 million credit-card applicants in the US and Canada in 2019, including names, addresses, credit scores, and roughly 140,000 Social Security numbers and 80,000 linked bank account numbers.
People Data Labs 1.2B+ 2019
1.2 billion people's profiles exposed
In 2019 researchers found an open database holding about 1.2 billion people's aggregated profiles -- names, email addresses, phone numbers, and social-media handles -- traced largely to data brokers People Data Labs and OxyData, illustrating how brokers concentrate risk.
Canva 140M+ 2019
140 million users breached
Design platform Canva was hacked in 2019, exposing about 140 million users' names, usernames, email addresses, and hashed passwords.
Airtel 320M+ 2019
320 million subscribers exposed by an app flaw
A security flaw in an app from Indian telecom giant Airtel exposed the data of about 320 million subscribers in 2019, including names, birth dates, addresses, and other subscriber details.
Facebook 540M+ 2019
540 million records left on public servers
In 2019 researchers found more than 540 million Facebook user records -- account IDs, comments, likes, and some contact details -- sitting exposed on public cloud servers by third-party app developers.
2018
Aadhaar 1.1B+ 2018
1.1 billion citizens' national ID and biometric data exposed
India's Aadhaar national identity system, which links biometric and demographic data to a unique ID number, was reported in 2018 to be accessible through insecure government portals and third-party endpoints, exposing the records of close to 1.1 billion citizens and raising lasting concerns about centralized digital-ID systems.
Marriott / Starwood 500M+ 2018
500 million guests' records, including passports, exposed
Attackers sat inside Starwood's guest reservation system from 2014 until Marriott discovered the intrusion in 2018, exposing data on up to 500 million guests -- names, addresses, dates of birth, and encrypted passport numbers, with some payment data. The UK ICO fined Marriott and it had to reimburse guests for replacement passports.
Exactis 340M+ 2018
340 million records left on an open server
In 2018 marketing data broker Exactis exposed a database of about 340 million records on a publicly accessible server, including phone numbers, emails, home addresses, and detailed personal characteristics -- assembled on people who never knowingly did business with the firm.
Cathay Pacific 9.4M 2018
9.4 million passengers, with passport numbers
Hong Kong carrier Cathay Pacific disclosed a 2018 breach affecting about 9.4 million passengers, exposing names, birth dates, phone numbers, addresses, and -- for many -- passport and Hong Kong ID numbers.
US Postal Service 60M+ 2018
60 million users exposed by an API flaw
A flaw in the US Postal Service's Informed Visibility tool exposed the account details of about 60 million users in 2018 -- usernames, addresses, phone numbers, and mailing data -- to any logged-in user.
Dubsmash 162M+ 2018
162 million accounts breached
The video app Dubsmash was breached in 2018, with about 162 million records -- usernames, email addresses, and hashed passwords -- later put up for sale among a large batch of stolen databases.
MyFitnessPal 150M+ 2018
150 million users breached
Under Armour's MyFitnessPal app was breached in 2018, exposing about 150 million users' usernames, email addresses, and hashed passwords.
MyHeritage 92M+ 2018
92 million users breached
The genealogy site MyHeritage disclosed a 2018 breach exposing the email addresses and hashed passwords of about 92 million users.
2017
Uber 57M Nov 2017
57 million riders and drivers exposed in a concealed breach
In late 2016 two attackers used an AWS key found in a private Uber GitHub repository to download data on 57 million riders and drivers from a cloud storage bucket, including 600,000 U.S. drivers' license numbers plus rider names, emails and phone numbers. Rather than report it, Uber paid the hackers $100,000 to delete the data and stay quiet, disguising it as a bug-bounty payout. New leadership revealed the concealed breach in November 2017; Uber later paid $148 million to settle with all 50 states and its former security chief was criminally convicted.
River City Media 393M+ Mar 2017
1.4 billion records (393 million emails) exposed by a spam operation
A misconfigured backup left the databases of River City Media, a large spam operation, exposed online with no password. A researcher found about 1.4 billion records -- names, email addresses, IP addresses and often physical addresses -- amounting to roughly 393 million unique email addresses. Disclosed in March 2017, it was described at the time as one of the largest single data exposures ever.
Equifax 147M+ 2017
147 million consumers' SSNs and IDs exposed
Credit bureau Equifax failed to patch a known Apache Struts vulnerability, letting attackers roam its network for 76 days in 2017 and steal the Social Security numbers, birth dates, addresses, driver's license details, and some credit card numbers of about 147 million people -- roughly half the US population.
US voter file 198M+ 2017
nearly 200 million voters' profiles left exposed
In 2017 an analytics firm working for the Republican National Committee left a 1.1TB database on an unsecured cloud server, exposing details on nearly 200 million registered US voters -- names, addresses, birth dates, phone numbers, party, and modeled 'ethnicity' and 'religion' fields used for political profiling.
Bell Canada 1.9M+ 2017
1.9 million customer records exposed
Canadian telecom Bell disclosed a 2017 breach exposing about 1.9 million customer email addresses, along with some names and phone numbers.
2016
Uber 57M+ 2016
57 million riders and drivers, breach concealed for a year
Attackers accessed data on about 57 million Uber riders and drivers in 2016, including names, emails, phone numbers, and around 600,000 US drivers' license numbers. Uber paid the hackers to stay quiet and concealed the breach for more than a year.
Mexico 87M+ 2016
87 million voters' records with national IDs exposed
In 2016 a researcher found Mexico's entire voter roll -- about 87 million records including names, addresses, birth dates, and national ID numbers -- sitting in a misconfigured, publicly reachable cloud database. Electoral authorities later fined a political party for failing to secure its copy of the list.
Turkey 50M+ 2016
50 million citizens' national ID database posted online
In 2016 an unnamed hacker posted a downloadable database titled 'Turkish Citizenship Database' containing the personal data of roughly 50 million citizens -- names, addresses, parents' names, places and dates of birth, and national ID numbers.
MySpace 360M+ 2016
360 million accounts leaked
In 2016 about 360 million MySpace account credentials from a pre-2013 breach appeared for sale online. Though the platform was long past its peak, the reused emails and passwords fueled credential-stuffing attacks on other services for years.
Philippines COMELEC 55M+ 2016
55 million voters, with fingerprints, leaked
In the 2016 'Comeleak', the entire voter database of the Philippine Commission on Elections -- about 55 million voters -- was hacked and published, including names, addresses, birth dates, passport data, and fingerprint records.
FriendFinder Networks 412M+ 2016
412 million adult-site accounts breached
The adult-networking company FriendFinder Networks (AdultFriendFinder, Cams.com, Penthouse.com and others) was hacked in 2016, exposing about 412 million accounts spanning two decades -- usernames, email addresses, and passwords stored in plaintext or weak SHA-1 hashes. The sensitive nature of the sites made the exposure especially damaging.
2015
Anthem 78.8M+ 2015
78.8 million health-insurance records stolen
Health insurer Anthem disclosed in 2015 that attackers stole records on 78.8 million people -- names, dates of birth, Social Security numbers, addresses, and employment data. Anthem settled a class action for a then-record $115 million.
US OPM 22.1M+ 2015
22 million federal workers' clearance and fingerprint data stolen
A breach of the US Office of Personnel Management, attributed to Chinese state hackers, exposed the deeply sensitive SF-86 background-investigation files of about 21.5 million security-clearance applicants and relatives, plus 5.6 million fingerprint records -- data that cannot be reissued.
Ashley Madison 32M+ 2015
32 million users of an affair site exposed and extorted
The 2015 breach of Ashley Madison, a site marketed for extramarital affairs, exposed about 32 million users' account details, including names, email addresses, and payment records. The intensely sensitive nature of the data fueled extortion campaigns and lasting personal harm, and remains a landmark case in how breach data can be weaponized against individuals.
Experian / T-Mobile 15M+ 2015
15 million credit applicants exposed
A 2015 breach at credit bureau Experian exposed about 15 million people who had applied for T-Mobile service, including names, addresses, birth dates, and the Social Security or ID numbers used for credit checks.
Excellus BlueCross BlueShield 10M+ 2015
10 million members' SSNs and health data
Excellus BlueCross BlueShield disclosed a 2015 breach affecting about 10 million people, exposing names, birth dates, Social Security numbers, and medical claims -- with attacker access traced back to 2013.
2014
eBay 145M+ 2014
145 million accounts accessed via employee credentials
Attackers used stolen employee credentials to reach eBay's corporate network in 2014 and exfiltrate about 145 million account records, including names, encrypted passwords, and contact information, prompting a company-wide password reset.
JPMorgan Chase 76M+ 2014
76 million households' data accessed
A 2014 intrusion at JPMorgan Chase reached the contact information of about 76 million households and 7 million small businesses -- names, addresses, phone numbers, and emails -- one of the largest breaches of a US bank.
Home Depot 56M+ 2014
56 million payment cards stolen
Point-of-sale malware at Home Depot in 2014 compromised about 56 million payment cards along with tens of millions of email addresses, one of the largest retail card breaches on record.
Community Health Systems 4.5M 2014
4.5 million patients' SSNs stolen
Community Health Systems, one of the largest US hospital operators, disclosed a 2014 breach -- attributed to a group exploiting the Heartbleed flaw -- that stole names, addresses, birth dates, and Social Security numbers of about 4.5 million patients.
Benesse 35M+ 2014
35 million records sold by an insider
Japanese education company Benesse suffered a 2014 insider breach in which a contractor copied and sold data on about 35 million customers, largely families of students, including names, addresses, and children's details.
Yahoo 500M+ 2014
500 million accounts stolen in a second breach
Separate from its record 2013 breach, Yahoo suffered a 2014 intrusion by state-sponsored attackers that stole data on about 500 million accounts -- names, email addresses, phone numbers, birth dates, hashed passwords, and security questions. The full scope was not disclosed until 2016.
2013
Yahoo 3B+ 2013
all 3 billion user accounts compromised
Russian state-linked hackers breached Yahoo starting in 2013, ultimately compromising all 3 billion user accounts -- names, email addresses, phone numbers, dates of birth, and hashed passwords. Yahoo did not disclose the full scope until 2017, and it remains the largest confirmed breach on record.
Adobe 153M+ 2013
153 million accounts and credentials stolen
Adobe's 2013 breach, first thought to affect 3 million users, ultimately exposed more than 153 million accounts -- email addresses, poorly encrypted passwords, password hints, and some credit card details -- a landmark example of weak encryption practices.
Target 70M+ 2013
40 million cards and 70 million customers' data stolen
Point-of-sale malware at Target during the 2013 holiday season stole about 40 million credit and debit card numbers and the personal information of up to 70 million customers, a landmark retail breach that reshaped payment security.
Evernote 50M+ 2013
50 million users forced to reset passwords
Note-taking service Evernote forced a password reset for about 50 million users in 2013 after attackers accessed usernames, email addresses, and hashed passwords.
LivingSocial 50M+ 2013
50 million customers breached
The daily-deals site LivingSocial disclosed a 2013 breach affecting about 50 million customers, exposing names, email addresses, birth dates, and salted password hashes.
2012
Dropbox 68M+ 2012
68 million user credentials stolen
A 2012 Dropbox breach exposed about 68 million users' email addresses and hashed passwords; the full scale only became clear in 2016 when the data surfaced online, a classic case of credential reuse fueling later attacks.
Blizzard (Battle.net) 14M+ 2012
14 million gaming accounts breached
A 2012 breach of Blizzard Entertainment's Battle.net service exposed data on about 14 million accounts, including email addresses, security-question answers, and scrambled passwords.
South Carolina Dept. of Revenue 6.4M 2012
6.4 million taxpayers' SSNs stolen
Hackers stole about 6.4 million South Carolina taxpayer records in 2012 after an employee fell for a phishing email, exposing Social Security numbers and hundreds of thousands of credit and debit card numbers.
LinkedIn 117M+ 2012
117 million accounts stolen
A 2012 breach of LinkedIn, first reported as only a few million, ultimately exposed about 117 million members' email addresses and unsalted SHA-1 password hashes, which surfaced for sale years later.
2011
Citigroup 360K Jun 2011
360,000 credit card accounts breached
Attackers walked through Citi's Account Online web platform in May 2011 by manipulating account numbers in the browser's address bar, harvesting data from 360,083 U.S. credit-card accounts. Names, account numbers and contact details including email addresses were taken; Citi said Social Security numbers, birth dates, card expiration dates and CVV codes were not exposed. The bank waited about three weeks to notify customers and reissued cards on affected accounts.
Epsilon n/a Apr 2011
customer names and emails exposed across 75+ major brands
Epsilon, then the world's largest permission-based email marketing firm, said an intrusion detected on March 30, 2011 exposed the names and email addresses of customers belonging to a subset of its 2,500+ corporate clients -- among them Chase, Citi, Capital One, Best Buy, Walgreens and Verizon. No financial data was taken, but the exposure across dozens of major brands was called one of the largest breaches in history at the time and drove a wave of targeted phishing. Prosecutors later tied it to a spam ring that blasted stolen addresses.
Sony PlayStation Network 77M+ 2011
77 million accounts compromised
The 2011 breach of Sony's PlayStation Network exposed about 77 million accounts -- names, addresses, emails, birth dates, logins, and in some cases card data -- and forced the gaming service offline for weeks, a landmark early mega-breach.
Tricare / SAIC 4.9M+ 2011
4.9 million military health records lost
Backup tapes holding the health records of about 4.9 million US military members, retirees, and their families in the Tricare program were lost in 2011, exposing Social Security numbers, addresses, phone numbers, and clinical data.
CSDN 6M+ 2011
6 million developer accounts with plaintext passwords
China Software Developer Network, a major Chinese programming portal, was breached in 2011, exposing about 6 million usernames, email addresses, and passwords that had been stored in plain text.
2010
Gawker Media 1.3M+ Dec 2010
1.3 million commenter accounts leaked by Gnosis
A group calling itself Gnosis broke into Gawker Media's servers in December 2010, dumping about 1.3 million commenter usernames, email addresses, and weakly hashed passwords -- plus the site's source code -- onto file-sharing networks. The old DES-based hashes were quickly cracked, and reused credentials were used to hijack thousands of Twitter accounts for spam. The breach hit Gizmodo, Lifehacker, Kotaku, Jezebel, and other Gawker sites.
Educational Credit Management Corp 3.3M+ Mar 2010
3.3 million student-loan borrowers' data stolen
Portable media holding the names, addresses, dates of birth, and Social Security numbers of about 3.3 million federal student-loan borrowers was physically stolen from the Minnesota headquarters of guaranty agency ECMC in March 2010. No bank-account data was included. The media was later recovered and investigators said they found no evidence of misuse, but the theft ranked among the largest identity-data losses of the year.
2009
RockYou 32M+ Dec 2009
32 million accounts with plaintext passwords exposed
A hacker exploiting a basic SQL-injection flaw pulled the entire user database of RockYou, a maker of social-media widgets and games, in December 2009 -- about 32 million accounts. The passwords were stored in plain text with no hashing, and because users often reused their email credentials, the exposure reached well beyond the site. The leaked list became 'rockyou.txt,' still the most widely used password-cracking wordlist.
Heartland Payment Systems 130M+ Jan 2009
130 million payment cards stolen
One of the largest U.S. card processors disclosed on January 20, 2009 that malware planted through a SQL-injection attack had captured unencrypted card data in transit through its network during 2008. Prosecutors later put the total at roughly 130 million credit- and debit-card accounts, the largest payment-card breach reported at the time. Albert Gonzalez, mastermind of the TJX breach, was indicted for it and sentenced to 20 years.
2008
Countrywide Financial 2M+ Aug 2008
~2 million mortgage applicants' records stolen and sold by an insider
Rene Rebollo, a senior financial analyst in Countrywide's subprime lending division, spent about two years copying roughly 20,000 customer records a week onto a USB drive and selling the data. The FBI arrested him in August 2008; an estimated 2 million mortgage applicants' records -- names, Social Security numbers, addresses and financial-account details -- were taken. A later class-action settlement covered about 17 million people whose data sat in the affected systems.
Hannaford Bros. 4.2M Mar 2008
4.2 million credit and debit card numbers stolen
Malware planted on servers at more than 300 Hannaford and Sweetbay grocery stores captured credit- and debit-card numbers in transit during card authorization between December 2007 and March 2008. About 4.2 million unique card numbers were exposed and at least 1,800 fraud cases were tied to the breach. Only card numbers and expiration dates were taken; it was an early, widely studied case of card data stolen in transit.
2007
Certegy / Fidelity National 8.5M Jul 2007
8.5 million consumer records stolen and sold by an insider
A senior database administrator at Certegy Check Services, a Fidelity National Information Services unit, stole 8.5 million consumer records over roughly five years and sold them to data brokers who resold them to direct marketers. The records included names, addresses, dates of birth, checking-account numbers and, for about 1.5 million people, credit-card details. Fidelity first disclosed 2.3 million records in July 2007, then raised the figure to 8.5 million in an SEC filing.
TJX Companies (T.J. Maxx, Marshalls) 94M+ Jan 2007
up to 94 million payment cards stolen
Hackers led by Albert Gonzalez broke into TJX's networks through a poorly secured store Wi-Fi connection in 2005 and installed sniffer software that captured payment-card 'track' data for about 18 months before the intrusion was found in December 2006. TJX disclosed it in January 2007 and acknowledged at least 45.7 million cards; court filings citing Visa and MasterCard put the exposure at up to 94 million accounts, the largest retail card breach reported at the time.
Counts reflect the most complete figures reported to date; several are still under investigation and may grow. "Undisclosed" means the organization has not released a victim count. Missing one? Submit a sourced breach.
If your data's been stolen
You can't un-leak data, but you can shut down most of the ways it gets used against you. Start here.
General guidance, not legal or financial advice. If a breach notice offers free credit monitoring, it costs you nothing to accept. For health-data breaches, also review benefits statements for care or claims you don't recognize.

Every breach on this page started with data somebody collected.
You can't leak what you never log. vp.net is a privacy network with no activity logs and no identity database to steal -- hardware-verified, not policy-promised. Nothing stored, nothing breached.
Visit vp.net →
Every breach notice lands in your inbox. So do the phishers who follow it.
Leaked address books become phishing lists. bmail is verifiably private email that cannot read your mail or mine your address book -- so your inbox is a dead end for data thieves, not a directory.
Visit bmail.ag →