Calendar & News

Data Breach Ledger

The breaches spilling your data

A breach isn't a place on a map -- its victims are everywhere its customers are. So this is a ledger, not a map: every breach we can source that spilled personal records. The focus is on what's newest, but it reaches back years, because a Social Security number stolen in 2017 or a passport leaked in 2018 still works against you today. Led by the number that matters most, tagged by exactly what leaked. The throughline: as age-verification and KYC laws force more people to upload driver's licenses and passports, those are the very documents turning up in the spills.

249.2M+

people's records exposed in 2026

across 54 breaches disclosed in 2026

20.6B+

records exposed, all time

summed across every tracked breach -- most people appear in more than one

180

breaches in the ledger

tracked back to 2007, and still counting

52

exposed driver's licenses or passports

the same IDs age-verification laws demand

Been caught in a breach? Jump to what to do ↓

People affected per year

Records exposed each year across the breaches in this ledger. A single mega-breach can tower over an entire year, and people caught in more than one are counted each time.

Sum of disclosed victim counts per year across tracked breaches; breaches with an undisclosed scale aren't included, and people hit by more than one breach are counted each time. 2026 is only a partial year. Bar color runs yellow for lighter years through orange to red for the worst on record.

2026, month by month

Each cell is a month -- darker means more breaches disclosed. Tap a month to filter the ledger to it.

What was exposed

How often each kind of personal data turned up across the 180 breaches.

Contact info 152
Date of birth 66
Name 57
Social Security number 53
Financial 49
Home address 46
Phone number 39
Login credentials 34
Medical / health 32
Passport 26
Driver's license 26
Government ID 26
Biometrics 16
Surveillance records 7
Account details 5
Student ID 2

The largest on record

The biggest breaches in the ledger by people affected. Many are years old -- and still fuel identity theft today, because a stolen SSN, passport, or fingerprint can't be reset.

Yahoo · 2013 3B+
National Public Data · 2024 1.3B+
People Data Labs · 2019 1.2B+
Aadhaar · 2018 1.1B+
Shanghai police · 2022 1B+
First American Financial · 2019 885M+
India (ICMR) · 2023 815M+
LinkedIn · 2021 700M+
Ticketmaster · 2024 560M+
Facebook · 2019 540M+
Weibo · 2020 538M+
Facebook · 2021 533M+

The ledger

Every tracked breach, grouped by year, newest first. Open a year to read its breaches. Filter by region, what was exposed, or sector -- matches open automatically.

Region
Exposed
Sector
180 breaches
2026 54 breaches·249.2M+ people
Suno 55.3M Jul 2026

55.3M AI-music accounts exposed, users never individually notified

55.3M affected Technology United States

The November 2025 breach of AI music platform Suno finally got a number on July 20, 2026, when Have I Been Pwned ingested the stolen dataset: 55.3 million unique accounts. Exposed data includes email addresses, phone numbers used as logins, names, physical addresses, purchase records, and partial payment-card details from tens of thousands of Stripe records -- card type, expiry, and last four digits. Suno had decided individual customer notifications were not required, so for most of its users the HIBP listing eight months later is the first practical way to learn they were in the dump. The case is becoming a reference point for how AI startups handle disclosure: a consumer platform with tens of millions of accounts, a breach it acknowledged only generally, and a notification standard outsourced to a volunteer-run lookup site.

Contact info Financial

Source →

Hugging Face n/a Jul 2026

first breach executed by an autonomous AI agent

Scale undisclosed Technology United States

Hugging Face, the platform hosting much of the world's open AI models, disclosed a high-severity breach on July 20, 2026 with a first for this ledger: the intrusion was carried out by an autonomous AI agent system exploiting vulnerabilities in production infrastructure. Entering through the data-processing pipeline, the attacker's agent stole cloud and cluster credentials, moved laterally across internal clusters, and took internal datasets before Hugging Face closed the holes, evicted the actor, and rebuilt compromised nodes. The inevitable milestone, arrived: AI attacking the AI supply chain, at machine speed, against the company whose job is distributing AI.

Login credentials

Source →

Eurail 309K Jul 2026

300,000+ rail travelers' passport and ID details exposed

309K affected Travel World Government ID exposed

A breach at Eurail, which sells Interrail and Eurail passes, exposed the personal data of more than 300,000 travelers, including names, contact details, dates of birth, and passport or ID details, with some IBANs or health-related information. Some travelers were advised to replace their passports.

Passport Contact info Date of birth Financial

Source →

DHS Homeland Security Information Network (HSIN) n/a Jul 2026

intelligence-sharing platform breached

Scale undisclosed Government United States

The Department of Homeland Security confirmed on July 1, 2026 that an unknown attacker had breached HSIN, the sensitive-but-unclassified network that federal, state, local, tribal, and private-sector partners use to share intelligence, coordinate security for major events, and respond to incidents. First reported by Nextgov, the intrusion is believed to have happened between late May and early June and also hit an associated SharePoint system; DHS said it isolated the affected systems and that classified networks were not impacted, while it stayed unclear whether any data was taken. Sen. Mark Warner, vice chair of the Senate Intelligence Committee, called for a DHS and DOJ investigation, noting HSIN was supporting security for the World Cup underway in the US.

Surveillance records

Source →

Medtronic 9M+ Jul 2026

SSNs and health data of ~9M claimed stolen; listing quietly removed

9M+ affected Healthcare United States

Medical-device giant Medtronic began notifying customers in July 2026 of a breach detected in April, in which attackers accessed names, contact details, dates of birth, Social Security numbers, and health-related information. The ShinyHunters extortion group claimed more than 9 million records -- and then the listing vanished from the group's leak site, a removal that in extortion economics usually means one thing: the victim likely paid. For patients whose cardiac devices, insulin pumps, and health profiles run through Medtronic systems, the combination of SSN plus health data is the full identity-theft kit, and the quiet delisting means the records' fate is unverifiable either way.

Social Security number Medical / health Contact info

Source →

NAIC n/a Jul 2026

US insurance regulators breached via Oracle PeopleSoft zero-day

Scale undisclosed Government United States

The National Association of Insurance Commissioners -- the standard-setting body for US insurance regulators -- was breached by ShinyHunters through a zero-day in an Oracle PeopleSoft server. The group claimed 3.1 TB across roughly 105,000 files, including regulatory filings from 2017-2024, customer, order, and payment records, and credentials for production environments; NAIC's response was that only publicly available data, outdated logs, and configuration files were taken. The gap between those two descriptions is the story, and either way a regulator that holds filings from every US insurer was reachable through one unpatched enterprise server -- the same PeopleSoft vector ShinyHunters has been running against universities and agencies all year. Scale update: by mid-July the same PeopleSoft zero-day campaign had breached more than 100 organizations -- including Nissan's employee records across four countries -- before Oracle had even published an advisory.

Financial

Source →

Novo Nordisk n/a Jun 2026

attackers copy personal data from internal systems

Scale undisclosed Healthcare World

The Danish maker of Ozempic and Wegovy disclosed on June 11, 2026 that attackers had reached a limited number of internal IT systems and copied non-public data, including personal data. The group claiming responsibility said it got in months earlier through an exposed high-privilege developer credential; healthcare-professional records were directly identifying, while clinical-trial patient data was pseudonymized.

Medical / health Contact info

Source →

Texas 3M+ Jun 2026

3M+ hunting/fishing license holders' IDs stolen from state agency

3M+ affected Government United States Government ID exposed

The Texas Parks and Wildlife Department said a breach may have exposed the driver's license and passport numbers of more than 3 million people who bought hunting and fishing licenses. The theft of state-held government ID numbers underscores the risk created as age-verification and KYC systems push more people to hand over identity documents.

Driver's license Passport Contact info Home address Phone number

Source →

AssuranceAmerica 7M Jun 2026

6.99M people's driver's licenses exposed by auto insurer

7M affected Insurance United States Government ID exposed

Auto insurer AssuranceAmerica told customers that hackers who breached its systems (discovered March 17, 2026) stole names, contact information, and driver's license numbers, along with policy, vehicle, and claims details. The company said the attackers targeted an employee and it disabled the compromised credentials. Regulatory filings to the Maine and Indiana attorneys general put the total at about 6.99 million people. Update, July 8, 2026: filings with the Indiana and Maine attorneys general put the toll at 6.99 million people, with notification letters going out July 10 -- among the largest driver's-license spills in the year's run of identity-document breaches. TechCrunch noted Maine's own breach-disclosure portal was offline at the time, under review after someone published a fraudulent breach notice on it.

Driver's license Social Security number Contact info Financial

Source →

DentaQuest 2.6M Jun 2026

2.6M dental-benefits accounts with IDs and health data leaked

2.6M affected Healthcare United States Government ID exposed

After a May 2026 extortion campaign, the ShinyHunters group published a 234GB archive from dental-benefits administrator DentaQuest. Have I Been Pwned verified 2.6 million unique email addresses alongside names, phone numbers, addresses, dates of birth, government-issued IDs, and health-insurance information.

Government ID Medical / health Contact info Name Date of birth Phone number Home address

Source →

University of Nottingham 455K+ Jun 2026

455K students' and alumni records, including passports, leaked

455K+ affected Education World Government ID exposed

ShinyHunters leaked files from the University of Nottingham's student records system. Have I Been Pwned found roughly 455,000 unique email addresses along with names, addresses, phone numbers, passport numbers, and sensitive fields such as ethnicity, disability, citizenship status, and fee-payment data for current students and alumni.

Passport Name Contact info Home address Phone number

Source →

France 73K Jun 2026

Tchap government messaging platform breach hits 73K accounts

73K affected Government World

France's interministerial digital directorate DINUM disclosed a breach of Tchap, the government's sovereign messaging platform, after an account-hijacking incident on June 7, 2026. Officials said 73,467 accounts were affected; an actor using the name 'misere' claimed to have taken 13.5GB of messages and user data, a larger claim officials had not verified.

Login credentials Contact info Account details

Source →

KDDI 14.2M+ Jun 2026

14.2M email accounts exposed across six Japanese ISPs

14.2M+ affected Telecom World

Japanese carrier KDDI disclosed a breach of an email platform it provides to six ISPs (STNet, KDDI Web Communications, JCOM, Chubu Telecommunications, Nifty, and Biglobe). Up to 14.22 million email addresses and passwords may have been exposed after attackers exploited a third-party software vulnerability; the company urged users to change passwords.

Login credentials Contact info

Source →

Kodak 2.2M+ Jun 2026

2.2M customer and corporate records claimed stolen

2.2M+ affected Retail United States

Kodak confirmed a June 2026 breach after ShinyHunters claimed it stole 2.2 million customer and corporate records and listed the company on its leak site. Kodak said an unauthorized third party temporarily accessed a limited amount of data but had not verified the record count or full scope.

Contact info Name Account details

Source →

Amazon One Medical n/a Jun 2026

legacy senior-patient records accessed

Scale undisclosed Healthcare United States

Amazon-owned One Medical disclosed that a third-party file-storage platform holding archived records for legacy Iora Health and One Medical Seniors patients was accessed in June 2026. Affected files included demographic and clinical data across nine metro areas; ShinyHunters claimed 8.8TB of data, which One Medical had not confirmed.

Medical / health Contact info

Source →

iRhythm n/a Jun 2026

cardiac-monitoring patient data stolen

Scale undisclosed Healthcare United States

Cardiac-monitoring company iRhythm disclosed a June 2026 cyberattack after detecting unauthorized activity in third-party-hosted applications. An actor claimed to have stolen patients' protected health information and other personal data and demanded payment; iRhythm confirmed some data was stolen but had not confirmed the number of people affected.

Medical / health Contact info

Source →

Madison Square Garden 26M+ Jun 2026

26M+ records with facial-recognition and biometric data exposed

26M+ affected Entertainment United States

ShinyHunters used a voice-phishing call to breach Madison Square Garden Entertainment and published a trove the group said covered up to 26 million people. The leaked data reportedly included MSG's facial-recognition entry-surveillance logs, biometric data, background-check reports, and threat-assessment profiles built on visitors and celebrities, plus attendee contact details. MSG had not confirmed the scope; multiple class actions followed.

Biometrics Surveillance records Contact info Name Home address

Source →

Aflac 4.4M Jun 2026

insurer breach exposes personal and bank-account data

4.4M affected Insurance World

US supplemental-insurance giant Aflac disclosed a 2026 breach after attackers compromised its Japan subsidiary, stealing personal information and bank account details for about 4.38 million customers, along with policy and coverage data.

Financial Contact info

Source →

Age-verification vendor 985K+ Jun 2026

985,000 passports and licenses left on the open web

985K+ affected Age verification World Government ID exposed

A security researcher found roughly 985,000 passport and driver's-license photos from an identity-verification company sitting on public web servers -- no password, no encryption, reachable by anyone with the URL, for months. The firm had collected the documents to perform age and identity checks, exactly the kind of KYC and age-verification screening that laws are pushing onto more of the internet, then stored the resulting ID scans as if they were disposable public images.

Passport Driver's license Biometrics

Source →

LastPass n/a Jun 2026

customer contact and support data stolen via the Klue supply-chain hack

Scale undisclosed Security United States

LastPass disclosed on June 24, 2026 that attackers reached customer data in its Salesforce environment after the Icarus extortion group compromised Klue, a market-intelligence vendor, and stole the OAuth tokens Klue held for many of its customers. Exposed data was limited to names, email addresses, phone numbers, physical addresses, and customer support-case records; LastPass said its products, infrastructure, and encrypted password vaults were not affected. The same Klue supply-chain attack hit more than a dozen firms including Recorded Future, Tanium, and Jamf.

Name Contact info Phone number Home address

Source →

University of Oxford n/a Jun 2026

students' and alumni data exposed in a careers-platform breach

Scale undisclosed Education World

The University of Oxford disclosed in early June 2026 that its CareerConnect careers platform, run by third-party provider Group GTI, had been breached on May 28. Attackers accessed the first names, last names, and email addresses of students, alumni, research staff, and recruiters, plus encrypted passwords for users who logged in with a local password rather than Oxford's single sign-on. Oxford said the attack appeared aimed at harvesting credentials for phishing; no financial or course data was involved. It was Oxford's second third-party breach of 2026.

Name Contact info Login credentials

Source →

Nintendo of America n/a Jun 2026

employee survey data stolen from a third-party HR tool

Scale undisclosed Gaming United States

A hacker using the handle SHADOWBYT3$ claimed on June 13, 2026 to have stolen about 859 MB of data from TinyPulse, a third-party employee-survey service used by Nintendo of America, and demanded a $2 million ransom. Nintendo confirmed the incident but said it was limited to internal survey content for a small subset of employees, that its own systems were not compromised, and that no customer or financial data was involved -- disputing the attacker's claim that bank statements and W-9 tax forms were included. Most of the data reportedly dated back several years.

Name Contact info

Source →

24 billion stolen credential records found exposed in a giant online compilation n/a Jun 2026
Scale undisclosed Data broker World

Researchers at Cybernews found a publicly exposed database of more than 8.3 terabytes holding about 24 billion credential records -- usernames, passwords, and other account data -- reportedly drawn from 36 sources including Telegram channels, earlier breach compilations, and infostealer logs, with some datasets apparently exported directly from live servers. The trove was taken offline soon after discovery, so the number of duplicate records could not be confirmed.

Login credentials Contact info

Source →

Council of Europe n/a Jun 2026

staff payslips, personnel files, and CVs claimed stolen

Scale undisclosed Government World Government ID exposed

The Council of Europe, the continent's oldest intergovernmental body, said in June 2026 that it was investigating a data-breach claim by the ShinyHunters extortion group. The attackers claimed to have taken more than 409,000 payslips covering over 10,000 staff from 2011 to 2026, along with thousands of personnel files and CVs, said to include names, dates of birth, home addresses, phone numbers, employee IDs, salaries, bank-account and tax details, and some medical records.

Name Date of birth Financial Government ID Medical / health

Source →

Mediaworks Hungary n/a May 2026

15 million files leaked from the country's largest media group

Scale undisclosed Media World

Mediaworks, Hungary's largest media group, disclosed on May 4, 2026 that it had suffered a serious cyberattack on April 30. Hungary's data protection authority later said the attackers had unlawfully obtained nearly 15 million files, about 8.5 terabytes, and published them on the dark web, including names, addresses, bank-account details, internal records, and public-interest documents. The company said its investigation was ongoing and warned readers about phishing abuse.

Name Home address Financial Contact info

Source →

Instructure/Canvas 30M+ May 2026

30M+ students' and staff data stolen

30M+ affected Education United States

ShinyHunters breached the Canvas learning-management system run by Instructure twice within two weeks in April-May 2026, claiming data from nearly 9,000 institutions (including Harvard and Princeton). Personal information of more than 30 million students and staff was taken -- names, emails, student IDs and private messages -- and the attackers defaced Canvas login screens during finals. Instructure paid a ransom.

Name Contact info Student ID

Source →

Blank Rome n/a May 2026

law-firm breach exposes clients' IDs and health data

Scale undisclosed Legal United States Government ID exposed

Law firm Blank Rome disclosed a May 2026 breach in which an attacker posed as IT over the phone and tricked an attorney into uploading files to an external account. The exposed client information may have included Social Security numbers, driver's license, state ID and passport numbers, other government IDs, financial account and payment-card data, and medical and health-insurance information.

Social Security number Driver's license Passport Government ID Financial Medical / health Contact info

Source →

Tabiq 1M+ May 2026

1 million hotel guests' passports and licenses left on the open web

1M+ affected Hospitality World Government ID exposed

Tabiq, a Japanese hotel check-in platform run by startup Reqrea, left an Amazon S3 storage bucket public, exposing more than 1 million guests' passports, driver's licenses, and facial-verification selfies to anyone who knew the bucket name. Files spanned early 2020 to May 2026 and covered travelers from many countries. A researcher found it and TechCrunch alerted the company and Japan's JPCERT, after which it was locked down; the exposure window and whether others accessed it remain unknown.

Passport Driver's license Name Home address Date of birth Biometrics

Source →

France 11.7M+ Apr 2026

national ID portal (ants.gouv.fr) breach hits 11.7M accounts

11.7M+ affected Government World

France Titres, which runs the government identity portal ants.gouv.fr, confirmed a breach exposing about 11.7 million accounts (a threat actor advertised up to 19 million). Exposed fields included login IDs, names, email addresses, dates of birth and unique account IDs, and sometimes postal addresses, birthplaces and phone numbers. A 15-year-old suspect was detained on April 25, 2026.

Login credentials Contact info Name

Source →

FBI n/a Apr 2026

China-linked breach of a wiretap surveillance system

Scale undisclosed Government United States

The FBI told Congress that a suspected China-linked intrusion into an unclassified network holding pen-register and trap-and-trace surveillance data (the DCS-3000 'Red Hook' collection system) was a 'major incident' under FISMA. First detected Feb 17, 2026 and reportedly reached through a commercial ISP's vendor infrastructure, the breach is believed to have exposed the phone numbers of people under active FBI surveillance.

Phone number Surveillance records

Source →

Charter/Spectrum 4.9M+ Apr 2026

vishing call exposes millions of customer records

4.9M+ affected Telecom United States

One of the largest U.S. broadband providers was compromised on April 1, 2026 when the ShinyHunters group used a voice-phishing call to obtain an employee's Microsoft Entra credentials and reach Charter's Salesforce environment. Charter said only sales tools were affected, but breach monitoring tied the published data to about 4.9 million people (the group claimed 42 million records): names, emails, phone numbers and home addresses.

Contact info Name Account details

Source →

Medtronic 9M+ Apr 2026

medical-device maker breach exposes SSNs and health data

9M+ affected Healthcare United States

Medical-device company Medtronic began notifying customers of a breach detected in April 2026 that exposed names, contact details, dates of birth, Social Security numbers, and health-related information. The ShinyHunters group claimed more than 9 million records; the listing was later removed, suggesting a ransom was paid.

Social Security number Medical / health Date of birth Contact info

Source →

Carnival 6M+ Apr 2026

cruise operator breach exposes 6M passengers' passport and license numbers

6M+ affected Travel United States Government ID exposed

Carnival, the world's largest cruise operator, disclosed that a social-engineering attack on a single employee account (identified April 14, 2026) let an attacker copy personal data on about 6 million people, including names, addresses, dates of birth, and government-issued ID numbers such as driver's license and passport numbers.

Passport Driver's license Contact info Date of birth Home address

Source →

Kubota n/a Apr 2026

breach exposes SSNs of customers and dependents

Scale undisclosed Manufacturing United States

Equipment maker Kubota disclosed a breach that took place between March and April 2026, which may have exposed full names -- including those of dependents -- and Social Security numbers, among other personal details. The company had not confirmed the number of people affected.

Social Security number Name Contact info

Source →

Duc money-transfer app n/a Apr 2026

KYC passports, licenses and selfies left on open server

Scale undisclosed Age verification World Government ID exposed

A misconfigured, password-free Amazon server run by the money-transfer app Duc left hundreds of thousands of files reachable to anyone, dating back to 2020 -- government-issued IDs such as driver's licenses and passports, know-your-customer selfies, and spreadsheets of names, addresses, and transactions. Another example of KYC identity checks becoming the leak.

Passport Driver's license Government ID Biometrics Financial Contact info

Source →

Citizens and Frost banks 3.7M+ Apr 2026

3.6 million exposed through a shared vendor

3.7M+ affected Financial United States

In April 2026 the Everest ransomware group claimed data from two major US banks breached through a shared third-party vendor rather than the banks themselves -- about 3.4 million records from Citizens and over 250,000 Social Security numbers and tax IDs from Frost Bank -- a textbook case of shared-vendor risk cascading across financial institutions.

Social Security number Financial Contact info

Source →

McGraw-Hill 13.5M Apr 2026

13.5 million accounts exposed in Salesforce data theft

13.5M affected Education United States

Education publisher McGraw-Hill was caught in the 2026 wave of Salesforce-related thefts by ShinyHunters; Have I Been Pwned confirmed 13.5 million unique email addresses in the leaked data, alongside names, phone numbers, and physical addresses -- a broad spear-phishing risk across its student and educator base.

Contact info Name Phone number Home address

Source →

ADT 5.5M Apr 2026

5.5 million customers' data stolen

5.5M affected Security United States

Home-security company ADT confirmed an April 2026 intrusion after ShinyHunters claimed the theft; Have I Been Pwned measured about 5.5 million people in the exposed dataset. Stolen data was mostly names, phone numbers, and addresses, with dates of birth and the last four digits of Social Security or tax IDs included for a smaller share.

Contact info Home address Date of birth Social Security number

Source →

Hallmark Cards 2.8M Mar 2026

2.8 million accounts leaked after extortion

2.8M affected Retail United States

In March 2026 ShinyHunters claimed records from Hallmark Cards' Salesforce environment and, after an unmet extortion deadline, leaked more than 2.8 million unique accounts -- customer names, phone numbers, physical and email addresses, and dates of birth.

Contact info Date of birth Name Phone number Home address

Source →

Aura 1.5M Mar 2026

1.5 million exposed at an identity-protection company

1.5M affected Technology United States

In March 2026 identity-protection company Aura confirmed a breach after an employee fell for a voice-phishing (vishing) attack, giving ShinyHunters access through a marketing tool. More than 1.5 million records of customer names, addresses, phone numbers, and email addresses were exposed -- a pointed irony for a firm that sells identity protection.

Contact info Name Home address Phone number

Source →

Lloyds Banking Group 500K+ Mar 2026

500,000 customers' bank and National Insurance data exposed

500K+ affected Financial World Government ID exposed

A March 2026 software glitch at Lloyds Banking Group let around half a million UK customers of Lloyds, Halifax, and Bank of Scotland view other people's sensitive data -- transactions, sort codes, account numbers, and even National Insurance numbers -- and in some cases data belonging to customers of other banks.

Financial Government ID Contact info

Source →

NYC Health + Hospitals 1.8M+ Feb 2026

1.8M patients' records, IDs and biometrics taken

1.8M+ affected Healthcare United States Government ID exposed

The largest public health system in the U.S. said an attacker reached its network through a third-party vendor from late November 2025 through February 2026 and copied files on at least 1.8 million people -- medical records, Social Security numbers, driver's licenses and passports, and biometric fingerprints and palm prints -- one of the largest healthcare breaches reported to HHS in 2026.

Medical / health Social Security number Driver's license Passport Financial Biometrics Login credentials

Source →

Odido (T-Mobile Netherlands) 6.4M Feb 2026

6.2 million customers, with passport and license numbers

6.4M affected Telecom World Government ID exposed

In February 2026 attackers broke into a customer-contact system at Odido, the largest mobile operator in the Netherlands (formerly T-Mobile NL), and downloaded data on about 6.39 million people -- roughly one in three Dutch residents. The haul included names, addresses, phone numbers, dates of birth, bank account (IBAN) numbers, and, for many, passport or driver's-license numbers, a near-complete identity-theft toolkit.

Passport Driver's license Financial Date of birth Home address Phone number Name

Source →

Figure Lending 3M+ Feb 2026

3 million records with SSNs stolen

3M+ affected Financial United States

US fintech lender Figure Lending confirmed a February 2026 breach after an employee was socially engineered into giving ShinyHunters access via the company's Okta single-sign-on. More than 3 million records were exposed, including names, dates of birth, addresses, phone numbers, email addresses, passwords, and Social Security numbers.

Social Security number Date of birth Home address Contact info Login credentials

Source →

Senegal (DAF) n/a Feb 2026

national biometric, passport and voter database hit

Scale undisclosed Government World Government ID exposed

Senegal's Directorate of File Automation (DAF), the agency that manages national ID cards, biometric records, passports, and electoral data, was hit by a February 2026 cyberattack that compromised about 139 terabytes -- the citizen database, biometric records, and immigration files -- and halted document production for days. The number of individuals was not quantified, but it reaches much of the country.

Government ID Biometrics Passport Surveillance records

Source →

TriZetto Provider Solutions 3.4M Feb 2026

3.4M affected in healthcare billing vendor breach

3.4M affected Healthcare United States

TriZetto Provider Solutions, a Cognizant-owned revenue-cycle vendor that processes billions of US healthcare transactions a year, reported a breach to the HHS Office for Civil Rights in February 2026 affecting about 3,433,965 people -- the largest single healthcare breach reported to OCR in the first half of 2026. An unauthorized party had accessed insurance eligibility-verification records, with access beginning around November 2024.

Medical / health Contact info

Source →

Match Group 10M+ Jan 2026

10M+ records claimed stolen from Hinge, Match, and OkCupid

10M+ affected Dating United States

ShinyHunters claimed in late January 2026 to have stolen more than 10 million records tied to Match Group's dating apps -- Hinge, Match, and OkCupid -- via a social-engineering attack on Okta SSO access. The data reportedly included user IDs, IP addresses, Hinge subscription transaction IDs and amounts paid, and internal employee emails. Match Group said it was investigating.

Account details Financial Contact info

Source →

Basic-Fit 1M+ 2026

1 million gym members' bank details exposed

1M+ affected Fitness World

European gym chain Basic-Fit confirmed a 2026 breach affecting around 1 million members, exposing bank account details, names, dates of birth, and other contact information -- the account numbers being the standout risk for direct-debit fraud.

Financial Date of birth Contact info Name

Source →

Navia Benefit Solutions 2.7M Jan 2026

2.7 million people's SSNs and licenses stolen

2.7M affected Financial United States Government ID exposed

Benefits administrator Navia disclosed a breach spanning late December 2025 into January 2026 that hit about 2.7 million people, exposing names, dates of birth, Social Security numbers, driver's-license information, phone numbers, email addresses, and details of their benefits accounts.

Social Security number Driver's license Date of birth Contact info

Source →

Hyundai 2.7M+ 2026

2.7 million owners' SSNs and driver's licenses exposed

2.7M+ affected Automotive United States Government ID exposed

Automaker Hyundai suffered a 2026 breach compromising the personal data of up to 2.7 million owners, with the stolen records including Social Security numbers and driver's-license details.

Social Security number Driver's license Contact info

Source →

Nissan n/a 2026

employees' SSNs and national IDs stolen via Oracle zero-day

Scale undisclosed Automotive World Government ID exposed

Nissan warned current and former employees of a 2026 breach after attackers exploited an Oracle PeopleSoft vulnerability, part of a wider extortion campaign. Exposed data could include contact and banking information, Social Security numbers, Social Insurance Numbers, national identification numbers, and tax and beneficiary details.

Social Security number Government ID Financial Contact info

Source →

Illinois and Minnesota human-services agencies 1M+ Jan 2026

~1 million exposed

1M+ affected Government United States

System failures at the Illinois and Minnesota human-services departments exposed the personal data of nearly a million people in early 2026. In Illinois sensitive case information sat publicly visible for years; in Minnesota excessive internal access led to improper disclosure. Exposed fields included names, addresses, dates of birth, Medicaid IDs, and the first digits of Social Security numbers.

Social Security number Medical / health Contact info Date of birth

Source →

7-Eleven 185K+ 2026

185,000 people's SSNs and licenses in franchise-document leak

185K+ affected Retail United States Government ID exposed

A 2026 breach tied to 7-Eleven's franchisee-document systems exposed roughly 185,000 people; filings reportedly referenced Social Security numbers and driver's-license numbers, and the company offered identity-protection services to those affected.

Social Security number Driver's license Contact info

Source →

Xsolis 1.4M Jan 2026

1.4 million patients' SSNs and health data stolen

1.4M affected Healthcare United States

Tennessee healthtech firm Xsolis disclosed a January 2026 breach, blamed on a phishing attack, that affected roughly 1.4 million people. Social Security numbers and health-insurance information were among the data believed stolen.

Social Security number Medical / health Contact info

Source →

2025 27 breaches·640M+ people
Petco n/a Dec 2025

customers' SSNs and driver's licenses left accessible by a software setting

Scale undisclosed Retail United States Government ID exposed

Petco disclosed in December 2025 that a misconfigured setting in one of its applications had left customer files accessible online, exposing names, Social Security numbers, driver's license numbers, financial account and card numbers, and dates of birth. Discovered during a July 2025 security review, the retailer notified customers months later and filed breach reports in Texas, California, Massachusetts, and Montana. Petco, which serves over 24 million customers a year, did not disclose the total number affected.

Name Social Security number Driver's license Financial Date of birth

Source →

F5 n/a Oct 2025

nation-state actor lived in BIG-IP source code for a year

Scale undisclosed Technology United States

F5 disclosed on October 15, 2025 that a nation-state actor -- linked by Bloomberg to China's BRICKSTORM/UNC5221 cluster -- had persistent access to the development environment of BIG-IP, the load balancers and gateways that sit in front of a huge share of the world's networks, for at least twelve months. Stolen: portions of BIG-IP source code, F5's internal notes on undisclosed vulnerabilities, some customer configurations, and employee data. Detection came August 9; disclosure waited until October at the Justice Department's direction. CISA issued an emergency directive the same day -- its language was that the actor posed an imminent threat capable of full compromise of targeted systems -- ordering every federal civilian agency to patch or disconnect, with roughly 680,000 F5 devices visible on the open internet. Nobody's personal data was the product here; the product was the master key to everyone else's.

Login credentials

Source →

Discord 70K+ Oct 2025

70,000 government-ID photos stolen from an age-verification vendor

70K+ affected Technology United States Government ID exposed

Discord said in October 2025 that hackers breached a third-party support vendor and stole data from users who had filed age-related appeals, including about 70,000 photos of government IDs (driver's licenses and passports) taken as selfies to prove their age. Also exposed were names, usernames, emails, support-chat transcripts, limited billing metadata including the last four digits of cards, and IP addresses. The attackers claimed a far larger haul of up to 2.1 million ID images, which Discord disputed as an extortion tactic.

Government ID Biometrics Name Contact info Financial

Source →

SSA 300M+ Aug 2025

live copy of every American's Social Security file moved to a cloud only DOGE could see

300M+ affected Government United States Government ID exposed

The Social Security Administration's own chief data officer, Charles Borges, filed a whistleblower complaint with the Office of Special Counsel and Congress on August 26, 2025: DOGE staffers had copied NUMIDENT -- the master file of every Social Security number ever issued, over 548 million records with names, birth dates, parents' names, citizenship, and ethnicity for 300M+ living Americans -- into a cloud environment only DOGE personnel could access, with no security oversight and no logging of who touched it. Career security officials had refused the request; a DOGE-affiliated official approved it with one word. Borges, who was never consulted, warned that a compromise could mean reissuing every American a new SSN. No exfiltration was proven -- that is precisely the problem: with no tracking, no one can say. Filed here as an exposure, not a confirmed theft, and as the ledger's largest single concentration of identity data placed outside normal controls.

Social Security number Government ID Date of birth

Source →

TransUnion 4.4M Aug 2025

4.4 million people's SSNs exposed at a credit bureau

4.4M affected Financial United States

Credit bureau TransUnion disclosed in August 2025 that attackers reached a third-party Salesforce environment and took data on more than 4.4 million US individuals, including names, addresses, dates of birth, and unredacted Social Security numbers. TransUnion said its core credit database was not affected.

Social Security number Date of birth Contact info Home address

Source →

Salesloft Drift supply-chain campaign n/a Aug 2025

Salesforce data siphoned from hundreds of companies

Scale undisclosed Technology World

Between roughly August 8 and 18, 2025, the threat actor tracked as UNC6395 used OAuth tokens stolen from Salesloft's Drift chat integration to reach the Salesforce environments of around 760 organizations, exporting an estimated 1.5 billion records. The exposed data was mostly business contact details (names, email addresses, phone numbers, job titles) and customer support-case content; investigators found the attackers combed the data for embedded secrets such as AWS keys and passwords to pivot into other systems. Confirmed victims included Cloudflare, Palo Alto Networks, Zscaler, Proofpoint, Tenable, and a small number of Google Workspace accounts.

Name Contact info Phone number Login credentials

Source →

Farmers Insurance 1.1M Aug 2025

1.11M customers' licenses taken in the Salesforce wave

1.1M affected Insurance United States Government ID exposed

Farmers Insurance notified 1,111,386 customers in August 2025 that names, addresses, birth dates, driver's license numbers, and partial Social Security numbers were stolen from a third-party vendor's database on May 29 -- one hit among dozens in the year's ShinyHunters/UNC6040 Salesforce campaign, in which voice-phishing calls talked employees into linking a malicious OAuth app to their Salesforce instance, after which the attackers simply downloaded the CRM and extorted the owner. The Farmers entry earns its place as the wave's insurance-sector exemplar: a company serving 10 million households, breached through a vendor it wouldn't name, in a campaign whose victims routinely say third-party CRM rather than the word Salesforce.

Driver's license Social Security number Date of birth Contact info

Source →

Qantas 5.7M Jul 2025

5.7 million customers' data taken via a call-center vendor

5.7M affected Travel World

Qantas confirmed that a June-July 2025 attack on a third-party call-center platform, attributed to the Scattered Spider group, exposed data on 5.7 million customers -- names, email addresses, phone numbers, dates of birth, addresses, and frequent-flyer details. The data was later leaked after the airline refused an extortion demand.

Contact info Name Date of birth Phone number

Source →

Allianz Life 1.4M+ Jul 2025

most of 1.4 million customers' data stolen

1.4M+ affected Insurance United States

Allianz Life disclosed a July 2025 breach, tied to the Salesforce-targeting extortion wave, that reached a majority of its roughly 1.4 million customers along with financial professionals and some employees, exposing personal data including Social Security numbers. The company said it contained the intrusion within a day.

Social Security number Contact info Date of birth Financial

Source →

Tea 72K+ Jul 2025

72,000 images including women's verification IDs leaked on 4chan

72K+ affected Dating United States Government ID exposed

Tea, a women-only dating-safety app that required a selfie and government ID to join, left a legacy Firebase storage bucket unsecured, exposing about 72,000 images in July 2025 -- roughly 13,000 verification selfies and government IDs (driver's licenses and passports) plus 59,000 images from posts and messages. A second flaw exposed more than a million private messages. The verification photos were downloaded and reposted on 4chan, putting the app's users at risk.

Government ID Driver's license Passport Biometrics

Source →

City of St. Paul, Minnesota 12K Jul 2025

residents' and staff data leaked in the Interlock ransomware attack

12K affected Government United States

The Interlock ransomware group attacked the City of St. Paul in late July 2025, prompting a full network shutdown, a local state of emergency, and activation of the Minnesota National Guard. After the city refused to pay, the gang leaked about 43 GB taken from a Parks and Recreation network drive. The city confirmed the exposed data covered 12,484 people -- current and former employees, interns, volunteers, and program participants -- including names, addresses, phone numbers, dates of birth, and Social Security numbers.

Name Home address Phone number Date of birth Social Security number

Source →

Episource 5.4M Jun 2025

5.4 million patients' health data exposed

5.4M affected Healthcare United States

Episource, an Optum-owned medical billing and risk-adjustment firm, detected unauthorized network access in early 2025 and disclosed in June that the breach affected more than 5.4 million people across the health systems it serves, exposing health and personal information.

Medical / health Social Security number Contact info

Source →

AT&T 86M+ Jun 2025

86 million records re-leaked in 2025 with SSNs decrypted

86M+ affected Telecom United States

In May-June 2025 a threat actor posted a repackaged AT&T customer database on a Russian cybercrime forum -- about 86 million unique records including full names, addresses, phone numbers, and nearly 44 million Social Security numbers. Crucially, SSNs and birthdates that were encrypted in the earlier 2021/2024 thefts were now circulating fully decrypted in plaintext, turning old stolen data into ready-to-use identity-theft kits.

Social Security number Date of birth Contact info Home address Phone number Name

Source →

McHire (Paradox.ai) 64M+ Jun 2025

64 million McDonald's job applicants exposed by a '123456' password

64M+ affected Technology United States

Security researchers found that McHire, the McDonald's hiring chatbot built by Paradox.ai, protected an admin account with the password '123456' and had an insecure API (IDOR) that together exposed up to 64 million job applicants' names, emails, phone numbers, IP addresses, some home addresses, and chat transcripts. Disclosed on June 30, 2025 and fixed within a day, no Social Security numbers or financial data were involved. Paradox.ai said only the researchers accessed the data and that no records were leaked publicly.

Name Contact info Phone number Home address

Source →

Coinbase 69K May 2025

69,000 customers' data leaked by bribed support agents

69K affected Financial United States Government ID exposed

Cybercriminals bribed overseas support contractors at vendor TaskUs to pull data on 69,461 Coinbase customers, an intrusion that began in December 2024 and was discovered in May 2025. The stolen records included names, addresses, phone numbers, email addresses, masked Social Security and bank-account numbers, and images of government-issued IDs submitted for identity verification. No passwords, private keys, or funds were taken. Coinbase refused a $20 million ransom and offered a matching bounty instead.

Name Home address Phone number Contact info Government ID Social Security number Financial

Source →

UK Legal Aid Agency 2.1M+ May 2025

2.1 million applicants' sensitive records stolen

2.1M+ affected Government World Government ID exposed

The UK's Legal Aid Agency, part of the Ministry of Justice, was hit by a cyberattack detected on April 23, 2025 and disclosed on May 19. Attackers downloaded a large amount of data on people who applied for legal aid through its online service going back to 2007 -- contact details, addresses, dates of birth, national ID numbers, criminal history, employment status, and financial data such as debts and payments. The group claimed about 2.1 million records, and the MoJ admitted the agency's systems had been known to be vulnerable for years.

Government ID Date of birth Home address Contact info Financial Name

Source →

Kettering Health 1.7M May 2025

1.7 million patients' records stolen in the Interlock ransomware attack

1.7M affected Healthcare United States Government ID exposed

Interlock ransomware operators breached the 14-hospital Ohio health system Kettering Health, holding access from April 9 to May 20, 2025, when they deployed ransomware and triggered a system-wide outage that forced staff back to paper records. The gang exfiltrated roughly 941 GB of data and published it after Kettering refused to pay. Confirmed at 1,695,382 individuals, the stolen data included names, Social Security numbers, driver's license and passport numbers, financial account numbers, medical and treatment information, health insurance and billing records, and account usernames and passwords.

Name Social Security number Driver's license Passport Medical / health Financial Login credentials

Source →

TeleMessage n/a May 2025

the Signal clone archiving officials' texts, cracked in 20 minutes

Scale undisclosed Government United States

After a Reuters photo caught national security adviser Mike Waltz using TM SGNL -- a modified Signal that archives messages for compliance -- a hacker breached its maker TeleMessage in what they described as 15-20 minutes of effort. The clone kept plaintext copies of supposedly end-to-end-encrypted messages on its archive servers; the haul included message contents and metadata tied to Customs and Border Protection, Coinbase, Scotiabank, and, per a Reuters review of the later 410GB DDoSecrets release, more than 60 government users -- disaster responders, diplomats, Secret Service members, a White House staffer. Cabinet-level chats weren't in the stolen set, but the architecture was the story: every agency that bolted an archiving middleman onto Signal had quietly traded away the encryption itself. Smarsh suspended the service; CBP disabled it immediately.

Surveillance records Contact info

Source →

DaVita 2.7M Apr 2025

2.7 million dialysis patients' SSNs and health data stolen

2.7M affected Healthcare United States

The Interlock ransomware group attacked kidney-dialysis giant DaVita in April 2025, exfiltrating and encrypting data on about 2.7 million patients from a lab database -- names, dates of birth, addresses, Social Security numbers, dialysis and health-insurance records, and even images of checks.

Social Security number Medical / health Financial Contact info Date of birth

Source →

Hertz n/a Apr 2025

customers' driver's licenses stolen via Cleo file-transfer flaw

Scale undisclosed Automotive United States Government ID exposed

Hertz, including its Dollar and Thrifty brands, confirmed in April 2025 that customer data had been stolen after attackers exploited zero-day flaws in Cleo's file-transfer software in late 2024. Exposed data included names, contact details, dates of birth, credit-card and driver's license information; a smaller group also had Social Security or other government-ID numbers, passport data, or Medicare/Medicaid IDs taken. Hertz gave no total but said it would be inaccurate to call it millions. The Clop ransomware gang was behind the wider Cleo campaign.

Name Contact info Date of birth Financial Driver's license Passport Social Security number

Source →

Co-op 6.5M Apr 2025

all 6.5 million members' personal data stolen

6.5M affected Retail World

UK retailer Co-op confirmed that a late-April 2025 cyberattack by Scattered Spider affiliates stole the personal data of all 6.5 million of its members -- names, addresses, email addresses, phone numbers, and dates of birth. No financial, transaction, or password data was taken. The attack forced Co-op to shut down systems, emptying some store shelves, but early isolation stopped the DragonForce ransomware from being deployed. Four suspects aged 17-20 were later arrested.

Name Home address Contact info Phone number Date of birth

Source →

SK Telecom 23.2M Apr 2025

23.2M subscribers' SIM keys stolen; record $97M fine

23.2M affected Telecom World

South Korea's biggest carrier disclosed in April 2025 that attackers had reached its Home Subscriber Server and siphoned 25 categories of data on 23.2 million people -- phone numbers, IMSI subscriber identities, and the USIM authentication keys that make SIM cloning possible. The regulator's autopsy was brutal: internet-facing, management, and internal networks linked on one system, management servers needlessly connected to the subscriber core, 26.1 million SIM authentication keys stored unencrypted, and, in the privacy commission chairperson's words, a company in a vulnerable state for a long time that kept missing its chances. SKT replaced every subscriber's SIM card and spent about $812M on remediation and compensation; the PIPC still levied a record 134.8 billion won (~$97M) fine -- the largest in Korean history -- which SKT sued to overturn in January 2026, arguing no user suffered financial loss.

Phone number Login credentials

Source →

Yale New Haven Health 5.5M+ Mar 2025

5.5 million patients' data stolen

5.5M+ affected Healthcare United States

Yale New Haven Health, Connecticut's largest health system, disclosed a March 2025 hack in which attackers stole the personal data of about 5.5 million patients, including names, dates of birth, contact details, Social Security numbers, and medical-record information. Patient care was not disrupted.

Medical / health Social Security number Contact info Date of birth

Source →

Absolute Dental 1.2M Feb 2025

1.2 million patients exposed after a managed-services account was abused

1.2M affected Healthcare United States Government ID exposed

Absolute Dental, a Nevada practice with more than 50 locations, was breached between February 19 and March 5, 2025 after attackers ran a malicious version of a legitimate software tool through an account tied to its third-party managed-services provider. A file review concluded on July 28, 2025 confirmed 1,223,635 people affected. Exposed data included names, contact details, dates of birth, Social Security numbers, driver's license or state-ID information, passport or other government-ID information, and health information; a smaller subset also had financial-account or payment-card data exposed.

Name Contact info Date of birth Social Security number Driver's license Passport Government ID Medical / health Financial

Source →

Conduent 62.2M+ 2025

62 million people's SSNs and health data exposed

62.2M+ affected Gov services United States

Business-services and government-contracting giant Conduent disclosed a ransomware breach in an April 2025 SEC filing; attackers had been in its systems from October 2024 to January 2025 and took more than 8TB of data. Notifications expanded through 2026 as states reported millions of residents affected, and healthcare-breach reporting ultimately placed the total above 62 million people, with Social Security numbers and medical information among the exposed data.

Social Security number Medical / health Financial Contact info

Source →

PowerSchool 62M+ Jan 2025

62 million students' records, including SSNs, stolen

62M+ affected Education United States

A single stolen contractor login let attackers into PowerSchool's K-12 student-information system in January 2025; reporting placed the reach at more than 62 million students and 9.5 million teachers across North America. Exposed data included grades, medical information, and Social Security numbers. PowerSchool paid a ransom but data still surfaced.

Social Security number Medical / health Student ID Name Contact info

Source →

Blue Shield of California 4.7M 2025

4.7 million members' health data shared with Google Ads

4.7M affected Healthcare United States

Blue Shield of California disclosed in 2025 that a misconfigured Google Analytics setup had, from 2021 to 2024, shared the protected health information of about 4.7 million members with Google's advertising system -- names, insurance plan details, medical claims data, and doctor-search activity -- potentially fueling targeted ad campaigns. A textbook case of ad-tech tracking quietly leaking medical data.

Medical / health Contact info

Source →

2024 10 breaches·2.4B+ people
Salt Typhoon n/a Oct 2024

China inside US phone networks, through the wiretap door

Scale undisclosed Telecom United States

Chinese state hackers spent years inside at least nine major US carriers -- AT&T, Verizon, T-Mobile, Lumen, Charter and more -- in what Sen. Mark Warner called the worst telecom hack in the nation's history and the FBI called gigantic and seemingly indiscriminate: over a million call records, who called whom, when, and from where, with the ability to geolocate millions and record calls at will, sparing no one, not even children. The entry that should haunt every lawful-access debate: Salt Typhoon compromised the CALEA wiretap portals that carriers are legally required to build for court-ordered surveillance -- the mandated backdoor became the foreign intelligence service's front door. Targets included the phones of both 2024 presidential campaigns. By August 2025 the FBI counted 200+ victim companies across 80 countries; one carrier had hosted the intruders for three years before detection. No breach notification letters, no credit monitoring -- the people affected are simply everyone with a phone.

Surveillance records Phone number

Source →

National Public Data 1.3B+ 2024

1.3 billion people's SSNs exposed by a data broker

1.3B+ affected Data broker United States

Background-check data broker National Public Data exposed roughly 2.9 billion records covering about 1.3 billion people through a misconfigured database -- full names, addresses, dates of birth, Social Security numbers, phone numbers, and emails. The fallout pushed NPD into bankruptcy.

Social Security number Contact info Home address Date of birth Phone number

Source →

Change Healthcare 193M+ 2024

190 million people in the largest US health breach

193M+ affected Healthcare United States

A ransomware attack on UnitedHealth's Change Healthcare -- which processes a huge share of US medical claims -- exposed the data of roughly 193 million people (a tally that nearly doubled UnitedHealth's initial estimate), including health records, Social Security numbers, and financial information, making it the largest healthcare breach in US history.

Medical / health Social Security number Contact info Financial

Source →

AT&T 73M+ 2024

73 million account records exposed, plus near-total call logs

73M+ affected Telecom United States

AT&T disclosed in 2024 that data on about 73 million current and former account holders -- including Social Security numbers -- had leaked online, and separately that call and text metadata for nearly all its wireless customers had been downloaded from a third-party cloud platform.

Social Security number Contact info Phone number

Source →

El Salvador 5.1M 2024

national ID and facial photos of 80% of citizens leaked

5.1M affected Government World Government ID exposed

In April 2024 a threat actor dumped 144GB of data on more than 5.1 million Salvadorans -- over 80% of the population -- including a high-definition headshot of each person labeled with their national ID (DUI) number, plus names, birthdates, phone numbers, emails, and addresses. It is among the first breaches to expose the biometric data of nearly an entire country.

Government ID Biometrics Contact info Date of birth Home address Phone number

Source →

Ticketmaster 560M+ 2024

560 million customers exposed in the Snowflake wave

560M+ affected Entertainment United States

As part of the 2024 Snowflake campaign -- in which stolen logins gave attackers access to about 165 companies' cloud data because multi-factor authentication was not enforced -- an alleged 560 million Ticketmaster customer records were taken, including names, contact details, and partial payment information.

Contact info Financial Name

Source →

Advance Auto Parts 2.3M 2024

job applicants' SSNs exposed via Snowflake

2.3M affected Retail United States

Advance Auto Parts was among the Snowflake-wave victims in 2024; the breach exposed sensitive data on more than 2.3 million people, largely job applicants, including Social Security numbers and other personal details.

Social Security number Contact info Name

Source →

Kaiser Permanente 13.4M 2024

13.4 million members' health data sent to ad trackers

13.4M affected Healthcare United States

Kaiser Permanente disclosed in 2024 that tracking technologies on its websites and apps had transmitted the personal and health-related data of about 13.4 million members to third-party advertisers including Google, Microsoft Bing, and X -- names, IP addresses, and details of how members used its health sites. It was the largest confirmed US health breach of 2024 and a stark example of surveillance-style ad tracking spilling medical data.

Medical / health Contact info

Source →

Indonesia (KPU) 252M+ 2024

252 million voter records, including passport data, put up for sale

252M+ affected Government World Government ID exposed

Ahead of Indonesia's 2024 election, a threat actor calling themselves 'Jimbo' advertised a breach of the General Elections Commission (KPU) system totaling about 252 million voter entries -- national identity (NIK) numbers, names, birthplaces and dates, addresses, and reportedly passport details -- for roughly two bitcoin, in a country of about 274 million people.

Government ID Passport Contact info Date of birth Home address

Source →

Dell 49M+ 2024

49 million customer records scraped

49M+ affected Technology World

Dell disclosed a 2024 breach in which an attacker abused a partner portal to scrape a database of about 49 million customer records, including names, physical addresses, and order and hardware information.

Contact info Home address

Source →

2023 10 breaches·1.1B+ people
23andMe 6.9M+ 2023

6.9 million people's genetic and ancestry data exposed

6.9M+ affected Healthcare World

A credential-stuffing attack on 23andMe in 2023 reached about 6.9 million people's profiles, exposing ancestry, relationship, and in some cases health-related genetic data -- information that, once out, can never be changed.

Biometrics Medical / health Contact info

Source →

MOVEit / Clop 95M+ 2023

95 million+ people hit across thousands of organizations

95M+ affected Supply chain World

The Clop ransomware group exploited a zero-day in the widely used MOVEit file-transfer tool in 2023, cascading through thousands of companies and government agencies and ultimately exposing the data of more than 95 million people -- a defining supply-chain breach.

Social Security number Contact info Name

Source →

Latitude Financial 14M+ 2023

14 million people's licenses and passports stolen

14M+ affected Financial World Government ID exposed

A 2023 breach of Australian lender Latitude Financial, begun with stolen employee credentials, affected about 14 million people across Australia and New Zealand -- including roughly 7.9 million driver's license numbers and 53,000 passport numbers, some records dating back to 2005. Latitude offered to reimburse customers who replaced stolen ID documents.

Driver's license Passport Government ID Contact info Date of birth Home address

Source →

India (ICMR) 815M+ 2023

815 million citizens' Aadhaar and passport data leaked

815M+ affected Government World Government ID exposed

In late 2023 a threat actor put the personal data of more than 800 million Indian citizens up for sale, drawn from records held by the Indian Council of Medical Research, including names, addresses, passport numbers, and Aadhaar national-ID numbers -- one of the largest exposures of government-ID data ever.

Government ID Passport Contact info Home address

Source →

HCA Healthcare 11M+ 2023

11 million patients' data stolen and posted for sale

11M+ affected Healthcare United States

Hospital giant HCA Healthcare disclosed in 2023 that an external storage location was accessed and data on about 11 million patients was stolen and offered for sale, including names, contact details, dates of birth, and appointment information. It was the largest US health-data breach reported that year until Change Healthcare.

Medical / health Contact info Date of birth

Source →

Comcast Xfinity 35.8M 2023

35.8 million customers exposed via Citrix Bleed

35.8M affected Telecom United States

Attackers exploited the Citrix Bleed vulnerability in October 2023 to reach Comcast Xfinity's internal systems, exposing usernames and hashed passwords for about 35.8 million customers -- essentially the entire base -- and, for many, names, contact details, the last four digits of Social Security numbers, dates of birth, and security questions. Comcast later settled for $117.5 million.

Login credentials Social Security number Contact info Date of birth

Source →

Mr. Cooper 14.7M+ 2023

14.7 million mortgage customers' data stolen

14.7M+ affected Financial United States

Mortgage servicing giant Mr. Cooper disclosed a late-2023 cyberattack that exposed the data of about 14.7 million current and former customers, including names, addresses, dates of birth, Social Security numbers, and bank account numbers tied to their home loans.

Social Security number Contact info Date of birth Financial

Source →

Bangladesh 50M+ 2023

50 million citizens' national ID data exposed by a government site

50M+ affected Government World Government ID exposed

In mid-2023 a researcher found a Bangladeshi government website leaking the personal data of tens of millions of citizens -- names, contact details, and national ID card numbers drawn from the country's birth-and-death registration system -- reachable without authentication. Reporting placed the exposure at around 50 million people.

Government ID Contact info Name

Source →

UK Electoral Commission 40M+ 2023

up to 40 million voters' registers accessed

40M+ affected Government World

The UK Electoral Commission disclosed in 2023 that hackers had sat undetected in its systems for over a year, gaining access to electoral registers holding the names and addresses of up to 40 million voters, including many not otherwise on public rolls. The intrusion was discovered 14 months after it began.

Contact info Name Home address

Source →

Indonesia 34.9M 2023

34.9 million passport holders' data leaked from Immigration

34.9M affected Government World Government ID exposed

In July 2023 the hacker 'Bjorka' leaked data on 34.9 million Indonesian passport holders taken from the Immigration Directorate General -- full names, passport numbers, issue and expiry dates, dates of birth, and gender -- and offered it for sale, spanning documents issued from 2009 to 2020.

Passport Date of birth Name Contact info

Source →

2022 8 breaches·1.1B+ people
Optus 9.8M+ 2022

9.8 million Australians' passports and licenses exposed

9.8M+ affected Telecom World Government ID exposed

A 2022 breach of Australian telecom Optus, traced to an exposed, unauthenticated API, exposed the data of about 9.8 million current and former customers -- roughly a third of Australia's population -- including names, dates of birth, addresses, and passport, driver's license, and Medicare numbers. Optus reserved A$140 million partly to replace compromised identity documents.

Passport Driver's license Government ID Contact info Date of birth Home address

Source →

Medibank 9.7M+ 2022

9.7 million health-insurance customers' records leaked

9.7M+ affected Healthcare World Government ID exposed

A 2022 breach of Australian health insurer Medibank, entered via stolen admin credentials, exposed data on about 9.7 million current and former customers -- names, dates of birth, Medicare and passport numbers, and highly sensitive health-claims data including diagnoses and procedures. When Medibank refused a US$10M ransom, the data was published on the dark web.

Medical / health Government ID Passport Contact info Date of birth

Source →

Shanghai police 1B+ 2022

1 billion residents' IDs and surveillance records exposed

1B+ affected Government World Government ID exposed

In 2022 a hacker offered a 23TB dump from the Shanghai National Police database -- roughly one billion Chinese residents -- exposing names, addresses, national ID numbers, phone numbers, and photos of ID cards, passports, and driver's licenses, alongside detailed police and criminal-case records. Files included movement tracking and reports of people punished for using a VPN to post critical remarks, laying bare a state surveillance apparatus. Likely left exposed by a misconfigured, password-free dashboard.

Government ID Passport Driver's license Biometrics Surveillance records Contact info Home address Phone number

Source →

Twitter 5.4M 2022

5.4 million accounts exposed via an API flaw

5.4M affected Technology World

A now-patched Twitter API flaw let attackers match email addresses and phone numbers to accounts, and in 2022 a dataset of about 5.4 million users built this way was put up for sale.

Contact info Phone number

Source →

Neopets 69M 2022

69 million players breached

69M affected Gaming World

The children's virtual-pet game Neopets was breached in 2022 after attackers spent 18 months inside its systems, stealing data on about 69 million current and former users -- names, emails, birth dates, gender, PINs, and hashed passwords -- plus source code.

Login credentials Contact info Date of birth

Source →

Cash App 8.2M 2022

8.2 million users' financial data taken by an ex-employee

8.2M affected Financial United States

Block disclosed in 2022 that a former employee had downloaded internal reports covering about 8.2 million Cash App Investing users, exposing names, brokerage account numbers, portfolio holdings, and trading activity.

Financial Name

Source →

Shields Health Care 2M+ 2022

2 million patients' SSNs and health data stolen

2M+ affected Healthcare United States

Massachusetts medical provider Shields Health Care Group disclosed a 2022 breach affecting more than 2 million people across 56 facilities, exposing Social Security numbers, diagnoses, medical records, billing information, and other personal data.

Social Security number Medical / health Date of birth Contact info

Source →

Los Angeles Unified School District n/a 2022

students' IDs and records leaked

Scale undisclosed Government United States Government ID exposed

The Vice Society ransomware group leaked about 500GB of data from the Los Angeles Unified School District, the second-largest US school district, in 2022 -- including students' passport and Social Security details, health information, and psychological assessments -- after the district refused to pay.

Social Security number Passport Medical / health

Source →

2021 6 breaches·1.4B+ people
LinkedIn 700M+ 2021

700 million users' profile data scraped and sold

700M+ affected Tech World

Data associated with about 700 million LinkedIn users -- roughly 90% of its base -- was scraped and offered for sale in 2021, including names, email addresses, phone numbers, geolocation, and professional details usable for targeted phishing and social engineering.

Contact info Name Account details

Source →

Facebook 533M+ 2021

533 million users' phone numbers leaked

533M+ affected Tech World

The phone numbers and profile details of about 533 million Facebook users across 106 countries were posted online for free in 2021, tied to a vulnerability abused before 2019. Phone numbers cannot be changed as easily as passwords, keeping the data useful to scammers for years.

Phone number Contact info Name

Source →

T-Mobile 76.6M+ 2021

76.6 million customers' SSNs and licenses exposed

76.6M+ affected Telecom United States Government ID exposed

T-Mobile confirmed in 2021 that a breach exposed the personal data of about 76.6 million current, former, and prospective customers, including names, dates of birth, Social Security numbers, and driver's license or ID information.

Social Security number Driver's license Contact info Date of birth

Source →

Argentina (RENAPER) 45M+ 2021

national ID data for the entire population stolen

45M+ affected Government World Government ID exposed

In 2021 a hacker obtained the contents of RENAPER, Argentina's National Registry of Persons, which issues national ID cards to every citizen -- exposing the ID-card data, including photos, of essentially the country's entire population of about 45 million. The government suspected an insider; the data was offered for sale on hacking forums.

Government ID Biometrics Contact info Date of birth Home address

Source →

Air India 4.5M 2021

4.5 million passengers, with passport data

4.5M affected Travel World Government ID exposed

Air India disclosed a 2021 breach, stemming from a compromise at IT provider SITA, that affected about 4.5 million passengers worldwide and exposed names, birth dates, contact details, passport information, and some payment card data.

Passport Contact info Date of birth Financial

Source →

EssilorLuxottica 77M+ 2021

77 million records exposed

77M+ affected Healthcare World

Eyewear giant EssilorLuxottica had about 77 million records exposed tied to a 2021 breach, including names, contact details, and health-related eyecare information.

Contact info Medical / health

Source →

2020 7 breaches·1.3B+ people
MGM Resorts 142M+ 2020

142 million hotel guests' details posted online

142M+ affected Hospitality United States

Details of MGM Resorts hotel guests -- names, addresses, phone numbers, dates of birth, and emails -- were posted on hacker forums. First reported in early 2020 as 10.6 million guests, the exposed set was later found being sold at about 142 million records. MGM said no passwords or payment card data were included.

Contact info Date of birth Phone number Home address

Source →

Wattpad 270M+ 2020

270 million records leaked

270M+ affected Technology World

The storytelling platform Wattpad suffered a 2020 breach exposing roughly 270 million records -- names, email addresses, hashed passwords, dates of birth, and other profile data. The database, tied to the ShinyHunters group, was first sold privately and later dumped for free on hacker forums.

Login credentials Contact info Date of birth

Source →

easyJet 9M 2020

9 million travelers' data stolen

9M affected Travel World

UK low-cost airline easyJet disclosed a 2020 breach that exposed the email addresses, names, and travel records of about 9 million customers, and the full credit card details (including CVV) of roughly 2,200 of them. The airline was criticized for waiting months to notify customers.

Contact info Financial

Source →

Marriott 5.2M 2020

5.2 million guests hit in a second breach

5.2M affected Hospitality United States

In March 2020 Marriott disclosed a fresh breach -- distinct from its 2018 Starwood incident -- after attackers used two employees' login credentials to siphon data on about 5.2 million guests over roughly a month, including names, contact details, dates of birth, gender, and loyalty account information. No payment data was taken.

Contact info Date of birth Phone number

Source →

Broadvoice 350M+ 2020

350 million records, including voicemail transcripts

350M+ affected Telecom United States

A researcher found unsecured databases from VoIP provider Broadvoice exposing more than 350 million records -- caller names, phone numbers, and locations -- along with hundreds of thousands of transcribed voicemails, some revealing sensitive medical and financial details.

Contact info Phone number Medical / health Financial

Source →

Weibo 538M+ 2020

538 million users' data offered for sale

538M+ affected Technology World

Data on about 538 million users of the Chinese microblogging platform Weibo surfaced for sale in 2020 -- real names, site usernames, gender, and location, with phone numbers for roughly 172 million of them. No passwords or payment data were reported in the set.

Contact info Phone number

Source →

Antheus Tecnologia n/a 2020

76,000 fingerprints exposed by a biometrics firm

Scale undisclosed Technology World

Researchers found an unsecured server run by Brazilian biometrics company Antheus Tecnologia holding about 76,000 fingerprint records -- stored as binary data that could be reverse-engineered back into usable fingerprints -- alongside some 81.5 million records with employee and administrator details. Unlike a password, a leaked fingerprint can never be changed.

Biometrics

Source →

2019 6 breaches·3.2B+ people
First American Financial 885M+ 2019

885 million mortgage records exposed

885M+ affected Financial United States Government ID exposed

A website design flaw (an insecure direct object reference) left roughly 885 million First American Financial mortgage and title documents publicly accessible without authentication, including Social Security numbers, driver's licenses, bank account details, and images of sensitive financial records going back years.

Social Security number Driver's license Financial Contact info

Source →

Capital One 106M+ 2019

106 million applicants' data stolen

106M+ affected Financial United States

A misconfigured web application firewall let an attacker access Capital One data on about 106 million credit-card applicants in the US and Canada in 2019, including names, addresses, credit scores, and roughly 140,000 Social Security numbers and 80,000 linked bank account numbers.

Social Security number Financial Contact info Date of birth

Source →

People Data Labs 1.2B+ 2019

1.2 billion people's profiles exposed

1.2B+ affected Data broker United States

In 2019 researchers found an open database holding about 1.2 billion people's aggregated profiles -- names, email addresses, phone numbers, and social-media handles -- traced largely to data brokers People Data Labs and OxyData, illustrating how brokers concentrate risk.

Contact info Name Phone number

Source →

Canva 140M+ 2019

140 million users breached

140M+ affected Technology World

Design platform Canva was hacked in 2019, exposing about 140 million users' names, usernames, email addresses, and hashed passwords.

Login credentials Contact info

Source →

Airtel 320M+ 2019

320 million subscribers exposed by an app flaw

320M+ affected Telecom World

A security flaw in an app from Indian telecom giant Airtel exposed the data of about 320 million subscribers in 2019, including names, birth dates, addresses, and other subscriber details.

Contact info Phone number Date of birth

Source →

Facebook 540M+ 2019

540 million records left on public servers

540M+ affected Technology World

In 2019 researchers found more than 540 million Facebook user records -- account IDs, comments, likes, and some contact details -- sitting exposed on public cloud servers by third-party app developers.

Contact info

Source →

2018 8 breaches·2.4B+ people
Aadhaar 1.1B+ 2018

1.1 billion citizens' national ID and biometric data exposed

1.1B+ affected Government World Government ID exposed

India's Aadhaar national identity system, which links biometric and demographic data to a unique ID number, was reported in 2018 to be accessible through insecure government portals and third-party endpoints, exposing the records of close to 1.1 billion citizens and raising lasting concerns about centralized digital-ID systems.

Government ID Biometrics Contact info Home address Phone number

Source →

Marriott / Starwood 500M+ 2018

500 million guests' records, including passports, exposed

500M+ affected Travel World Government ID exposed

Attackers sat inside Starwood's guest reservation system from 2014 until Marriott discovered the intrusion in 2018, exposing data on up to 500 million guests -- names, addresses, dates of birth, and encrypted passport numbers, with some payment data. The UK ICO fined Marriott and it had to reimburse guests for replacement passports.

Passport Contact info Date of birth Home address Financial

Source →

Exactis 340M+ 2018

340 million records left on an open server

340M+ affected Data broker United States

In 2018 marketing data broker Exactis exposed a database of about 340 million records on a publicly accessible server, including phone numbers, emails, home addresses, and detailed personal characteristics -- assembled on people who never knowingly did business with the firm.

Contact info Date of birth Home address Phone number

Source →

Cathay Pacific 9.4M 2018

9.4 million passengers, with passport numbers

9.4M affected Travel World Government ID exposed

Hong Kong carrier Cathay Pacific disclosed a 2018 breach affecting about 9.4 million passengers, exposing names, birth dates, phone numbers, addresses, and -- for many -- passport and Hong Kong ID numbers.

Passport Contact info Date of birth

Source →

US Postal Service 60M+ 2018

60 million users exposed by an API flaw

60M+ affected Government United States

A flaw in the US Postal Service's Informed Visibility tool exposed the account details of about 60 million users in 2018 -- usernames, addresses, phone numbers, and mailing data -- to any logged-in user.

Contact info Home address

Source →

Dubsmash 162M+ 2018

162 million accounts breached

162M+ affected Technology World

The video app Dubsmash was breached in 2018, with about 162 million records -- usernames, email addresses, and hashed passwords -- later put up for sale among a large batch of stolen databases.

Login credentials Contact info

Source →

MyFitnessPal 150M+ 2018

150 million users breached

150M+ affected Technology World

Under Armour's MyFitnessPal app was breached in 2018, exposing about 150 million users' usernames, email addresses, and hashed passwords.

Login credentials Contact info

Source →

MyHeritage 92M+ 2018

92 million users breached

92M+ affected Technology World

The genealogy site MyHeritage disclosed a 2018 breach exposing the email addresses and hashed passwords of about 92 million users.

Login credentials Contact info

Source →

2017 5 breaches·796.9M+ people
Uber 57M Nov 2017

57 million riders and drivers exposed in a concealed breach

57M affected Technology United States Government ID exposed

In late 2016 two attackers used an AWS key found in a private Uber GitHub repository to download data on 57 million riders and drivers from a cloud storage bucket, including 600,000 U.S. drivers' license numbers plus rider names, emails and phone numbers. Rather than report it, Uber paid the hackers $100,000 to delete the data and stay quiet, disguising it as a bug-bounty payout. New leadership revealed the concealed breach in November 2017; Uber later paid $148 million to settle with all 50 states and its former security chief was criminally convicted.

Name Contact info Phone number Driver's license

Source →

River City Media 393M+ Mar 2017

1.4 billion records (393 million emails) exposed by a spam operation

393M+ affected Data broker United States

A misconfigured backup left the databases of River City Media, a large spam operation, exposed online with no password. A researcher found about 1.4 billion records -- names, email addresses, IP addresses and often physical addresses -- amounting to roughly 393 million unique email addresses. Disclosed in March 2017, it was described at the time as one of the largest single data exposures ever.

Name Contact info Home address

Source →

Equifax 147M+ 2017

147 million consumers' SSNs and IDs exposed

147M+ affected Financial United States Government ID exposed

Credit bureau Equifax failed to patch a known Apache Struts vulnerability, letting attackers roam its network for 76 days in 2017 and steal the Social Security numbers, birth dates, addresses, driver's license details, and some credit card numbers of about 147 million people -- roughly half the US population.

Social Security number Driver's license Date of birth Contact info Financial

Source →

US voter file 198M+ 2017

nearly 200 million voters' profiles left exposed

198M+ affected Political United States

In 2017 an analytics firm working for the Republican National Committee left a 1.1TB database on an unsecured cloud server, exposing details on nearly 200 million registered US voters -- names, addresses, birth dates, phone numbers, party, and modeled 'ethnicity' and 'religion' fields used for political profiling.

Contact info Date of birth Home address Name

Source →

Bell Canada 1.9M+ 2017

1.9 million customer records exposed

1.9M+ affected Telecom World

Canadian telecom Bell disclosed a 2017 breach exposing about 1.9 million customer email addresses, along with some names and phone numbers.

Contact info Phone number

Source →

2016 6 breaches·1B+ people
Uber 57M+ 2016

57 million riders and drivers, breach concealed for a year

57M+ affected Tech World Government ID exposed

Attackers accessed data on about 57 million Uber riders and drivers in 2016, including names, emails, phone numbers, and around 600,000 US drivers' license numbers. Uber paid the hackers to stay quiet and concealed the breach for more than a year.

Contact info Phone number Driver's license

Source →

Mexico 87M+ 2016

87 million voters' records with national IDs exposed

87M+ affected Government World Government ID exposed

In 2016 a researcher found Mexico's entire voter roll -- about 87 million records including names, addresses, birth dates, and national ID numbers -- sitting in a misconfigured, publicly reachable cloud database. Electoral authorities later fined a political party for failing to secure its copy of the list.

Government ID Contact info Date of birth Home address

Source →

Turkey 50M+ 2016

50 million citizens' national ID database posted online

50M+ affected Government World Government ID exposed

In 2016 an unnamed hacker posted a downloadable database titled 'Turkish Citizenship Database' containing the personal data of roughly 50 million citizens -- names, addresses, parents' names, places and dates of birth, and national ID numbers.

Government ID Contact info Date of birth Home address

Source →

MySpace 360M+ 2016

360 million accounts leaked

360M+ affected Tech United States

In 2016 about 360 million MySpace account credentials from a pre-2013 breach appeared for sale online. Though the platform was long past its peak, the reused emails and passwords fueled credential-stuffing attacks on other services for years.

Login credentials Contact info

Source →

Philippines COMELEC 55M+ 2016

55 million voters, with fingerprints, leaked

55M+ affected Government World Government ID exposed

In the 2016 'Comeleak', the entire voter database of the Philippine Commission on Elections -- about 55 million voters -- was hacked and published, including names, addresses, birth dates, passport data, and fingerprint records.

Government ID Biometrics Contact info Date of birth

Source →

FriendFinder Networks 412M+ 2016

412 million adult-site accounts breached

412M+ affected Technology World

The adult-networking company FriendFinder Networks (AdultFriendFinder, Cams.com, Penthouse.com and others) was hacked in 2016, exposing about 412 million accounts spanning two decades -- usernames, email addresses, and passwords stored in plaintext or weak SHA-1 hashes. The sensitive nature of the sites made the exposure especially damaging.

Login credentials Contact info

Source →

2015 5 breaches·157.9M+ people
Anthem 78.8M+ 2015

78.8 million health-insurance records stolen

78.8M+ affected Healthcare United States

Health insurer Anthem disclosed in 2015 that attackers stole records on 78.8 million people -- names, dates of birth, Social Security numbers, addresses, and employment data. Anthem settled a class action for a then-record $115 million.

Social Security number Medical / health Date of birth Contact info Home address

Source →

US OPM 22.1M+ 2015

22 million federal workers' clearance and fingerprint data stolen

22.1M+ affected Government United States

A breach of the US Office of Personnel Management, attributed to Chinese state hackers, exposed the deeply sensitive SF-86 background-investigation files of about 21.5 million security-clearance applicants and relatives, plus 5.6 million fingerprint records -- data that cannot be reissued.

Social Security number Biometrics Contact info Date of birth Home address

Source →

Ashley Madison 32M+ 2015

32 million users of an affair site exposed and extorted

32M+ affected Dating World

The 2015 breach of Ashley Madison, a site marketed for extramarital affairs, exposed about 32 million users' account details, including names, email addresses, and payment records. The intensely sensitive nature of the data fueled extortion campaigns and lasting personal harm, and remains a landmark case in how breach data can be weaponized against individuals.

Contact info Financial Name

Source →

Experian / T-Mobile 15M+ 2015

15 million credit applicants exposed

15M+ affected Financial United States

A 2015 breach at credit bureau Experian exposed about 15 million people who had applied for T-Mobile service, including names, addresses, birth dates, and the Social Security or ID numbers used for credit checks.

Social Security number Date of birth Contact info

Source →

Excellus BlueCross BlueShield 10M+ 2015

10 million members' SSNs and health data

10M+ affected Healthcare United States

Excellus BlueCross BlueShield disclosed a 2015 breach affecting about 10 million people, exposing names, birth dates, Social Security numbers, and medical claims -- with attacker access traced back to 2013.

Social Security number Medical / health Date of birth Contact info

Source →

2014 6 breaches·816.5M+ people
eBay 145M+ 2014

145 million accounts accessed via employee credentials

145M+ affected Retail World

Attackers used stolen employee credentials to reach eBay's corporate network in 2014 and exfiltrate about 145 million account records, including names, encrypted passwords, and contact information, prompting a company-wide password reset.

Login credentials Contact info Name

Source →

JPMorgan Chase 76M+ 2014

76 million households' data accessed

76M+ affected Financial United States

A 2014 intrusion at JPMorgan Chase reached the contact information of about 76 million households and 7 million small businesses -- names, addresses, phone numbers, and emails -- one of the largest breaches of a US bank.

Contact info Name

Source →

Home Depot 56M+ 2014

56 million payment cards stolen

56M+ affected Retail United States

Point-of-sale malware at Home Depot in 2014 compromised about 56 million payment cards along with tens of millions of email addresses, one of the largest retail card breaches on record.

Financial Contact info

Source →

Community Health Systems 4.5M 2014

4.5 million patients' SSNs stolen

4.5M affected Healthcare United States

Community Health Systems, one of the largest US hospital operators, disclosed a 2014 breach -- attributed to a group exploiting the Heartbleed flaw -- that stole names, addresses, birth dates, and Social Security numbers of about 4.5 million patients.

Social Security number Date of birth Contact info

Source →

Benesse 35M+ 2014

35 million records sold by an insider

35M+ affected Education World

Japanese education company Benesse suffered a 2014 insider breach in which a contractor copied and sold data on about 35 million customers, largely families of students, including names, addresses, and children's details.

Contact info Date of birth Name

Source →

Yahoo 500M+ 2014

500 million accounts stolen in a second breach

500M+ affected Technology World

Separate from its record 2013 breach, Yahoo suffered a 2014 intrusion by state-sponsored attackers that stole data on about 500 million accounts -- names, email addresses, phone numbers, birth dates, hashed passwords, and security questions. The full scope was not disclosed until 2016.

Contact info Login credentials Date of birth Phone number

Source →

2013 5 breaches·3.3B+ people
Yahoo 3B+ 2013

all 3 billion user accounts compromised

3B+ affected Tech World

Russian state-linked hackers breached Yahoo starting in 2013, ultimately compromising all 3 billion user accounts -- names, email addresses, phone numbers, dates of birth, and hashed passwords. Yahoo did not disclose the full scope until 2017, and it remains the largest confirmed breach on record.

Login credentials Contact info Date of birth Phone number Name

Source →

Adobe 153M+ 2013

153 million accounts and credentials stolen

153M+ affected Tech World

Adobe's 2013 breach, first thought to affect 3 million users, ultimately exposed more than 153 million accounts -- email addresses, poorly encrypted passwords, password hints, and some credit card details -- a landmark example of weak encryption practices.

Login credentials Financial Contact info

Source →

Target 70M+ 2013

40 million cards and 70 million customers' data stolen

70M+ affected Retail United States

Point-of-sale malware at Target during the 2013 holiday season stole about 40 million credit and debit card numbers and the personal information of up to 70 million customers, a landmark retail breach that reshaped payment security.

Financial Contact info

Source →

Evernote 50M+ 2013

50 million users forced to reset passwords

50M+ affected Technology World

Note-taking service Evernote forced a password reset for about 50 million users in 2013 after attackers accessed usernames, email addresses, and hashed passwords.

Login credentials Contact info

Source →

LivingSocial 50M+ 2013

50 million customers breached

50M+ affected Technology World

The daily-deals site LivingSocial disclosed a 2013 breach affecting about 50 million customers, exposing names, email addresses, birth dates, and salted password hashes.

Login credentials Contact info Date of birth

Source →

2012 4 breaches·205.4M+ people
Dropbox 68M+ 2012

68 million user credentials stolen

68M+ affected Tech World

A 2012 Dropbox breach exposed about 68 million users' email addresses and hashed passwords; the full scale only became clear in 2016 when the data surfaced online, a classic case of credential reuse fueling later attacks.

Login credentials Contact info

Source →

Blizzard (Battle.net) 14M+ 2012

14 million gaming accounts breached

14M+ affected Gaming World

A 2012 breach of Blizzard Entertainment's Battle.net service exposed data on about 14 million accounts, including email addresses, security-question answers, and scrambled passwords.

Login credentials Contact info

Source →

South Carolina Dept. of Revenue 6.4M 2012

6.4 million taxpayers' SSNs stolen

6.4M affected Government United States

Hackers stole about 6.4 million South Carolina taxpayer records in 2012 after an employee fell for a phishing email, exposing Social Security numbers and hundreds of thousands of credit and debit card numbers.

Social Security number Financial Contact info

Source →

LinkedIn 117M+ 2012

117 million accounts stolen

117M+ affected Technology World

A 2012 breach of LinkedIn, first reported as only a few million, ultimately exposed about 117 million members' email addresses and unsalted SHA-1 password hashes, which surfaced for sale years later.

Login credentials Contact info

Source →

2011 5 breaches·88.3M+ people
Citigroup 360K Jun 2011

360,000 credit card accounts breached

360K affected Financial United States

Attackers walked through Citi's Account Online web platform in May 2011 by manipulating account numbers in the browser's address bar, harvesting data from 360,083 U.S. credit-card accounts. Names, account numbers and contact details including email addresses were taken; Citi said Social Security numbers, birth dates, card expiration dates and CVV codes were not exposed. The bank waited about three weeks to notify customers and reissued cards on affected accounts.

Name Financial Contact info

Source →

Epsilon n/a Apr 2011

customer names and emails exposed across 75+ major brands

Scale undisclosed Technology United States

Epsilon, then the world's largest permission-based email marketing firm, said an intrusion detected on March 30, 2011 exposed the names and email addresses of customers belonging to a subset of its 2,500+ corporate clients -- among them Chase, Citi, Capital One, Best Buy, Walgreens and Verizon. No financial data was taken, but the exposure across dozens of major brands was called one of the largest breaches in history at the time and drove a wave of targeted phishing. Prosecutors later tied it to a spam ring that blasted stolen addresses.

Name Contact info

Source →

Sony PlayStation Network 77M+ 2011

77 million accounts compromised

77M+ affected Gaming World

The 2011 breach of Sony's PlayStation Network exposed about 77 million accounts -- names, addresses, emails, birth dates, logins, and in some cases card data -- and forced the gaming service offline for weeks, a landmark early mega-breach.

Login credentials Contact info Financial

Source →

Tricare / SAIC 4.9M+ 2011

4.9 million military health records lost

4.9M+ affected Healthcare United States

Backup tapes holding the health records of about 4.9 million US military members, retirees, and their families in the Tricare program were lost in 2011, exposing Social Security numbers, addresses, phone numbers, and clinical data.

Social Security number Medical / health Home address Phone number

Source →

CSDN 6M+ 2011

6 million developer accounts with plaintext passwords

6M+ affected Technology World

China Software Developer Network, a major Chinese programming portal, was breached in 2011, exposing about 6 million usernames, email addresses, and passwords that had been stored in plain text.

Login credentials Contact info

Source →

2010 2 breaches·4.6M+ people
Gawker Media 1.3M+ Dec 2010

1.3 million commenter accounts leaked by Gnosis

1.3M+ affected Media United States

A group calling itself Gnosis broke into Gawker Media's servers in December 2010, dumping about 1.3 million commenter usernames, email addresses, and weakly hashed passwords -- plus the site's source code -- onto file-sharing networks. The old DES-based hashes were quickly cracked, and reused credentials were used to hijack thousands of Twitter accounts for spam. The breach hit Gizmodo, Lifehacker, Kotaku, Jezebel, and other Gawker sites.

Login credentials Contact info

Source →

Educational Credit Management Corp 3.3M+ Mar 2010

3.3 million student-loan borrowers' data stolen

3.3M+ affected Education United States

Portable media holding the names, addresses, dates of birth, and Social Security numbers of about 3.3 million federal student-loan borrowers was physically stolen from the Minnesota headquarters of guaranty agency ECMC in March 2010. No bank-account data was included. The media was later recovered and investigators said they found no evidence of misuse, but the theft ranked among the largest identity-data losses of the year.

Social Security number Date of birth Home address Name

Source →

2009 2 breaches·162M+ people
RockYou 32M+ Dec 2009

32 million accounts with plaintext passwords exposed

32M+ affected Technology United States

A hacker exploiting a basic SQL-injection flaw pulled the entire user database of RockYou, a maker of social-media widgets and games, in December 2009 -- about 32 million accounts. The passwords were stored in plain text with no hashing, and because users often reused their email credentials, the exposure reached well beyond the site. The leaked list became 'rockyou.txt,' still the most widely used password-cracking wordlist.

Login credentials Contact info

Source →

Heartland Payment Systems 130M+ Jan 2009

130 million payment cards stolen

130M+ affected Financial United States

One of the largest U.S. card processors disclosed on January 20, 2009 that malware planted through a SQL-injection attack had captured unencrypted card data in transit through its network during 2008. Prosecutors later put the total at roughly 130 million credit- and debit-card accounts, the largest payment-card breach reported at the time. Albert Gonzalez, mastermind of the TJX breach, was indicted for it and sentenced to 20 years.

Financial Name

Source →

2008 2 breaches·6.2M+ people
Countrywide Financial 2M+ Aug 2008

~2 million mortgage applicants' records stolen and sold by an insider

2M+ affected Financial United States

Rene Rebollo, a senior financial analyst in Countrywide's subprime lending division, spent about two years copying roughly 20,000 customer records a week onto a USB drive and selling the data. The FBI arrested him in August 2008; an estimated 2 million mortgage applicants' records -- names, Social Security numbers, addresses and financial-account details -- were taken. A later class-action settlement covered about 17 million people whose data sat in the affected systems.

Name Social Security number Financial Home address

Source →

Hannaford Bros. 4.2M Mar 2008

4.2 million credit and debit card numbers stolen

4.2M affected Retail United States

Malware planted on servers at more than 300 Hannaford and Sweetbay grocery stores captured credit- and debit-card numbers in transit during card authorization between December 2007 and March 2008. About 4.2 million unique card numbers were exposed and at least 1,800 fraud cases were tied to the breach. Only card numbers and expiration dates were taken; it was an early, widely studied case of card data stolen in transit.

Financial

Source →

2007 2 breaches·102.5M+ people
Certegy / Fidelity National 8.5M Jul 2007

8.5 million consumer records stolen and sold by an insider

8.5M affected Financial United States

A senior database administrator at Certegy Check Services, a Fidelity National Information Services unit, stole 8.5 million consumer records over roughly five years and sold them to data brokers who resold them to direct marketers. The records included names, addresses, dates of birth, checking-account numbers and, for about 1.5 million people, credit-card details. Fidelity first disclosed 2.3 million records in July 2007, then raised the figure to 8.5 million in an SEC filing.

Name Home address Date of birth Financial Phone number

Source →

TJX Companies (T.J. Maxx, Marshalls) 94M+ Jan 2007

up to 94 million payment cards stolen

94M+ affected Retail United States

Hackers led by Albert Gonzalez broke into TJX's networks through a poorly secured store Wi-Fi connection in 2005 and installed sniffer software that captured payment-card 'track' data for about 18 months before the intrusion was found in December 2006. TJX disclosed it in January 2007 and acknowledged at least 45.7 million cards; court filings citing Visa and MasterCard put the exposure at up to 94 million accounts, the largest retail card breach reported at the time.

Financial

Source →

No tracked breaches match those filters.

Counts reflect the most complete figures reported to date; several are still under investigation and may grow. "Undisclosed" means the organization has not released a victim count. Missing one? Submit a sourced breach.

If your data's been stolen

You can't un-leak data, but you can shut down most of the ways it gets used against you. Start here.

1Change the password on the breached account and anywhere you reused it. A password manager makes every login unique, so one leak can't unlock the rest.
2Turn on two-factor authentication. Prefer an authenticator app or a passkey over text-message codes, which are easier to intercept.
3Freeze your credit -- it's free, and it's the strongest block on someone opening accounts in your name. Do it at all three bureaus: Equifax, Experian, and TransUnion. A fraud alert is a lighter-weight alternative.
4Expect targeted scams. Leaked details make phishing emails and calls far more convincing. Never act on a link inside a "breach notice" -- open the company's site yourself instead.
5Watch your statements and credit reports. Pull your free weekly reports at annualcreditreport.com and report anything you don't recognize.
6If a Social Security number or government ID leaked, get a personalized recovery plan at identitytheft.gov, consider an IRS Identity Protection PIN, and replace a compromised license or passport.

General guidance, not legal or financial advice. If a breach notice offers free credit monitoring, it costs you nothing to accept. For health-data breaches, also review benefits statements for care or claims you don't recognize.