Europe's largest breaches no longer start inside the organizations that get named in the headlines. They start in shared third-party operators, public-sector systems, and software supply chains, where a single compromise can expose an entire national population at once. That concentration is what makes the European picture distinct: identity records for half of France, tax data for nearly every Bulgarian adult, and health records for one in seven Swedes were each exposed through a handful of intermediaries.
This list ranks the 29 largest and most consequential data breaches in Europe, current as of July 2026, ordered primarily by the number of people or records affected, with several lower-volume but high-notability incidents included for their regulatory or operational significance. The biggest by headcount are France Travail (up to 43 million people), Turkey's Mernis identity leak (49.6 million citizens), and the combined Viamedis and Almerys health payment breach (more than 33 million people). Several figures remain disputed or attacker-claimed, and those flags are preserved throughout.
Enforcement under the General Data Protection Regulation (GDPR) has become sustained rather than sporadic. The CMS GDPR Enforcement Tracker Report found that documented fines passed the €6 billion mark for the first time, reaching approximately €6.11 billion across 2,685 publicly recorded cases by its March 1, 2026 cut-off. The DLA Piper survey, which also captures penalties that aren't always published, puts the cumulative total closer to €7.1 billion since May 2018. Ireland's Data Protection Commission (DPC) remains the largest enforcer by value at around €4.04 billion, followed by France's CNIL at over €1 billion.
Two cross-border transfer cases sit at the top of the table. Meta's €1.2 billion fine is still the largest ever issued, and TikTok's €530 million penalty now stands as the second largest, a scale that stands out even against broader data breach statistics. The figures below reflect the current standings.
RankOrganisationAmountRegulatorDate announcedGrounds1Meta Platforms Ireland€1.2 billionIrish DPCMay 22, 2023Unlawful EU to US transfers (Chapter V)2TikTok Technology Ltd€530 millionIrish DPCMay 2, 2025Unlawful transfers to China plus transparency3Google LLC and Google Ireland€325 millionCNIL (France)2025Advertising in Gmail and cookie consent failures4Meta Platforms Ireland€405 millionIrish DPCSeptember 5, 2022Instagram processing of children's data5Meta Platforms Ireland€390 millionIrish DPCJanuary 4, 2023Lawful basis for behavioural advertising6Meta Platforms Ireland€265 millionIrish DPCNovember 25, 2022Data scraping and data protection by design7Meta Platforms Ireland€251 millionIrish DPCDecember 17, 20242018 Facebook access token breach8WhatsApp Ireland€225 millionIrish DPCSeptember 2, 2021Transparency failures9Shein (Infinite Styles Services)€150 millionCNIL (France)2025Cookie consent violations10Google LLC€90 millionCNIL (France)January 6, 2022Cookie refusal mechanisms
One important correction to older rankings concerns Amazon. The €746 million fine against Amazon Europe Core, imposed by Luxembourg's CNPD in 2021, was set aside by the Luxembourg Administrative Court of Appeal in March 2026 on procedural grounds and referred back, as the CMS GDPR Enforcement Tracker confirms in noting that nine of the ten highest fines now originate from the Irish DPC. The findings were largely upheld, so Amazon has not been "cleared," but the €746 million figure no longer stands as an enforceable fine and should be footnoted rather than listed as current.
The entries below are ranked primarily by the number of people or records affected. Several incidents with smaller headcounts appear because of their regulatory weight, operational damage, or precedent-setting importance. For a wider view beyond the continent, compare this list against the biggest data breaches worldwide and region-specific roundups such as Australia's largest data breaches. Where a figure is disputed, estimated, or claimed only by the attacker, that flag is stated explicitly.
RankIncidentCountryRecords affectedYear disclosed1France TravailFranceUp to 43 million (max exposure)20242Turkey Mernis identity leakTurkey49.6 million20163Viamedis and AlmerysFrance33 million+20244Banco SantanderSpain~30 million (attacker claim)20245Spain DGTSpain~27 million (attacker claim)20246Deutsche Telekom / T-Mobile GermanyGermany17 million20087Free and Free MobileFrance~19.2 million20248Bulgaria NRABulgaria~5 million20199Meta Platforms Ireland (fine)IrelandHundreds of millions202310TikTok (fine)Ireland150 million+ EU users202511Ireland HSE ransomwareIreland~100,000 notified202112Ho MobileItaly~2.5 million202113KyivstarUkraine~24 million subscribers (service)202314MiljodataSweden1.5 million+202515Netherlands GGDNetherlandsMillions accessible (unverified)202116Dutch National PoliceNetherlands~63,000202417Norsk HydroNorway35,000 employees (operational)201918Coop Sweden (Kaseya)Sweden~800 stores (operational)202119Polish Anti-Doping AgencyPoland50,000+ files202420ALAB LaboratoriaPolandTens of thousands (unverified)202321XplainSwitzerland~65,000 documents202322RadixSwitzerland~1.3 TB (unverified headcount)202523Air EuropaSpainNot quantified202324Collins Aerospace MUSEMulti-countryDisputed (attacker claim)202525European CommissionEU institutions~92 GB (no headcount)202626Greek Ministry of InteriorGreeceNot published202427EasyJetUnited Kingdom9 million202028Marriott and British AirwaysUnited Kingdom339 million / 429,612201829Change Healthcare and ConduentUnited States192.7 million / 25 million+ (rising)2024
Records affected: Up to 43 million people, France Travail's own upper bound; the agency could not confirm all 43 million records were exfiltrated, so treat this as maximum exposure rather than a confirmed count.
Date of breach: February 6 to March 5, 2024. Date disclosed: March 13, 2024. Country: France. Sector: Government, public employment services.
Attack vector: Impersonation of Cap Emploi advisers to obtain legitimate credentials and query the jobseeker database.
Data exposed: Full name, date and place of birth, social security number, France Travail identifier, email, postal address, and phone number. Bank details and passwords were not affected.
Attackers using credentials tied to partner organization Cap Emploi queried the jobseeker database over roughly a month, potentially exposing the identity records of everyone registered as a jobseeker in the previous two decades. The exposure of social security numbers alongside full identity data made this the single largest personal data incident ever disclosed in Europe by headcount, and it heads a run of incidents in France's biggest data breaches. Three suspects were arrested in March 2024, and the CNIL opened an investigation; no public fine had been issued as of July 2026.
Source: France Travail statement, CNIL
Records affected: 49.6 million Turkish citizens, roughly two thirds of the population at the time. A separate 2023 claim of about 85 million records has never been officially confirmed and should be treated as unverified.
Date of breach: Believed to date from 2008 to 2009. Date disclosed: April 2016. Country: Turkey. Sector: Government, civil registry.
Attack vector: Unknown; the leaked database appeared to originate from the Mernis central civil registration system.
Data exposed: National identity number, full name, parents' names, gender, city and date of birth, and full registered address.
An unidentified group published a searchable 1.5 GB database containing the national identity records of nearly 50 million citizens, including the then president and prime minister. Because Turkish national identity numbers are used widely for authentication, the leak created a durable identity fraud risk that couldn't be remediated by reissuing credentials. Turkey was not subject to GDPR at the time, and no sanction was publicly issued.
Source: Al Jazeera, Daily Sabah
Records affected: More than 33 million people, per the CNIL, covering both third-party payment operators.
Date of breach: Late January 2024 (Viamedis) and early February 2024 (Almerys). Date disclosed: February 1 and February 7, 2024. Country: France. Sector: Health insurance, third-party payment.
Attack vector: Phishing and compromise of healthcare professionals' access credentials to the operators' portals.
Data exposed: Marital status, date of birth, social security number, insurer name, and policy guarantee details. Neither operator held bank details, medical data, addresses, phone numbers, or emails.
Two operators that process complementary health insurance payments on behalf of dozens of French insurers were breached within days of each other through compromised health-professional accounts. The CNIL confirmed that data on more than 33 million people had been affected, making it the largest health-related data incident in French history and one of the largest healthcare data breaches on record. Its significance lies in concentration risk: two mid-sized companies held identity and insurance data for roughly half the French population. The CNIL opened investigations under GDPR Article 32; no public fine had been issued as of July 2026.
Source: CNIL statement, Le Monde
Records affected: Around 30 million customer records claimed by the extortion group across Spain, Chile, and Uruguay. Santander confirmed a breach affecting those three markets plus current and some former employees but did not confirm the 30 million figure, so that number is the attacker's claim and remains unverified.
Date of breach: Detected May 2024. Date disclosed: May 14, 2024. Country: Spain, with impact in Chile and Uruguay. Sector: Banking.
Attack vector: Unauthorized access to a database hosted by a third-party provider, tied to the wider Snowflake tenant compromise campaign that relied on stolen credentials without multi-factor authentication (MFA).
Data exposed: Names, account numbers, balances, credit card numbers (per attacker claims), and HR data. Santander said no transactional data, online banking credentials, or passwords were accessed.
Santander was one of the highest-profile victims of the 2024 campaign against cloud data warehouse tenants, in which attackers used credentials harvested by infostealers to reach environments that lacked MFA. The disclosure showed how a single third-party analytics platform could expose customer data across multiple national banking subsidiaries at once, a recurring theme among financial services data breaches. Two suspects were arrested in the UK in May 2024. No public GDPR fine had been issued as of July 2026.
Source: Banco Santander statement, BleepingComputer
Records affected: Around 27 million driver records were initially claimed by the seller, with later listings advertised as more than 34 million. The DGT acknowledged unauthorized access through a professional account but didn't confirm the volume, so these figures are attacker claims and unverified.
Date of breach: Late 2023 and early 2024. Date disclosed: March 2024. Country: Spain. Sector: Government, transport.
Attack vector: Abuse of legitimate credentials belonging to an authorized professional subscriber account with query access to the vehicle and driver register.
Data exposed: Name, national identity number (DNI), address, vehicle registration and technical data, and licence details.
A threat actor advertised a bulk database of Spanish drivers and vehicles for sale, apparently assembled by systematically querying the DGT's professional access service rather than by breaching the register directly. It's a reference example of subscriber-account abuse in the public sector, where the technical controls held but the authorization model allowed mass extraction. The DGT reported the incident to the AEPD and police and suspended the account involved.
Source: AEPD, El Economista
Records affected: 17 million T-Mobile Germany subscribers.
Date of breach: 2006. Date disclosed: October 2008. Country: Germany. Sector: Telecommunications.
Attack vector: Theft of a copy of a customer database, initially treated as internal data theft and not disclosed publicly for two years.
Data exposed: Names, addresses, dates of birth, mobile numbers, and in some cases emails and bank account details of high-profile subscribers.
Deutsche Telekom lost a customer database covering 17 million German mobile subscribers in 2006, but the loss only became public when Der Spiegel reported it in 2008. The two-year delay, in the pre-GDPR era with no mandatory 72-hour notification, became a central argument in Germany for tighter breach-notification duties. It remains the largest telecoms customer data loss ever disclosed in Germany.
Source: The Local, Reuters
Records affected: Around 19.2 million subscriber accounts, including about 5.11 million IBANs. Free confirmed the breach and the presence of IBANs; the exact figures come from analysis of the data offered for sale, with Free confirming the order of magnitude rather than the precise count.
Date of breach: Late October 2024. Date disclosed: October 25 to 26, 2024. Country: France. Sector: Telecommunications.
Attack vector: Unauthorized access to a subscriber management tool; data subsequently auctioned on a cybercrime forum.
Data exposed: Names, emails, postal addresses, phone numbers, subscription details, and, for a subset, IBAN bank account numbers. Passwords and card numbers were not affected.
France's second-largest internet service provider confirmed that an attacker had accessed a subscriber management tool and exfiltrated data on the majority of its customer base, with bank account identifiers for around a quarter of them. The presence of IBANs at that scale created direct SEPA direct-debit fraud exposure rather than just phishing risk. A suspect was arrested in France in November 2024, and no public CNIL fine had been issued as of July 2026.
Source: Iliad, BleepingComputer
Records affected: Around 5 million individuals, roughly most of Bulgaria's adult population, plus company records.
Date of breach: June 2019. Date disclosed: July 15, 2019. Country: Bulgaria. Sector: Government, tax administration.
Attack vector: Exploitation of a web application vulnerability, after which the attacker emailed the stolen archive to Bulgarian media.
Data exposed: Names, national identification numbers, addresses, income and tax declarations, and social security and health insurance contributions.
An attacker exfiltrated the tax authority's records and mailed them to journalists, exposing the income and tax history of nearly every Bulgarian adult. It became the first large-scale test of GDPR enforcement against a national government body. The Commission for Personal Data Protection fined the NRA 5.1 million leva (about €2.6 million) in August 2019 for Article 32 failures, though the fine was later reduced on appeal.
Source: Reuters, GDPR Enforcement Tracker
Records affected: Not a breach in the intrusion sense. The decision concerned the personal data of essentially all EU and European Economic Area (EEA) Facebook users transferred to the United States, a population in the hundreds of millions.
Date of conduct: Continued transfers after the July 2020 Schrems II judgment. Date disclosed: May 22, 2023. Country: Ireland. Sector: Social media, technology.
Attack vector: Not applicable; unlawful international data transfers under Chapter V GDPR.
Data exposed: All Facebook user data transferred to US infrastructure and subject to US surveillance law.
The Irish DPC fined Meta €1.2 billion, the largest GDPR fine ever imposed, for continuing to transfer EU user data to the US on standard contractual clauses that couldn't remedy the risks identified in Schrems II. The decision followed a binding EDPB dispute resolution decision that raised the sanction, and it remains the ceiling reference point for GDPR exposure. Meta appealed, and the July 2023 EU-US Data Privacy Framework later provided a new transfer route.
Source: Irish DPC, EDPB
Records affected: All EEA TikTok users whose data was remotely accessed from China; TikTok reported over 150 million monthly EU users at the time of the inquiry.
Date of conduct: Assessed from July 29, 2020 onward. Date disclosed: May 2, 2025. Country: Ireland. Sector: Social media, technology.
Attack vector: Not applicable; unlawful transfers and transparency failures under Chapter V and Article 13 GDPR.
Data exposed: EEA user personal data accessible to staff in China.
The DPC fined TikTok €530 million, the second-largest GDPR fine on record and the largest of 2025, finding that TikTok hadn't verified or demonstrated that EEA data remotely accessed from China received protection essentially equivalent to EU law. TikTok later confirmed that some EEA data had in fact been stored on Chinese servers, which the DPC treated as a serious aggravating factor. The fine comprised €485 million for the transfer breach and €45 million for transparency, and TikTok said it would appeal.
Source: Irish DPC, EDPB
Records affected: Around 100,000 people had data stolen and notified; the operational impact touched the entire national health service and its 4.9 million patient population.
Date of breach: Initial intrusion March 18, 2021; ransomware detonated May 14, 2021. Date disclosed: May 14, 2021. Country: Ireland. Sector: Healthcare, government.
Attack vector: Phishing email with a weaponized Excel document, followed by eight weeks of undetected lateral movement and Conti ransomware across roughly 80% of the IT estate.
Data exposed: Patient records, clinical correspondence, and staff records; a subset was published online.
Conti ransomware shut down the IT systems of Ireland's entire public health service, forcing hospitals onto paper records and disrupting diagnostics for months. An independent PwC review found the HSE had no single responsible cybersecurity leader, ran large volumes of unsupported systems, and had frail detection capability. Recovery and remediation costs were estimated at well over €100 million, making it the most expensive cyber incident ever suffered by a European public body.
Source: HSE and PwC review, Irish DPC
Records affected: Around 2.5 million customers.
Date of breach: Data offered for sale from late December 2020. Date disclosed: January 4, 2021. Country: Italy. Sector: Telecommunications.
Attack vector: Exfiltration of the customer database, including SIM identifiers.
Data exposed: Name, phone number, tax code, email, date and place of birth, nationality, and ICCID SIM serial number.
Ho Mobile confirmed that a database containing the personal data and SIM serial numbers of about 2.5 million Italian customers had been stolen and was being sold. The inclusion of ICCID numbers made SIM swap fraud straightforward, so the company offered free SIM replacement to all affected customers, an unusually costly remediation. It became the reference Italian case for telecoms breach response and SIM swap risk.
Source: Garante privacy, BleepingComputer
Records affected: Service disruption for around 24 million mobile subscribers. Kyivstar said no subscriber personal data was leaked, a claim contested by the attackers and unverified independently.
Date of breach: Intrusion from at least May 2023; destructive stage December 12, 2023. Date disclosed: December 12, 2023. Country: Ukraine. Sector: Telecommunications.
Attack vector: Compromise of an employee account, months of persistence, then wiping of core infrastructure; attributed by Ukraine's SBU to the Russian military intelligence linked Sandworm group.
Data exposed: Kyivstar stated subscriber data and call records weren't stolen. The primary harm was destruction of infrastructure and loss of service, including air raid alert delivery.
Ukraine's largest mobile operator was knocked offline for civilians and businesses in the most damaging wartime cyberattack on a European telecoms operator, taking down mobile service, internet, ATMs, and some air raid alarm systems. Officials described the attack as having destroyed core infrastructure, requiring rebuild rather than restore. It's the clearest demonstration in Europe that a state actor can convert months of quiet access into national-scale service destruction. This was treated as an act of war rather than a compliance failure.
Source: Reuters, The Record
Records affected: More than 1.5 million people, per the Swedish Authority for Privacy Protection (IMY) and municipal notifications.
Date of breach: Around August 23 to 24, 2025. Date disclosed: Late August 2025, with the leak published September 13, 2025. Country: Sweden. Sector: IT services supplier to the public sector.
Attack vector: Ransomware, attributed by researchers to the Datacarry group, against a shared SaaS supplier used by around 80% of Swedish municipalities.
Data exposed: Names, personal identity numbers, emails, addresses, phone numbers, dates of birth, and, critically, medical certificates, rehabilitation plans, and occupational injury records.
Miljodata supplies HR and occupational health software to around 200 Swedish municipalities and regions, so a single ransomware intrusion exposed sensitive sickness and rehabilitation records for more than 1.5 million people, roughly one in seven Swedes. Datacarry published a 224 MB archive on its leak site after no ransom was paid. This is Sweden's largest personal data breach and the clearest European example of municipal-sector concentration risk in a single shared vendor. IMY opened GDPR investigations into Miljodata and three public-sector controllers.
Source: BleepingComputer, City of Stockholm notice
Records affected: Not precisely established. Call centre staff could access the records of millions of tested citizens, but the number actually sold was far smaller. Treat any specific total as unverified.
Date of breach: Late 2020 into January 2021. Date disclosed: January 25, 2021. Country: Netherlands. Sector: Public health.
Attack vector: Insider abuse. Call centre workers with broad access to the CoronIT and HPZone systems exported and sold personal records via messaging apps.
Data exposed: Names, addresses, dates of birth, BSN citizen service numbers, phone numbers, and COVID test data.
An RTL Nieuws investigation found Dutch GGD call centre staff openly advertising sets of citizen data taken from national COVID test and contact tracing systems, exposing how weak access controls created a resale market for BSN numbers. The case matters less for its exfiltration volume than for the access model itself: thousands of temporary workers could query the records of millions. The Dutch DPA fined the Ministry of Health €460,000 in 2023 for inadequate security.
Source: Autoriteit Persoonsgegevens, Reuters
Records affected: Nearly 63,000 police employees, described as covering effectively every serving officer plus support staff.
Date of breach: Detected September 26, 2024. Date disclosed: September 27, 2024. Country: Netherlands. Sector: Law enforcement.
Attack vector: Not fully disclosed. Dutch police stated the actor was "very likely a state actor."
Data exposed: Names, work email addresses, and phone numbers of police employees. Police said no other personal or investigative data was known to be taken.
An intrusion into Dutch police systems exposed the work contact details of essentially the entire national police workforce, including undercover and specialist personnel whose identification carries operational and physical risk. The Dutch government attributed it to a state actor, making it one of the clearest examples in Europe of espionage-motivated targeting of law enforcement personnel records rather than citizen data. The relatively small record count belies the severity of the exposure. It was handled as a national security matter, with no data protection fine.
Source: The Record, NL Times
Records affected: Not a personal data breach at scale. Included for operational severity: 35,000 employees across 40 countries were affected operationally and 22,000 computers had to be rebuilt.
Date of breach: March 19, 2019. Date disclosed: March 19, 2019. Country: Norway. Sector: Manufacturing, aluminium.
Attack vector: LockerGoga ransomware, entering via a phishing email and spreading through Active Directory.
Data exposed: Primarily availability and integrity impact on production and business systems rather than confidentiality loss.
LockerGoga forced Norsk Hydro to switch its global aluminium production to manual operations, and the company chose not to pay, instead documenting its recovery publicly in near real time. Hydro estimated the total impact at roughly 800 million Norwegian kroner, of which insurance covered a fraction. It remains Europe's canonical case study in transparent ransomware response and in the industrial cost of a ransomware attack that bridges information technology and operational technology systems. Norway's Datatilsynet and ENISA praised the transparency as a model.
Source: Microsoft Source, Reuters
Records affected: No confirmed personal data exfiltration. Around 800 Coop grocery stores across Sweden were forced to close.
Date of breach: July 2, 2021. Date disclosed: July 3, 2021. Country: Sweden. Sector: Retail, grocery.
Attack vector: REvil ransomware delivered through a zero-day in Kaseya VSA remote monitoring software, reaching Coop via managed service provider Visma Esscom.
Data exposed: Payment and checkout systems were encrypted; Coop reported no evidence of customer data theft.
The Kaseya supply chain attack hit roughly 1,500 downstream organizations worldwide, and Coop Sweden was the most visible European casualty, unable to process payments in around 800 stores over a weekend. It became the reference case in Europe for third- and fourth-party ransomware risk, showing that a grocery chain's availability depended on a software vendor four steps removed from its own IT team. The incident contributed to Swedish and EU policy work that fed into NIS2.
Source: Reuters, ENISA
Records affected: More than 50,000 confidential files, including athlete medical records and testing histories. The number of distinct individuals was not published.
Date of breach: Disclosed in the run-up to the Paris 2024 Olympics. Date disclosed: August 2024. Country: Poland. Sector: Sport, anti-doping.
Attack vector: Not disclosed in detail. Polish authorities attributed the operation to actors "supported by the services of a hostile state"; a group calling itself Beregini claimed responsibility.
Data exposed: Athlete medical records, doping test results and testing histories, and correspondence.
Attackers stole and published tens of thousands of files from Poland's anti-doping agency, then circulated claims that named Polish athletes had failed tests. POLADA confirmed the intrusion but said the specific doping allegations were fabricated, framing the incident as a hack-and-leak information operation timed to the Olympics rather than a straightforward data theft. It's the clearest European case of special-category health data being weaponized for disinformation.
Source: The Record, Notes From Poland
Records affected: Not officially confirmed. RA World claimed to have exfiltrated around 246 GB of data and published test results for tens of thousands of patients. ALAB confirmed the incident and the publication of patient results but did not publish a count, so any specific individual total is unverified.
Date of breach: November 19, 2023. Date disclosed: November 27, 2023. Country: Poland. Sector: Healthcare, diagnostic laboratories.
Attack vector: Ransomware, with exfiltration before encryption and publication on a leak site after the ransom was refused.
Data exposed: Patient names, PESEL national identity numbers, addresses, and laboratory test results including sensitive diagnostic data.
One of Poland's largest private diagnostic laboratory networks was breached and refused to pay, after which the attackers published patient laboratory results online in tranches. The publication of raw test results for named patients made this the most damaging health data leak in Polish history and forced Poland's UODO to handle an unprecedented volume of individual notifications. It became a national reference point for the harm caused when special-category health data is leaked rather than merely stolen.
Source: UODO, DataGuidance
Records affected: Around 65,000 Federal Administration documents, of which about 5,000 contained sensitive personal data. Roughly 1.3 million lines of data relating to federal police systems were among the material.
Date of breach: May 2023. Date disclosed: June 2023, with the full federal analysis published March 2024. Country: Switzerland. Sector: Government IT supplier.
Attack vector: Play ransomware against Xplain, with exfiltration and publication on the group's leak site.
Data exposed: Federal police operational data, personal data of individuals in law enforcement records, technical documents, and some classified material.
Play ransomware hit a small Swiss software supplier whose clients included the Federal Office of Police, the army, and customs, and the leaked archive turned out to contain live federal operational data that Xplain should never have retained. The National Cyber Security Centre's March 2024 analysis confirmed roughly 65,000 federal documents were affected. It's Switzerland's defining third-party government supply chain breach, and Xplain lost federal contracts.
Source: Swiss Federal Council, Reuters
Records affected: Around 1.3 TB of documents published, including federal data. Individual counts were not published; treat any headcount as unverified.
Date of breach: June 16, 2025. Date disclosed: June 30, 2025. Country: Switzerland. Sector: Non-profit health promotion foundation serving federal offices.
Attack vector: Sarcoma ransomware, with data theft and encryption, followed by publication on the group's leak portal.
Data exposed: Financial records, contracts, private correspondence, and personal data held on behalf of federal offices.
Two years after Xplain, Swiss federal data was exposed again through a contractor, this time the Zurich-based health promotion foundation Radix. The federal government confirmed that federal data had been leaked while stressing that Radix held no direct connections into core government systems. The repeat pattern prompted criticism that Switzerland had not fixed the supplier data governance problems identified after Xplain.
Source: BleepingComputer, Infosecurity Magazine
Records affected: Not officially quantified. Air Europa notified customers whose card details were exposed but did not publish a number, so any circulating figure is unverified.
Date of breach: Detected October 2023. Date disclosed: October 2023. Country: Spain. Sector: Aviation.
Attack vector: Unauthorized access to a system containing payment card data.
Data exposed: Payment card numbers, expiry dates, and CVV codes.
Air Europa emailed customers advising them to cancel their credit cards after an intrusion exposed full card data including CVV codes, an unusually severe payment data exposure for a European carrier. The initial communication was criticized for being vague about scope and timing, which itself became part of the regulatory story. It's a standing example of payment card data being retained where it should not have been. Air Europa had earlier been fined €500,000 by the AEPD over a separate 2018 breach.
Source: AEPD, Reuters
Records affected: Passenger data exposure remains disputed. The Everest group claimed exfiltration of roughly a 50 GB database, and separate claims circulated of millions of Dublin Airport passenger records. Collins Aerospace and the affected airports did not confirm those volumes, so all passenger record figures should be treated as unverified attacker claims.
Date of breach: September 19 to 20, 2025. Date disclosed: September 20, 2025. Country: Multi-country: Belgium, Germany, United Kingdom, and others. Sector: Aviation, airport IT.
Attack vector: Ransomware against the MUSE common-use passenger processing platform used for check-in and boarding at multiple European airports.
Data exposed: Operationally, check-in and boarding capability. Any passenger personal data exposure remains claimed rather than confirmed.
A ransomware attack on Collins Aerospace's MUSE platform knocked out automated check-in and boarding at Brussels, Berlin Brandenburg, London Heathrow, and other European airports, forcing manual processing and causing more than a hundred flight delays and cancellations over a weekend. It's Europe's clearest recent demonstration that a single aviation IT vendor is systemically important infrastructure across borders. ENISA confirmed ransomware was involved, and the incident is being treated as a test case for NIS2 obligations.
Source: Reuters, Cybernews
Records affected: Around 92 GB of compressed data stolen from a compromised AWS account, including names, emails, and email contents. CERT-EU said data belonging to at least 29 other EU entities may be affected. No individual headcount was published.
Date of breach: March 19, 2026. Date disclosed: March 27, 2026, with CERT-EU attribution published April 3, 2026. Country: EU institutions. Sector: Government, EU institutions.
Attack vector: Supply chain. Attackers compromised the open source security scanner Trivy, the Commission downloaded a backdoored copy, and the attackers harvested a secret AWS API key from it and pivoted into cloud storage.
Data exposed: Names, emails, and the contents of sent emails; close to 52,000 files contained sent email messages.
CERT-EU attributed the intrusion to the cybercrime group TeamPCP and said the stolen data was subsequently leaked online by ShinyHunters, an unusual two-group attribution for a single incident. The breach is the most significant compromise of EU institutional infrastructure to date and a direct consequence of the 2026 wave of open source supply chain attacks that also hit Bitwarden and Checkmarx. It puts the EU's own institutions in the position of demonstrating the incident response standards they legislate for others.
Source: TechCrunch, CERT-EU report
Records affected: Not published as a headcount. The case concerned a file of expatriate voters' personal data unlawfully disclosed and used for political emailing.
Date of breach: Disclosure occurring in 2022 and 2023. Date disclosed: May 2024. Country: Greece. Sector: Government, elections.
Attack vector: Not an intrusion. Unlawful onward disclosure of a government-held voter file to a Member of the European Parliament, who used it for campaign email.
Data exposed: Names and emails of expatriate Greek voters.
The Hellenic Data Protection Authority fined the Ministry of Interior €400,000 and separately sanctioned the MEP after a file of expatriate voters' contact data held by the state was used for political emailing. It's Greece's largest data protection sanction against a central government body and the leading Greek precedent on repurposing of electoral rolls. A widely referenced claim of a separate Greek education-ministry student data breach could not be verified against any authoritative source and should not be published without primary confirmation.
Source: Hellenic DPA, EDPB
Records affected: 9 million customers, including 2,208 whose full credit card details were accessed.
Date of breach: January 2020 (activity detected). Date disclosed: May 19, 2020. Country: United Kingdom. Sector: Aviation.
Attack vector: Described by EasyJet as a highly sophisticated intrusion; the airline didn't disclose the technical vector.
Data exposed: Emails and travel details for 9 million customers; full payment card details including CVV for 2,208 customers.
EasyJet disclosed four months after detection that a sophisticated attacker had accessed the emails and travel itineraries of 9 million customers, and complete card details for a small subset. The travel itinerary exposure was significant beyond fraud risk because it revealed movement patterns. The long gap between detection and notification became the focus of criticism and litigation, though a group claim was later constrained by the UK Supreme Court's Lloyd v Google decision. No fine from the Information Commissioner's Office (ICO) was issued.
Source: UK ICO, BBC News
Records affected: Marriott: up to 339 million guest records globally, of which around 30.1 million related to EEA residents and 7 million to UK residents. British Airways: around 429,612 customers and staff, revised down from an initial 500,000.
Date of breach: Marriott: Starwood systems compromised from 2014, discovered September 2018. British Airways: June to September 2018. Date disclosed: Marriott November 30, 2018; British Airways September 6, 2018; final ICO fines October 30, 2020. Country: United Kingdom. Sector: Hospitality and aviation.
Attack vector: Marriott: long-term intrusion into the acquired Starwood reservation database. British Airways: attacker modified the payment flow to skim card data, consistent with Magecart techniques.
Data exposed: Marriott: names, contact details, passport numbers, and encrypted payment cards. British Airways: names, addresses, payment card numbers and CVVs, plus some staff data.
These two cases produced the first substantial GDPR fines in the UK and established that acquisition due diligence and payment-page integrity are enforceable security obligations, and they still anchor most rankings of the biggest UK data breaches. The ICO's initial notices of intent were £99 million for Marriott and £183 million for British Airways, but the final fines were cut to £18.4 million and £20 million respectively, with the ICO citing the economic impact of COVID and mitigation steps. Those reductions are still cited as the reason UK fines diverged sharply from EU practice.
Source: Cybersecurity Dive on the Marriott fine, Cleary Gottlieb on the British Airways fine
Records affected: Change Healthcare: 192.7 million individuals, revised upward twice from an initial 100 million estimate. Conduent: revised from around 10.5 million in early 2026 to more than 25 million within weeks, and reported to climb higher still through mid-2026. Both totals relate overwhelmingly to US residents.
Date of breach: Change Healthcare: intrusion February 12, 2024, ransomware February 21, 2024. Conduent: October 2024 to January 2025. Date disclosed: Change Healthcare February 21, 2024; Conduent January 2026. Country: United States, with both firms operating in Europe. Sector: Healthcare payments and government business process outsourcing.
Attack vector: Change Healthcare: ALPHV/BlackCat ransomware via a Citrix remote access portal lacking MFA. Conduent: roughly three months of undetected access with around 8 TB exfiltrated.
Data exposed: Change Healthcare: health insurance, medical, billing, and personal identifiers including Social Security numbers. Conduent: Social Security numbers and medical records tied to government benefits programmes.
These are included because they're the two largest breaches of the current period globally and because both organizations run European operations, so European entities relying on them faced supplier assurance questions even where EU personal data wasn't directly implicated. Change Healthcare remains the largest healthcare breach in history and a fixture among the biggest US data breaches, as well as the clearest demonstration of concentration risk in a payments clearinghouse. Conduent's repeated upward revisions, from 10.5 million to more than 25 million within weeks and higher still afterward, are the standing example of why initial breach counts should never be treated as final.
Source: US HHS OCR breach portal, Malwarebytes
Read together, the largest recent European incidents share a pattern that traditional perimeter defense wasn't built to catch. France Travail and Spain's DGT were reached through trusted partner and professional accounts. Viamedis and Almerys, Miljodata, Xplain, and Radix were all shared operators or suppliers holding data for dozens of downstream institutions. Collins Aerospace and the European Commission were compromised through common-use platforms and open source software components. In each, the weak point sat one or more steps removed from the organization whose name ended up in the headline, which is why the practical work increasingly centers on how to prevent third-party data breaches.
That distance is exactly why exposure keeps growing faster than most programs can track it. DLA Piper found that reported breach notifications across Europe rose 22% to an average of 443 per day, the first time the daily figure has topped 400 since GDPR took effect. Continuous visibility into your own attack surface and your vendors' security posture, rather than point-in-time questionnaires, is the practitioner response to concentration risk of this kind.
Reducing exposure to breaches like these means seeing risk continuously across your own environment and the third parties you depend on, rather than once a year, and it pairs with the operational steps you take to reduce the risk of data breaches. The UpGuard platform gives security and risk teams that visibility to monitor breach risk in a few ways:
Start a free trial to see how continuous monitoring maps to your own vendor ecosystem.
By people affected, Turkey's Mernis identity leak (49.6 million citizens) and France Travail (up to 43 million) are the largest, though France Travail described its figure as maximum exposure rather than a confirmed count.
Meta's €1.2 billion fine from Ireland's Data Protection Commission in May 2023 remains the largest, followed by TikTok's €530 million fine in 2025.
No. The €746 million fine against Amazon was annulled by a Luxembourg appeal court in March 2026 on procedural grounds; the findings were largely upheld and the matter referred back, so Amazon was not cleared, but the fine no longer stands as enforceable.
France Travail (up to 43 million) was the largest of 2024, and Miljodata (more than 1.5 million, with sensitive health data) was among the most damaging of 2025, the year TikTok also received its €530 million fine.
Most of the recent large incidents came from abuse of legitimate credentials for partner or professional accounts and from compromise of shared third-party operators or software supply chains, rather than direct attacks on the named organization.