The United States remains the most breached country on earth, and it's also the most expensive place in the world to suffer a breach. That combination is why a US-focused view of the largest incidents matters more than a global tally dominated by aggregate leaks and scraped compilations.
This ranks the 40 largest and most consequential data breaches affecting US organizations or US residents, current as of July 2026. Ranks 1 to 37 are ordered primarily by the number of records or individuals affected. Ranks 38 to 40 are included for exceptional notability rather than raw volume.
One caution on the numbers: breach totals move. Several incidents below were revised sharply upward or downward months or years after disclosure, and a handful of the largest figures come from criminal claims the victim organization never confirmed. Every disputed, estimated, or attacker-supplied figure is flagged.
The headline trend in 2025 was volume without a single dominant mega-breach. The Identity Theft Resource Center's 2025 Annual Data Breach Report tracked 3,322 data compromises, an all-time record that surpassed the previous high of 3,202 in 2023 and represented a 79% increase over five years. Victim notices told the opposite story, falling to 278,827,933, down roughly 80% from 2024. The ITRC attributes that drop to the near absence of mega-breaches in 2025 rather than to improved security, and its later reporting revised the full-year figure to approximately 297.5 million notices.
The first half of 2026 erased that reprieve. The ITRC's H1 2026 Data Breach Report counted 1,803 compromises in six months and 471.2 million victim notices, already more than all of 2025, with the Instructure Canvas incident alone accounting for an estimated 275 million notices, or 58% of the H1 total. Transparency reached a record low: 76% of breach notices omitted any information about the attack vector, the worst rate the ITRC has ever recorded, compared with 93% that included that detail back in 2021. Financial services led all sectors with 387 compromises, followed by healthcare with 281.
Cost is where the US stands apart. IBM's Cost of a Data Breach Report 2025 put the US average at $10.22 million, an all-time high and a 9% year-over-year increase, even as the global average fell to $4.44 million. The US has ranked most expensive in the world for 15 consecutive years, and healthcare remains the costliest sector at $7.42 million per breach. That gap, roughly 2.3 times the global figure, is the practical reason US organizations can't treat breach economics as an abstract risk.
The entries below preserve the reported facts, dates, and dispute flags for each incident. Read them less as a hall of shame than as a pattern library: the same failure modes, unmonitored third parties, missing multi-factor authentication (MFA), unpatched software, and misconfigured cloud storage, recur across two decades and every sector.
Records affected: 3 billion accounts (every Yahoo account in existence; revised upward from an initial 1 billion)
Date of breach: August 2013 and late 2014
Date disclosed: September 2016 (500 million), December 2016 (1 billion), October 2017 (revised to 3 billion)
Sector: Technology / Internet services
Attack vector: State-sponsored intrusion plus forged authentication cookies; Russian FSB officers and criminal hackers were later indicted
Data exposed: Names, email addresses, phone numbers, dates of birth, hashed passwords (MD5), and in some cases encrypted and unencrypted security questions and answers
Two separate intrusions together compromised every one of Yahoo's 3 billion user accounts, making this the largest breach in history by account count. Yahoo disclosed 500 million affected accounts in 2016, then 1 billion, and only after Verizon's acquisition closed did it confirm in October 2017 that all 3 billion had been touched. The delay in disclosure, spanning nearly three years for the 2013 incident, became the defining regulatory issue and reportedly knocked $350 million off Verizon's acquisition price.
Aftermath: The SEC charged Altaba (Yahoo's post-sale successor entity) with failing to disclose the breach to investors, resulting in a $35 million penalty in April 2018, the first SEC enforcement action of its kind. A consumer class action settled for $117.5 million in 2019. The US Department of Justice indicted two Russian FSB officers and two criminal hackers in March 2017.
Source: SEC press release on the $35 million Altaba penalty
Records affected: Approximately 2.9 billion records claimed, including roughly 272 million unique Social Security numbers and 137 million unique email addresses. Heavily disputed. Researchers found substantial duplication and inaccurate records, and estimates of distinct real people affected range from roughly 170 million upward. Treat the 2.9 billion figure as a record count, not a person count.
Date of breach: December 2023 (initial access); data leaked April through August 2024
Date disclosed: August 2024 (company confirmation followed public leak and class action filings)
Sector: Data brokerage / background screening
Attack vector: Unauthorized network access; separately, a sister site was found publishing a plaintext file of administrative passwords
Data exposed: Full names, Social Security numbers, current and historical physical addresses, phone numbers, email addresses, and relative data
National Public Data was a Florida background-check broker that had scraped and aggregated personal data on hundreds of millions of Americans who had never heard of it and never consented. When the full dataset was dumped publicly in mid-2024, it became the single largest exposure of US Social Security numbers on record. The incident matters because it showed that the highest-risk data holders are often invisible third parties with no consumer relationship, no brand to protect, and minimal security investment.
Aftermath: The parent company, Jerico Pictures, filed for Chapter 11 bankruptcy in October 2024 in the face of more than 20 class actions and multiple state attorney general inquiries. The breach became a central exhibit in US debates over federal data broker regulation.
Source: Microsoft Support advisory on the National Public Data breach | Malwarebytes follow-up reporting
Records affected: Attackers claimed 1.5 billion Salesforce records across approximately 760 companies. Unverified attacker claim. Salesforce and most named victims have not confirmed the aggregate figure, and individual victim counts vary from thousands to millions.
Date of breach: March through August 2025 (Drift OAuth token abuse concentrated in August 2025); related vishing campaign ran from roughly June 2025
Date disclosed: August and September 2025, with victim notifications continuing into 2026
Sector: Cross-sector (technology, retail, insurance, financial services, hospitality, aviation)
Attack vector: Compromise of Salesloft's GitHub repository yielded stored OAuth access tokens for the Drift chatbot integration; a parallel track used voice phishing to trick employees into authorizing a malicious Salesforce Data Loader connected app
Data exposed: Salesforce Accounts and Contacts objects, support case content, and in many instances embedded credentials, API keys and tokens found inside case text
This was the defining supply chain event of 2025 and arguably the largest multi-victim SaaS compromise ever recorded. Rather than attacking hundreds of companies individually, the attackers stole one integration's tokens and used them to query every Salesforce tenant where Drift had been authorized. Confirmed or reported victims include Google, Cisco, Workday, Cloudflare, Palo Alto Networks, TransUnion, Allianz Life, Farmers Insurance, Qantas, Adidas, LVMH brands, Marriott, Walgreens, McDonald's, KFC, Disney, Albertsons and Saks Fifth Avenue.
Aftermath: Salesforce publicly refused to pay the extortion demand and pointed to the third-party integration as the point of failure. ShinyHunters launched a dedicated Salesforce victim leak site in October 2025. Dozens of individual class actions followed against downstream victims, and Salesloft took Drift offline while it rotated credentials.
Source: BleepingComputer on the ShinyHunters 1.5 billion record claim
Records affected: 1.37 billion email records
Date of breach: Exposure discovered January 2017 (no attacker involved)
Date disclosed: March 2017
Sector: Marketing / spam operations
Attack vector: Misconfigured Rsync backup with no password protection, leaving the entire operation's databases publicly downloadable
Data exposed: Email addresses, full names, IP addresses, physical addresses, and the operator's own internal chat logs, business plans and infrastructure documentation
A spam operation accidentally exposed its own entire database here, including 1.37 billion email records and, remarkably, the internal documentation describing how it evaded anti-spam controls. Security researcher Chris Vickery found the open backups. It remains one of the largest single exposures of email address data ever and a textbook illustration that cloud misconfiguration, not sophisticated hacking, is responsible for a large share of mass exposures.
Aftermath: The operation was effectively shut down after the exposure. Spamhaus blacklisted the infrastructure and the leaked internal documents were used by anti-spam researchers to map the network. No formal regulatory penalty was recorded.
Source: The Guardian on the River City Media leak of 1.37 billion records
Records affected: 885 million documents (record count, not individuals; documents dated back to 2003)
Date of breach: Exposure existed from at least 2014; discovered May 2019
Date disclosed: May 24, 2019, by Brian Krebs
Sector: Title insurance / real estate financial services
Attack vector: Insecure direct object reference in the EaglePro web application. Any authenticated document URL could be edited by changing a sequential number in the address bar, exposing unrelated customers' files with no authentication at all.
Data exposed: Mortgage and title closing documents containing Social Security numbers, bank account numbers, mortgage records, tax records, wire transfer receipts and driver's license images
One of the largest exposures of financial documents in history was also one of the purest examples of a preventable design flaw. First American's own penetration test had flagged the vulnerability in December 2018, but the company misclassified the risk and did not remediate before the public disclosure five months later. The exposed documents were exactly the material needed to run mortgage wire fraud at scale.
Aftermath: The SEC charged First American in June 2021 with disclosure controls violations and the company paid $487,616. The New York Department of Financial Services announced a $1 million penalty in November 2023 for violations of the NYDFS Cybersecurity Regulation, one of the first enforcement actions under Part 500.
Source: KrebsOnSecurity on the NYDFS charges | First American Financial Form 8-K on the SEC settlement
Records affected: 560 million customers claimed by the attackers. Unverified. Live Nation confirmed the intrusion in an SEC filing but has never confirmed the 560 million figure.
Date of breach: April to May 2024; unauthorized activity identified May 20, 2024
Date disclosed: May 27, 2024 (dark web listing); Live Nation Form 8-K filed May 31, 2024
Sector: Entertainment / ticketing
Attack vector: Credentials for a Snowflake cloud data warehouse instance obtained via infostealer malware on a contractor device; the account lacked multi-factor authentication
Data exposed: Names, addresses, email addresses, phone numbers, ticket sales and order history, event information and partial payment card data
Ticketmaster was the highest-profile casualty of the 2024 Snowflake campaign, in which threat actors used stolen credentials to reach roughly 165 customer tenants that had not enforced MFA. Approximately 1.3 TB of data was offered for sale by ShinyHunters. The lesson lands because Snowflake itself was not breached: every compromise traced to a customer's own credential hygiene, which reframed the shared responsibility model for cloud data platforms.
Aftermath: Live Nation disclosed the incident in a Form 8-K under the SEC's cybersecurity disclosure rules. Multiple class actions were consolidated into the Snowflake MDL in the District of Montana. Two suspects tied to the wider Snowflake campaign were arrested in Canada and Turkey, and Connor Moucka was later extradited to the US.
Source: The Record on Live Nation's confirmation
Records affected: 533 million users across 106 countries, including approximately 32 million US users. Separately, the Cambridge Analytica incident affected 87 million users.
Date of breach: Data scraped via a contact importer flaw before September 2019
Date disclosed: Limited disclosure in 2019; the full dataset was published free on a hacking forum in April 2021
Sector: Technology / social media
Attack vector: Abuse of the contact import feature, which allowed mass enumeration of phone numbers against profiles. Meta characterized this as scraping rather than a hacking incident.
Data exposed: Phone numbers, Facebook IDs, full names, locations, birth dates, relationship status, employer and, for a subset, email addresses
Meta's position that scraping doesn't constitute a breach was rejected by regulators, and the 533 million record set has since become a permanent free resource for SIM swap and social engineering attacks, since phone numbers can't be reset like passwords. Combined with the earlier Cambridge Analytica scandal, in which the data of 87 million users was harvested via a third-party app and used for political profiling, these incidents produced the largest privacy penalties in US history.
Aftermath: The FTC imposed a $5 billion civil penalty on Facebook in July 2019 over Cambridge Analytica, the largest privacy penalty ever levied by any regulator worldwide, plus sweeping governance restrictions. The SEC separately fined the company $100 million. A $725 million consumer class settlement was approved in 2023. Ireland's Data Protection Commission fined Meta 265 million euros in November 2022 specifically over the 533 million record scrape.
Source: FTC press release on the $5 billion penalty
Records affected: Up to 383 million guest records. Revised downward. Marriott's initial November 2018 disclosure said up to 500 million; the January 2019 revision put the upper bound at 383 million records with a smaller number of unique individuals. The FTC's 2024 action covered three breaches from 2014 to 2020 affecting 344 million customers worldwide.
Date of breach: July 2014 (Starwood network, before Marriott's acquisition) through September 2018
Date disclosed: November 30, 2018
Sector: Hospitality
Attack vector: Long-dwell intrusion into the legacy Starwood guest reservation database, widely attributed to Chinese state-sponsored actors, which persisted undetected through Marriott's 2016 acquisition of Starwood
Data exposed: Names, mailing addresses, phone numbers, email addresses, passport numbers (roughly 5.25 million unencrypted, 20.3 million encrypted), Starwood loyalty account information, dates of birth, gender, arrival and departure information, and encrypted payment card numbers
The Starwood breach is the canonical case study in acquisition due diligence failure. The attackers were inside the Starwood reservation environment for two years before Marriott bought the company and for two more years afterward. Roughly 5.25 million unencrypted passport numbers made this a national security concern as well as a consumer privacy one.
Aftermath: The FTC announced a settlement in October 2024 requiring Marriott to implement a comprehensive information security program, provide US customers a mechanism to request deletion of personal data, and review loyalty account activity on request. A parallel settlement with the attorneys general of 49 states and the District of Columbia carried a $52 million penalty. The UK ICO had earlier fined Marriott 18.4 million pounds, reduced from an initial 99 million pound notice.
Source: FTC action against Marriott and Starwood
Records affected: Approximately 340 million records, covering roughly 230 million US consumers and 110 million business contacts
Date of breach: Exposure discovered June 2018 (no attacker involved)
Date disclosed: June 2018
Sector: Data brokerage / marketing analytics
Attack vector: A database left on a publicly accessible server with no firewall, discovered by security researcher Vinny Troia
Data exposed: Names, phone numbers, home and email addresses, and approximately 400 behavioural and demographic attributes per person including religion, smoking habits, pet ownership, children's ages and genders, and personal interests
Almost nobody had heard of Exactis, a Florida marketing firm that nonetheless held roughly 400 data points on nearly every American adult. No Social Security numbers or payment cards were involved, but the sheer granularity of the profiling data made it a landmark privacy event and one of the earliest mass demonstrations of how much data brokers quietly accumulate.
Aftermath: Exactis took the database offline and faced a class action in Florida. The incident is frequently cited in support of comprehensive US federal privacy legislation and in state data broker registration laws such as California's Delete Act.
Source: WIRED on the Exactis exposure
Records affected: 275 million users claimed by the attackers across approximately 8,809 institutions. Attacker claim; Instructure has not independently confirmed that 275 million unique people were affected. ITRC nonetheless counts an estimated 275 million victim notices, making it 58% of all H1 2026 US breach notices.
Date of breach: Initial access April 29, 2026; a second compromise followed within roughly two weeks. This was Instructure's second compromise by the same group in eight months.
Date disclosed: May 1, 2026 (initial disclosure); contained by May 6, 2026
Sector: Education technology
Attack vector: ShinyHunters gained access reportedly by abusing the Free-For-Teacher program to obtain a foothold, then exfiltrated roughly 3.65 TB of data
Data exposed: Student and faculty names, email addresses, student ID numbers, course enrolment details and private messages exchanged inside Canvas
This is the largest education sector breach on record and the largest single US breach of the 2020s by notice volume. Canvas is used by roughly 41% of US higher education institutions plus many K-12 districts, so the blast radius covered a substantial fraction of everyone who has attended an American college in the past decade. The disruption also hit during finals week at many institutions, taking the learning management system offline during exams and assignment deadlines.
Aftermath: On May 11, 2026, one day before the attackers' leak deadline, Instructure said it had reached an agreement with the "unauthorized actor" and that the stolen data had been destroyed. Reports of a roughly $10 million ransom payment remain unverified. State attorney general inquiries and class actions are underway, and the incident has driven higher education procurement scrutiny of learning management vendors.
Source: UC Berkeley Law analysis of the Instructure Canvas breach | AP News coverage
Records affected: Over 200 million user records in the January 2023 dump; a related earlier dataset claimed 400 million. Both are scraped compilations rather than a database theft, and the exact unique count is disputed.
Date of breach: Underlying API vulnerability existed from June 2021 and was patched in January 2022; datasets circulated from mid-2022
Date disclosed: January 2023
Sector: Technology / social media
Attack vector: An API flaw allowed submission of an email address or phone number to determine the associated Twitter account, enabling mass deanonymisation of accounts
Data exposed: Email addresses linked to public profile data including names, usernames, follower counts and creation dates
The dataset matters less for what it contains than for what it enables: it permanently links pseudonymous accounts to real email addresses, a direct safety risk for activists, journalists and dissidents. Twitter's handling of the disclosure, in the middle of the post-acquisition turmoil, drew regulatory attention on both sides of the Atlantic.
Aftermath: Ireland's Data Protection Commission opened an inquiry in December 2022. Separately, in May 2022 the FTC and DOJ fined Twitter $150 million for deceptively using phone numbers and email addresses collected for account security purposes to serve targeted advertising, a violation of a 2011 consent order.
Source: FTC and DOJ action against Twitter over security data
Records affected: 198 million US voters, roughly 61% of the US population at the time
Date of breach: Exposure discovered June 12, 2017 (no attacker involved)
Date disclosed: June 19, 2017, by UpGuard
Sector: Political data analytics
Attack vector: An Amazon S3 bucket configured for public access with no password, containing 1.1 terabytes of unsecured data
Data exposed: Names, dates of birth, home addresses, phone numbers, voter registration details, and modelled ethnicity and religion, plus predictive scores on individual voters' likely positions on issues such as gun control, abortion and stem cell research
Discovered by the UpGuard research team, this remains the largest known exposure of US voter data. The files were compiled for the Republican National Committee by Deep Root Analytics, TargetPoint Consulting and Data Trust, and included not just registration data but inferred political opinions on 198 million individuals. It permanently changed how the security community talks about political data and cloud storage defaults.
Aftermath: Deep Root Analytics accepted full responsibility and faced a class action in Florida. No regulatory penalty followed, largely because the US has no comprehensive federal privacy law covering political data. The incident is frequently cited in Congressional testimony on election data security.
Source: UpGuard, The RNC Files: Inside the Largest US Voter Data Leak
Records affected: 192.7 million individuals. Revised upward three times: initially reported to HHS OCR as "more than 500," then approximately 100 million in October 2024, 190 million in January 2025, and finally 192.7 million on July 31, 2025.
Date of breach: Initial access February 12, 2024; ransomware deployed February 21, 2024
Date disclosed: February 21, 2024 (operational outage); victim counts finalised July 2025
Sector: Healthcare / medical claims clearinghouse
Attack vector: ALPHV/BlackCat ransomware. Attackers used stolen credentials to access a Citrix remote access portal that had no multi-factor authentication enabled.
Data exposed: Names, addresses, dates of birth, Social Security numbers, driver's licence and passport numbers, health insurance member IDs, diagnoses, medications, test results, treatment details, and billing and payment information
This is the largest healthcare data breach in US history by a wide margin, affecting roughly 57% of the US population and surpassing the 2015 Anthem record that had stood for nine years. Beyond the data loss, the ransomware shut down the largest medical claims clearinghouse in the country for weeks, cutting off payments to hospitals, physician practices and pharmacies nationwide and creating a genuine public health emergency. UnitedHealth paid a reported $22 million ransom, after which a second group, RansomHub, re-extorted the company with the same data.
Aftermath: UnitedHealth reported total incident costs exceeding $3 billion. HHS OCR opened an investigation in March 2024. CEO Andrew Witty testified before both the Senate Finance Committee and a House subcommittee in May 2024. Nebraska's attorney general sued Change Healthcare, and the suit survived a motion to dismiss. Hundreds of class actions were consolidated in an MDL in Minnesota. The incident directly prompted the HHS proposed HIPAA Security Rule overhaul.
Source: HHS Change Healthcare Cybersecurity Incident FAQ
Records affected: 165 million accounts in the 2012 breach (only 6.5 million password hashes were initially known; the full scale emerged in 2016). A separate 2021 scraping incident produced datasets covering 500 million and then 700 million profiles.
Date of breach: June 2012; scraping datasets published April and June 2021
Date disclosed: June 2012 (partial); May 2016 (full 165 million scope); 2021 (scraping)
Sector: Technology / professional networking
Attack vector: 2012: network intrusion attributed to Russian national Yevgeniy Nikulin. 2021: mass API scraping of public and semi-public profile fields.
Data exposed: 2012: email addresses and unsalted SHA-1 password hashes, which were trivially crackable. 2021: full names, email addresses, phone numbers, geolocation, job titles, employer details and social media handles.
The 2012 LinkedIn breach is one of the most consequential in history not for its size but for its downstream effects. Because the passwords were unsalted SHA-1, the vast majority were cracked, and the resulting credential list fuelled years of credential stuffing attacks, including the 2012 Dropbox breach and the 2016 compromise of Mark Zuckerberg's own social accounts. The 2021 scraping datasets remain in wide circulation for social engineering.
Aftermath: LinkedIn paid $1.25 million to settle a class action over the 2012 breach. Yevgeniy Nikulin was extradited from the Czech Republic, convicted in 2020, and sentenced to 88 months in federal prison. LinkedIn maintained that the 2021 scraping did not constitute a breach, a position that regulators in the EU disputed.
Source: CSO Online, The biggest data breaches of the 21st century
Records affected: 153 million user records. Revised upward from an initial disclosure of 2.9 million.
Date of breach: September 2013
Date disclosed: October 3, 2013 (2.9 million); scope revised to 38 million and then 153 million by late October 2013
Sector: Technology / software
Attack vector: Network intrusion; attackers also stole source code for Acrobat, ColdFusion and other products
Data exposed: Internal IDs, usernames, email addresses, encrypted passwords and password hints in plaintext, plus encrypted payment card numbers and expiry dates for approximately 3 million customers
Adobe's breach is remembered chiefly for a catastrophic cryptographic error. The passwords were encrypted with 3DES in ECB mode using a single key rather than being properly hashed and salted, and the password hints were stored in plaintext alongside them. Identical passwords therefore produced identical ciphertext, and the plaintext hints let researchers and attackers alike reconstruct the most common passwords across the entire dataset.
Aftermath: Adobe paid $1.1 million in legal fees and an undisclosed amount (reported at approximately $1 million) to settle claims from 15 state attorneys general in November 2015. A separate consumer class action settled for an undisclosed sum.
Source: KrebsOnSecurity on the Adobe breach scope
Records affected: 150 million MyFitnessPal accounts (2018). Separately, approximately 72.7 million unique email addresses published in January 2026, following an Everest ransomware claim of 343 GB of stolen data.
Date of breach: February 2018 (MyFitnessPal); November 2025 (Everest ransomware listing)
Date disclosed: March 29, 2018; January 22, 2026
Sector: Retail / consumer apparel and fitness apps
Attack vector: 2018: unauthorized access to the MyFitnessPal user database. 2025-26: ransomware intrusion by the Everest group, with data published to a public hacking forum after Under Armour apparently declined to pay.
Data exposed: 2018: usernames, email addresses and hashed passwords (bcrypt for most accounts, weaker SHA-1 for some). 2026: names, email addresses, dates of birth, gender, location and purchase history.
The 2018 MyFitnessPal breach was, at the time, one of the largest single-app compromises ever. Under Armour's mixed hashing (bcrypt for most, SHA-1 for a subset) meant a meaningful minority of passwords were recoverable, and the credentials appeared for sale on dark web markets by early 2019. The January 2026 incident is a separate and more recent event: Everest listed Under Armour in November 2025 and the data surfaced publicly two months later, making it one of the largest US retail breaches of the current cycle.
Aftermath: Under Armour sold MyFitnessPal in 2020. The company faced class actions over both incidents; the 2026 litigation is ongoing. Under Armour states that passwords, payment systems and the main UA.com site were not affected in the 2026 incident.
Source: TechCrunch on the January 2026 Under Armour records | Malwarebytes on the Everest leak
Records affected: 147 million US consumers, plus roughly 15.2 million UK and 19,000 Canadian records. Includes 145.5 million Social Security numbers and 209,000 payment card numbers.
Date of breach: May 13 to July 30, 2017
Date disclosed: September 7, 2017
Sector: Financial services / credit reporting
Attack vector: Failure to patch a known Apache Struts vulnerability (CVE-2017-5638) for which a fix had been available since March 2017. An expired TLS certificate on an inspection appliance meant Equifax could not see the exfiltration traffic for 76 days.
Data exposed: Names, Social Security numbers, dates of birth, addresses, driver's licence numbers, credit card numbers and dispute documents containing personally identifying information
Equifax remains the defining US data breach in the public imagination because the victims were never customers and had no ability to opt out. A credit bureau holds the most sensitive identity data in the economy on people who never chose to hand it over, and Equifax lost that data because of a two-month patching failure. The incident permanently reshaped US expectations around executive accountability and breach remediation.
Aftermath: The largest data breach settlement in US history followed: a global resolution with the FTC, CFPB and all 50 states and territories requiring at least $575 million and up to $700 million, comprising a $300 million consumer restitution fund (expandable to $425 million), $175 million to the states and a $100 million CFPB civil penalty. Equifax must maintain a comprehensive security program with board-level certification and biennial third-party assessments. Four Chinese military hackers were indicted by the DOJ in February 2020. Several executives faced insider trading scrutiny for share sales made before the public disclosure.
Source: FTC press release on the Equifax settlement
Records affected: 145 million users
Date of breach: Late February to early March 2014
Date disclosed: May 21, 2014
Sector: E-commerce
Attack vector: Compromise of a small number of employee login credentials, which gave attackers access to the corporate network and a user database
Data exposed: Names, encrypted passwords, email addresses, physical addresses, phone numbers and dates of birth. eBay stated that financial data was stored separately on PayPal systems and was not accessed.
eBay's breach was one of the largest ever at the time and was notable for the company's handling. eBay waited over two months from initial compromise before disclosing, then asked all 145 million users to reset their passwords in a single announcement, which overwhelmed its own password reset infrastructure. Because no financial data was confirmed stolen, regulatory consequences were comparatively light.
Aftermath: Connecticut, Florida and Illinois attorneys general launched a joint investigation. No significant fine was reported. A class action was dismissed for lack of demonstrated harm, an outcome that would be far less likely under current state privacy statutes.
Source: CSO Online, The biggest data breaches of the 21st century
Records affected: Approximately 134 million payment cards
Date of breach: Ongoing through 2008; discovered January 2009
Date disclosed: January 20, 2009
Sector: Financial services / payment processing
Attack vector: SQL injection against a web-facing application, followed by installation of packet-sniffing malware on the card processing network that captured card data in transit while it was unencrypted
Data exposed: Payment card magnetic stripe data including card numbers, expiry dates and, in some cases, cardholder names
Heartland was the largest payment card breach in history when disclosed, and it directly drove the payments industry toward point-to-point encryption and EMV chip adoption in the US. The attack was carried out by Albert Gonzalez and co-conspirators, the same crew responsible for the TJX breach, using techniques that were well understood and defensible at the time.
Aftermath: Heartland paid roughly $145 million in compensation to card issuers and settlements, including approximately $60 million to Visa and $41 million to MasterCard. The company was removed from the PCI DSS compliant service provider list. Albert Gonzalez was sentenced to 20 years in federal prison in March 2010, the longest sentence ever imposed in a US computer crime case at the time.
Source: US Department of Justice on the Gonzalez sentencing
Records affected: 40 million payment card records plus personal information for up to 70 million customers, with overlap. Commonly cited as 110 million total.
Date of breach: November 27 to December 18, 2013
Date disclosed: December 19, 2013, after Brian Krebs broke the story on December 18
Sector: Retail
Attack vector: Credentials stolen from Fazio Mechanical Services, an HVAC contractor with access to Target's vendor billing portal, were used to pivot into the corporate network and then onto point-of-sale terminals, where RAM-scraping malware harvested card data
Data exposed: Payment card numbers, expiry dates, CVVs and PINs (encrypted), plus names, mailing addresses, phone numbers and email addresses
Target is the origin story of third-party risk management as a board-level discipline. An HVAC vendor's credentials led to 40 million cards, Target's FireEye alerts fired and were ignored, and the fallout took down both the CIO and the CEO. It arrived at the peak of the 2013 holiday shopping season, and it's the reason "supply chain risk" entered mainstream corporate vocabulary.
Aftermath: Target reported total breach costs of $202 million. It paid $18.5 million to settle with 47 state attorneys general in May 2017, the largest multistate data breach settlement at the time, plus $10 million to consumers and $39 million to financial institutions. CIO Beth Jacob resigned in March 2014 and CEO Gregg Steinhafel resigned in May 2014, the first Fortune 500 CEO to lose his job over a cyber incident.
Source: KrebsOnSecurity, Target hackers broke in via HVAC company
Records affected: 109 million customers across two distinct 2024 incidents. Breach one: approximately 73 million current and former account holders (data dated to 2019 or earlier). Breach two: call and text metadata for "nearly all" AT&T wireless customers plus Cricket Wireless and MVNO customers.
Date of breach: Breach one: data originally stolen in or before 2019, published March 2024. Breach two: April 14 to April 25, 2024, discovered April 19, 2024.
Date disclosed: March 30, 2024 and July 12, 2024
Sector: Telecommunications
Attack vector: Breach one: origin never fully established; AT&T initially denied its systems were the source. Breach two: stolen credentials used against an AT&T workspace on the Snowflake cloud platform lacking MFA.
Data exposed: Breach one: names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers and AT&T account passcodes. Breach two: phone numbers of parties called and texted, interaction counts, aggregate call durations and, for a subset, cell site identification numbers that reveal approximate location.
The second AT&T breach is uniquely serious because call detail records are a map of everyone a person knows. Even without message content, metadata for nearly every AT&T customer over a six-month window represents an unprecedented exposure of the social graph of a large share of the American population, with obvious implications for journalists, law enforcement and national security personnel. AT&T reportedly paid a ransom of around $370,000 for deletion of the Snowflake data.
Aftermath: AT&T agreed in March 2025 to a $177 million class action settlement, split into a $149 million pool for the March 2024 breach and a $28 million pool for the Snowflake breach, with preliminary approval granted June 20, 2025. AT&T filed Form 8-K disclosures for both incidents under the SEC cybersecurity rules. The FCC opened an investigation.
Source: ClassAction.org on the $177 million AT&T settlement | Wikipedia summary of the Snowflake campaign
Records affected: Approximately 106 million individuals (100 million in the US, 6 million in Canada), including about 140,000 Social Security numbers and 80,000 linked bank account numbers
Date of breach: March 22 to 23, 2019
Date disclosed: July 29, 2019
Sector: Financial services / banking
Attack vector: Server-side request forgery against a misconfigured web application firewall running in AWS. The WAF's IAM role had excessive permissions, allowing the attacker to query the EC2 instance metadata service, retrieve temporary credentials and list and exfiltrate S3 buckets.
Data exposed: Credit card application data from 2005 to 2019 including names, addresses, ZIP codes, phone numbers, email addresses, dates of birth, self-reported income, credit scores, credit limits, balances, payment history and transaction data
Capital One was the first mega-breach in which a cloud misconfiguration by a sophisticated, cloud-native financial institution was the sole cause. The attacker, Paige Thompson, was a former AWS engineer who found the misconfigured WAF and then boasted about the theft on Slack and GitHub, which is how she was caught. The case reset how regulators think about cloud shared responsibility in banking.
Aftermath: The Office of the Comptroller of the Currency imposed an $80 million civil penalty in August 2020 and a consent order requiring remediation, which was terminated in 2022. The Federal Reserve issued a separate cease and desist order. Capital One agreed in December 2021 to a $190 million class action settlement. Paige Thompson was convicted in June 2022 on wire fraud and Computer Fraud and Abuse Act charges and sentenced in October 2022 to time served plus five years of probation.
Source: KrebsOnSecurity on the Capital One theft | DOJ case page, United States v. Paige Thompson
Records affected: Approximately 93.3 to 95 million individuals across more than 2,700 organizations worldwide, with US entities heavily represented. Estimated; counts continued to rise for over a year as downstream victims completed their reviews.
Date of breach: Exploitation began May 27, 2023
Date disclosed: May 31, 2023 (Progress advisory); victim disclosures continued through 2024 and 2025
Sector: Cross-sector (government, healthcare, education, financial services, pensions, insurance)
Attack vector: Cl0p exploited a zero-day SQL injection vulnerability (CVE-2023-34362) in Progress Software's MOVEit Transfer managed file transfer product to deploy a web shell and exfiltrate data from customer environments
Data exposed: Varied by victim but included Social Security numbers, dates of birth, addresses, driver's licence numbers, bank account details, medical records and pension data
MOVEit was the largest mass-exploitation event ever run against a single product and the template for the supply chain extortion campaigns that dominated 2024 and 2025. Cl0p did not deploy ransomware; it simply stole data and published victim names on a leak site to force payment. Major US victims included the US Department of Energy, Louisiana OMV, Oregon DMV, Maximus (11 million), Delta Dental of California (approximately 7 million), Welltok, Genworth Financial, PBI Research Services and hundreds of pension funds.
Aftermath: CISA and the FBI issued a joint #StopRansomware advisory (AA23-158A) in June 2023. The MOVEit MDL in the District of Massachusetts survived a motion to dismiss in 2025 and is proceeding. Progress Software disclosed material breach-related costs in SEC filings and faced shareholder scrutiny. Cl0p is estimated to have collected in excess of $100 million in ransoms across the campaign.
Source: CISA #StopRansomware advisory AA23-158A | Cybersecurity Dive on the MOVEit fallout
Records affected: 94 million payment cards. Revised upward from an initial 45.7 million.
Date of breach: July 2005 to December 2006
Date disclosed: January 17, 2007
Sector: Retail
Attack vector: Attackers used a laptop and antenna to break the weak WEP encryption on wireless networks at Marshalls stores in Miami, then moved laterally into the central TJX network in Framingham, Massachusetts, where card data was stored unencrypted
Data exposed: Payment card numbers, expiry dates, and for a subset, driver's licence numbers, names and addresses tied to unreceipted merchandise returns
For nearly two years, TJX was the largest breach in history, and it's the incident that made PCI DSS enforcement real. The attackers exploited WEP encryption that was already publicly known to be broken, retained card data the company had no business retaining, and went undetected through an 18-month intrusion. Albert Gonzalez, who also masterminded the Heartland breach, led the operation.
Aftermath: TJX paid $9.75 million to settle with 41 state attorneys general in June 2009, plus roughly $40.9 million to Visa issuers and $24 million to MasterCard issuers. Total costs were estimated at over $250 million. Albert Gonzalez received a 20-year federal sentence in 2010. The FTC required TJX to establish a comprehensive information security program subject to biennial third-party audits for 20 years.
Source: WIRED, TJX hacker Albert Gonzalez gets 20 years
Records affected: 76 million households and 7 million small businesses (commonly cited as 83 million accounts)
Date of breach: June to August 2014; discovered mid-August 2014
Date disclosed: October 2, 2014, in a Form 8-K filing with the SEC
Sector: Financial services / banking
Attack vector: Attackers obtained an employee's credentials and accessed a server that had not been upgraded to require two-factor authentication, then moved laterally across more than 90 servers
Data exposed: Names, addresses, phone numbers and email addresses. JPMorgan stated that account numbers, passwords, Social Security numbers and dates of birth were not compromised.
The largest breach of a US bank by customer count is remarkable for how it happened: a single overlooked server in a network of tens of thousands lacked two-factor authentication. JPMorgan was spending roughly $250 million a year on cybersecurity at the time. The intrusion was part of a sprawling securities fraud and pump-and-dump scheme rather than a straightforward identity theft operation.
Aftermath: The DOJ indicted Gery Shalon, Ziv Orenstein and Joshua Samuel Aaron in November 2015 on charges spanning computer hacking, securities fraud and money laundering across a scheme prosecutors described as the largest theft of customer data from a US financial institution. Shalon and Orenstein pleaded guilty in 2018. JPMorgan doubled its annual cybersecurity budget to roughly $500 million.
Source: The New York Times DealBook on the JPMorgan Chase breach
Records affected: 78.8 million individuals, including approximately 12 million minors
Date of breach: February 18, 2014 to January 2015; discovered January 27, 2015
Date disclosed: February 4, 2015
Sector: Healthcare / health insurance
Attack vector: Spear phishing against a subsidiary led to credential theft; attackers then used a compromised database administrator account to query a data warehouse. Attribution pointed to Chinese state-sponsored actors.
Data exposed: Names, dates of birth, Social Security numbers, health care ID numbers, home addresses, email addresses, employment information and income data. Medical records and claims data were not taken.
Anthem held the record as the largest US healthcare breach for nine years, until Change Healthcare surpassed it in 2024. Its significance lies in the nature of the target: a nation-state stealing bulk identity data on 78.8 million Americans including 12 million children, whose Social Security numbers would remain valid and unmonitored for decades. Anthem stored the data unencrypted at rest, which HIPAA permitted as an addressable rather than required specification.
Aftermath: HHS OCR imposed a $16 million HIPAA settlement in October 2018, nearly triple the previous record. Anthem paid $115 million to settle consumer class actions in 2018, the largest data breach class settlement at the time, and $39.5 million to a coalition of state attorneys general in 2020. Anthem also paid $9.8 million to settle with state insurance regulators. The DOJ indicted two Chinese nationals in May 2019.
Source: HHS press release on the $16 million Anthem HIPAA settlement
Records affected: 76.6 million US consumers in the August 2021 breach. A separate January 2023 breach exposed 37 million accounts. T-Mobile has disclosed at least eight breaches since 2018.
Date of breach: August 2021 (disclosed August 16, 2021); the 2023 breach began November 25, 2022 and was discovered January 5, 2023
Date disclosed: August 16, 2021 and January 19, 2023
Sector: Telecommunications
Attack vector: 2021: an unprotected GPRS gateway exposed to the internet, followed by lateral movement to over 100 servers using brute-forced credentials. 2023: abuse of a single application programming interface with inadequate rate limiting and monitoring.
Data exposed: 2021: names, dates of birth, Social Security numbers, driver's licence and ID information, and for prepaid customers, phone numbers and account PINs. 2023: names, billing addresses, emails, phone numbers, dates of birth, account numbers and plan features.
T-Mobile's value as a case study is the repetition. The company was breached in 2018, 2019, 2020, twice in 2021, in 2022 and again in 2023, which turned a series of incidents into a regulatory pattern. The 2021 intrusion was carried out by John Binns, a 21-year-old American living in Turkey, who publicly described T-Mobile's security as "awful."
Aftermath: T-Mobile paid $350 million to settle class actions over the 2021 breach in 2022, plus $150 million committed to security improvements. In September 2024, the FCC announced a $31.5 million settlement covering the 2021, 2022 and 2023 incidents, comprising a $15.75 million civil penalty and $15.75 million in mandated security spending. The consent decree requires zero trust architecture, phishing-resistant MFA across the internal network, data minimisation and independent third-party assessments.
Source: FCC Consent Decree DA-24-860
Records affected: Approximately 70 million transaction records containing gift card data and customer IP addresses; roughly 64,472 individuals notified under state breach laws for sensitive personal data. The 70 million figure is a record count, not an individual count.
Date of breach: April to May 2024
Date disclosed: June 2024
Sector: Retail / luxury department stores
Attack vector: Stolen credentials used against the company's Snowflake cloud data warehouse instance, part of the same 2024 campaign that hit Ticketmaster, Advance Auto Parts and roughly 165 other Snowflake customers
Data exposed: Names, contact information, dates of birth, gift card numbers (without PINs), transaction records, IP addresses and, for a subset, Social Security numbers
Neiman Marcus was one of the highest-volume victims of the Snowflake campaign and had also suffered a separate breach in 2020 affecting 4.6 million customers. The 2024 incident reinforced the campaign's core lesson: none of these organizations were compromised through Snowflake's own infrastructure, but through their own failure to enforce MFA on cloud data warehouse accounts holding their most concentrated customer datasets.
Aftermath: Neiman Marcus Group agreed to pay $3.5 million to settle Snowflake-related class action claims, alongside a $10 million settlement by Advance Auto Parts. Litigation was consolidated in the Snowflake MDL in the District of Montana. Neiman Marcus had previously paid $1.5 million to settle with 43 state attorneys general over its 2020 breach.
Source: Bloomberg Law on the Advance Auto and Neiman Marcus settlements
Records affected: Approximately 62 million students and 9.5 million teachers across roughly 6,500 school districts in the US and Canada
Date of breach: December 19 to December 28, 2024
Date disclosed: January 7, 2025
Sector: Education technology / K-12 student information systems
Attack vector: A stolen support technician credential used against the PowerSource customer support portal, which had no multi-factor authentication, gave the attacker access to a maintenance tool with broad database export capability
Data exposed: Names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, parent and guardian information, medical alert information and grades
The largest student data breach in US history is also among the most sensitive by data type, since it exposed the Social Security numbers and medical alerts of tens of millions of minors who will carry that exposure for decades. PowerSchool paid a ransom of approximately $2.85 million in Bitcoin on the assurance the data would be deleted. It was not: by May 2025, individual school districts in the US and Canada were receiving direct extortion demands using the same stolen data.
Aftermath: Matthew Lane, a Massachusetts college student, pleaded guilty in May 2025 to federal charges in connection with the extortion. Texas Attorney General Ken Paxton sued PowerSchool. Dozens of class actions were filed. Separately, PowerSchool agreed to a $17.25 million settlement resolving unrelated claims that it unlawfully intercepted confidential student communications through its Naviance platform, with a final approval hearing held June 10, 2026.
Source: TechTarget breakdown of the PowerSchool breach
Records affected: 62,224,658 individuals. Revised upward three times: initially reported at approximately 10.5 million, revised to 25.5 million in February 2026, and finalised at 62,224,658 in Conduent's June 4, 2026 filing with HHS OCR. This makes it the third-largest healthcare breach ever recorded in the US.
Date of breach: October 21, 2024 to January 13, 2025
Date disclosed: January 2025 (service disruption); breach notifications from late 2025; final count June 2026
Sector: Government services / business process outsourcing (Medicaid, SNAP, child support, unemployment administration)
Attack vector: SafePay ransomware group maintained unauthorized network access for nearly three months before detection
Data exposed: Names, addresses, dates of birth, Social Security numbers, medical histories and health insurance information
Conduent administers benefits programs for state and local governments, so the victims are disproportionately Medicaid recipients, unemployment claimants and food assistance beneficiaries, the people least equipped to absorb identity theft. The near-sixfold revision from 10.5 million to 62.2 million over 17 months is one of the most dramatic upward revisions in US breach history and a caution against treating early victim counts as reliable.
Aftermath: Conduent disclosed in SEC filings that it had accrued approximately $25 million in non-recurring breach-related expenses. At least nine class actions were consolidated in New Jersey federal court. The incident has become a leading case study in HIPAA business associate liability, since Conduent's downstream covered entities inherit notification obligations for a breach they did not cause.
Source: HIPAA Journal on the final 62.2 million figure | SecurityWeek initial reporting
Records affected: 57 million riders and drivers, including approximately 600,000 US driver's licence numbers
Date of breach: October 2016
Date disclosed: November 21, 2017, more than a year after the fact
Sector: Technology / ride-hailing
Attack vector: Credentials found in a private GitHub repository used by Uber engineers granted access to an AWS S3 bucket containing rider and driver data
Data exposed: Names, email addresses, phone numbers for 57 million users, plus driver's licence numbers for approximately 600,000 US drivers
Uber's breach is remembered for the cover-up rather than the intrusion. Uber paid the attackers $100,000 through its bug bounty program, had them sign non-disclosure agreements, and characterised the extortion payment as a legitimate bounty, concealing the incident for 13 months while the FTC was actively investigating an earlier 2014 breach. That decision produced the first criminal conviction of a US security executive for breach concealment.
Aftermath: Uber paid $148 million in September 2018 to settle with all 50 state attorneys general plus DC, the largest multistate data breach settlement at the time. Former Chief Security Officer Joe Sullivan was convicted in October 2022 of obstruction of justice and misprision of a felony, and was sentenced in May 2023 to three years of probation and a $50,000 fine. Uber entered a non-prosecution agreement with the DOJ in 2022. The FTC expanded its existing consent order.
Source: US Department of Justice on the Uber CSO conviction
Records affected: 56 million payment cards plus approximately 53 million email addresses
Date of breach: April to September 2014
Date disclosed: September 8, 2014, after Brian Krebs broke the story on September 2
Sector: Retail
Attack vector: Credentials stolen from a third-party vendor were used to access the network, followed by privilege escalation and deployment of custom memory-scraping malware on self-checkout point-of-sale terminals across US and Canadian stores
Data exposed: Payment card numbers and expiry dates, plus email addresses
Home Depot surpassed Target as the largest retail card breach less than a year later, using an almost identical playbook: third-party vendor credentials, lateral movement, POS memory scrapers. Its POS terminals were running Windows XP Embedded and the company had reportedly deferred security investment despite internal warnings, which became central to the shareholder derivative litigation.
Aftermath: Home Depot reported gross breach costs of approximately $298 million, offset by insurance. It paid $17.5 million to settle with 46 state attorneys general in November 2020, $19.5 million to consumers in 2016 and $25 million to financial institutions in 2017. Shareholder derivative claims settled with governance reforms in 2017.
Source: KrebsOnSecurity, Home Depot: 56M cards impacted
Records affected: 29.8 million accounts, roughly 20% of the platform's global user base
Date of breach: Detected December 2025; SoundCloud confirmed the incident December 15, 2025
Date disclosed: December 2025; data published by the attackers in January 2026
Sector: Technology / music streaming
Attack vector: Unauthorized access to an internal system, which the attackers used to correlate private email addresses with public profile information. ShinyHunters claimed responsibility and attempted extortion before publishing.
Data exposed: Names, email addresses, usernames, avatars, follower and following counts, and country for a subset of users. SoundCloud states no passwords or financial data were accessed.
Although the data types are relatively low-sensitivity, the SoundCloud breach is significant as one of the largest confirmed US-consumer-facing breaches of the H1 2026 period, contributing 29.8 million of the 471.2 million victim notices ITRC recorded. It also fits the dominant pattern of the current era: ShinyHunters compromising a peripheral system, extorting, and publishing when refused.
Aftermath: SoundCloud declined to pay, and the data was published in January 2026 and indexed by Have I Been Pwned. Class action activity is in early stages. No regulatory penalty has been announced.
Source: BleepingComputer on the 29.8 million SoundCloud accounts
Records affected: 22.65 million individuals globally per Aflac's own confirmation; protected health information of at least 13,924,906 individuals per the company's update to HHS OCR. The two figures measure different populations; both are Aflac-reported.
Date of breach: June 2025
Date disclosed: June 2025 (initial); reported to HHS OCR August 8, 2025, with the victim count updated subsequently
Sector: Insurance / supplemental health
Attack vector: Social engineering against the identity and access layer, consistent with the Scattered Spider playbook targeting the US insurance sector in mid-2025
Data exposed: Names, Social Security numbers, health information, insurance claims data and other personal information
Aflac was the largest casualty of the coordinated 2025 campaign against US insurers, which also hit Erie Insurance, Philadelphia Insurance Companies and others in quick succession. The incident is instructive because Aflac detected and contained the intrusion within hours, which was operationally impressive, yet the attackers still exfiltrated data on more than 22 million people in that window. Speed of detection does not by itself limit blast radius when the compromised account has broad data access.
Aftermath: Multiple class actions were filed in Georgia federal court. HHS OCR opened an investigation given the volume of protected health information. Aflac offered affected individuals free credit monitoring and identity theft protection.
Source: HIPAA Journal on the Aflac breach
Records affected: 22.1 million total, comprising 21.5 million background investigation records and 4.2 million personnel records, with overlap. Includes 5.6 million fingerprint records.
Date of breach: Two intrusions beginning around November 2013 and May 2014; discovered April 2015
Date disclosed: June 4, 2015 and July 9, 2015
Sector: Federal government
Attack vector: Credentials stolen from KeyPoint Government Solutions, an OPM background investigation contractor, used to establish persistence. Attribution points to Chinese state-sponsored actors.
Data exposed: Standard Form 86 background investigation files containing Social Security numbers, financial histories, mental health treatment records, drug and alcohol use, foreign contacts, family member details, criminal histories, and 5.6 million sets of fingerprints
The single most damaging breach of the US federal government exposed the most intimate documents the government holds on its own people. SF-86 forms are compiled specifically to identify anything that could be used for blackmail, and 21.5 million of them were taken by a foreign intelligence service, along with fingerprints that can never be reissued. Every clearance holder, their spouses and their foreign contacts were exposed.
Aftermath: OPM Director Katherine Archuleta resigned on July 10, 2015. A 2016 House Oversight Committee report concluded the breach was preventable and criticised OPM leadership. OPM and KeyPoint agreed to a $63 million class settlement approved in 2022. The breach drove the creation of the National Background Investigation Bureau and accelerated federal adoption of continuous diagnostics and mitigation, PIV cards and continuous monitoring.
Source: House Oversight Committee report on the OPM data breach | OPM Cybersecurity Resource Center
Records affected: Approximately 17.6 million accounts
Date of breach: June to August 2025; detected September 2, 2025
Date disclosed: Notifications began September 17, 2025; full scope confirmed October 2025
Sector: Financial services / peer-to-peer lending
Attack vector: Unauthorized actors queried the customer and loan applicant database directly and exfiltrated results. Prosper states user accounts and funds were not accessed.
Data exposed: Names, addresses, email addresses, IP addresses, dates of birth, Social Security numbers, government-issued ID numbers, employment status, income levels, credit status and browser user agent strings
Prosper was the largest single-organization US breach of 2025 by confirmed record count. The exposed dataset is unusually complete for identity fraud purposes, since loan applications require exactly the combination of SSN, government ID, income and employment verification that a fraudster needs to open credit in someone else's name. The victims include people who merely applied for a loan and were never customers.
Aftermath: Multiple class actions were filed in the Northern District of California. Prosper offered affected individuals credit monitoring. State attorney general inquiries are ongoing. No regulatory penalty has been announced as of July 2026.
Source: SecurityWeek on the Prosper breach
Records affected: Up to 13.4 million individuals
Date of breach: Ongoing from at least 2017 to April 2024; identified through a voluntary internal review
Date disclosed: April 2024
Sector: Healthcare / integrated health system
Attack vector: Not an intrusion. Third-party tracking technologies including the Meta Pixel, Google Analytics, Microsoft Bing and Hotjar were embedded across Kaiser's websites and mobile apps, including authenticated patient portal pages, transmitting logged-in patient activity to advertising and analytics vendors.
Data exposed: Names, IP addresses, sign-in status, search terms entered in health encyclopaedias, and navigation activity across pages relating to appointments, lab results and specific conditions
The second-largest US healthcare breach reported in 2024 was caused entirely by marketing technology rather than by any attacker. Because users were authenticated, health-related browsing was linkable to identifiable patients and was shared with third parties for advertising. It's the largest of the pixel-tracking HIPAA cases and it forced a sector-wide audit of web analytics on patient-facing properties.
Aftermath: Kaiser agreed to pay up to $47.5 million to settle web tracker litigation. HHS OCR had already issued guidance in December 2022 and an updated bulletin in March 2024 on online tracking technologies and HIPAA, and the Kaiser disclosure became the largest incident reported under that framing. Numerous other health systems disclosed comparable pixel breaches in the same window.
Source: HIPAA Journal on the Kaiser Permanente web tracker breach and settlement
Records affected: 6.9 million individuals, of whom approximately 14,000 accounts were directly compromised via credential stuffing. The remaining 6.9 million were exposed through the DNA Relatives feature (approximately 5.5 million profiles) and Family Tree feature (approximately 1.4 million profiles).
Date of breach: April to September 2023
Date disclosed: October 2023
Sector: Consumer genetics / biotechnology
Attack vector: Credential stuffing using passwords recycled from prior unrelated breaches. 23andMe did not require MFA at the time, and the DNA Relatives opt-in feature meant compromising one account exposed the profile data of thousands of genetic relatives.
Data exposed: Names, birth years, relationship labels, percentage of DNA shared with relatives, ancestry reports and self-reported location. Raw genotype data was accessed for a smaller subset. Attackers specifically compiled and advertised lists targeting people of Ashkenazi Jewish and Chinese descent.
23andMe is the clearest demonstration that some data can't be reset, revoked or reissued. Genetic and ancestry data is permanent and implicates biological relatives who never used the service. The targeting of specific ethnic groups moved the incident beyond financial fraud into the territory of persecution risk.
Aftermath: 23andMe agreed to a $30 million class settlement in September 2024 plus three years of security monitoring. The UK ICO fined the company 2.31 million pounds in June 2025 for failing to protect UK users. 23andMe filed for Chapter 11 bankruptcy in March 2025, which triggered a scramble by state attorneys general over the fate of 15 million customers' genetic data in a bankruptcy sale; the assets were acquired by the nonprofit TTAM Research Institute. The case drove new state genetic privacy legislation.
Source: BleepingComputer on the 23andMe data theft
Records affected: 5,995,277 people, per Carnival's filing with the Maine Attorney General
Date of breach: April 10, 2026; unauthorized activity identified April 14, 2026; scope confirmed April 22, 2026
Date disclosed: May 2026
Sector: Travel / cruise lines
Attack vector: Social engineering against an employee account, giving the attacker access to a restricted part of Carnival's IT environment. ShinyHunters claimed the breach.
Data exposed: Names, addresses, email addresses, phone numbers, dates of birth, loyalty membership information and government-issued identification numbers including driver's licence and passport numbers
The second-largest US breach of H1 2026 after Instructure is the more damaging of the two on a per-victim basis, because it exposed passport and driver's licence numbers, which can't be changed as easily as a password or a card. Carnival has now suffered four disclosed breaches since 2019, which makes the 2026 incident a repeat-offender problem as much as a new one.
Aftermath: Carnival is offering 24 months of TransUnion credit monitoring to all affected individuals. Class actions were filed in Florida federal court. Carnival previously paid $1.25 million to settle with 45 state attorneys general over its 2019 breaches and $5 million to New York's Department of Financial Services in 2022, which is likely to be an aggravating factor in any new regulatory action.
Source: BleepingComputer on the Carnival breach
Records affected: Not quantified in individual terms. US officials described metadata access affecting "over a million" users, with call content intercepted for a smaller set of high-value targets. No victim count has been officially published; treat all circulating figures as unverified.
Date of breach: Intrusions dating to at least 2022, with Cisco reporting persistence of up to three years in at least one network
Date disclosed: Publicly reported October 2024; joint government advisories followed in 2024 and 2025
Sector: Telecommunications / critical infrastructure
Attack vector: Chinese state-sponsored actors exploited vulnerabilities in public-facing network edge devices including VPN appliances, routers, firewalls and Exchange servers, then deployed custom backdoors such as GhostSpider for long-term persistence
Data exposed: Call detail records and metadata at scale, plus, for a small number of targets, actual call content and text messages. Critically, the attackers accessed CALEA lawful intercept systems, meaning they could see which individuals US law enforcement had under court-authorised surveillance.
Ranked here for consequence rather than record count, Salt Typhoon compromised AT&T, Verizon, Lumen Technologies, T-Mobile, Charter, Windstream and others, and reached the wiretap infrastructure that US law enforcement is legally mandated to build into carrier networks. Communications of Trump and Harris campaign staff were reportedly captured. Senator Mark Warner called it the worst telecom hack in US history, and it's the strongest real-world argument to date that mandated lawful access backdoors become adversary access backdoors.
Aftermath: CISA, the FBI, the NSA and international partners issued joint advisories. The FCC in January 2025 issued a declaratory ruling holding that Section 105 of CALEA requires carriers to secure their networks, and adopted proposed cybersecurity rules, though the FCC subsequently moved to rescind parts of that ruling in 2025. The House Select Committee on the CCP demanded briefings from AT&T, Verizon and Lumen. The US Treasury sanctioned a Chinese cybersecurity firm and an individual linked to the campaign in January 2025.
Source: Washington Post investigation into Salt Typhoon | House Select Committee letter to Verizon, AT&T and Lumen
These fell outside the top 40 by volume but are significant for their attack vectors, sectors or regulatory consequences:
Read the list from top to bottom and a pattern emerges: the largest recent breaches rarely start with an exotic exploit. They start with an unmonitored third party, a cloud account missing MFA, a reused credential, or an internet-facing system nobody was watching. Those are exposures you can find before an attacker does, and that's where continuous monitoring changes the math.
The through-line across two decades of major breaches is that visibility precedes prevention. Start a free trial to experience the UpGuard cybersecurity platform.
By records exposed, Yahoo remains the largest single-organization breach tied to a US company, with all 3 billion of its user accounts compromised across intrusions in 2013 and 2014. By exposure of US Social Security numbers, the National Public Data leak is the largest on record.
The largest recent US incident is the Instructure Canvas breach, disclosed in May 2026, which the ITRC estimates generated around 275 million victim notices, or 58% of all US breach notices in the first half of 2026.
No. The June 2025 "16 billion credentials" figure is an aggregation of more than 30 datasets harvested by infostealer malware and older breach dumps, not a single organization's breach, so it shouldn't be ranked as one.
Change Healthcare is the largest US healthcare breach by a wide margin, affecting 192.7 million individuals after three upward revisions, and it surpassed the 2015 Anthem breach that had held the record for nine years.
Most mega-breaches trace back to preventable exposures rather than novel exploits: unmonitored third parties, cloud accounts and portals without multi-factor authentication, unpatched software, misconfigured storage, and reused or stolen credentials.