The biggest data breaches no longer deal in millions of records. The incidents at the top of this list involve billions, and the gap between a headline number and the real damage has never been wider. This is a ranked reference to the 40 largest and most consequential data breaches of all time, current as of July 2026, ordered primarily by the number of records or individuals affected. A handful of lower-count incidents earn a place anyway because of their impact on national security, critical infrastructure, or breach law.
Two rules of interpretation matter before you read on. First, several of the largest "breaches" in the press are not breaches of a single organization at all; they are aggregations of credentials harvested by infostealer malware and recycled from older dumps, then repackaged and re-advertised. RockYou2024, Collection #1, and the June 2025 "16 billion credentials" story all fall into that category, and they are labeled as such rather than ranked alongside genuine single-organization compromises. Second, figures marked estimated or disputed come from third parties or from attacker claims the affected organization has not confirmed, and widely reported counts for Yahoo, Change Healthcare, and National Public Data were all revised after the fact.
Three patterns run through the most recent entries on this list, and they change how you should read the older ones. The first is that attackers have shifted from breaking into companies to logging into them. Stolen credentials, missing multi-factor authentication, help desk social engineering, and abuse of OAuth tokens account for most of the largest recent events, including Snowflake, PowerSchool, Salesloft Drift, Qantas, Coupang, ADT, and Aura. None of these required a novel exploit; they required a valid login the victim failed to protect. For the broader trend lines, our data breach statistics roundup tracks how these numbers have moved year over year.
The second pattern is concentration. One compromise now routinely produces hundreds of victim organizations, because the target is a shared platform rather than a single company. The scale is measurable: the HIPAA Journal reported that just 38 supply chain incidents in the first half of 2026 generated more than 280 million victim notices, a multiplier effect that turns one vendor's bad day into an industry-wide event.
The third pattern is that transparency is getting worse. That same reporting found 76% of breach notices issued in the first half of 2026 omitted any information about the attack vector, the lowest disclosure rate the Identity Theft Resource Center has ever recorded. For defenders, the practical takeaway is that the controls that would have prevented the largest recent breaches are unglamorous: phishing-resistant multi-factor authentication on every remote access path and admin portal, short-lived tokens with real revocation at offboarding, least privilege on cloud identity roles, tight limits and alerting on bulk data export, continuous monitoring of third- and fourth-party attack surface, and no secrets stored in free-text customer relationship management (CRM) fields.
The list runs from the largest exposed datasets ever documented down to smaller but landmark incidents. Each entry preserves the reported record count and any dispute or estimate flag, along with the attack vector and aftermath that make it worth studying.
Records affected: 10.88 billion records (estimated by researchers; not a count of unique individuals)
Date of breach: Exposure discovered March 16, 2020
Date disclosed: March 2020
Country / HQ: Cyprus (operator Granity Entertainment)
Sector: Adult entertainment / streaming
Attack vector: Misconfigured Elasticsearch cluster left accessible without authentication
Data exposed: Names, email addresses, sexual orientation, chat and email transcripts, payment logs, IP addresses, hashed passwords, country of origin, fraud detection logs
Researchers at Safety Detectives found a production Elasticsearch cluster belonging to the adult streaming site Cam4 sitting on the open internet with no password. The 7-terabyte index held roughly 10.88 billion log rows going back to 2018. That row count is not a count of unique people, and the researchers identified around 11 million records containing email addresses and around 26 million containing hashed passwords. It remains the largest single exposed dataset ever documented by record volume, and because it tied real identities to sexual preferences and private chat logs, it became a textbook case for why cloud misconfiguration is treated as a critical risk rather than a housekeeping issue.
Aftermath: The server was taken offline shortly after disclosure. The operator sits outside the European Union's main enforcement spotlight, and because no mass exfiltration was ever proven, no significant regulatory fine followed, which itself became a talking point about the limits of privacy enforcement.
Source: Safety Detectives: Cam4 data breach report
Records affected: 3 billion accounts (revised upward; originally disclosed as 500 million in September 2016, then 1 billion in December 2016, then all 3 billion accounts in October 2017)
Date of breach: August 2013 (the 3 billion account theft) and late 2014 (a separate state-sponsored intrusion)
Date disclosed: September 2016, December 2016, and October 2017
Country / HQ: United States
Sector: Technology / web services
Attack vector: Network intrusion, including spear phishing of an employee and forging of authentication cookies; the 2014 event was attributed to Russian state-linked actors
Data exposed: Names, email addresses, telephone numbers, dates of birth, hashed passwords (MD5 in the 2013 set), and in some cases encrypted or unencrypted security questions and answers
Yahoo suffered two distinct intrusions in 2013 and 2014 but did not disclose either until 2016, in the middle of its acquisition by Verizon. The company first said 500 million accounts were affected, then 1 billion, and finally admitted in October 2017 that every one of its roughly 3 billion accounts had been compromised in the August 2013 event. Those repeated upward revisions are the reason Yahoo is still the reference case for treating initial breach numbers as provisional, and the disclosure delay reshaped how breach risk is handled in mergers and acquisitions.
Aftermath: Verizon cut its acquisition price by 350 million dollars. The SEC fined Altaba, Yahoo's successor entity, 35 million dollars in April 2018 for failing to disclose the breach to investors, the first such SEC penalty of its kind. Yahoo also paid a 117.5 million dollar consumer class action settlement, and a Russian intelligence officer and co-conspirators were indicted by the US Department of Justice in 2017.
Source: SEC: Altaba, formerly Yahoo, charged with failing to disclose massive cybersecurity breach
Records affected: RockYou2024, 9.9 billion plaintext passwords. Collection #1, 773 million email addresses and 21 million unique passwords. The June 2025 story, roughly 16 billion credential pairs across 30 datasets. All figures are aggregate line counts with heavy duplication.
Date of breach: Not applicable; these are compilations assembled over many years
Date disclosed: Collection #1 in January 2019, RockYou2024 in July 2024, the 16 billion compilation reported in June 2025
Attack vector: Infostealer malware logs, credential stuffing lists, and recycled data from historic breaches, repackaged and re-advertised on forums and Telegram
Data exposed: Email addresses, usernames, plaintext and hashed passwords, and in the case of stealer logs, session cookies and URLs
These are not breaches of any single organization, and they appear here specifically because they are routinely and wrongly presented as such. RockYou2024 was a 9.9 billion line password file that was overwhelmingly a re-aggregation of older lists. The June 2025 "16 billion credentials" story described 30 loosely documented datasets found in exposed storage, and reporting at the time made clear there was no new compromise of Google, Apple, or Facebook despite headlines to that effect. All three companies confirmed their systems had not been breached. Treat these events as evidence of how much stolen credential material is in circulation, not as discrete incidents with a victim organization, a breach date, or a regulator.
Aftermath: No regulatory action followed, because there is no single accountable organization. The practical consequence is sustained credential stuffing pressure across every consumer service, which is why passkeys and phishing-resistant multi-factor authentication moved up the roadmap at most large platforms.
Source: BleepingComputer: No, the 16 billion credentials leak is not a new data breach
Records affected: 2.9 billion rows claimed by the seller (disputed). Independent analysis found roughly 899 million unique Social Security numbers and around 134 million unique email addresses. The company's own regulator filing in Maine initially cited only 1.3 million people, a figure widely regarded as understated.
Date of breach: Around December 2023, with data advertised from April 2024
Date disclosed: August 2024, after the full dataset was posted publicly
Country / HQ: United States (Jerico Pictures, trading as National Public Data, Florida)
Sector: Data brokerage / background checks
Attack vector: Unauthorized access to the broker's aggregated database; a related sister site was also found publishing a plaintext file of administrator credentials
Data exposed: Names, Social Security numbers, mailing address histories going back decades, phone numbers, and in some records relatives' names. No payment card data.
A threat actor using the handle USDoD advertised a database of 2.9 billion records aggregated by the background check broker National Public Data, then leaked it publicly in August 2024. The 2.9 billion figure is a row count rather than a person count, and deduplication reduced it substantially, but the roughly 899 million unique Social Security numbers identified in the dataset still make it one of the most damaging identity exposures ever. It matters because none of the affected people were customers of National Public Data; their data had been collected and resold without any direct relationship, which turned the incident into a policy argument about data brokers.
Aftermath: National Public Data filed for Chapter 11 bankruptcy in October 2024, listing assets of 25,000 to 75,000 dollars against roughly 20 class actions plus FTC scrutiny and investigations by more than 20 state attorneys general. The collapse became the standard example of a breach that ends the company rather than producing a fine.
Source: The Record: National Public Data files for bankruptcy, citing fallout from cyberattack
Records affected: Approximately 1.1 billion residents' records reported as accessible (disputed; UIDAI denied a breach of the core database)
Date of breach: Access reportedly available from around August 2017
Date disclosed: January 4, 2018
Country / HQ: India
Sector: Government / national identity
Attack vector: Illicit resale of administrator-level portal credentials; separately, insecure third-party and state government portals exposed Aadhaar-linked records
Data exposed: Aadhaar numbers, names, addresses, phone numbers, email addresses, photographs. UIDAI maintains biometric templates were not exposed.
The Tribune of India reported that its reporters paid 500 rupees to anonymous sellers on WhatsApp and received working credentials that let them query the Aadhaar database for any of the roughly 1.1 billion enrolled residents. UIDAI denied that the central repository had been breached and filed a police complaint against the newspaper, but the episode, combined with a long series of leaks from state portals and third parties that stored Aadhaar-linked data insecurely, made Aadhaar the reference case for the risks of a single national identifier. The World Economic Forum's 2019 Global Risks Report cited it as the largest breach of its kind.
Aftermath: UIDAI restricted access to Aadhaar lookup tools, introduced virtual IDs and masked Aadhaar, and pursued the case against the reporting journalists, which drew heavy criticism from press freedom groups. India's Supreme Court upheld Aadhaar's constitutionality in September 2018 while striking down mandatory private sector use.
Source: Al Jazeera: India probes breach of biometric identity database
Records affected: More than 1.1 billion pieces of user information (data points, not unique users)
Date of breach: November 2019 to July 2020
Date disclosed: June 2021, via a Chinese court verdict
Country / HQ: China
Sector: E-commerce
Attack vector: Automated web scraping using custom crawler software that abused Taobao's public interfaces
Data exposed: User IDs, mobile phone numbers, usernames, and customer product comments
A software developer surnamed Lu built a crawler that harvested more than 1.1 billion data points from Alibaba's Taobao marketplace over roughly eight months, passing the data to the marketing consultancy he worked for so it could better target Taobao merchants' customers. Alibaba detected the activity and reported it to police. The case is instructive because no system was hacked in the conventional sense; the exposure came entirely from tolerating high-volume automated access to data that was nominally public, the same failure pattern behind the LinkedIn and Facebook scrapes.
Aftermath: A court in Suiyang District, Henan Province sentenced both the developer and his employer to three years in prison and imposed a fine of 450,000 yuan, roughly 70,000 dollars. Alibaba said no data was sold to third parties. The case preceded China's Personal Information Protection Law, which took effect in November 2021 and substantially raised the stakes for this kind of harvesting.
Source: The Register: Alibaba suffers billion-item data leak of usernames and mobile numbers
Records affected: Approximately 1 billion Chinese residents claimed (unverified; a 750,000 record sample was validated by journalists)
Date of breach: Believed to be 2022, with the database reportedly left exposed without a password
Date disclosed: Late June / early July 2022
Country / HQ: China
Sector: Government / law enforcement
Attack vector: An Elasticsearch instance holding police records reportedly left accessible without authentication, later reported to have been exposed via a dashboard on the public internet
Data exposed: Names, national ID numbers, addresses, birthplaces, phone numbers, photographs, and details of criminal case files
A seller using the handle ChinaDan advertised 23 terabytes of data from the Shanghai National Police database on Breach Forums for 10 bitcoin, claiming it covered around 1 billion Chinese residents. Reporters at multiple outlets verified entries from the 750,000 record sample by calling individuals listed in it, and the presence of police case notes made the exposure unusually sensitive. Beijing censored discussion of the incident domestically and never officially acknowledged it, so the full scope has never been confirmed, but if accurate it is the largest known breach of a government-held citizen database.
Aftermath: No public regulatory or enforcement outcome followed. Chinese authorities censored coverage and reportedly restricted searches for the incident. Reuters reported that officials later held meetings on data security, and China's Cyberspace Administration issued penalties in other cases, but no accountability for this incident has been made public.
Source: NBC News: Hacker claims to have stolen 1 billion records of Chinese citizens from police
Records affected: Approximately 885 million documents relating to mortgage transactions going back to 2003
Date of breach: Exposure existed from 2003 until May 2019
Date disclosed: May 24, 2019, by KrebsOnSecurity
Country / HQ: United States
Sector: Title insurance / real estate financial services
Attack vector: Insecure direct object reference in the EaglePro document sharing application, meaning anyone with one valid document link could increment the URL and read any other customer's documents without authentication
Data exposed: Bank account numbers and statements, mortgage and tax records, Social Security numbers, wire transfer receipts, driver's license images
KrebsOnSecurity revealed that First American, the second largest title insurer in the United States, had been publishing hundreds of millions of scanned real estate closing documents on its website in a way that required no login at all. Changing a single digit in a document URL returned somebody else's financial paperwork. The flaw required no attacker sophistication, which is precisely why the case is cited so often, and the exposure ran for roughly 16 years before an outside journalist reported it.
Aftermath: The New York Department of Financial Services filed charges in July 2020, the first ever enforcement action under its Part 500 cybersecurity regulation, and the matter settled in November 2023 for 1 million dollars. The SEC separately settled with First American for around 488,000 dollars in June 2021 over disclosure control failures. Critics, including Krebs, called the penalties small relative to the exposure.
Source: KrebsOnSecurity: NY charges First American Financial for massive data leak
Records affected: Approximately 763 million unique email addresses (about 809 million total records)
Date of breach: Exposure found February 2019
Date disclosed: March 2019
Country / HQ: United States
Sector: Email marketing / data validation
Attack vector: Unsecured MongoDB instance publicly accessible with no authentication
Data exposed: Email addresses, names, phone numbers, dates of birth, genders, employer and job title, and in a business-focused subset, revenue figures and company details
Researcher Bob Diachenko found a 150-gigabyte MongoDB database belonging to the email validation service Verifications.io sitting open on the internet. The company's business was checking whether email addresses in its clients' marketing lists were live, which meant it had accumulated a vast aggregation of contact records about people who had never heard of it. Have I Been Pwned loaded around 763 million unique addresses from the set, one of the largest single additions to that service.
Aftermath: The company took its site offline permanently rather than continue operating. No public fine was issued. The incident is frequently cited in arguments for regulating marketing data intermediaries, since the affected people had no relationship with the breached company and no way to opt out.
Source: Have I Been Pwned: Verifications.io breach entry
Records affected: Approximately 700 million member profiles (about 92% of LinkedIn's membership at the time). LinkedIn disputes the "breach" characterization.
Date of breach: Scraping conducted into mid-2021; a related 500 million record set surfaced in April 2021
Date disclosed: June 22, 2021
Country / HQ: United States (Microsoft subsidiary)
Sector: Social networking / professional
Attack vector: Abuse of LinkedIn's API to enumerate and harvest profile data at scale, combined with enrichment from other sources
Data exposed: Full names, email addresses, phone numbers, geolocation, LinkedIn usernames and profile URLs, professional and employment history, genders, and in some records inferred salary
A seller calling himself Tom Liner advertised 700 million LinkedIn records on RaidForums with a one million record sample, having abused the platform's API over several months. LinkedIn's position, which is defensible and worth stating, is that this was not a breach of its systems and no private member data was exposed, because the harvested fields were visible on public profiles or came from elsewhere. The distinction matters legally but not much practically, because the aggregation gave attackers a single, searchable, machine-readable list linking real names to employers, phone numbers, and email addresses, which is exactly what is needed to run convincing spear phishing at scale.
Aftermath: No fine was imposed for the 2021 scrape. LinkedIn tightened API abuse controls and continued a longstanding litigation campaign against scrapers, including the hiQ Labs case. The incident, alongside the Facebook scrape, pushed regulators to start treating large-scale scraping as a data protection issue in its own right, and in August 2023 a dozen global privacy regulators issued a joint statement to that effect.
Source: The Record: Hackers leak LinkedIn 700 million data scrape
Records affected: 560 million customers claimed by the attackers (disputed and unconfirmed by Live Nation). Live Nation's breach notifications covered a smaller confirmed population, including around 1,000 people in Maine filings and separate notifications in other jurisdictions.
Date of breach: Unauthorized activity around April 2 to May 18, 2024
Date disclosed: May 31, 2024, via a Live Nation SEC Form 8-K
Country / HQ: United States
Sector: Ticketing / live entertainment
Attack vector: Credentials for a third-party cloud database environment at Snowflake, stolen by infostealer malware from contractor and employee machines, used to log in to accounts that lacked multi-factor authentication
Data exposed: Names, addresses, email addresses, phone numbers, order histories, and partial payment card data including last four digits and expiry dates
ShinyHunters listed 1.3 terabytes of Ticketmaster data for 500,000 dollars in May 2024, claiming records on 560 million customers. Live Nation confirmed in an 8-K that data had been taken from a third-party cloud database, later identified as Snowflake. Snowflake itself was not breached; the attackers logged in with stolen credentials to customer tenants that had no multi-factor authentication enforced. The campaign hit roughly 165 Snowflake customers in total, including AT&T, Santander, and Advance Auto Parts, and it is the clearest demonstration to date that a software platform's security posture is only as strong as its customers' identity hygiene.
Aftermath: Live Nation faces consolidated class action litigation. Two suspects were arrested in Canada and Turkey, and US prosecutors charged Connor Moucka and John Binns in connection with the Snowflake campaign; Moucka was extradited and pleaded guilty in 2025. Snowflake made multi-factor authentication enforcement available and later default for new accounts.
Source: The Record: Live Nation confirms Ticketmaster breach after hackers hawk stolen info of 560 million
Records affected: 538 million user records, including 172 million with phone numbers
Date of breach: Reportedly mid-2019
Date disclosed: March 2020
Country / HQ: China
Sector: Social media
Attack vector: Reported abuse of a Weibo feature that let users look up accounts by phone number, combined with a claimed database compromise. Weibo attributed the phone numbers to matching against externally sourced data rather than a breach of its systems.
Data exposed: Usernames, real names, gender, location, and phone numbers. Weibo said passwords were not included.
A seller advertised the personal details of 538 million Weibo accounts for about 250 dollars, of which 172 million entries included phone numbers. Weibo denied that its systems had been breached, arguing the phone numbers had been assembled by brute forcing its contact lookup feature in 2019 and then matched to public profile data. China's Ministry of Industry and Information Technology summoned Weibo executives over the incident. Whichever explanation is correct, the practical result was one of the largest exposures of Chinese social media users' identity and contact details.
Aftermath: The ministry ordered Weibo to rectify its data protection practices. No large monetary penalty was made public. The incident is one of the events cited in the run-up to China's Personal Information Protection Law.
Source: ZDNet: Hacker selling data of 538 million Weibo users
Records affected: More than 1.5 billion Salesforce records claimed across 760 organizations (attacker claim, unverified). Ranked here rather than near the top because the figure is an unconfirmed record count spanning hundreds of separate corporate tenants, not a count of individuals at one company.
Date of breach: GitHub access from March 2025; mass exfiltration from around August 8 to 18, 2025
Date disclosed: August and September 2025
Country / HQ: United States (Salesloft, Atlanta; Drift acquired 2024)
Sector: Sales technology / SaaS supply chain
Attack vector: Compromise of Salesloft's GitHub account, from which the attackers used the secret scanning tool TruffleHog to extract Drift and Drift Email OAuth tokens, then used those tokens to authenticate to customers' Salesforce and Google Workspace tenants
Data exposed: CRM contact and account records, support case contents, and critically, secrets stored inside Salesforce records including AWS access keys, Snowflake credentials, VPN details, and API tokens
This was the defining breach pattern of 2025. Rather than attacking 760 companies individually, the group tracked as ShinyHunters and UNC6395 compromised one integration vendor and inherited authorized OAuth access to every customer that had connected the Drift chatbot to Salesforce. Confirmed victims included Cloudflare, Zscaler, Palo Alto Networks, Google, Qantas, Allianz Life, Farmers Insurance, and TransUnion, and because attackers specifically hunted for credentials stored in CRM notes, the initial theft seeded follow-on intrusions elsewhere.
Aftermath: Salesforce disabled the Drift integration and removed Drift from AppExchange; Salesloft took Drift offline entirely for a period and engaged Mandiant. Multiple downstream victims filed their own regulatory notifications and face class actions. The campaign triggered an industry-wide re-examination of OAuth token scope, token lifetime, and the practice of storing secrets in CRM free-text fields.
Source: BleepingComputer: ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks
Records affected: 533 million users across 106 countries
Date of breach: Data harvested up to around September 2019 via the contact importer feature
Date disclosed: Partially in 2019; the full dataset was posted free on a hacking forum on April 3, 2021
Country / HQ: United States
Sector: Social media
Attack vector: Abuse of Facebook's contact importer, which allowed attackers to feed in huge ranges of phone numbers and receive back the matching profiles
Data exposed: Phone numbers, Facebook IDs, full names, locations, dates of birth, relationship status, employer, and in some cases email addresses
A dataset covering 533 million Facebook users, including around 32 million in the United States and 11 million in the United Kingdom, was dumped free of charge on a hacking forum in April 2021, having previously been sold privately. Facebook's position was that this was old scraped data relating to a vulnerability fixed in 2019 and not a new breach, but the company had not notified users at the time. The lasting significance is the phone numbers, which are durable identifiers that enable SIM swapping and messaging account takeover and, unlike a password, cannot be rotated.
Aftermath: Ireland's Data Protection Commission fined Meta 265 million euros in November 2022 for failing to apply data protection by design to the contact importer, a finding under Article 25 of the General Data Protection Regulation. Meta also faces class actions in several jurisdictions. The case established that large-scale scraping enabled by a platform's own features can be a regulatory violation.
Source: BleepingComputer: 533 million Facebook users' phone numbers leaked on hacker forum
Records affected: 412 million accounts across six sites, including 339 million from AdultFriendFinder alone and around 15 million accounts users had already "deleted"
Date of breach: October 2016
Date disclosed: November 2016
Country / HQ: United States
Sector: Adult dating
Attack vector: Local file inclusion vulnerability in the FriendFinder Networks web application
Data exposed: Usernames, email addresses, passwords stored either in plaintext or hashed with unsalted SHA-1, site membership details, and last visit timestamps
FriendFinder Networks lost 412 million accounts across AdultFriendFinder, Cams.com, Penthouse.com, Stripshow.com, and iCams.com. Two details make it worse than the raw number suggests. Passwords were either in plaintext or hashed with SHA-1 in lowercase without salting, which is trivially crackable, and the dump included roughly 15 million accounts that users believed they had deleted. The company had already been breached in 2015, exposing 3.5 million users' sexual preferences, so this was a repeat failure at an organization holding some of the most sensitive personal data imaginable.
Aftermath: The data was widely circulated and used in sextortion campaigns for years afterward. FriendFinder Networks faced litigation and reputational collapse, and the earlier 2015 breach had already contributed to a failed public offering attempt. No headline regulatory fine followed in the United States.
Source: Have I Been Pwned: AdultFriendFinder breach entry
Records affected: Approximately 383 million guest records (revised down from an initial estimate of up to 500 million), including around 5.25 million unencrypted passport numbers and 8.6 million encrypted payment cards
Date of breach: July 2014 (in Starwood's systems, pre-acquisition) until September 2018
Date disclosed: November 30, 2018
Country / HQ: United States
Sector: Hospitality
Attack vector: Persistent intrusion into the Starwood guest reservation database, with a web shell and remote access trojan present for four years; widely reported to be Chinese state-linked activity
Data exposed: Names, addresses, phone numbers, email addresses, passport numbers, dates of birth, gender, arrival and departure dates, reservation details, Starwood Preferred Guest account information, and encrypted card data
Attackers were inside Starwood's reservation system from 2014 and remained there through Marriott's 2016 acquisition of the chain and for two more years afterward. Marriott initially said up to 500 million guests were affected, then revised the figure to roughly 383 million records once duplicates were removed, which is why this incident is a standard example of an early number being wrong in the other direction. The four-year dwell time, spanning a major acquisition, made it the canonical cautionary tale about cyber due diligence in mergers and acquisitions.
Aftermath: The UK Information Commissioner's Office fined Marriott 18.4 million pounds in October 2020, reduced from a proposed 99 million pounds partly on pandemic grounds, one of the penalties that puts it among the costliest data breaches in the UK. In October 2024 the FTC and attorneys general from 49 states plus the District of Columbia settled over three breaches from 2014 to 2020, with a 52 million dollar payment to the states and a 20-year FTC security order. Marriott reported breach-related expenses well over 100 million dollars, much of it insured.
Source: Cybersecurity Dive: FTC settles yearslong investigation into Marriott's security failures
Records affected: Approximately 360 million accounts
Date of breach: Believed to be around 2008 to 2013
Date disclosed: May 2016
Country / HQ: United States
Sector: Social media
Attack vector: Unknown historic compromise; the data surfaced years later for sale by the actor known as Peace
Data exposed: Email addresses, usernames, and passwords stored as unsalted SHA-1 hashes of the first ten characters of the password, converted to lowercase
A trove of roughly 360 million MySpace accounts went up for sale in 2016, years after the platform's relevance had faded and years after the breach itself occurred. The password storage was catastrophically weak: unsalted SHA-1, lowercased, and truncated to the first ten characters, meaning most were cracked almost immediately. MySpace matters here less for its own sake than because it supplied one of the largest sources of reusable credentials for the credential stuffing wave that followed, proving that abandoned platforms remain a liability long after users move on.
Aftermath: MySpace forced password resets on affected accounts. No significant regulatory action followed, in part because the breach predated modern notification regimes. The dataset remains a staple of credential stuffing lists.
Source: Have I Been Pwned: MySpace breach entry
Records affected: Approximately 340 million records, covering an estimated 230 million US consumers and 110 million businesses
Date of breach: Exposure discovered June 2018
Date disclosed: June 27, 2018
Country / HQ: United States (Palm Coast, Florida)
Sector: Data brokerage / marketing
Attack vector: Elasticsearch database left publicly accessible with no authentication
Data exposed: Names, phone numbers, home and email addresses, and hundreds of behavioral and demographic attributes including religion, smoking habits, pet ownership, interests, and the ages and genders of children in the household. No Social Security numbers or card data.
Security researcher Vinny Troia found a two-terabyte Exactis database on a public server, containing around 400 fields per person on roughly 230 million American adults. There were no Social Security numbers, but the granularity was the story: whether you own a dog, whether you smoke, your religion, and the ages and genders of your children, all indexed against your name and address. Exactis was a small company most consumers had never heard of, which made the incident a central exhibit in the case for regulating data brokers.
Aftermath: Exactis took the database offline and faced a class action lawsuit. The incident was cited repeatedly in US Senate hearings and in state legislative debates on data broker registration, contributing to laws such as Vermont's and California's data broker registries and later to Oregon and Texas broker rules.
Source: Wired: Marketing firm Exactis leaked a personal info database with 340 million records
Records affected: 279 million records claimed, more than Indonesia's entire population, apparently including deceased citizens (figure never fully confirmed by authorities)
Date of breach: Discovered May 2021
Date disclosed: May 20, 2021
Country / HQ: Indonesia
Sector: Government / national health insurance
Attack vector: Not conclusively established; data appeared for sale on Raid Forums and the ministry confirmed the sample matched BPJS records
Data exposed: National identity numbers, identity card data, full names, addresses, phone numbers, email addresses, dates and places of birth, and salary information
A seller using the handle Kotz advertised the personal data of 279 million Indonesians, living and deceased, on Raid Forums for around 2,000 dollars, releasing a sample for free. Indonesia's Ministry of Communication and Informatics confirmed the sample matched BPJS Kesehatan's database, even though it contained about 100,000 records rather than the claimed one million. Because the exposure included national identity numbers, which are the backbone of Indonesian identity verification, it triggered the country's most serious data protection reckoning to date.
Aftermath: Police opened a criminal investigation and summoned BPJS Kesehatan's leadership, but no prosecution was publicly concluded. The incident, together with subsequent leaks of Indonesian telecom and immigration data, was a direct driver of Indonesia's Personal Data Protection Law, passed in September 2022 and establishing penalties and a supervisory authority for the first time.
Records affected: 275 million users across nearly 9,000 institutions claimed by the attackers (attacker claim; Instructure has not confirmed 275 million unique individuals). The Identity Theft Resource Center counted the incident as roughly 275 million victim notices in its H1 2026 report, making it the largest single event of the year so far.
Date of breach: Late April 2026, with a second intrusion on May 7, 2026
Date disclosed: May 2026
Country / HQ: United States (Salt Lake City)
Sector: Education technology
Attack vector: Exploitation of a vulnerability in Instructure's cloud environment, registration of malicious connected applications, and automated bulk extraction via Canvas APIs
Data exposed: Names, email addresses, student identification numbers, and messages sent within the Canvas platform. Instructure said it found no evidence that passwords, dates of birth, financial information, or government identifiers were involved.
The extortion group ShinyHunters compromised the production systems behind Canvas, the learning management system used by thousands of schools and universities, and claimed 3.65 terabytes of data covering roughly 275 million students, teachers, and staff. The group returned roughly two weeks later through a second vulnerability and defaced Canvas login pages at universities across the country, including Harvard, Columbia, Princeton, and Georgetown, with ransom messages. Access was disrupted during final exams, which is why the incident is widely regarded as the largest and most damaging education sector breach on record even though the 275 million figure remains unverified.
Aftermath: Instructure reached an agreement with the extortion group, reported as a ransom payment, to prevent publication of the data. Institutions were left to run their own notification obligations under federal student privacy law, state breach laws, and the General Data Protection Regulation where EU students were involved. Class actions and state attorney general inquiries followed, and the incident intensified scrutiny of concentration risk in education technology.
Source: BleepingComputer: Instructure confirms data breach, ShinyHunters claims attack
Records affected: More than 223 million records, exceeding Brazil's population of roughly 213 million, plus data on 104 million vehicles
Date of breach: Exposure reported January 2021
Date disclosed: January 19, 2021
Country / HQ: Brazil
Sector: Credit bureau / data aggregation (source never officially confirmed)
Attack vector: Publicly accessible Elasticsearch instance on a cloud server, with the data also offered for sale
Data exposed: Full names, CPF taxpayer numbers, dates of birth, gender, credit scores, income and purchasing power estimates, education level, and detailed vehicle registration records
Researchers found a cloud-hosted Elasticsearch cluster holding more than 223 million Brazilian records keyed by CPF, the national taxpayer identifier used for everything from banking to mobile contracts. Many observers pointed to Serasa Experian as the likely source given the presence of credit scoring fields, but Serasa denied it and no official attribution was ever made. The exposure effectively covered the entire adult population of Brazil, including deceased individuals, and arrived just as Brazil's data protection law was becoming enforceable.
Aftermath: Brazil's consumer protection authorities and the new data protection authority opened inquiries, and prosecutors in São Paulo pursued Serasa; no definitive public attribution or major fine resulted from the 2021 exposure itself. The incident is repeatedly cited as the event that forced Brazil to stand up real enforcement capacity.
Source: Cybernews: Entire population of Brazil possibly exposed in massive data leak
Records affected: Approximately 200 million user records in the January 2023 dump, drawn from a larger 400 million record set offered in late 2022 (deduplicated; Twitter disputed that the data came from a system exploit)
Date of breach: Data harvested in 2021 via an API flaw that was fixed in January 2022
Date disclosed: Vulnerability acknowledged August 2022; the 200 million record file was published in January 2023
Country / HQ: United States
Sector: Social media
Attack vector: An API vulnerability that allowed anyone submitting an email address or phone number to learn which Twitter account it belonged to, defeating the pseudonymity of the platform
Data exposed: Email addresses, names, screen names, follower counts, and account creation dates, linked to Twitter handles. Passwords were not included.
The flaw let attackers take a list of email addresses or phone numbers and get back the associated Twitter accounts, which is uniquely harmful on a platform where anonymity protects journalists, activists, and dissidents. Multiple actors exploited it before the fix, and in January 2023 a file with around 200 million deduplicated records was posted free on a forum. Twitter's public position was that no system was exploited to obtain the data, a claim widely disputed by researchers who traced it to the known API bug.
Aftermath: Ireland's Data Protection Commission opened an inquiry into the incident, and the case has been repeatedly cited in the commission's oversight of X. Twitter had already agreed a 150 million dollar FTC and DOJ penalty in May 2022 over unrelated misuse of phone numbers collected for security purposes, and the 2023 dump added to arguments that the company was in breach of its FTC consent order.
Source: BleepingComputer: 200 million Twitter users' email addresses allegedly leaked online
Records affected: 192.7 million individuals (revised repeatedly upward from an initial "substantial proportion of people in America", then 100 million in October 2024, then 190 million in January 2025, then a final 192.7 million reported to HHS OCR on July 31, 2025)
Date of breach: Intrusion from around February 12, 2024; ransomware deployed and detected February 21, 2024
Date disclosed: February 2024, with the individual count finalized in July 2025
Country / HQ: United States
Sector: Healthcare claims processing
Attack vector: Stolen credentials used on a Citrix remote access portal that lacked multi-factor authentication, followed by ALPHV/BlackCat ransomware
Data exposed: Names, addresses, dates of birth, Social Security numbers, health insurance and Medicaid/Medicare identifiers, medical diagnoses and treatment records, test results, images, prescriptions, billing and claims data, driver's license and passport numbers
Change Healthcare processes roughly a third of all US medical claims, and its shutdown paralyzed pharmacy and provider payments nationwide for weeks, with UnitedHealth advancing billions of dollars to keep practices solvent. The intrusion began with a single Citrix account without multi-factor authentication. It is the largest of many healthcare data breaches in US history by individuals affected, and the figure moved from vague to 100 million to 190 million to a final 192.7 million over eighteen months, making it the clearest recent example of why early breach counts should be treated as a floor rather than a total.
Aftermath: UnitedHealth reported total incident costs of roughly 3 billion dollars across 2024. The company paid a reported 22 million dollar ransom, after which a second group, RansomHub, attempted to extort it again over the same data. HHS OCR opened an investigation, hundreds of class actions were consolidated in Minnesota, the Nebraska attorney general sued and survived a motion to dismiss, and the incident drove HHS proposals to strengthen the HIPAA Security Rule.
Source: HIPAA Journal: Change Healthcare breach, 192.7 million individuals affected
Records affected: 153 million accounts (revised upward from an initial 2.9 million)
Date of breach: September 2013
Date disclosed: October 2013, with the true scale established in November 2013
Country / HQ: United States
Sector: Software
Attack vector: Intrusion into Adobe's network, with source code for products including ColdFusion and Acrobat also stolen
Data exposed: Email addresses, encrypted passwords, password hints in plaintext, and encrypted payment card numbers and expiry dates for around 2.9 million customers
Adobe first said 2.9 million customers were affected, then researchers analyzing the leaked file established that the real number was around 153 million accounts. The password handling was the notorious part: Adobe encrypted passwords with 3DES in ECB mode using a single key rather than hashing them, and stored password hints in plaintext next to them, which meant patterns across the dataset made large numbers of passwords recoverable without breaking the encryption at all. The breach became the standard teaching example of why encryption is not a substitute for proper password hashing.
Aftermath: Adobe agreed a settlement with 15 state attorneys general for 1 million dollars in 2015 and settled a consumer class action for an undisclosed sum plus 1.1 million dollars in legal fees. The dataset is still one of the most heavily used sources in password cracking research and in credential stuffing lists.
Source: KrebsOnSecurity: Adobe breach impacted at least 38 million users
Records affected: 147.9 million US consumers, plus around 15.2 million UK records and roughly 19,000 Canadians
Date of breach: Intrusion from mid-May to late July 2017
Date disclosed: September 7, 2017
Country / HQ: United States
Sector: Credit reporting
Attack vector: Unpatched Apache Struts vulnerability (CVE-2017-5638) on a consumer dispute portal, exploited more than two months after a patch was available; the attackers then moved laterally, found unencrypted credentials in plaintext files, and exfiltrated data undetected because an expired TLS inspection certificate had blinded monitoring for ten months
Data exposed: Names, Social Security numbers, dates of birth, addresses, driver's license numbers, and around 209,000 payment card numbers
Equifax failed to patch a known critical vulnerability in a public-facing application, then failed to notice 76 days of data exfiltration because a certificate on its inspection tooling had expired. The result was the exposure of Social Security numbers for roughly 40% of the US population, people who were not Equifax customers and had never consented to their data being held. It remains the most consequential breach in the history of consumer finance, a sector with its own record of major financial data breaches, and reset expectations for executive and board accountability.
Aftermath: Equifax agreed a global settlement in July 2019 of at least 575 million dollars, rising to a potential 700 million, with the FTC, the Consumer Financial Protection Bureau, and 50 states and territories. The UK Information Commissioner's Office fined Equifax 500,000 pounds under pre-GDPR rules. The chief executive, chief information officer, and chief security officer all departed, the SEC charged a former executive with insider trading, and the US Department of Justice indicted four members of China's People's Liberation Army in 2020. Total costs exceeded 1.4 billion dollars.
Source: FTC: Equifax data breach settlement
Records affected: 145 million active users
Date of breach: Late February to early March 2014
Date disclosed: May 21, 2014
Country / HQ: United States
Sector: E-commerce / marketplace
Attack vector: Compromise of a small number of employee login credentials, used to access eBay's corporate network
Data exposed: Names, encrypted passwords, email addresses, physical addresses, phone numbers, and dates of birth. Financial data was held separately in PayPal systems and was not affected.
Attackers obtained employee credentials and used them to reach a database containing every active eBay user. eBay asked all 145 million users to reset their passwords, but its communication drew wide criticism: the notice went out days after internal discovery, the password reset prompt was initially missing from the homepage, and the company gave few details about the encryption used. The incident is a durable example of how a handful of stolen staff credentials, absent strong internal segmentation and multi-factor authentication, translate directly into a total customer database loss.
Aftermath: Three US state attorneys general opened a joint investigation, and the UK and other regulators made inquiries, but no major fine was ultimately reported. eBay faced class action litigation, much of which struggled on standing grounds because no financial loss was demonstrated, a recurring feature of pre-2018 US breach litigation.
Source: Washington Post: eBay asks 145 million users to change passwords after data breach
Records affected: Call and text metadata for approximately 109 million customers (nearly all wireless customers, plus certain network partner and landline interaction data). A separate leak in March 2024 exposed personal data on around 73 million current and former customers.
Date of breach: Snowflake environment accessed April 14 to 25, 2024; the records themselves cover May 1 to October 31, 2022 plus some from January 2, 2023
Date disclosed: July 12, 2024, via SEC Form 8-K, after two national security delays granted by the DOJ and FBI
Country / HQ: United States
Sector: Telecommunications
Attack vector: Credentials for AT&T's Snowflake tenant stolen via infostealer malware, used because multi-factor authentication was not enforced
Data exposed: Records of which numbers called or texted which numbers, call durations, and for some records cell site identifiers that approximate location. No names, Social Security numbers, or content. The separate 73 million record set did include names, addresses, dates of birth, and Social Security numbers.
AT&T disclosed that essentially its entire wireless customer base had six months of call and text metadata stolen from its Snowflake instance. There was no message content, but metadata at this scale reveals social graphs, patterns of life, and, via cell site identifiers, approximate movements, which is why privacy advocates treated it as more sensitive than a conventional contact list leak. AT&T also reportedly paid a hacker around 370,000 dollars to delete the data, one of the few publicly documented deletion payments by a major US carrier.
Aftermath: The FCC opened an investigation. In September 2024, AT&T agreed a 13 million dollar settlement with the FCC over a separate 2023 vendor breach. AT&T agreed a 177 million dollar consumer class action settlement in 2025 covering both the March 2024 leak and the Snowflake incident. US prosecutors charged Connor Moucka and John Binns over the wider Snowflake campaign.
Source: Cybersecurity Dive: Massive Snowflake-linked attack exposes data on nearly 110M AT&T customers
Records affected: Approximately 106 million people, made up of about 100 million in the United States and 6 million in Canada
Date of breach: Around March 22 to 23, 2019
Date disclosed: July 29, 2019
Country / HQ: United States
Sector: Banking / financial services
Attack vector: Server-side request forgery against a misconfigured web application firewall in AWS, used to obtain instance metadata credentials with excessive permissions, which were then used to list and copy S3 buckets
Data exposed: Names, addresses, dates of birth, credit scores, payment history, self-reported income, around 140,000 Social Security numbers, 80,000 linked bank account numbers, and about one million Canadian Social Insurance Numbers
A former Amazon Web Services employee, Paige Thompson, exploited a misconfigured firewall to retrieve temporary AWS credentials and then copied credit card application data covering 106 million applicants and customers going back to 2005. She discussed the theft on Slack and GitHub, which is how she was identified. The case is the reference example of cloud misconfiguration rather than cloud provider failure, and of the danger of over-permissioned identity roles.
Aftermath: The Office of the Comptroller of the Currency fined Capital One 80 million dollars in August 2020 and the Federal Reserve issued a cease and desist order. Capital One settled consumer litigation for 190 million dollars in 2021 and reported around 150 million dollars in incident costs. Thompson was convicted in 2022 and sentenced in 2023 to time served plus five years of probation, a sentence that drew criticism for leniency.
Source: OCC: 80 million dollar civil money penalty against Capital One
Records affected: More than 95 million individuals across approximately 2,770 organizations, according to independent tracking. Individual victims ranged from Maximus (11 million) and Welltok (8.5 million) to Delta Dental of California (7 million), the US Department of Energy, Shell, the BBC, British Airways, and Boots.
Date of breach: Zero-day exploitation began around May 27, 2023
Date disclosed: May 31, 2023 (Progress advisory); victim disclosures continued into 2025
Country / HQ: United States (Progress Software, Massachusetts)
Sector: Managed file transfer software, affecting every sector downstream
Attack vector: SQL injection zero-day in MOVEit Transfer (CVE-2023-34362) exploited by the CL0P ransomware group to deploy a web shell and exfiltrate data in bulk
Data exposed: Varied by victim, but included Social Security numbers, health records, pension and payroll data, bank details, dates of birth, and national insurance numbers
CL0P weaponized a zero-day in MOVEit, a file transfer product used by thousands of enterprises and government agencies to move sensitive bulk data, and harvested from every reachable instance over a matter of days. The group did not encrypt anything; it stole data and extorted. MOVEit is the archetypal third- and fourth-party risk event, because most affected individuals had no relationship with Progress Software and often none with the organization that held their data either, having been swept up via payroll processors, pension administrators, and benefit vendors.
Aftermath: Progress Software disclosed SEC and state investigations and hundreds of consolidated class actions in Massachusetts federal court. The US State Department offered a 10 million dollar reward for information on CL0P. Individual victims paid their own notification and settlement costs; Maximus alone reported tens of millions in expenses. The event drove the Cybersecurity and Infrastructure Security Agency's push on secure by design and on software bill of materials adoption for file transfer tooling.
Source: CISA advisory AA23-158A: CL0P ransomware gang exploits CVE-2023-34362 MOVEit vulnerability
Records affected: 78.8 million individuals
Date of breach: Intrusion from around February 18, 2014, detected January 29, 2015
Date disclosed: February 4, 2015
Country / HQ: United States
Sector: Health insurance
Attack vector: Spear phishing of an Anthem subsidiary employee, followed by escalation to a data warehouse using compromised administrator credentials; attributed to Chinese state-linked actors
Data exposed: Names, dates of birth, Social Security numbers, member IDs, addresses, email addresses, employment information, and income data. No medical claims or credit card data.
A single successful phishing email against a subsidiary gave attackers a foothold that eventually reached a data warehouse containing 78.8 million member and employee records, including Social Security numbers stored without encryption. It remained the largest US healthcare breach for nine years until Change Healthcare surpassed it. The forensic picture, with long dwell time and no monetization of the data, pointed to espionage rather than fraud, which changed how the health sector thought about threat actors.
Aftermath: Anthem paid a 16 million dollar HIPAA settlement to HHS OCR in October 2018, then a record, and a 39.5 million dollar settlement with state attorneys general in 2020. It settled consumer class actions for 115 million dollars in 2017, the largest US data breach settlement at the time. A DOJ indictment in 2019 charged two Chinese nationals.
Source: HHS: Anthem pays OCR 16 million dollars in record HIPAA settlement
Records affected: 77 million PSN accounts, plus 24.6 million Sony Online Entertainment accounts in a related incident
Date of breach: Around April 17 to 19, 2011
Date disclosed: April 26, 2011, six days after the service was taken offline
Country / HQ: Japan
Sector: Gaming / entertainment
Attack vector: Exploitation of a known application vulnerability on an unpatched server, with reports of outdated software and no firewall on the affected network segment
Data exposed: Names, addresses, email addresses, dates of birth, PSN login credentials and handles, purchase history, billing addresses, and around 12,700 credit card numbers from an outdated database
Sony took PlayStation Network offline on April 20, 2011 but did not tell users their data had been stolen until April 26, and the service stayed down for 23 days. It was the first breach to keep consumer data security in mainstream news for weeks on end, and it defined the modern expectation that a company must disclose promptly, not after it has finished investigating. Sony's testimony to the US Congress and the UK Information Commissioner's Office's later findings both criticized the state of its patching.
Aftermath: The UK Information Commissioner's Office fined Sony 250,000 pounds in January 2013, finding the attack preventable. Sony estimated costs of around 171 million dollars, offered a "Welcome Back" package of free games and identity theft protection, and settled US class actions for up to 15 million dollars in games and credits. Executives publicly apologized at a press conference in Tokyo.
Source: PlayStation Blog: Update on PlayStation Network and Qriocity
Records affected: Approximately 76.6 million current, former, and prospective customers, including 40 million people who had merely applied for credit
Date of breach: August 2021
Date disclosed: August 16, 2021
Country / HQ: United States (parent Deutsche Telekom, Germany)
Sector: Telecommunications
Attack vector: An unprotected router exposed to the internet, found via internet scanning, then used to reach testing environments and over 100 servers; the attacker, John Binns, described T-Mobile's security publicly as awful
Data exposed: Names, dates of birth, Social Security numbers, driver's license and ID numbers, phone numbers, IMEIs and IMSIs, and account PINs for some prepaid customers
T-Mobile's 2021 breach stands out both for size and for context: it was at least the fifth publicly disclosed T-Mobile breach since 2018, and further incidents followed in January 2023 (37 million accounts via an abused API) and via a vendor in 2023. The 2021 event exposed Social Security numbers for tens of millions of people who were not even customers, having only submitted credit applications. The repetition is what turned T-Mobile into the FCC's test case for enforcing carrier data security.
Aftermath: T-Mobile settled consumer class actions for 350 million dollars plus a commitment to spend 150 million dollars on security upgrades, one of the largest US breach settlements ever. In September 2024 it agreed a 31.5 million dollar resolution with the FCC covering multiple breaches, split between a 15.75 million dollar penalty and 15.75 million dollars of mandated security investment.
Source: FCC: T-Mobile data breach investigations settlement
Records affected: Approximately 72.7 million records, with 72 million unique email addresses loaded into Have I Been Pwned (attacker-published dataset; Under Armour said it was "aware" of the claims)
Date of breach: Attack claimed November 2025
Date disclosed: Data published publicly on a hacking forum around January 21 to 22, 2026
Country / HQ: United States
Sector: Retail / apparel
Attack vector: Ransomware and data theft attributed by the attackers to the Everest group, which claimed roughly 343 GB of exfiltrated data. No regulator or law enforcement attribution has been published and Under Armour has not named a culprit.
Data exposed: Email addresses, names, dates of birth, gender, geographic location, and purchase history. No payment card data has been reported.
The Everest ransomware group claimed an attack on Under Armour in November 2025, and when extortion failed, published the customer dataset in January 2026. Troy Hunt loaded 72.7 million records into Have I Been Pwned on January 21, 2026, making it the second largest single event of the first half of 2026 by victim notices in the Identity Theft Resource Center's count. This is Under Armour's second major exposure, following the 2018 MyFitnessPal breach that affected around 150 million accounts, which is why the incident attracted disproportionate regulatory attention.
Aftermath: Class action litigation was filed in the United States within weeks. State attorney general notifications followed. As of July 2026 no fine has been announced, and Under Armour has not published a confirmed victim count of its own.
Records affected: 62.4 million students and 9.5 million teachers claimed by the attacker (attacker claim; PowerSchool has not published a global confirmed figure). PowerSchool serves more than 18,000 schools and around 60 million students in North America.
Date of breach: Intrusion began December 19, 2024, undetected for around nine days
Date disclosed: January 7, 2025
Country / HQ: United States (Folsom, California)
Sector: Education technology
Attack vector: Stolen credentials used to access the PowerSource customer support portal, which had no multi-factor authentication, then a legitimate maintenance tool used to export district student information system databases
Data exposed: Names, addresses, dates of birth, Social Security numbers for some students and staff, medical and health information, grades, and parent and guardian contact details. Historical records for former students and staff were included.
An attacker logged into PowerSchool's support portal with stolen credentials, then used a built-in maintenance tool to bulk export student information system data from district after district. PowerSchool paid an extortion demand for assurances of deletion, and the data resurfaced months later when districts including in Toronto and North Carolina were extorted individually, demonstrating that ransom payments buy nothing durable. Because the records covered children going back years, including medical notes and Social Security numbers, it is the most consequential kindergarten-through-grade-12 breach in North America before the 2026 Canvas incident.
Aftermath: Matthew Lane pleaded guilty in federal court in Massachusetts in May 2025 to cyber extortion and aggravated identity theft relating to the breach. Texas Attorney General Ken Paxton sued PowerSchool in September 2025 over data on more than 880,000 Texas children and teachers, and other state actions and class actions followed. PowerSchool provided identity protection and credit monitoring.
Source: BleepingComputer: PowerSchool hacker claims they stole data of 62 million students
Records affected: Approximately 33.7 million customer accounts, roughly two thirds of South Korea's population
Date of breach: Unauthorized access from June 24, 2025 to November 8, 2025; detected November 18, 2025
Date disclosed: November 29 to December 1, 2025
Country / HQ: South Korea (parent Coupang Inc. is US listed)
Sector: E-commerce
Attack vector: Insider threat. A dismissed IT specialist is alleged to have retained a signed authentication token, valid under company policy for between five and ten years, and used it via overseas servers to bypass access controls.
Data exposed: Names, email addresses, phone numbers, shipping addresses, partial order histories, and delivery metadata. Coupang said no passwords or payment card data were exposed.
South Korea's largest e-commerce company disclosed that a former employee had used a long-lived signing key taken on departure to extract data on 33.7 million accounts over roughly four and a half months. The attack ran through overseas servers, and Coupang did not detect the unauthorized access until November 18, 2025. It is the largest breach in South Korean history and a textbook demonstration of why token lifetimes and offboarding revocation matter more than perimeter controls, since no perimeter was breached at all.
Aftermath: South Korea's Personal Information Protection Commission, the National Police Agency, and the Korea Internet & Security Agency all opened investigations, and the National Assembly summoned Coupang executives. The commission can impose fines of up to 3% of relevant revenue under Korea's amended privacy law, and proceedings remain open as of July 2026. Class actions were filed in Korea and the company's US listing drew shareholder scrutiny.
Source: The Register: South Korea's answer to Amazon admits breach exposed 33.7M customers
Records affected: 29.8 million accounts, roughly 20% of the platform's user base
Date of breach: Unauthorized activity detected December 2025
Date disclosed: Data leaked and confirmed early January 2026
Country / HQ: Germany (Berlin), with major US operations
Sector: Music streaming
Attack vector: Unauthorized access to an internal service dashboard, which allowed private email addresses to be joined to public profile data. Claimed by ShinyHunters.
Data exposed: Email addresses, names, usernames, avatars, follower counts, and in some cases geographic location. No passwords or financial data.
ShinyHunters accessed an internal SoundCloud dashboard in December 2025 and used it to link 29.8 million users' private email addresses to their otherwise public profiles, then published the set through its leak portal in January 2026. No credentials or payment data were taken, but the value to attackers is the mapping between a real email address and a named creator profile, high-quality raw material for targeted phishing against musicians and rights holders. Troy Hunt loaded the dataset into Have I Been Pwned.
Aftermath: A proposed class action was filed against SoundCloud in the US District Court for the Southern District of New York on February 4, 2026 alleging negligence and related claims. As a Berlin-headquartered company, and one of the more recent data breaches across Europe, SoundCloud is subject to the General Data Protection Regulation and notified its lead supervisory authority; no fine had been announced as of July 2026.
Source: BleepingComputer: Have I Been Pwned, SoundCloud data breach impacts 29.8 million accounts
Records affected: 21.5 million individuals in the background investigation breach, plus 4.2 million personnel records, including 5.6 million sets of fingerprints
Date of breach: Intrusions from around 2014, discovered April 2015
Date disclosed: June and July 2015
Country / HQ: United States
Sector: Federal government / human resources
Attack vector: Stolen contractor credentials and malware, with no multi-factor authentication on remote access; attributed to Chinese state-linked actors
Data exposed: Social Security numbers, addresses, employment and residency histories, mental health and financial records, foreign contacts, criminal history, interview notes from security clearance investigations, and fingerprints
The Office of Personnel Management lost the completed background investigation files of 21.5 million current, former, and prospective federal employees, contractors, and their families. These are the most intrusive documents the US government holds on its own people: drug use, therapy, debts, affairs, relatives abroad. Included alongside them were 5.6 million fingerprint sets, which unlike a password can never be reissued. It appears here well above its raw record count because it is the most damaging counterintelligence data loss in modern US history.
Aftermath: The agency's director resigned. Congress produced a scathing majority report in 2016. The agency and contractor KeyPoint settled class actions for 63 million dollars in 2022. The government spent hundreds of millions on credit monitoring. The breach directly produced the federal Cybersecurity Sprint, accelerated adoption of smart card authentication, and led to the creation of the National Background Investigation Bureau.
Source: OPM: Cybersecurity incidents
Records affected: Approximately 9.8 million current, former, and prospective customers, including around 2.1 million with current or expired government identification numbers. The regulator's court filing alleges serious interference with the privacy of about 9.5 million Australians.
Date of breach: September 2022
Date disclosed: September 22, 2022
Country / HQ: Australia (parent Singtel, Singapore)
Sector: Telecommunications
Attack vector: An unauthenticated, internet-exposed API endpoint that allowed customer records to be enumerated without any credentials
Data exposed: Names, dates of birth, phone numbers, email addresses, and for a subset, home addresses, driver's license numbers, passport numbers, and Medicare numbers
An API sitting on the public internet with no authentication allowed an attacker to walk Optus's customer database. The attacker briefly demanded a ransom, published a sample of 10,000 records, then withdrew the demand. Because millions of driver's license and passport numbers were exposed, state governments had to reissue identity documents at public expense, and the incident, together with Medibank weeks later, is the single biggest reason Australia overhauled its privacy penalties and remains a landmark among data breaches in Australia.
Aftermath: Australia raised maximum privacy penalties to the greater of 50 million Australian dollars, three times the benefit obtained, or 30% of adjusted turnover, in legislation passed in November 2022. The communications regulator sued Optus in the Federal Court in 2023 under telecommunications interception law. The Office of the Australian Information Commissioner commenced civil penalty proceedings in 2025 alleging one contravention per affected individual, with a maximum of 2.22 million Australian dollars each. Optus reported costs of around 140 million Australian dollars and its chief executive resigned in November 2023 after a separate network outage.
Source: OAIC: Australian Information Commissioner takes civil penalty action against Optus
Records affected: 9.7 million current and former customers, including around 480,000 health claims records
Date of breach: Access from around August 2022; detected October 12, 2022
Date disclosed: October 13, 2022, with the full scope confirmed November 9, 2022
Country / HQ: Australia
Sector: Private health insurance
Attack vector: Stolen credentials belonging to a third-party IT contractor, used to log in to Medibank's network via a VPN that did not require multi-factor authentication; the actor was linked to the REvil ransomware ecosystem
Data exposed: Names, dates of birth, addresses, phone numbers, email addresses, Medicare and passport numbers, visa details, and health claims data including diagnoses and procedures
Medibank refused to pay the ransom, so the attackers published the data in stages on the dark web, deliberately grouping files under headings such as "abortions" to maximize harm to individuals. That escalation, more than the record count, is why Medibank appears on this list: it demonstrated that health data extortion can be weaponized against patients personally rather than just against the company. Australia's government publicly backed the decision not to pay and condemned the attackers in blunt terms.
Aftermath: The Office of the Australian Information Commissioner commenced Federal Court civil penalty proceedings in June 2024 alleging Medibank seriously interfered with the privacy of 9.7 million Australians between March 2021 and October 2022, with a theoretical maximum of 2.22 million Australian dollars per contravention. Australia sanctioned Russian national Aleksandr Ermakov in January 2024, its first ever use of cyber sanctions. Medibank reported costs of around 80 million Australian dollars and faces class actions and a shareholder action.
Source: OAIC: OAIC takes civil penalty action against Medibank
Records affected: 6.9 million people, comprising around 5.5 million DNA Relatives profiles and 1.4 million Family Tree profiles, reached from only about 14,000 directly compromised accounts
Date of breach: Credential stuffing from around April to September 2023
Date disclosed: October 2023, with the full scope confirmed December 2023
Country / HQ: United States
Sector: Consumer genetics
Attack vector: Credential stuffing using passwords reused from other breaches, then amplification through the opt-in DNA Relatives feature, which exposed data on relatives of each compromised account
Data exposed: Names, birth years, relationship labels, ancestry composition and haplogroups, self-reported location, profile photos, and percentage of DNA shared with matches. Raw genetic sequences were not taken.
Attackers broke into roughly 14,000 accounts using recycled passwords and then leveraged the DNA Relatives feature to harvest profile data on 6.9 million people who had never had their own accounts compromised. Datasets specifically targeting people of Ashkenazi Jewish and Chinese descent were advertised for sale, which turned the incident into an ethnic targeting concern rather than a conventional identity theft case. 23andMe initially blamed customers for password reuse and changed its terms of service to restrict class actions, both of which drew heavy criticism.
Aftermath: The UK Information Commissioner's Office and the Office of the Privacy Commissioner of Canada ran a joint investigation, and the UK regulator fined 23andMe 2.31 million pounds in June 2025 for failing to implement adequate authentication and monitoring. 23andMe had earlier settled US class actions for 30 million dollars, then filed for Chapter 11 bankruptcy in March 2025, after which its genetic database was sold through a court-supervised auction, triggering state attorney general intervention and consumer deletion campaigns over who inherits DNA data when a company fails.
Source: TechCrunch: 23andMe confirms hackers stole ancestry data on 6.9 million users
These incidents are smaller by record count but heavily searched, and several are still developing as of July 2026. Country-specific roundups, including our list of the biggest data breaches in France, track regional incidents in more depth.
The through line across four decades of incidents is that scale rarely comes from sophistication. Misconfigured databases, unpatched applications, missing multi-factor authentication, and reused credentials account for the overwhelming majority of the records on this list, and the newest entries show attackers concentrating on shared platforms and trusted integrations to multiply their reach. That shifts the defensive priority from your own perimeter to the security posture of every vendor, contractor, and connected application you rely on. Continuous visibility into third-party exposure, not a once-a-year questionnaire, is what helps you prevent data breaches of the kind that fill this list.
UpGuard gives security teams continuous visibility into the exposures that produce breaches like the ones above, across their own attack surface and their vendor ecosystem.
Start a free trial to experience the UpGuard cybersecurity platform.
Cam4's roughly 10.88 billion exposed records is the largest single documented dataset by volume, though that figure is a count of log rows rather than unique people. Yahoo's 3 billion accounts is the largest confirmed breach of a single organization.
No. It is an aggregation of infostealer malware logs and recycled credentials from many prior leaks, not a compromise of a single organization, and Google, Apple, and Meta all confirmed their systems were not breached.
Change Healthcare is the largest healthcare data breach in US history, with a final count of 192.7 million individuals affected after the figure was revised upward several times.
Recent large events include the Instructure Canvas breach, with roughly 275 million victim notices claimed, and Under Armour, at about 72.7 million records, alongside developing incidents at Carnival, ADT, and Panera Bread.