List of data breaches
This is a list of data breaches, using data compiled from various sources, including press reports, government news releases, and mainstream news articles. The list includes those involving the theft or compromise of 30,000 or more records, although many smaller breaches occur continually. Breaches of large organizations where the number of records is still unknown are also listed. In addition, the various methods used in the breaches are listed, with hacking being the most common.
Most reported breaches are in North America, at least in part because of relatively strict disclosure laws in North American countries. 95% of data breaches come from government, retail, or technology industries. It is estimated that the average cost of a data breach will be over $150 million by 2020, with the global annual cost forecast to be $2.1 trillion. As a result of data breaches, it is estimated that in first half of 2018 alone, about 4.5 billion records were exposed. In 2019, a collection of 2.7 billion identity records, consisting of 774 million unique email addresses and 21 million unique passwords, was posted on the web for sale.
Entity | Year | Records | Organization type | Method | Sources |
---|---|---|---|---|---|
21st Century Oncology | 2016 | 2,200,000 | healthcare | hacked | |
500px | 2020 | 14,870,304 | social networking | hacked | |
Accendo Insurance Co. | 2020 | 175,350 | healthcare | poor security | |
Adobe Systems Incorporated | 2013 | 152,000,000 | tech | hacked | |
Adobe Inc. | 2019 | 7,500,000 | tech | poor security | |
Advocate Medical Group | 2017 | 4,000,000 | healthcare | lost / stolen media | |
AerServ (subsidiary of InMobi) | 2018 | 75,000 | advertising | hacked | |
Affinity Health Plan, Inc. | 2013 | 344,579 | healthcare | lost / stolen media | |
Airtel | 2019 | 320,000,000 | telecommunications | poor security | |
India Government Aadhar data breach | 2023 | 810,000,000+ | government | data leak due to security vulnerabilities | |
Air Canada | 2018 | 20,000 | transport | hacked | |
Amazon Japan G.K. | 2019 | unknown | web | accidentally published | |
TD Ameritrade | 2005 | 200,000 | financial | lost / stolen media | |
Ancestry.com | 2021 | 300,000 | web | poor security | |
Animal Jam | 2020 | 46,000,000 | gaming | hacked | |
Ankle & Foot Center of Tampa Bay, Inc. | 2021 | 156,000 | healthcare | hacked | |
Anthem Inc. | 2015 | 80,000,000 | healthcare | hacked | |
AOL | 2004 | 92,000,000 | web | inside job, hacked | |
AOL | 2006 | 20,000,000 | web | accidentally published | |
AOL | 2014 | 2,400,000 | web | hacked | |
Apple, Inc./BlueToad | 2021 | 12,367,232 | tech, retail | accidentally published | |
Apple | 2021 | 275,000 | tech | hacked | |
Apple Health Medicaid | 2021 | 91,000 | healthcare | poor security | |
Ashley Madison | 2015 | 32,000,000 | web | hacked | |
AT&T | 2008 | 113,000 | telecoms | lost / stolen computer | |
AT&T | 2010 | 114,000 | telecoms | hacked | |
Atraf | 2021 | unknown | dating | hacked | |
Auction.co.kr | 2008 | 18,000,000 | web | hacked | |
Australian Immigration Department | 2015 | G20 world leaders | government | accidentally published | |
Australian National University | 2019 | 19 years of data | academic | hacked | |
Automatic Data Processing | 2005 | 125,000 | financial | poor security | |
AvMed, Inc. | 2009 | 1,220,000 | healthcare | lost / stolen computer | |
Bailey's Inc. | 2015 | 250,000 | retail | hacked | |
The Bank of New York Mellon | 2008 | 12,500,000 | financial | lost / stolen media | |
Bangladesh Government website data breach | 2023 | 50,000,000+ | government | data leak due to security vulnerabilities | |
Bank of America | 2005 | 1,200,000 | financial | lost / stolen media | |
Barnes & Noble | 2012 | 63 stores | retail | hacked | |
Bell Canada | 2017 | 1,900,000 | telecoms | poor security | |
Bell Canada | 2018 | 100,000 | telecoms | hacked | |
Benesse | 2014 | 35,040,000 | educational services | hacked | |
Betfair | 2010 | 2,300,000 | web | hacked | |
Bethesda Game Studios | 2011 | 200,000 | gaming | hacked | |
Bethesda Game Studios | 2018 | gaming | accidentally published | ||
Betsson Group | 2020 | unknown | gambling | unknown | |
Blank Media Games | 2018 | 7,633,234 | gaming | hacked | |
Blizzard Entertainment | 2012 | 14,000,000 | gaming | hacked | |
BlueCross BlueShield of Tennessee | 2009 | 1,023,209 | healthcare | lost / stolen media | |
BMO and Simplii | 2018 | 90,000 | banking | poor security | |
2018 British Airways cyberattack | 2018 | 500,000 | transport | hacked | |
British Airways | 2015 | tens of thousands | retail | hacked | |
2019 Bulgarian revenue agency hack | 2019 | over 5,000,000 | government | hacked | |
California Department of Child Support Services | 2012 | 800,000 | government | lost / stolen media | |
Canva | 2019 | 140,000,000 | web | hacked | |
Capcom | 2020 | 350,000 | game | hacked | |
Capital One | 2019 | 106,000,000 | financial | unsecured S3 bucket | |
CardSystems Solutions Inc.
(MasterCard, Visa, Discover Financial Services and American Express) |
2005 | 40,000,000 | financial | hacked | |
Cathay Pacific Airways | 2018 | 9,400,000 | transport | hacked | |
CareFirst BlueCross Blue Shield - Maryland | 2015 | 1,100,000 | healthcare | hacked | |
Central Coast Credit Union | 2016 | 60,000 | financial | hacked | |
Central Hudson Gas & Electric | 2013 | 110,000 | energy | hacked | |
CheckFree Corporation | 2009 | 5,000,000 | financial | hacked | |
Central Intelligence Agency | 2017 | 91 | malware tools | Internal job | |
CheckPeople | 2020 | 56,000,000 | background check | unknown | |
China Software Developer Network | 2011 | 6,000,000 | web | hacked | |
Chinese gaming websites (three: Duowan, 7K7K, 178.com) | 2011 | 10,000,000 | web | hacked | |
Citigroup | 2005 | 3,900,000 | financial | lost / stolen media | |
Citigroup | 2011 | 360,083 | financial | hacked | |
Citigroup | 2013 | 150,000 | financial | poor security | |
City and Hackney Teaching Primary Care Trust | 2007 | 160,000 | healthcare | lost / stolen media | |
Clearview AI | 2020 | unknown (client list) | information technology | hacked | |
Collection No. 1 | 2019 | 773,000,000 | various | compilation of multiple data breaches | |
Colorado state government | 2010 | 105,470 | healthcare | lost / stolen computer | |
Community Health Systems | 2014 | 4,500,000 | healthcare | hacked | |
Philippines Commission on Elections | 2016 | 55,000,000 | government | hacked | |
Compass Bank | 2007 | 1,000,000 | financial | inside job | |
Countrywide Financial Corp | 2006 | 2,600,000 | financial | inside job | |
Countrywide Financial Corp | 2011 | 2,500,000 | financial | inside job | |
Centers for Medicare & Medicaid Services | 2018 | 75,000 | healthcare | hacked | |
Cox Communications | 2016 | 40,000 | telecoms | hacked | |
Crescent Health Inc., Walgreens | 2013 | 100,000 | healthcare | lost / stolen computer | |
CVS | 2015 | millions | retail | hacked | |
CyberServe | 2021 | 1,107,034 | hosting provider | hacked | |
Dai Nippon Printing | 2007 | 8,637,405 | retail | inside job | |
Data Processors International (MasterCard, Visa, Discover Financial Services and American Express) | 2008 | 8,000,000 | financial | hacked | |
Defense Integrated Data Center (South Korea) | 2017 | 235 GB | military | hacked | |
Dedalus Biologie (a division of Dedalus Global) | 2021 | 500,000 | health | poor security | |
Deloitte | 2017 | 350 clients emails | consulting, accounting | poor security | |
Democratic National Committee | 2016 | 19,252 | political | hacked | |
US Department of Homeland Security | 2016 | 30,000 | government | poor security | |
Desjardins | 2019 | 9,700,000 | financial | inside job | |
Domino's Pizza (France) | 2014 | 600,000 | web | hacked | |
DonorView | 2023 | 948,029 | charity | poor security | |
DoorDash | 2019 | 4,900,000 | web | hacked | |
UK Driving Standards Agency | 2007 | 3,000,000 | government | lost / stolen media | |
Dropbox | 2012 | 68,648,009 | web | hacked | |
Drupal | 2013 | 1,000,000 | web | hacked | |
DSW Inc. | 2005 | 1,400,000 | retail | hacked | |
Dubsmash | 2018 | 162,000,000 | messaging app | hacked | |
Dun & Bradstreet | 2013 | 1,000,000 | tech | hacked | |
Duolingo | 2023 | 2,676,696 | educational services | web scraping | |
EasyJet | 2019-2020 | 9,000,000 (approx) - basic booking, 2208 (credit card details) | transport | hacked | |
eBay | 2014 | 145,000,000 | web | hacked | |
Earl Enterprises (Buca di Beppo, Earl of Sandwich, Planet Hollywood, Chicken Guy, Mixology, Tequila Taqueria) | 2018-2019 | 2,000,000 | restaurant | hacked | |
Educational Credit Management Corporation | 2010 | 3,300,000 | financial | lost / stolen media | |
Eisenhower Medical Center | 2011 | 514,330 | healthcare | lost / stolen computer | |
ElasticSearch | 2019 | 108,000,000 | tech | poor security | |
Embassy Cables | 2010 | 251,000 | government | inside job | |
Emergency Healthcare Physicians, Ltd. | 2010 | 180,111 | healthcare | lost / stolen media | |
Emory Healthcare | 2012 | 315,000 | healthcare | poor security | |
Equifax | 2017 | 163,119,000 | financial, credit reporting | poor security | |
EssilorLuxottica | 2021 | 77,093,812 | healthcare, retail | hacked | |
European Central Bank | 2014 | unknown | financial | hacked | |
Evernote | 2013 | 50,000,000 | web | hacked | |
Evide data breach | 2023 | 1,000 | computer services for charities | ransomware hacked | |
Exactis | 2018 | 340,000,000 | data broker | poor security | |
Excellus BlueCross BlueShield | 2015 | 10,000,000 | healthcare | hacked | |
Experian - T-Mobile US | 2015 | 15,000,000 | telecoms | hacked | |
EyeWire | 2016 | unknown | tech | lost / stolen computer | |
2013 | 6,000,000 | social network | accidentally published | ||
2018 | 50,000,000 | social network | poor security | ||
2019 | 540,000,000 | social network | poor security | ||
2019 | 1,500,000 | social network | accidentally uploaded | ||
2019 | 267,000,000 | social network | poor security | ||
Fast Retailing | 2019 | 461,091 | retail | hacked | |
Federal Reserve Bank of Cleveland | 2010 | 400,000 | financial | hacked | |
Fidelity National Information Services | 2007 | 8,500,000 | financial | inside job | |
First American Corporation | 2019 | 885,000,000 | financial service company | poor security | |
FireEye | 2020 | Unknown | Information Security | hacked | |
Florida Department of Juvenile Justice | 2013 | 100,000 | government | lost / stolen computer | |
Friend Finder Networks | 2016 | 412,214,295 | web | poor security / hacked | |
Funimation | 2016 | 2,500,000 | web | hacked | |
Formspring | 2012 | 420,000 | web | accidentally published | |
Unknown | 2020 | 201,000,000 | personal and demographic data about residents and their properties of US | Poor security | |
Gamigo | 2012 | 8,000,000 | web | hacked | |
Gap Inc. | 2007 | 800,000 | retail | lost / stolen computer | |
Gawker | 2010 | 1,500,000 | web | hacked | |
Global Payments | 2012 | 7,000,000 | financial | hacked | |
Gmail | 2014 | 5,000,000 | web | hacked | |
Google Plus | 2018 | 500,000 | social network | poor security | |
goregrish.com | 2021 | 300,000 | web | hacked | |
Greek government | 2012 | 9,000,000 | government | hacked | |
Grozio Chirurgija | 2017 | 25,000 | healthcare | hacked | |
GS Caltex | 2008 | 11,100,000 | energy | inside job | |
Gyft | 2016 | unknown | web | hacked | |
Hannaford Brothers Supermarket Chain | 2007 | 4,200,000 | retail | hacked | |
HauteLook | 2018 | 28,517,244 | retail | hacked | |
Health Net | 2009 | 500,000 | healthcare | lost / stolen media | |
HCA Healthcare | 2023 | 11,270,000 | healthcare | hacked | |
Health Net — IBM | 2011 | 1,900,000 | healthcare | lost / stolen media | |
Health Sciences Authority (Singapore) | 2019 | 808,000 | healthcare | poor security | |
Health Service Executive | 2021 | unknown | healthcare | unknown | |
Heartland | 2009 | 130,000,000 | financial | hacked | |
Heathrow Airport | 2017 | 2.5GB | transport | lost / stolen media | |
Hewlett Packard | 2006 | 200,000 | tech, retail | lost / stolen media | |
Hilton Hotels | 2014 and 2015 | 363,000 | hotel | hacked | |
Home Depot | 2014 | 56,000,000 | retail | hacked | |
Honda Canada | 2011 | 283,000 | retail | poor security | |
Hyatt Hotels | 2015 | 250 locations | hotel | hacked | |
Iberdrola | 2022 | 1,300,000 | energy | poor security | |
2020 | 200,000,000 | social network | poor security | ||
Internal Revenue Service | 2015 | 720,000 | financial | hacked | |
International Committee of the Red Cross | 2022 | 515,000 | humanitarian | unknown | |
Inuvik hospital | 2016 | 6,700 | healthcare | inside job | |
Iranian banks (three: Saderat, Eghtesad Novin, and Saman) | 2012 | 3,000,000 | financial | hacked | |
Japan Pension Service | 2015 | 1,250,000 | special public corporation | hacked | |
Japanet Takata | 2004 | 510,000 | shopping | inside job | |
Jefferson County, West Virginia | 2008 | 1,600,000 | government | accidentally published | |
JP Morgan Chase | 2010 | 2,600,000 | financial | lost / stolen media | |
JP Morgan Chase | 2014 | 76,000,000 | financial | hacked | |
Justdial | 2019 | 100,000,000 | local search | unprotected api | |
KDDI | 2006 | 4,000,000 | telecoms | hacked | |
Kirkwood Community College | 2013 | 125,000 | academic | hacked | |
KM.RU | 2016 | 1,500,000 | web | hacked | |
Koodo Mobile | 2020 | unknown | mobile carrier | hacked | |
Korea Credit Bureau | 2014 | 20,000,000 | financial | inside job | |
Kroll Background America | 2013 | 1,000,000 | tech | hacked | |
KT Corporation | 2012 | 8,700,000 | telecoms | hacked | |
LexisNexis | 2014 | 1,000,000 | tech | hacked | |
Landry's, Inc. | 2015 | 500 locations | restaurant | hacked | |
Les Éditions Protégez-vous | 2020 | 380,000 | publisher (magazine) | unknown | |
LifeLabs | 2019 | 15,000,000 | healthcare | hacked | |
Lincoln Medical & Mental Health Center | 2010 | 130,495 | healthcare | lost / stolen media | |
LinkedIn, eHarmony, Last.fm | 2012 | 8,000,000 | web | accidentally published | |
Living Social | 2013 | 50,000,000 | web | hacked | |
Lyca Mobile | 2023 | 16,000,000 | telecommunications | hacked | |
MacRumors.com | 2014 | 860,000 | web | hacked | |
Mandarin Oriental Hotels | 2014 | 10 locations | hotel | hacked | |
Manipulated Caiman | 2023 | 40,000,000 | financial | hacked | |
Marriott International | 2018 | 500,000,000 | hotel | hacked | |
Marriott International | 2020 | 5,200,000 | hotel | poor security/inside job | |
Massachusetts Government | 2011 | 210,000 | government | poor security | |
Massive American business hack including 7-Eleven and Nasdaq | 2012 | 160,000,000 | financial | hacked | |
Medibank & AHM | 2022 | 9,700,000 | healthcare | hacked | |
US Medicaid | 2012 | 780,000 | government, healthcare | hacked | |
Medical Informatics Engineering | 2015 | 3,900,000 | healthcare | hacked | |
Memorial Healthcare System | 2011 | 102,153 | healthcare | lost / stolen media | |
MGM Resorts | 2019 | 10,600,000 | hotel/casino | hacked | |
Michaels | 2014 | 3,000,000 | retail | hacked | |
Microsoft | 2019 | 250,000,000 | tech | data exposed by misconfiguration | |
Microsoft Exchange servers | 2021 | unknown | software | zero-day vulnerabilities | |
Militarysingles.com | 2012 | 163,792 | web, military | accidentally published | |
Ministry of Education (Chile) | 2008 | 6,000,000 | government | accidentally published | |
Ministry of Health (Singapore) | 2019 | 14,200 | healthcare | poor security/inside job | |
Mitsubishi Tokyo UFJ Bank | 2006 | 960,000 | financial | intentionally lost | |
MongoDB | 2019 | 202,000,000 | tech | poor security | |
MongoDB | 2019 | 275,000,000 | tech | poor security | |
Mobile TeleSystems (MTS) | 2019 | 100,000,000 | telecommunications | misconfiguration/poor security | |
Monster.com | 2007 | 1,600,000 | web | hacked | |
Morgan Stanley Smith Barney | 2011 | 34,000 | financial | lost / stolen media | |
Morinaga Confectionery | 2022 | 1,648,922 | online shopping | ransomware hacked | |
Mozilla | 2014 | 76,000 | web | poor security | |
MyHeritage | 2018 | 92,283,889 | genealogy | unknown | |
NASDAQ | 2014 | unknown | financial | hacked | |
Natural Grocers | 2015 | 93 stores | retail | hacked | |
NEC Networks, LLC | 2021 | 1,600,000 | healthcare | hacked | |
Neiman Marcus | 2014 | 1,100,000 | retail | hacked | |
Nemours Foundation | 2011 | 1,055,489 | healthcare | lost / stolen media | |
Network Solutions | 2009 | 573,000 | tech | hacked | |
New York City Health & Hospitals Corp. | 2010 | 1,700,000 | healthcare | lost / stolen media | |
New York State Electric & Gas | 2012 | 1,800,000 | energy | inside job | |
New York Taxis | 2014 | 52,000 | transport | poor security | |
Nexon Korea Corp | 2011 | 13,200,000 | web | hacked | |
NHS | 2011 | 8,300,000 | healthcare | lost / stolen media | |
Nintendo (Club Nintendo) | 2013 | 240,000 | gaming | hacked | |
Nintendo (Nintendo Account) | 2020 | 160,000 | gaming | hacked | |
Nippon Television | 2016 | 430,000 | media | hacked | |
Nival Networks | 2016 | 1,500,000 | gaming | hacked | |
Norwegian Tax Administration | 2008 | 3,950,000 | government | accidentally published | |
Now:Pensions | 2020 | 30,000 | financial | rogue contractor | |
NTT Business Solutions | 2023 | 9,000,000 | telecoms | hacked | |
NTT Docomo | 2023 | 5,960,000 | telecoms | hacked | |
Ofcom | 2016 | unknown | telecom | inside job | |
US Office of Personnel Management | 2015 | 21,500,000 | government | hacked | |
Office of the Texas Attorney General | 2012 | 6,500,000 | government | accidentally published | |
OGUsers | 2022 | 529,000 | web | hacked | |
Optus | 2022 | 9,800,000 | telecommunications | hacked | |
Orbitz | 2018 | 880,000 | web | hacked | |
Ohio State University | 2010 | 760,000 | academic | hacked | |
Oregon Department of Transportation | 2011 | unknown | government | poor security | |
OVH | 2013 | undisclosed | web | hacked | |
Patreon | 2015 | 2,300,000 | web | hacked | |
PayPay | 2020 | 20,076,016 | QR code payment | improper setting, hacked | |
Philippine law enforcement agencies (Philippine National Police, National Bureau of Investigation, Bureau of Internal Revenue) | 2023 | 1,279,437 | government | poor security | |
Popsugar | 2018 | 123,857 | fashion | hacked | |
Premera | 2015 | 11,000,000 | healthcare | hacked | |
Puerto Rico Department of Health | 2010 | 515,000 | healthcare | hacked | |
Quest Diagnostics | 2019 | 11,900,000 | Clinical Laboratory | poor security | |
Quora | 2018 | 100,000,000 | Question & Answer | hacked | |
Rakuten | 2020 | 1,381,735 | web | improper setting, hacked | |
Rambler.ru | 2012 | 98,167,935 | web | hacked | |
RBS Worldpay | 2008 | 1,500,000 | financial | hacked | |
RENAPER (Argentina) | 2018 | 45,000,000 | government | poor security | |
2021 | unknown | web | hacked | ||
Restaurant Depot | 2011 | 200,000 | retail | hacked | |
RockYou! | 2009 | 32,000,000 | web, gaming | hacked | |
Rosen Hotels | 2016 | unknown | hotel | hacked | |
Sakai City, Japan | 2015 | 680,000 | government | inside job | |
San Francisco Public Utilities Commission | 2011 | 180,000 | government | hacked | |
Scottrade | 2015 | 4,600,000 | financial | hacked | |
Scribd | 2013 | 500,000 | web | hacked | |
Seacoast Radiology, PA | 2010 | 231,400 | healthcare | hacked | |
Sega | 2011 | 1,290,755 | gaming | hacked | |
Service NSW (New South Wales) | 2020 | 104,000 | government | hacked | |
Service Personnel and Veterans Agency (UK) | 2008 | 50,500 | government | lost / stolen media | |
ShopBack | 2020 | unknown | tech | hacked | |
SingHealth | 2018 | 1,500,000 | government, database | hacked | |
Slack | 2015 | 500,000 | tech | poor security | |
SlickWraps | 2020 | 377,428 | phone accessories | poor security | |
Snapchat | 2013 | 4,700,000 | web, tech | hacked | |
SolarWinds | 2020 | Source Code Compromised | Network Monitoring | hacked | |
Sony Online Entertainment | 2011 | 24,600,000 | gaming | hacked | |
Sony Pictures | 2011 | 1,000,000 | web | hacked | |
Sony Pictures | 2014 | 100 terabytes | media | hacked | |
Sony PlayStation Network | 2011 | 77,000,000 | gaming | hacked | |
South Africa police | 2013 | 16,000 | government | hacked | |
South Carolina Government | 2012 | 6,400,000 | healthcare | inside job | |
South Shore Hospital, Massachusetts | 2010 | 800,000 | healthcare | lost / stolen media | |
Southern California Medical-Legal Consultants | 2011 | 300,000 | healthcare | hacked | |
Spartanburg Regional Healthcare System | 2011 | 400,000 | healthcare | lost / stolen computer | |
Stanford University | 2008 | 72,000 | academic | lost / stolen computer | |
Starbucks | 2008 | 97,000 | retail | lost / stolen computer | |
Starwood including Westin Hotels & Resorts and Sheraton Hotels and Resorts | 2015 | 54 locations | hotel | hacked | |
State of Texas | 2011 | 3,500,000 | government | accidentally published | |
Steam | 2011 | 35,000,000 | web | hacked | |
StockX | 2019 | 6,800,000 | retail | hacked | |
Stratfor | 2011 | 935,000 | military | accidentally published | |
Supervalu | 2014 | 200 stores | retail | hacked | |
Sutter Medical Center | 2011 | 4,243,434 | healthcare | lost / stolen computer | |
Syrian government (Syria Files) | 2012 | 2,434,899 | government | hacked | |
Taobao | 2016 | 20,000,000 | retail | hacked | |
Taringa! | 2017 | 28,722,877 | web | hacked | |
Target Corporation | 2013 | 110,000,000 | retail | hacked | |
TaxSlayer.com | 2016 | 8,800 | web | hacked | |
TD Ameritrade | 2007 | 6,300,000 | financial | hacked | |
TD Bank | 2012 | 260,000 | financial | hacked | |
TerraCom & YourTel | 2013 | 170,000 | telecoms | accidentally published | |
Tesla | 2023 | 75,000 | transport | inside job | |
Tetrad | 2020 | 120,000,000 | market analysis | poor security | |
Texas Lottery | 2007 | 89,000 | government | inside job | |
Ticketfly (subsidiary of Eventbrite) | 2018 | 26,151,608 | ticket distribution | hacked | |
Tic Hosting Solutions (known as Torchbyte) | 2023 | unknown | hosting provider | hacked | |
Tianya Club | 2011 | 28,000,000 | web | hacked | |
TikTok | 2020 | 42,000,000 | social media | poor security | |
TK / TJ Maxx | 2007 | 94,000,000 | retail | hacked | |
T-Mobile, Deutsche Telekom | 2006 | 17,000,000 | telecoms | lost / stolen media | |
T-Mobile | 2021 | 45,000,000 | telecom | hacked | |
T-Mobile | 2023 | 37,000,000 | telecom | hacked | |
Tokopedia | 2020 | 91,000,000 | online shopping | hacked | |
Tricare | 2011 | 4,901,432 | military, healthcare | lost / stolen computer | |
Triple-S Salud, Inc. | 2010 | 398,000 | healthcare | lost / stolen media | |
Truecaller | 2019 | 299,055,000 | Telephone directory | unknown | |
Trump Hotels | 2014 | 8 locations | hotel | hacked | |
Tumblr | 2013 | 65,469,298 | web | hacked | |
Twitch | 2015 | unknown | tech | hacked | |
Twitch | 2021 | unknown | tech | hacked/misconfiguration | |
2013 | 250,000 | web | hacked | ||
Typeform | 2018 | unknown | tech | poor security | |
Uber | 2014 | 50,000 | tech | poor security | |
Uber | 2017 | 57,000,000 | transport | hacked | |
Ubisoft | 2013 | unknown | gaming | hacked | |
Ubuntu | 2013 | 2,000,000 | tech | hacked | |
UCLA Medical Center, Santa Monica | 2015 | 4,500,000 | healthcare | hacked | |
UK Home Office | 2008 | 84,000 | government | lost / stolen media | |
UK Ministry of Defence | 2008 | 1,700,000 | government | lost / stolen media | |
UK Revenue & Customs | 2007 | 25,000,000 | government | lost / stolen media | |
Under Armour | 2018 | 150,000,000 | Consumer Goods | hacked | |
United Nations | 2019 | unknown | international | hacked | |
United Nations | 2021 | unknown | international | hacked | |
University of California, Berkeley | 2009 | 160,000 | academic | hacked | |
University of California, Berkeley | 2016 | 80,000 | academic | hacked | |
University of Maryland, College Park | 2014 | 300,000 | academic | hacked | |
University of Central Florida | 2016 | 63,000 | academic | hacked | |
University of Miami | 2008 | 2,100,000 | academic | lost / stolen computer | |
University of Utah Hospital & Clinics | 2008 | 2,200,000 | academic | lost / stolen media | |
University of Wisconsin–Milwaukee | 2011 | 73,000 | academic | hacked | |
Universiti Teknologi MARA | 2019 | 1,164,540 | academic | hacked | |
United States Postal Service | 2018 | 60,000,000 | government | poor security | |
UPS | 2014 | 51 locations | retail | hacked | |
U.S. Army | 2011 | 50,000 | military | accidentally published | |
U.S. Army (classified Iraq War documents) | 2010 | 392,000 | government | inside job | |
U.S. Department of Defense | 2009 | 72,000 | military | lost / stolen media | |
U.S. Department of Veteran Affairs | 2006 | 26,500,000 | government, military | lost / stolen computer | |
U.S. federal government (2020 United States federal government data breach) | 2020 | TBC | government, military | hacked | |
U.S. law enforcement (70 different agencies) | 2011 | 123,461 | government | accidentally published | |
National Archives and Records Administration (U.S. military veterans records) | 2009 | 76,000,000 | military | lost / stolen media | |
U.S. government (United States diplomatic cables leak) | 2010 | 260,000 | military | inside job | |
National Guard of the United States | 2009 | 131,000 | military | lost / stolen computer | |
Vastaamo | 2020 | 130,000 | healthcare | hacked | |
Verifications.io (first leak) | 2019 | 809,000,000 | online marketing | poor security | |
Verifications.io (total leaks) | 2019 | 2,000,000,000 | online marketing | poor security | |
Verizon Communications | 2016 | 1,500,000 | telecoms | hacked | |
View Media | 2020 | 38,000,000 | online marketing | publicly accessible Amazon Web Services (AWS) server | |
Virgin Media | 2020 | 900,000 | mobile carrier | accidentally exposed | |
Virginia Department of Health | 2009 | 8,257,378 | government, healthcare | hacked | |
Virginia Prescription Monitoring Program | 2009 | 531,400 | healthcare | hacked | |
Vodafone | 2013 | 2,000,000 | telecoms | inside job | |
VTech | 2015 | 5,000,000 | retail | hacked | |
Walmart | 2015 | 1,300,000 | retail | hacked | |
Washington Post | 2011 | 1,270,000 | media | hacked | |
Washington State court system | 2013 | 160,000 | government | hacked | |
Wattpad | 2020 | 270,000,000 | web | hacked | |
Wawa (company) | 2020 | 30,000,000 | retail | hacked | |
Weebly | 2016 | 43,430,316 | web | hacked | |
Wendy's | 2015 | unknown | restaurant | hacked | |
Westpac | 2019 | 98,000 | financial | hacked | |
Woodruff Arts Center | 2019 | unknown | arts group | poor security | |
WordPress | 2018 | web service | hacked | ||
Writerspace.com | 2011 | 62,000 | web | hacked | |
Xat.com | 2015 | 6,054,459 | web | social engineering | |
Yahoo | 2013 | 3,000,000,000 | web | hacked | |
Yahoo | 2014 | 500,000,000 | web | hacked | |
Yahoo Japan | 2013 | 22,000,000 | tech, web | hacked | |
Yahoo! Voices | 2012 | 450,000 | web | hacked | |
Yale University | 2010 | 43,000 | academic | accidentally published | |
YouTube | 2020 | 4,000,000 | social media | poor security | |
Zappos | 2012 | 24,000,000 | web | hacked | |
Zynga | 2019 | 173,000,000 | social network | hacked | |
Unknown agency (believed to be tied to United States Census Bureau) | 2020 | 200,000,000 | financial | accidentally published | |
National Health Information Center (NCZI) of Slovakia | 2020 | 391,250 | healthcare | poor security | |
50 companies and government institutions | 2022 | 6,400,000 | various | poor security | |
IKEA | 2022 | 95,000 | retail | accidentally published | |
Consumer Financial Protection Bureau | 2023 | 256,000 | bureau | poor security | |
Directorate General of Immigration of Indonesia | 2023 | 34,900,867 | Government | hacked and published | |
Directorate General of Population and Civil Registration (Dukcapil) | 2023 | 337.225.463 | Government | leaked and published | |
23andMe data leak | 2023 | 6,900,000 | consumer genetics | credential stuffing | |
British Library | 2023 | unknown | government | ransomware | |
Chess.com | 2023 | 800,000 | game | web scraping | |
DC Health Link | 2023 | 56,000 | healthcare | misconfigured website | |
KitchenPal (iCuisto) | 2023 | 100,000 | web | hacking |