List of data breaches

This is a list of data breaches, using data compiled from various sources, including press reports, government news releases, and mainstream news articles. The list includes those involving the theft or compromise of 30,000 or more records, although many smaller breaches occur continually. Breaches of large organizations where the number of records is still unknown are also listed. In addition, the various methods used in the breaches are listed, with hacking being the most common.

Most reported breaches are in North America, at least in part because of relatively strict disclosure laws in North American countries. 95% of data breaches come from government, retail, or technology industries. It is estimated that the average cost of a data breach will be over $150 million by 2020, with the global annual cost forecast to be $2.1 trillion. As a result of data breaches, it is estimated that in first half of 2018 alone, about 4.5 billion records were exposed. In 2019, a collection of 2.7 billion identity records, consisting of 774 million unique email addresses and 21 million unique passwords, was posted on the web for sale.

EntityYear RecordsOrganization typeMethodSources
21st Century Oncology 2016 2,200,000 healthcare hacked
500px2020 14,870,304social networkinghacked
Accendo Insurance Co.2020 175,350healthcarepoor security
Adobe Systems Incorporated2013 152,000,000techhacked
Adobe Inc. 2019 7,500,000 tech poor security
Advocate Medical Group2017 4,000,000healthcarelost / stolen media
AerServ (subsidiary of InMobi) 2018 75,000 advertising hacked
Affinity Health Plan, Inc.2013 344,579healthcarelost / stolen media
Airtel 2019 320,000,000 telecommunications poor security
India Government Aadhar data breach 2023 810,000,000+ government data leak due to security vulnerabilities
Air Canada 2018 20,000 transport hacked
Amazon Japan G.K. 2019 unknown web accidentally published
TD Ameritrade2005 200,000financiallost / stolen media
Ancestry.com 2021 300,000 web poor security
Animal Jam 2020 46,000,000 gaming hacked
Ankle & Foot Center of Tampa Bay, Inc.2021 156,000healthcarehacked
Anthem Inc.2015 80,000,000healthcarehacked
AOL2004 92,000,000webinside job, hacked
AOL2006 20,000,000webaccidentally published
AOL2014 2,400,000webhacked
Apple, Inc./BlueToad2021 12,367,232tech, retailaccidentally published
Apple2021 275,000techhacked
Apple Health Medicaid2021 91,000healthcarepoor security
Ashley Madison2015 32,000,000webhacked
AT&T2008 113,000telecomslost / stolen computer
AT&T2010 114,000telecomshacked
Atraf 2021 unknown dating hacked
Auction.co.kr2008 18,000,000webhacked
Australian Immigration Department2015 G20 world leadersgovernmentaccidentally published
Australian National University2019 19 years of dataacademichacked
Automatic Data Processing2005 125,000financialpoor security
AvMed, Inc.2009 1,220,000healthcarelost / stolen computer
Bailey's Inc.2015 250,000retailhacked
The Bank of New York Mellon2008 12,500,000financiallost / stolen media
Bangladesh Government website data breach 2023 50,000,000+ government data leak due to security vulnerabilities
Bank of America 2005 1,200,000 financial lost / stolen media
Barnes & Noble2012 63 storesretailhacked
Bell Canada 2017 1,900,000 telecoms poor security
Bell Canada 2018 100,000 telecoms hacked
Benesse 2014 35,040,000 educational services hacked
Betfair2010 2,300,000webhacked
Bethesda Game Studios2011 200,000gaminghacked
Bethesda Game Studios2018 gamingaccidentally published
Betsson Group 2020 unknown gambling unknown
Blank Media Games 2018 7,633,234 gaming hacked
Blizzard Entertainment2012 14,000,000gaminghacked
BlueCross BlueShield of Tennessee2009 1,023,209healthcarelost / stolen media
BMO and Simplii2018 90,000bankingpoor security
2018 British Airways cyberattack 2018 500,000 transport hacked
British Airways2015 tens of thousandsretailhacked
2019 Bulgarian revenue agency hack 2019 over 5,000,000 government hacked
California Department of Child Support Services2012 800,000governmentlost / stolen media
Canva 2019 140,000,000 web hacked
Capcom 2020 350,000 game hacked
Capital One 2019 106,000,000 financial unsecured S3 bucket
CardSystems Solutions Inc.

(MasterCard, Visa, Discover Financial Services and American Express)

2005 40,000,000financialhacked
Cathay Pacific Airways 2018 9,400,000 transport hacked
CareFirst BlueCross Blue Shield - Maryland2015 1,100,000healthcarehacked
Central Coast Credit Union2016 60,000financialhacked
Central Hudson Gas & Electric2013 110,000energyhacked
CheckFree Corporation2009 5,000,000financialhacked
Central Intelligence Agency2017 91malware toolsInternal job
CheckPeople2020 56,000,000background checkunknown
China Software Developer Network2011 6,000,000webhacked
Chinese gaming websites (three: Duowan, 7K7K, 178.com)2011 10,000,000webhacked
Citigroup2005 3,900,000financiallost / stolen media
Citigroup2011 360,083financialhacked
Citigroup2013 150,000financialpoor security
City and Hackney Teaching Primary Care Trust2007 160,000healthcarelost / stolen media
Clearview AI2020 unknown (client list)information technologyhacked
Collection No. 1 2019 773,000,000 various compilation of multiple data breaches
Colorado state government2010 105,470healthcarelost / stolen computer
Community Health Systems2014 4,500,000healthcarehacked
Philippines Commission on Elections2016 55,000,000governmenthacked
Compass Bank2007 1,000,000financialinside job
Countrywide Financial Corp2006 2,600,000financialinside job
Countrywide Financial Corp2011 2,500,000financialinside job
Centers for Medicare & Medicaid Services 2018 75,000 healthcare hacked
Cox Communications2016 40,000telecomshacked
Crescent Health Inc., Walgreens2013 100,000healthcarelost / stolen computer
CVS2015 millionsretailhacked
CyberServe2021 1,107,034hosting providerhacked
Dai Nippon Printing2007 8,637,405retailinside job
Data Processors International
(MasterCard, Visa, Discover Financial Services and American Express)
2008 8,000,000financialhacked
Defense Integrated Data Center (South Korea)2017 235 GBmilitaryhacked
Dedalus Biologie (a division of Dedalus Global) 2021 500,000 health poor security
Deloitte 2017 350 clients emails consulting, accounting poor security
Democratic National Committee2016 19,252politicalhacked
US Department of Homeland Security2016 30,000governmentpoor security
Desjardins 2019 9,700,000 financial inside job
Domino's Pizza (France)2014 600,000webhacked
DonorView2023 948,029charitypoor security
DoorDash2019 4,900,000webhacked
UK Driving Standards Agency2007 3,000,000governmentlost / stolen media
Dropbox2012 68,648,009webhacked
Drupal2013 1,000,000webhacked
DSW Inc. 2005 1,400,000 retail hacked
Dubsmash2018 162,000,000messaging apphacked
Dun & Bradstreet2013 1,000,000techhacked
Duolingo 2023 2,676,696 educational services web scraping
EasyJet2019-2020 9,000,000 (approx) - basic booking, 2208 (credit card details)transporthacked
eBay2014 145,000,000webhacked
Earl Enterprises
(Buca di Beppo, Earl of Sandwich, Planet Hollywood,
Chicken Guy, Mixology, Tequila Taqueria)
2018-2019 2,000,000restauranthacked
Educational Credit Management Corporation2010 3,300,000financiallost / stolen media
Eisenhower Medical Center2011 514,330healthcarelost / stolen computer
ElasticSearch2019 108,000,000techpoor security
Embassy Cables2010 251,000governmentinside job
Emergency Healthcare Physicians, Ltd.2010 180,111healthcarelost / stolen media
Emory Healthcare2012 315,000healthcarepoor security
Equifax 2017 163,119,000 financial, credit reporting poor security
EssilorLuxottica 2021 77,093,812 healthcare, retail hacked
European Central Bank2014 unknownfinancialhacked
Evernote2013 50,000,000webhacked
Evide data breach2023 1,000computer services for charitiesransomware hacked
Exactis2018 340,000,000data brokerpoor security
Excellus BlueCross BlueShield2015 10,000,000healthcarehacked
Experian - T-Mobile US2015 15,000,000telecomshacked
EyeWire2016 unknowntechlost / stolen computer
Facebook2013 6,000,000social networkaccidentally published
Facebook 2018 50,000,000 social network poor security
Facebook 2019 540,000,000 social network poor security
Facebook 2019 1,500,000 social network accidentally uploaded
Facebook2019 267,000,000social networkpoor security
Fast Retailing2019 461,091retailhacked
Federal Reserve Bank of Cleveland2010 400,000financialhacked
Fidelity National Information Services2007 8,500,000financialinside job
First American Corporation 2019 885,000,000 financial service company poor security
FireEye 2020 Unknown Information Security hacked
Florida Department of Juvenile Justice2013 100,000governmentlost / stolen computer
Friend Finder Networks2016 412,214,295webpoor security / hacked
Funimation2016 2,500,000webhacked
Formspring2012 420,000webaccidentally published
Unknown 2020 201,000,000 personal and demographic data about residents and their properties of US Poor security
Gamigo2012 8,000,000webhacked
Gap Inc.2007 800,000retaillost / stolen computer
Gawker2010 1,500,000webhacked
Global Payments2012 7,000,000financialhacked
Gmail2014 5,000,000webhacked
Google Plus 2018 500,000 social network poor security
goregrish.com2021300,000webhacked
Greek government2012 9,000,000governmenthacked
Grozio Chirurgija2017 25,000healthcarehacked
GS Caltex2008 11,100,000energyinside job
Gyft2016 unknownwebhacked
Hannaford Brothers Supermarket Chain2007 4,200,000retailhacked
HauteLook 2018 28,517,244 retail hacked
Health Net2009 500,000healthcarelost / stolen media
HCA Healthcare2023 11,270,000healthcarehacked
Health Net IBM2011 1,900,000healthcarelost / stolen media
Health Sciences Authority (Singapore) 2019 808,000 healthcare poor security
Health Service Executive 2021 unknown healthcare unknown
Heartland2009 130,000,000financialhacked
Heathrow Airport 2017 2.5GB transport lost / stolen media
Hewlett Packard2006 200,000tech, retaillost / stolen media
Hilton Hotels2014 and 2015 363,000hotelhacked
Home Depot2014 56,000,000retailhacked
Honda Canada2011 283,000retailpoor security
Hyatt Hotels2015 250 locationshotelhacked
Iberdrola 2022 1,300,000 energy poor security
Instagram 2020 200,000,000 social network poor security
Internal Revenue Service2015 720,000financialhacked
International Committee of the Red Cross2022 515,000humanitarianunknown
Inuvik hospital2016 6,700healthcareinside job
Iranian banks (three: Saderat, Eghtesad Novin, and Saman)2012 3,000,000financialhacked
Japan Pension Service2015 1,250,000special public corporationhacked
Japanet Takata2004 510,000shoppinginside job
Jefferson County, West Virginia2008 1,600,000governmentaccidentally published
JP Morgan Chase2010 2,600,000financiallost / stolen media
JP Morgan Chase2014 76,000,000financialhacked
Justdial2019 100,000,000local searchunprotected api
KDDI2006 4,000,000telecomshacked
Kirkwood Community College2013 125,000academichacked
KM.RU2016 1,500,000webhacked
Koodo Mobile2020 unknownmobile carrierhacked
Korea Credit Bureau2014 20,000,000financialinside job
Kroll Background America2013 1,000,000techhacked
KT Corporation2012 8,700,000telecomshacked
LexisNexis2014 1,000,000techhacked
Landry's, Inc.2015 500 locationsrestauranthacked
Les Éditions Protégez-vous 2020 380,000 publisher (magazine) unknown
LifeLabs2019 15,000,000healthcarehacked
Lincoln Medical & Mental Health Center2010 130,495healthcarelost / stolen media
LinkedIn, eHarmony, Last.fm2012 8,000,000webaccidentally published
Living Social2013 50,000,000webhacked
Lyca Mobile 2023 16,000,000 telecommunications hacked
MacRumors.com2014 860,000webhacked
Mandarin Oriental Hotels2014 10 locationshotelhacked
Manipulated Caiman 2023 40,000,000 financial hacked
Marriott International2018 500,000,000hotelhacked
Marriott International2020 5,200,000hotelpoor security/inside job
Massachusetts Government2011 210,000governmentpoor security
Massive American business hack
including 7-Eleven and Nasdaq
2012 160,000,000financialhacked
Medibank & AHM 2022 9,700,000 healthcare hacked
US Medicaid2012 780,000government, healthcarehacked
Medical Informatics Engineering2015 3,900,000healthcarehacked
Memorial Healthcare System2011 102,153healthcarelost / stolen media
MGM Resorts2019 10,600,000hotel/casinohacked
Michaels2014 3,000,000retailhacked
Microsoft2019 250,000,000 tech data exposed by misconfiguration
Microsoft Exchange servers 2021 unknown software zero-day vulnerabilities
Militarysingles.com2012 163,792web, militaryaccidentally published
Ministry of Education (Chile)2008 6,000,000governmentaccidentally published
Ministry of Health (Singapore) 2019 14,200 healthcare poor security/inside job
Mitsubishi Tokyo UFJ Bank 2006 960,000 financial intentionally lost
MongoDB2019 202,000,000techpoor security
MongoDB2019 275,000,000techpoor security
Mobile TeleSystems (MTS) 2019 100,000,000 telecommunications misconfiguration/poor security
Monster.com2007 1,600,000webhacked
Morgan Stanley Smith Barney2011 34,000financiallost / stolen media
Morinaga Confectionery2022 1,648,922online shoppingransomware hacked
Mozilla2014 76,000webpoor security
MyHeritage 2018 92,283,889 genealogy unknown
NASDAQ2014 unknownfinancialhacked
Natural Grocers2015 93 storesretailhacked
NEC Networks, LLC2021 1,600,000healthcarehacked
Neiman Marcus2014 1,100,000retailhacked
Nemours Foundation2011 1,055,489healthcarelost / stolen media
Network Solutions2009 573,000techhacked
New York City Health & Hospitals Corp.2010 1,700,000healthcarelost / stolen media
New York State Electric & Gas2012 1,800,000energyinside job
New York Taxis2014 52,000transportpoor security
Nexon Korea Corp2011 13,200,000webhacked
NHS2011 8,300,000healthcarelost / stolen media
Nintendo (Club Nintendo)2013 240,000gaminghacked
Nintendo (Nintendo Account)2020 160,000gaminghacked
Nippon Television2016 430,000mediahacked
Nival Networks2016 1,500,000gaminghacked
Norwegian Tax Administration2008 3,950,000governmentaccidentally published
Now:Pensions2020 30,000financialrogue contractor
NTT Business Solutions20239,000,000telecomshacked
NTT Docomo20235,960,000telecomshacked
Ofcom2016 unknowntelecominside job
US Office of Personnel Management2015 21,500,000governmenthacked
Office of the Texas Attorney General2012 6,500,000governmentaccidentally published
OGUsers 2022 529,000 web hacked
Optus 2022 9,800,000 telecommunications hacked
Orbitz2018 880,000webhacked
Ohio State University2010 760,000academichacked
Oregon Department of Transportation2011 unknowngovernmentpoor security
OVH2013 undisclosedwebhacked
Patreon2015 2,300,000webhacked
PayPay2020 20,076,016QR code paymentimproper setting, hacked
Philippine law enforcement agencies (Philippine National Police, National Bureau of Investigation, Bureau of Internal Revenue)2023 1,279,437governmentpoor security
Popsugar2018 123,857fashionhacked
Premera2015 11,000,000healthcarehacked
Puerto Rico Department of Health2010 515,000healthcarehacked
Quest Diagnostics 2019 11,900,000 Clinical Laboratory poor security
Quora 2018 100,000,000 Question & Answer hacked
Rakuten 2020 1,381,735 web improper setting, hacked
Rambler.ru2012 98,167,935webhacked
RBS Worldpay2008 1,500,000financialhacked
RENAPER (Argentina) 2018 45,000,000 government poor security
Reddit 2021 unknown web hacked
Restaurant Depot2011 200,000retailhacked
RockYou!2009 32,000,000web, gaminghacked
Rosen Hotels2016 unknownhotelhacked
Sakai City, Japan2015 680,000governmentinside job
San Francisco Public Utilities Commission2011 180,000governmenthacked
Scottrade2015 4,600,000financialhacked
Scribd2013 500,000webhacked
Seacoast Radiology, PA2010 231,400healthcarehacked
Sega2011 1,290,755gaminghacked
Service NSW (New South Wales) 2020 104,000 government hacked
Service Personnel and Veterans Agency (UK)2008 50,500governmentlost / stolen media
ShopBack 2020 unknown tech hacked
SingHealth 2018 1,500,000 government, database hacked
Slack2015 500,000techpoor security
SlickWraps2020 377,428phone accessoriespoor security
Snapchat2013 4,700,000web, techhacked
SolarWinds 2020 Source Code Compromised Network Monitoring hacked
Sony Online Entertainment2011 24,600,000gaminghacked
Sony Pictures2011 1,000,000webhacked
Sony Pictures2014 100 terabytesmediahacked
Sony PlayStation Network2011 77,000,000gaminghacked
South Africa police2013 16,000governmenthacked
South Carolina Government2012 6,400,000healthcareinside job
South Shore Hospital, Massachusetts2010 800,000healthcarelost / stolen media
Southern California Medical-Legal Consultants2011 300,000healthcarehacked
Spartanburg Regional Healthcare System2011 400,000healthcarelost / stolen computer
Stanford University2008 72,000academiclost / stolen computer
Starbucks2008 97,000retaillost / stolen computer
Starwood
including Westin Hotels & Resorts and Sheraton Hotels and Resorts
2015 54 locationshotelhacked
State of Texas2011 3,500,000governmentaccidentally published
Steam2011 35,000,000webhacked
StockX2019 6,800,000retailhacked
Stratfor2011 935,000militaryaccidentally published
Supervalu2014 200 storesretailhacked
Sutter Medical Center2011 4,243,434healthcarelost / stolen computer
Syrian government (Syria Files)2012 2,434,899governmenthacked
Taobao2016 20,000,000retailhacked
Taringa! 2017 28,722,877 web hacked
Target Corporation2013 110,000,000retailhacked
TaxSlayer.com2016 8,800webhacked
TD Ameritrade2007 6,300,000financialhacked
TD Bank2012 260,000financialhacked
TerraCom & YourTel2013 170,000telecomsaccidentally published
Tesla 2023 75,000 transport inside job
Tetrad2020 120,000,000market analysispoor security
Texas Lottery2007 89,000governmentinside job
Ticketfly (subsidiary of Eventbrite) 2018 26,151,608 ticket distribution hacked
Tic Hosting Solutions (known as Torchbyte)2023 unknownhosting providerhacked
Tianya Club2011 28,000,000webhacked
TikTok 2020 42,000,000 social media poor security
TK / TJ Maxx2007 94,000,000retailhacked
T-Mobile, Deutsche Telekom2006 17,000,000telecomslost / stolen media
T-Mobile2021 45,000,000telecomhacked
T-Mobile2023 37,000,000telecomhacked
Tokopedia2020 91,000,000online shoppinghacked
Tricare2011 4,901,432military, healthcarelost / stolen computer
Triple-S Salud, Inc.2010 398,000healthcarelost / stolen media
Truecaller2019 299,055,000Telephone directoryunknown
Trump Hotels2014 8 locationshotelhacked
Tumblr 2013 65,469,298 web hacked
Twitch2015 unknowntechhacked
Twitch2021 unknowntechhacked/misconfiguration
Twitter2013 250,000webhacked
Typeform 2018 unknown tech poor security
Uber2014 50,000techpoor security
Uber 2017 57,000,000 transport hacked
Ubisoft2013 unknowngaminghacked
Ubuntu2013 2,000,000techhacked
UCLA Medical Center, Santa Monica2015 4,500,000healthcarehacked
UK Home Office2008 84,000governmentlost / stolen media
UK Ministry of Defence2008 1,700,000governmentlost / stolen media
UK Revenue & Customs2007 25,000,000governmentlost / stolen media
Under Armour2018 150,000,000Consumer Goodshacked
United Nations2019 unknowninternationalhacked
United Nations2021 unknowninternationalhacked
University of California, Berkeley2009 160,000academichacked
University of California, Berkeley2016 80,000academichacked
University of Maryland, College Park2014 300,000academichacked
University of Central Florida2016 63,000academichacked
University of Miami2008 2,100,000academiclost / stolen computer
University of Utah Hospital & Clinics2008 2,200,000academiclost / stolen media
University of Wisconsin–Milwaukee2011 73,000academichacked
Universiti Teknologi MARA 2019 1,164,540 academic hacked
United States Postal Service2018 60,000,000governmentpoor security
UPS2014 51 locationsretailhacked
U.S. Army2011 50,000militaryaccidentally published
U.S. Army
(classified Iraq War documents)
2010 392,000governmentinside job
U.S. Department of Defense2009 72,000militarylost / stolen media
U.S. Department of Veteran Affairs2006 26,500,000government, militarylost / stolen computer
U.S. federal government (2020 United States federal government data breach)2020 TBCgovernment, militaryhacked
U.S. law enforcement (70 different agencies)2011 123,461governmentaccidentally published
National Archives and Records Administration (U.S. military veterans records)2009 76,000,000militarylost / stolen media
U.S. government (United States diplomatic cables leak)2010 260,000militaryinside job
National Guard of the United States2009 131,000militarylost / stolen computer
Vastaamo2020 130,000healthcarehacked
Verifications.io (first leak) 2019 809,000,000 online marketing poor security
Verifications.io (total leaks) 2019 2,000,000,000 online marketing poor security
Verizon Communications2016 1,500,000telecomshacked
View Media 2020 38,000,000 online marketing publicly accessible Amazon Web Services (AWS) server
Virgin Media2020 900,000mobile carrieraccidentally exposed
Virginia Department of Health2009 8,257,378government, healthcarehacked
Virginia Prescription Monitoring Program2009 531,400healthcarehacked
Vodafone2013 2,000,000telecomsinside job
VTech2015 5,000,000retailhacked
Walmart2015 1,300,000retailhacked
Washington Post2011 1,270,000mediahacked
Washington State court system2013 160,000governmenthacked
Wattpad2020 270,000,000webhacked
Wawa (company)2020 30,000,000retailhacked
Weebly2016 43,430,316webhacked
Wendy's2015 unknownrestauranthacked
Westpac2019 98,000financialhacked
Woodruff Arts Center2019 unknownarts grouppoor security
WordPress2018 web servicehacked
Writerspace.com2011 62,000webhacked
Xat.com 2015 6,054,459 web social engineering
Yahoo2013 3,000,000,000webhacked
Yahoo2014 500,000,000webhacked
Yahoo Japan2013 22,000,000tech, webhacked
Yahoo! Voices2012 450,000webhacked
Yale University2010 43,000academicaccidentally published
YouTube 2020 4,000,000 social media poor security
Zappos2012 24,000,000webhacked
Zynga2019 173,000,000social networkhacked
Unknown agency
(believed to be tied to United States Census Bureau)
2020 200,000,000financialaccidentally published
National Health Information Center (NCZI) of Slovakia 2020 391,250 healthcare poor security
50 companies and government institutions 2022 6,400,000 various poor security
IKEA 2022 95,000 retail accidentally published
Consumer Financial Protection Bureau 2023 256,000 bureau poor security
Directorate General of Immigration of Indonesia 2023 34,900,867 Government hacked and published
Directorate General of Population and Civil Registration (Dukcapil) 2023 337.225.463 Government leaked and published
23andMe data leak 2023 6,900,000 consumer genetics credential stuffing
British Library 2023 unknown government ransomware
Chess.com 2023 800,000 game web scraping
DC Health Link 2023 56,000 healthcare misconfigured website
KitchenPal (iCuisto) 2023 100,000 web hacking
This article is issued from Wikipedia. The text is licensed under Creative Commons - Attribution - Sharealike. Additional terms may apply for the media files.