List of data breaches


This is a list of data breaches, using data compiled from various sources, including press reports, government news releases, and mainstream news articles. The list includes those involving the theft or compromise of 30,000 or more records, although many smaller breaches occur continually. Breaches of large organizations where the number of records is still unknown are also listed. The various methods used in the breaches are also listed, with hacking being the most common.
Most breaches occur in North America. It is estimated that the average cost of a data breach will be over $150 million by 2020, with the global annual cost forecast to be $2.1 trillion. It is estimated that in first half of 2018 alone, about 4.5 billion records were exposed as a result of data breaches. In 2019, a collection of 2.7 billion identity records, consisting of 774 million unique email addresses and 21 million unique passwords, was posted on the web for sale.
EntityYearRecordsOrganization typeMethodSources
21st Century Oncology20162,200,000healthcarehacked
500px201814,870,304social networkinghacked
Accendo Insurance Co.2011175,350healthcarepoor security
Adobe Systems2013152,000,000techhacked
Adobe Inc.20197,500,000techpoor security
Advocate Medical Group20134,000,000healthcarelost / stolen media
AerServ 201875,000advertisinghacked
Affinity Health Plan, Inc.2009344,579healthcarelost / stolen media
Air Canada201820,000transporthacked
Amazon Japan G.K.2019unknownwebaccidentally published
Ameritrade2005200,000financiallost / stolen media
Ancestry.com2015300,000webpoor security
Ankle & Foot Center of Tampa Bay, Inc.2010156,000healthcarehacked
Anthem Inc.201580,000,000healthcarehacked
AOL200492,000,000webinside job, hacked
AOL200620,000,000webaccidentally published
AOL20142,400,000webhacked
Apple, Inc./BlueToad201212,367,232tech, retailaccidentally published
Apple2013275,000techhacked
Apple Health Medicaid201691,000healthcarepoor security
Ashley Madison201532,000,000webhacked
AT&T2008113,000telecomslost / stolen computer
AT&T2010114,000telecomshacked
Auction.co.kr200818,000,000webhacked
Australian Immigration Department2015G20 world leadersgovernmentaccidentally published
Automatic Data Processing2005125,000financialpoor security
AvMed, Inc.20091,220,000healthcarelost / stolen computer
Bailey's Inc.2015250,000retailhacked
The Bank of New York Mellon200812,500,000financiallost / stolen media
Bank of America20051,200,000financiallost / stolen media
Barnes & Noble201263 storesretailhacked
Bell Canada20171,900,000telecomspoor security
Bell Canada2018100,000telecomshacked
Betfair20102,300,000webhacked
Bethesda Game Studios2011200,000gaminghacked
Bethesda Game Studios2018gamingaccidentally published
Betsson Group2020unknowngamingunknown
Blank Media Games20187,633,234gaminghacked
Blizzard Entertainment201214,000,000gaminghacked
BlueCross BlueShield of Tennessee20091,023,209healthcarelost / stolen media
BMO and Simplii201890,000bankingpoor security
2018 British Airways cyberattack2018500,000transporthacked
British Airways2015tens of thousandsretailhacked
2019 Bulgarian revenue agency hack2019over 5,000,000governmenthacked
California Department of Child Support Services2012800,000governmentlost / stolen media
Canva2019140,000,000webhacked
Capital One2019106,000,000financialunsecured S3 bucket
CardSystems Solutions Inc.
200540,000,000financialhacked
Cathay Pacific Airways20189,400,000transporthacked
CareFirst BlueCross Blue Shield - Maryland20151,100,000healthcarehacked
Central Coast Credit Union201660,000financialhacked
Central Hudson Gas & Electric2013110,000energyhacked
CheckFree Corporation20095,000,000financialhacked
CheckPeople202056,000,000background checkunknown
China Software Developer Network20116,000,000webhacked
Chinese gaming websites 201110,000,000webhacked
Citigroup20053,900,000financiallost / stolen media
Citigroup2011360,083financialhacked
Citigroup2013150,000financialpoor security
City and Hackney Teaching Primary Care Trust2007160,000healthcarelost / stolen media
Clearview AI20203,000,000,000
information technologyhacked
Colorado government2010105,470healthcarelost / stolen computer
Community Health Systems20144,500,000healthcarehacked
Philippines Commission on Elections201655,000,000governmenthacked
Compass Bank20071,000,000financialinside job
Countrywide Financial Corp20062,600,000financialinside job
Countrywide Financial Corp20112,500,000financialinside job
Centers for Medicare & Medicaid Services201875,000healthcarehacked
Cox Communications201640,000telecomshacked
Crescent Health Inc., Walgreens2013100,000healthcarelost / stolen computer
CVS2015millionsretailhacked
Dai Nippon Printing20078,637,405retailinside job
Data Processors International
20088,000,000financialhacked
Defense Integrated Data Center 2017235 GBmilitaryhacked
Deloitte2017350 clients emailsconsulting, accountingpoor security
Democratic National Committee201619,252political
US Department of Homeland Security201630,000governmentpoor security
Desjardins20192,900,000financialinside job
Domino's Pizza 2014600,000webhacked
DoorDash20194,900,000webhacked
UK Driving Standards Agency20073,000,000governmentlost / stolen media
Dropbox201268,648,009webhacked
Drupal20131,000,000webhacked
DSW Inc.20051,400,000retailhacked
Dubsmash2018162 millionmessaging apphacked
Dun & Bradstreet20131,000,000techhacked
EasyJet2019-20209,000,000 - basic booking, 2208 transporthacked
eBay2014145,000,000webhacked
Earl Enterprises
2018-20192,000,000restauranthacked
Educational Credit Management Corporation20103,300,000financiallost / stolen media
Eisenhower Medical Center2011514,330healthcarelost / stolen computer
ElasticSearch2019108,000,000techpoor security
Embassy Cables2010251,000governmentinside job
Emergency Healthcare Physicians, Ltd.2010180,111healthcarelost / stolen media
Emory Healthcare2012315,000healthcarepoor security
Equifax2017163,119,000financial, credit reportingpoor security
European Central Bank2014unknownfinancialhacked
Evernote201350,000,000webhacked
Exactis2018340,000,000data brokerpoor security
Excellus BlueCross BlueShield201510,000,000healthcarehacked
Experian - T-Mobile US201515,000,000telecomshacked
EyeWire2016unknowntechlost / stolen computer
Facebook20136,000,000social networkaccidentally published
Facebook201850,000,000social networkpoor security
Facebook2019540,000,000social networkpoor security
Facebook20191,500,000social networkaccidentally uploaded
Facebook2019267,000,000social networkpoor security
Federal Reserve Bank of Cleveland2010400,000financialhacked
Fidelity National Information Services20078,500,000financialinside job
First American Corporation2019885,000,000financial service companypoor security
Florida Department of Juvenile Justice2013100,000governmentlost / stolen computer
Friend Finder Networks2016412,214,295webpoor security / hacked
Formspring2012420,000webaccidentally published
Gamigo20128,000,000webhacked
Gap Inc.2007800,000retaillost / stolen computer
Gawker20101,500,000webhacked
Global Payments20127,000,000financialhacked
Gmail20145,000,000webhacked
Google Plus2018500,000social networkpoor security
Greek government20129,000,000governmenthacked
Grozio Chirurgija201725,000healthcarehacked
GS Caltex200811,100,000energyinside job
Gyft2016unknownwebhacked
Hannaford Brothers Supermarket Chain20074,200,000retailhacked
HauteLook201828,517,244retailhacked
Health Net2009500,000healthcarelost / stolen media
Health Net — IBM20111,900,000healthcarelost / stolen media
Health Sciences Authority 2019808,000healthcarepoor security
Heartland2009130,000,000financialhacked
Heathrow Airport20172.5GBtransportlost / stolen media
Hewlett Packard2006200,000tech, retaillost / stolen media
Hilton Hotels2014 and 2015363,000hotelhacked
Home Depot201456,000,000retailhacked
Honda Canada2011283,000retailpoor security
Hyatt Hotels2015250 locationshotelhacked
Internal Revenue Service2015720,000financialhacked
Inuvik hospital20166,700healthcareinside job
Iranian banks 20123,000,000financialhacked
JailCore202036,000governmentpoor security
Jefferson County, West Virginia20081,600,000governmentaccidentally published
JP Morgan Chase20102,600,000financiallost / stolen media
JP Morgan Chase201476,000,000financialhacked
Justdial2019100,000,000local searchunprotected api
KDDI20064,000,000telecomshacked
Kirkwood Community College2013125,000academichacked
KM.RU20161,500,000webhacked
Koodo Mobile2020unknownmobile carrierhacked
Korea Credit Bureau201420,000,000financialinside job
Kroll Background America20131,000,000techhacked
KT Corporation20128,700,000telecomshacked
LexisNexis20141,000,000techhacked
Landry's, Inc.2015500 locationsrestauranthacked
LifeLabs201915,000,000healthcarehacked
Lincoln Medical & Mental Health Center2010130,495healthcarelost / stolen media
LinkedIn, eHarmony, Last.fm20128,000,000webaccidentally published
Living Social201350,000,000webhacked
MacRumors.com2014860,000webhacked
Mandarin Oriental Hotels201410 locationshotelhacked
Marriott International2018500,000,000hotelhacked
Marriott International20205,200,000hotelpoor security/inside job
Massachusetts Government2011210,000governmentpoor security
Massive American business hack
including 7-Eleven and Nasdaq
2012160,000,000financialhacked
US Medicaid2012780,000government, healthcarehacked
Medical Informatics Engineering20153,900,000healthcarehacked
Memorial Healthcare System2011102,153healthcarelost / stolen media
Michaels20143,000,000retailhacked
Microsoft2019250,000,000techdata exposed by misconfiguration
Militarysingles.com2012163,792web, militaryaccidentally published
Ministry of Education 20086,000,000governmentaccidentally published
Ministry of Health 201914,200healthcarepoor security/inside job
MongoDB2019202,000,000techpoor security
MongoDB2019275,000,000techpoor security
Mobile TeleSystems 2019100,000,000telecommunicationsmisconfiguration/poor security
Monster.com20071,600,000webhacked
Morgan Stanley Smith Barney201134,000financiallost / stolen media
Mozilla201476,000webpoor security
MyHeritage201892,283,889genealogyunknown
NASDAQ2014unknownfinancialhacked
Natural Grocers201593 storesretailhacked
Neiman Marcus20141,100,000retailhacked
Nemours Foundation20111,055,489healthcarelost / stolen media
Network Solutions2009573,000techhacked
New York City Health & Hospitals Corp.20101,700,000healthcarelost / stolen media
New York State Electric & Gas20121,800,000energyinside job
New York Taxis201452,000transportpoor security
Nexon Korea Corp201113,200,000webhacked
NHS20118,300,000healthcarelost / stolen media
Nintendo 2013240,000gaminghacked
Nintendo 2020160,000gaminghacked
Nival Networks20161,500,000gaminghacked
Norwegian Tax Administration20083,950,000governmentaccidentally published
Ofcom2016unknowntelecominside job
US Office of Personnel Management201521,500,000governmenthacked
Office of the Texas Attorney General20126,500,000governmentaccidentally published
Ohio State University2010760,000academichacked
Orbitz2018880,000webhacked
Oregon Department of Transportation2011unknowngovernmentpoor security
OVH2013undisclosedwebhacked
Patreon20152,300,000webhacked
Popsugar2018123,857fashionhacked
Premera201511,000,000healthcarehacked
Puerto Rico Department of Health2010515,000healthcarehacked
Quest Diagnostics201911,900,000Clinical Laboratorypoor security
Quora2018100,000,000Question & Answerhacked
Rambler.ru201298,167,935webhacked
RBS Worldpay20081,500,000financialhacked
Reddit2018unknownwebhacked
Restaurant Depot2011200,000retailhacked
RockYou!200932,000,000web, gaminghacked
Rosen Hotels2016unknownhotelhacked
San Francisco Public Utilities Commission2011180,000governmenthacked
Scottrade20154,600,000financialhacked
Scribd2013500,000webhacked
Seacoast Radiology, PA2010231,400healthcarehacked
Sega20111,290,755gaminghacked
Service Personnel and Veterans Agency 200850,500governmentlost / stolen media
SingHealth20181,500,000government, databasehacked
Slack2015500,000techpoor security
SlickWraps2020377,428phone accessoriespoor security
SnapChat20134,700,000web, techhacked
Sony Online Entertainment201124,600,000gaminghacked
Sony Pictures20111,000,000webhacked
Sony Pictures2014100 terabytesmediahacked
Sony PlayStation Network201177,000,000gaminghacked
South Africa police201316,000governmenthacked
South Carolina Government20126,400,000healthcareinside job
South Shore Hospital, Massachusetts2010800,000healthcarelost / stolen media
Southern California Medical-Legal Consultants2011300,000healthcarehacked
Spartanburg Regional Healthcare System2011400,000healthcarelost / stolen computer
Stanford University200872,000academiclost / stolen computer
Starbucks200897,000retaillost / stolen computer
Starwood Hotels
including Westin Hotels and Sheraton Hotels
201554 locationshotelhacked
State of Texas20113,500,000governmentaccidentally published
Steam201135,000,000webhacked
StockX20196,800,000retailhacked
Stratfor2011935,000militaryaccidentally published
Supervalu2014200 storesretailhacked
Sutter Medical Center20114,243,434healthcarelost / stolen computer
Syrian government 20122,434,899governmenthacked
Taobao201620,000,000retailhacked
Taringa!201728,722,877webhacked
Target Corporation2013110,000,000retailhacked
TaxSlayer.com20168,800webhacked
TD Ameritrade20076,300,000financialhacked
TD Bank2012260,000financialhacked
TerraCom & YourTel2013170,000telecomsaccidentally published
Tetrad2020120,000,000market analysispoor security
Texas Lottery200789,000governmentinside job
Ticketfly 201826,151,608ticket distributionhacked
Tianya Club201128,000,000webhacked
TK / TJ Maxx200794,000,000retailhacked
T-Mobile, Deutsche Telekom200617,000,000telecomslost / stolen media
Tricare20114,901,432military, healthcarelost / stolen computer
Triple-S Salud, Inc.2010398,000healthcarelost / stolen media
Truecaller2019299,055,000Telephone directoryunknown
Trump Hotels20148 locationshotelhacked
Tumblr201365,469,298webhacked
Twitch2015unknowntechhacked
Twitter2013250,000webhacked
Typeform2018unknowntechpoor security
Uber201450,000techpoor security
Uber201757,000,000transporthacked
Ubisoft2013unknowngaminghacked
Ubuntu20132,000,000techhacked
UCLA Medical Center, Santa Monica20154,500,000healthcarehacked
UK Home Office200884,000governmentlost / stolen media
UK Ministry of Defence20081,700,000governmentlost / stolen media
UK Revenue & Customs200725,000,000governmentlost / stolen media
Universiti Teknologi MARA20191,164,540academichacked
Under Armour2018150,000,000Consumer Goodshacked
University of California, Berkeley2009160,000academichacked
University of California, Berkeley201680,000academichacked
University of Maryland, College Park2014300,000academichacked
University of Central Florida201663,000academichacked
University of Miami20082,100,000academiclost / stolen computer
University of Utah Hospital & Clinics20082,200,000academiclost / stolen media
University of Wisconsin–Milwaukee201173,000academichacked
United States Postal Service201860,000,000governmentpoor security
UPS201451 locationsretailhacked
U.S. Army201150,000militaryaccidentally published
U.S. Army
2010392,000governmentinside job
U.S. Department of Defense200972,000militarylost / stolen media
U.S. Department of Veteran Affairs200626,500,000government, militarylost / stolen computer
U.S. law enforcement 2011123,461governmentaccidentally published
National Archives and Records Administration 200976,000,000militarylost / stolen media
U.S. government 2010260,000militaryinside job
National Guard of the United States2009131,000militarylost / stolen computer
Verizon Communications20161,500,000telecomshacked
Virgin Media2020900,000mobile carrieraccidentally exposed
Virginia Department of Health20098,257,378government, healthcarehacked
Virginia Prescription Monitoring Program2009531,400healthcarehacked
Vodafone20132,000,000telecomsinside job
VTech20155,000,000retailhacked
Walmart20151,300,000retailhacked
Washington Post20111,270,000mediahacked
Washington State court system2013160,000governmenthacked
Wawa 202030,000,000retailhacked
Weebly201643,430,316webhacked
Wendy's2015unknownrestauranthacked
Woodruff Arts Center2019unknownarts grouppoor security
WordPress2018hacked
Writerspace.com201162,000webhacked
Xat.com20156,054,459websocial engineering
Yahoo20133,000,000,000webhacked
Yahoo2014500,000,000webhacked
Yahoo Japan201322,000,000tech, webhacked
Yahoo! Voices2012450,000webhacked
Yale University201043,000academicaccidentally published
Zappos201224,000,000webhacked
Zynga2019173,000,000social networkhacked
Westpac201998,000financialhacked
Australian National University201919 years of dataacademichacked
2020200,000,000financialaccidentally published