🏛️ Data Leaks Hall of Shame
Información y créditos
La siguiente tabla de brechas de seguridad es gentileza de information is beautiful. Iremos actualizándolo períodicamente en la medida en que el archivo original reciba actualizaciones.
Ojo a las 🍪
Toma en cuenta que se han facilitado un hipervínculo a la fuente original. Este link puede conducir a un sitio web que eventualmente podría contener cookies, trackers y otras tecnologías invasivas de la privacidad.
| organisation | alternative name | records lost | year | date | story | sector | method | interesting story | data sensitivity | displayed records | FIELD12 | source name | 1st source link | 2nd source link | ID |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Visualización aquí | (use 3m, 4m, 5m or 10m to approximate unknown figures) | year story broke | poor security hacked oops! lost device inside job | 1. Just email address/Online information 2 SSN/Personal details 3 Credit card information 4 Health & other personal records 5 Full details | |||||||||||
| Quantas | 5,700,000 | 2025 | Jul 25 | The records of nearly 6 million customers on the platform and Qantas expects a "significant" proportion of the data has been stolen. | transport | hacked | 2 | ABC | https://www.abc.net.au/news/2025-07-02/qantas-cyber-attack-significant-data-stolen/105484720 | 524 | |||||
| GiveSendGo | 92,000 | 2022 | Feb 22 | Crowdfunding site that raised funds for the anti-vax “freedom convoy” in Canada was hacked exposing the names and personal details of over 92,000 donors | web | hacked | y | 2 | Vice | https://www.vice.com/en/article/freedom-convoy-givesendgo-donors-leaked/ | 523 | ||||
| Tea | 72,000 | 2025 | Jul 25 | Web service providing safety for women online dating was breached, exposing over 13K photos of IDs used for account vertification, alongside 56K other images. ID photos were likely geotagged, worsening the severity of the leak | web | hacked | y | 4 | Tech Crunch | https://techcrunch.com/2025/07/26/dating-safety-app-tea-breached-exposing-72000-user-images/ | 522 | ||||
| Lee Enterprises | 39,000 | 2025 | Feb 25 | Attackers behind a ransomware attack in Feb also stole documents and information on ~40K individuals | misc | hacked | 2 | Beeping Computer | https://www.bleepingcomputer.com/news/security/media-giant-lee-enterprises-says-data-breach-affects-39-000-people/ | 521 | |||||
| Cartier | 100,000 | 2025 | Jun 25 | Luxury fashion brand Cartier warned customers of a data breach that exposed customers' personal information. | retail | hacked | 1 | Beeping Computer | https://www.bleepingcomputer.com/news/security/cartier-discloses-data-breach-amid-fashion-brand-cyberattacks/ | 520 | |||||
| The North Face | 100,000 | 2025 | Apr 25 | The North Face is warning customers that their personal information was stolen in credential stuffing attacks. | retail | hacked | 2 | Beeping Computer | https://www.bleepingcomputer.com/news/security/the-north-face-warns-customers-of-april-credential-stuffing-attack/ | 519 | |||||
| LexisNexis | 364,000 | 2024 | Dec 24 | Data broker giant LexisNexis Risk Solutions states attackers stole personal information of over 364k individuals in Dec. | tech | poor security | 2 | Beeping Computer | https://www.bleepingcomputer.com/news/security/data-broker-lexisnexis-discloses-data-breach-affecting-364-000-people/ | 518 | |||||
| Adidas | 100,000 | 2025 | May 25 | German sportswear giant Adidas disclosed attackers hacked a customer service provider and stole some user data. | retail | hacked | 1 | Beeping Computer | https://www.bleepingcomputer.com/news/security/adidas-warns-of-data-breach-after-customer-service-provider-hack/ | 517 | |||||
| Coinbase | 69,461 | 2025 | May 25 | Coinbase said, "individuals performing services at our overseas support locations, improperly accessed customer information." | finance | inside job | 3 | Beeping Computer | https://www.bleepingcomputer.com/news/security/coinbase-says-recent-data-breach-impacts-69-461-customers/ | 516 | |||||
| UK's Legal Aid Agency | LAA | 2,100,000 | 2025 | May 25 | Criminal records dating back to 2010, as well as personal data was stolen for up to two million people | government | hacked | y | 3 | Beeping Computer | https://www.bleepingcomputer.com/news/security/uk-legal-aid-agency-confirms-applicant-data-stolen-in-data-breach/ | 515 | |||
| Nova Scotia Power | 100,000 | 2025 | May 25 | Nova Scotia Power confirms hackers stole sensitive data. The company serves over 500k customers. | misc | hacked | 4 | Beeping Computer | https://www.bleepingcomputer.com/news/security/nova-scotia-power-confirms-hackers-stole-customer-data-in-cyberattack/ | 514 | |||||
| ColoCrossing | 7,200 | 2025 | May 25 | Breach impacted users of ColoCloud virtual server although was isolated to their cloud/VPS platform. 7k emails exposed. | web, tech | hacked | 2 | Have I Been Pwned | https://haveibeenpwned.com/Breach/ColoCrossing | 513 | |||||
| Free | 13,900,000 | 2024 | Oct 24 | French ISP "Free" suffered a breach which was posted for sale and later, leaked. 14m email, names, addresses etc. exposed. | web | hacked | 3 | Have I Been Pwned | https://haveibeenpwned.com/Breach/FreeMobile | 512 | |||||
| Fédération Francaise de Rugby | 282,000 | 2023 | Jul 23 | The French Rugby Federation had a breach and attempted ransom. 282k emails, names, dates of birth and phone numbers. | government | hacked | 1 | Have I Been Pwned | https://haveibeenpwned.com/Breach/FFR | 511 | |||||
| TehetségKapu | 54,400 | 2025 | Mar 25 | 55k records breached from the Hungarian education office TehetségKapu. Data was subsequently published to a hacking forum. | government | hacked | 1 | Have I Been Pwned | https://haveibeenpwned.com/Breach/TehetsegKapu | 510 | |||||
| Krispy Kreme | 161,676 | 2024 | Nov 24 | U.S. doughnut chain confirmed attackers stole the personal info of over 160k individuals in a cyberattack. | retail | hacked | 3 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/krispy-kreme-says-november-data-breach-impacts-over-160-000-people/ | 509 | |||||
| Episource | 5,418,866 | 2025 | Feb 25 | An investigation revealed that hackers accessed and exfiltrated 5.4m records stored on these systems. | health | hacked | 4 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/episource-says-data-breach-impacts-54-million-patients/ | 508 | |||||
| Cock.li | 1,023,800 | 2025 | Jun 25 | Email hosting provider confirmed exploited flaws in its retired Roundcube webmail platform exposed over 1m records. | web | poor security | 1 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/hacker-steals-1-million-cockli-user-records-in-webmail-data-breach/ | 507 | |||||
| UnitedHealth | 190,000,000 | 2024 | Oct 24 | 190m Americans had their personal and healthcare data stolen in the Change Healthcare ransomware attack. | health | hacked | 4 | 190m | Bleeping Computer | https://www.bleepingcomputer.com/news/security/unitedhealth-now-says-190-million-impacted-by-2024-data-breach/ | 506 | ||||
| Internet Archive | 33,000,000 | 2024 | Oct 24 | The Archive was hit by two different attacks, a data breach exposing 33m users data and a DDoS attack. | web | hacked | 1 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/internet-archive-hacked-data-breach-impacts-31-million-users/ | 505 | |||||
| National Public Data | 1,000,000,000 | 2024 | Aug 24 | 2.7bn records of US citizens used for background checks leaked on a hacking forum, names, social security, physical addresses, and aliases. | government | hacked | 2 | 2.7bn | Bleeping Computer | https://www.bleepingcomputer.com/news/security/hackers-leak-27-billion-data-records-with-social-security-numbers/ | 504 | ||||
| VeriSource | 4,000,000 | 2024 | Feb 24 | Employee benefits administration firm exposed the personal information of 4m people. | finance | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/verisource-now-says-february-data-breach-impacts-4-million-people/ | 503 | |||||
| Baltimore Public Schools | 31,000 | 2025 | Feb 25 | Tens of thousands of employees and students exposed in a breach incident when attackers hacked into its network. | academia | hacked | 3 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/baltimore-city-public-schools-data-breach-affects-over-31-000-people/ | 502 | |||||
| Robinsons | 195,600 | 2024 | Jun 24 | Philippine shopping-mall operator suffered a breach via mobile app exposing 195k emails, names, numbers, DOB, genders. | retail | poor security | 2 | Have I Been Pwned | https://haveibeenpwned.com/Breach/RobinsonsMalls | 501 | |||||
| Have Fun Teaching | 27,100 | 2021 | Aug 21 | Teaching resources site suffered a breach leaking 80k WooCommerce transactions, and posted to a hacking forum. | academia | hacked | 3 | Have I Been Pwned | https://haveibeenpwned.com/Breach/HaveFunTeaching | 500 | |||||
| Ualabee | 472,300 | 2025 | May 25 | South American mobility services platform had 472k records scraped from an interface on their platform. | transport | hacked | 2 | Have I Been Pwned | https://haveibeenpwned.com/Breach/Ualabee | 499 | |||||
| Wiredbucks | 918,500 | 2022 | May 22 | Social media influencer platform suffered a data breach exposing over 900k emails, IP addresses, names, usernames, etc. | web | hacked | 2 | Have I Been Pwned | https://haveibeenpwned.com/Breach/WiredBucks | 498 | |||||
| Disk Union | 690,700 | 2022 | Jun 22 | Japanese record chain store exposed 690k email, names, postcodes, phone numbers and passwords. | retail | hacked | 2 | Have I Been Pwned | https://haveibeenpwned.com/Breach/DiskUnion | 497 | |||||
| Spectos | 216,300 | 2025 | Mar 25 | Data breach of logistics provider, Spectos: 216k emails, names, physical addresses, and purchases. | telecoms | hacked | 2 | Have I Been Pwned | https://haveibeenpwned.com/Breach/SamsungGermany | 496 | |||||
| German Doner Kebab | 162,400 | 2025 | Mar 25 | Breched food company leaked 162k unique emails, names, phone numbers and physical addresses. | retail | hacked | 2 | Have I Been Pwned | https://haveibeenpwned.com/Breach/GermanDonerKebab | 495 | |||||
| Orange Romania | 556,600 | 2025 | Feb 25 | Published to a hacking forum: 556k emails, phone, subscription, partial credit card data. | telecoms | hacked | 2 | Have I Been Pwned | https://haveibeenpwned.com/Breach/OrangeRomania | 494 | |||||
| Thermomix Recipe World Forum | 3,100,000 | 2025 | Jan 25 | Forum for users of the popular food processer was breached, exposing 3.1m records inc. emails, physical address, and DOB. | web | hacked | 2 | Have I Been Pwned | https://haveibeenpwned.com/Breach/Thermomix | 493 | |||||
| Kaiser Permanente | 13,400,000 | 2024 | Apr 24 | A leading U.S. healthcare organization transmitted personal information to third-party vendors, including Google, Microsoft Bing, and X (formerly Twitter), including search terms entered in Kaiser's health encyclopedia. | health | oops! | 3 | Bleeping Computer | https://restoreprivacy.com/data-breach-at-kaiser-permanente-affects-13-4-million-people/ | 492 | |||||
| Ticketmaster | 560,000,000 | 2024 | Jun 24 | Hacker group ShinyHunters say it stole names, addresses, phone numbers and partial credit cards details from hundreds of millions of Ticketmaster customers around the world. | misc | hacked | y | 3 | 560m | BBC | https://www.bbc.co.uk/news/articles/cw99ql0239wo | 491 | |||
| Stanford University | 27,000 | 2023 | May 23 | The Akira ransomware group claims to have stolen 430 GB of data, including names and social security numbers. The breach went unnoticed for four months, suggesting a possible prolonged attacker presence | academia | hacked | 2 | Slashdot | https://yro.slashdot.org/story/24/03/13/2053224/stanford-university-failed-to-detect-ransomware-intruders-for-4-months?utm_source=feedly1.0mainlinkanon&utm_medium=feed | 490 | |||||
| Cooler Master | 500,000 | 2024 | May 24 | Threat actor 'Ghostr' hacked the company's Fanzone website, stealing 103 GB of data. Compromised info includes names, emails, phone numbers, birth dates, addresses, product details, employee info, and vendor correspondence. | tech | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/cooler-master-confirms-customer-info-stolen-in-data-breach/ | 489 | |||||
| Financial Business and Consumer Solutions | FBCS | 3,200,000 | 2024 | Feb 24 | A U.S. debt collection agency reported a breach Initially affecting 1.9m people but the number has since increased significantly. Stolen data includes names, SSNs, birthdates, account info, and driver's license numbers. | tech | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/collection-agency-fbcs-ups-data-breach-tally-to-32-million-people/ | 488 | ||||
| Santander | 30,000,000 | 2024 | May 24 | Threat actor 'ShinyHunters' claim to be selling Santander bank data on 30m customers from Chile, Spain and Uruguay. | finance | hacked | 3 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/banco-santander-warns-of-a-data-breach-exposing-customer-info/ | 487 | |||||
| Everbridge | 5,600,000 | 2024 | May 24 | The American crisis management software company, serving the U.S. Army, Atlanta Airport, and Norway and Australia, suffered a major data breach. Both business and user data compromised. | tech | hacked | 1 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/everbridge-warns-of-corporate-systems-breach-exposing-business-data/ | 486 | |||||
| BBC | 25,000 | 2024 | May 24 | Personal information of BBC Pension Scheme members, including current and former employees, was compromised. Data types include names, National Insurance numbers, birthdates, and home addresses. | misc | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/bbc-suffers-data-breach-impacting-current-former-employees/ | 485 | |||||
| First American | 44,000 | 2023 | Dec 23 | The second largest title insurance company in the US did not reveal which personal information was compromissed. | finance | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/first-american-december-data-breach-impacts-44-000-people/ | 484 | |||||
| Christie's | 500,000 | 2024 | May 24 | Famous auction house Christie's lost sensitive information on 500,000 clients to the RansomHub extortion gang. This includes full names, physical addresses, and ID details. Ironically, the cybercriminals also auction these stolen files to the highest bidder. | retail | hacked | y | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/christies-confirms-breach-after-ransomhub-threatens-to-leak-data/ | 483 | ||||
| Sav-Rx | 2,800,000 | 2023 | Oct 23 | Prescription management company Sav-Rx warned over 2.8m people in the US of a data breach. Compromised data includes full names, birthdates, SSNs, emails, addresses, phone numbers, eligibility data, and insurance IDs. | health | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/sav-rx-discloses-data-breach-impacting-28-million-americans/ | 482 | |||||
| Cencora | 100,000 | 2024 | Feb 24 | Major drug companies, including Novartis and Bayer, disclosed data breaches after a February 2024 cyberattack at Cencora, their pharmaceutical services partner. Compromised data includes names, addresses, diagnoses, medications, and prescriptions. | health | hacked | 4 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/cencora-data-breach-exposes-us-patient-info-from-11-drug-companies/ | 481 | |||||
| WebTPA | 2,400,00 | 2023 | Apr 23 | The breach at this employer service compromised names, contact info, birth/death dates, SSNs, and insurance details. Impacted individuals include customers of The Hartford, Transamerica, and Gerber Life Insurance. | tech | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/webtpa-data-breach-impacts-24-million-insurance-policyholders/ | 480 | |||||
| Nissan | Nissan North America | 53;000 | 2023 | Nov 23 | This breach of the car manufacturer exposed personal data (including Social Security numbers) belonging to current and former employees. | transport | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/nissan-north-america-data-breach-impacts-over-53-000-employees/ | 479 | ||||
| Singing River | Singing River Health System | 895,000 | 2023 | Aug 23 | A healthcare provider in the Gulf Coast region was breached by the Rhysida ransomware gang. Compromised data includes names, birthdates, addresses, SSNs, and medical info. | health | hacked | 4 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/singing-river-health-system-data-of-895-000-stolen-in-ransomware-attack/ | 478 | ||||
| City of Helsinki | Helsinki | 80,000 | 2024 | Apr 24 | A data breach in Helsinki's education division affected tens of thousands of students, guardians, and personnel. Compromised data includes usernames, emails, IDs, addresses, fee details, education info, welfare requests, and medical certificates. | government | hacked | 4 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/helsinki-suffers-data-breach-after-hackers-exploit-unpatched-flaw/ | https://poliisi.fi/en/-/police-investigate-extensive-data-breach-in-helsinki-city-s-computer-network | 477 | |||
| Firstmac | 100,000 | 2024 | Apr 24 | Australia's largest non-bank lender had 500GB of data stolen by the Embargo cyber-extortion group. Stolen data includes names, addresses, emails, phone numbers, birthdates, bank account info, and driver's license numbers. | finance | hacked | 3 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/largest-non-bank-lender-in-australia-warns-of-a-data-breach/ | https://www.cyberdaily.au/security/10487-exclusive-aussie-lender-firstmac-falls-victim-to-embargo-ransomware-gang | 476 | ||||
| The Post Millennial | 26,000,000 | 2024 | May 24 | A conservative Canadian news magazine was breached leaking data on mailing lists, subscriber info, and details of writers and editors: names, emails, usernames, passwords, IPs, phone numbers, addresses, and genders. | misc | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/the-post-millennial-hack-leaked-data-impacting-26-million-people/ | https://www.mediaite.com/politics/conservative-news-websites-hacked-replaced-with-page-leaking-private-information/ | 475 | ||||
| Dell | 49,000,000 | 2024 | Apr 24 | The Dell data breach by a threat actor scraped 49m customer records via a partner portal API accessed as a fake company. Data includes customer names, order info, warranty details, service tags, and locations. | tech | oops! | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/dell-api-abused-to-steal-49-million-customer-records-in-data-breach/ | 474 | |||||
| UK Ministry of Defense | 270,000 | 2024 | May 24 | A threat actor breached the Ministry of Defence, accessing the Armed Forces payment network. Compromised data includes personal and banking details and a few addresses of active, reserve, and some retired personnel. | government | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/uk-confirms-ministry-of-defence-payroll-data-exposed-in-data-breach/ | https://www.theguardian.com/technology/article/2024/may/06/uk-military-personnels-data-hacked-in-mod-payroll-breach | 473 | ||||
| Dropbox | Dropbox Sign | 100,000 | 2024 | Apr 24 | A Dropbox service which allows online document signatures, was breached. Hackers accessed authentication tokens, MFA keys, hashed passwords, and customer information. | tech | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/dropbox-says-hackers-stole-customer-data-auth-secrets-from-esignature-service/ | 472 | ||||
| Panda Restaurants | 47,000 | 2024 | Mar 24 | Information exposed includes names or other personal identifiers and their driver's license numbers or ID card numbers for an undisclosed cohort. | retail | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/panda-restaurants-discloses-a-data-breach-after-corporate-systems-hack/ | 471 | |||||
| Philadelphia Inquirer | 25,000 | 2023 | May 23 | A breach at this daily newspaper exposed names, personal identifiers, and financial account or credit/debit card numbers with security codes, passwords, or PINs. The Cuba ransomware gang claimed responsibility. | misc | hacked | 4 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/philadelphia-inquirer-data-of-over-25-000-people-stolen-in-2023-breach/ | 470 | |||||
| French government | 43,000,000 | 2024 | Feb 24 | A breach in a French government department - responsible for registering and assisting unemployed people - exposed 20 years of personal data, including names, birthdates, Social Security numbers, travel IDs, emails, postal addresses, and phone numbers. | government | hacked | 2 | 43m | The Register | https://www.theregister.com/2024/03/14/mega_data_breach_at_french/ | 469 | ||||
| USG | University System of Georgia | 800,000 | 2023 | May 24 | USG, operating 26 public colleges and universities in Georgia, was compromised in the 2023 Clop MOVEit attacks, which impacted thousands of organizations worldwide. Data included full/partial SSNs, birthdates, bank account numbers, and tax documents with Tax IDs. | government | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/university-system-of-georgia-800k-exposed-in-2023-moveit-attack/ | https://www.usg.edu/news/release/notice_of_data_breach | 468 | |||
| Ohio Lottery | 538,000 | 2023 | Dec 24 | The DragonForce ransomware gang claimed responsibility for the Christmas Eve attack on the Ohio Lottery. They accessed names, SSNs, and other personal identifiers of affected individuals. | gaming | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/ohio-lottery-ransomware-attack-impacts-over-538-000-individuals/ | 467 | |||||
| OmniVision | 100,000 | 2023 | Sep 24 | The Cactus ransomware gang claimed an attack, leaking passport scans, NDAs, contracts, and confidential documents from OmniVision, a subsidiary of Will Semiconductor, designs imaging sensors for various devices. | tech | hacked | 3 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/omnivision-discloses-data-breach-after-2023-ransomware-attack/ | 466 | |||||
| Western Sydney University | 7,500 | 2023 | May 24 | Hackers had accessed the University's Microsoft Office 365 environment, including email accounts and SharePoint files. | academia | hacked | 1 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/western-sydney-university-data-breach-exposed-student-data/ | 465 | |||||
| AT&T | 73,000,000 | 2024 | Apr 24 | Sensitive 2019 data from 7.6m current AT&T account holders and approximately 65.4m former account holders. Emails, passcodes, social security numbers. | telecoms | hacked | 4 | 73m | Ars Technica | https://arstechnica.com/tech-policy/2024/04/att-acknowledges-data-leak-that-hit-73-million-current-and-former-users/ | 464 | ||||
| Irish towing company | 512,000 | 2023 | Oct 23 | The driving licences and payment card etails of thousands of motorists who had vehicles towed on behalf of the Irish police | transport | poor security | 3 | Irish independent | https://www.independent.ie/irish-news/thousands-of-drivers-have-sensitive-data-exposed-to-hackers-in-major-it-breach/a1379036136.html | 463 | |||||
| Maine Government | 1,300,000 | 2023 | May 23 | Russian ransomware group Clop stole names, dates of birth, Social Security numbers, driver’s license and other state or taxpayer identification numbers. Some individuals had medical and health insurance information taken. | government | hacked | 4 | Tech Crunch | https://techcrunch.com/2023/11/09/maine-government-data-breach-clop-ransomware/ | 462 | |||||
| Welltok | 8,500,000 | 2023 | Nov 23 | Patient data was exposed during the breach, including full names, email addresses, physical addresses, and telephone numbers. For some, it also includes Social Security Numbers (SSNs), Medicare/Medicaid ID numbers, and certain Health Insurance information. | health | hacked | 4 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/welltok-data-breach-exposes-data-of-85-million-us-patients/ | 461 | |||||
| Maximus | 10,000,000 | 2023 | Jul 23 | Exploit of a zero-day flaw in the MOVEit file transfer application. Data stolen included social security numbers, protected health information. | government | hacked | 4 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/8-million-people-hit-by-data-breach-at-us-govt-contractor-maximus/ | 460 | |||||
| Okta | 134 | 2023 | Nov 23 | Names and email addresses of customers of the identity security company. 134 of the company's 18,400 clients were impacted, but that only five instances of successful session hijacking were logged | tech | hacked | 1 | Okta | https://sec.okta.com/harfiles | 459 | |||||
| Delta Dental | 7,000,000 | 2023 | May 23 | The dental insurance company suffered unauthorized access by threat actors through the MOVEit file transfer software application exposing full credit card details of customers | health | hacked | 3 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/delta-dental-of-california-data-breach-exposed-info-of-7-million-people/ | 458 | |||||
| Xfinity | 36,000,000 | 2023 | Oct 23 | Hackers using the CitrixBleed vulnerability accessed acocunt details like name, last four digits of social security numbers and hashed passwords | telecoms | hacked | 2 | Tech Crunch | https://techcrunch.com/2023/12/19/comcast-xfinity-hackers-36-million-customers/ | 457 | |||||
| Atlassian | 13,200 | 2023 | Feb 23 | SiegedSec hacked Atlassian, the owner of Trello and other apps, via a third party office app, leaking employee details and office floor plans after an employee publicly shared credentials. | tech | oops! | y | 1 | Cyberscoop | https://cyberscoop.com/atlassian-hack-employee-data-seigedsec/ | 456 | ||||
| 100,000 | 2023 | Feb 23 | A phishing attack granted access to Reddit's internal documents and systems, but without breaching main production systems, user passwords, or accounts. | web | hacked | y | 1 | Forbes | https://www.forbes.com/sites/daveywinder/2023/02/10/reddit-confirms-it-was-hacked-recommends-users-set-up-2fa/ | 455 | |||||
| Go Daddy | 1,228,000 | 2022 | Dec 23 | GoDaddy faced a multi-year breach (2020-2022) by a single intruder, resulting in stolen source code, user credentials, malware installation, and user redirects to malicious sites. WordPress customers’ email addresses, usernames, passwords, and even their SSL private keys were stolen. | web | hacked | y | 3 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/godaddy-hackers-stole-source-code-installed-malware-in-multi-year-breach/ | 454 | ||||
| MGM | 10,600,000 | 2023 | Sept 23 | AlphV and Scattered Spider's cyberattack on MGM caused slot machine errors and hotel queues in Las Vegas, stealing pre-March 2019 customer data and inflicting a $100m loss on the company's Q3 results. MGM declined to say if any ransom was paid. | retail | hacked | y | 3 | Reuters | https://www.reuters.com/business/mgm-expects-cybersecurity-issue-negatively-impact-third-quarter-earnings-2023-10-05/ | 453 | ||||
| Uber | 20,000,000 | 2022 | Dec 22 | Data on 77,000 Uber employees and internal reports were leaked on forums. While Uber denied ownership of the implicated source code, the breach stemmed from their third-party vendor, Teqtivity, which had a security incident earlier that year. | transport | hacked | y | 1 | Restore Privacy | https://restoreprivacy.com/uber-data-leak-breach-third-party-vendor-hacked/ | 452 | ||||
| X (Twitter) | 200,000,000 | 2023 | Jan 23 | From Nov 2022 to Jan 2023, over 200 million Twitter users' data, including emails and names, was exposed due to repeated security flaw exploitations and posted on hacker forums. But no highly sensitive data was revealed. | web | poor security | 1 | 200m | Firewall Times | https://firewalltimes.com/twitter-data-breach-timeline/ | 451 | ||||
| CommuteAir | 1,500,000 | 2023 | Jan 23 | Swiss hacker Maia Arson Crimew, stumbled upon a misconfigured AWS server containing TSA's No Fly list and exposed ~250,000 'selectees' (selectees are automatically chosen for additional screening each time they fly) to a hacker forum. | transport | hacked | y | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/us-no-fly-list-shared-on-a-hacking-forum-government-investigating/ | 450 | ||||
| Yum! | 10,000,000 | 2023 | Jan 23 | The brand owner of KFC, Pizza Hut, and Taco Bell fast food chains saw an undisclosed amount of personal user information stolen during a ransomware attack: names, driver's license numbers, and other ID card numbers. ~300 restaurants were shut down in the UK due to IT system disruptions caused by the attack. | retail | hacked | y | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/kfc-pizza-hut-owner-discloses-data-breach-after-ransomware-attack/ | 449 | ||||
| PharMerica | 5,800,000 | 2023 | May 23 | Full names, addresses, dates of birth, social security numbers (SSNs), medications, and health insurance information of 5,815,591 people. | health | hacked | 4 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/ransomware-gang-steals-data-of-58-million-pharmerica-patients/ | 448 | |||||
| NATO | 8,000 | 2023 | Jul 23 | Hacktivist group, SiegedSec, claimed to have broken into six NATO web portals and stolen >3,000 files and 9GB of data. Threat intel biz CloudSEK analysis revealed 20 unclassified documents and 8,000 personnel records with names, job titles, email addresses, home addresses, and photos. | government | hacked | y | 4 | The Register | https://www.theregister.com/2023/10/04/nato_data_attack/#:~:text=On%20Sunday%2C%20the%20SiegedSec%20crew,)%3B%20the%20Communities%20of%20Interest | 447 | ||||
| Topgolf Callaway | 1,114,954 | 2023 | Aug 23 | Only full names, shipping and email addresses, phone numbers, order histories, account passwords and answers to security questions were exposed. | retail | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/golf-gear-giant-callaway-data-breach-exposes-info-of-11-million/ | 446 | |||||
| Sony | 6,800 | 2023 | Oct 23 | Personal information belonging to current and former employees and their family members was stolen by Clop in a ransomware attack. Details unrevealed by Sony. | tech | hacked | 2 | The Verge | https://www.theverge.com/2023/10/5/23905370/sony-interactive-entertainment-security-breach-confirmation | https://www.bleepingcomputer.com/news/security/sony-confirms-data-breach-impacting-thousands-in-the-us/ | 445 | ||||
| 23andMe | 6,900,000 | 2023 | Oct 23 | Hackers accessed the genetic site's user data via login guesses and information from DNA relatives (users opt into sharing info through DNA relatives for others to see). Stolen data included personal and some genetic ancestry and health details. After two breaches, one unverified, 23andMe now faces legal action. | health | hacked | y | 4 | 6.9m | Tech Crunch | https://arstechnica.com/tech-policy/2023/12/hackers-stole-ancestry-data-of-6-9-million-users-23andme-finally-confirmed/ | https://www.bleepingcomputer.com/news/security/23andme-hit-with-lawsuits-after-hacker-leaks-stolen-genetics-data/ | 444 | ||
| Optus | 9,700,000 | 2022 | Sept 2022 | The telecom company faced a 'sophisticated attack' exposing ~10 million accounts including personal details (passport, driver’s licence & Medicare numbers). Hacker demanded $1m ransom but later apologized and claimed data deletion, unverified. | telecoms | hacked | 4 | The Guardian | https://www.theguardian.com/business/2022/sep/29/optus-data-breach-everything-we-know-so-far-about-what-happened | https://www.optus.com.au/about/media-centre/media-releases/2022/09/optus-notifies-customers-of-cyberattack | 443 | ||||
| PayPal | 34942 | 2023 | Dec 22 | PayPal's breach involved unauthorized account access using credential stuffing (exploiting users reusing the same password for multiple accounts). It wasn't from a direct security lapse and hackers couldn't transact. PayPal reset passwords. | finance | hacked | 2 | Office of the Maine Attorney General | https://apps.web.maine.gov/online/aeviewer/ME/40/766753f1-f9c7-4dc5-9a5c-fe0f3ff51c06.shtml | https://www.bleepingcomputer.com/news/security/paypal-accounts-breached-in-large-scale-credential-stuffing-attack/ | 442 | ||||
| Acer | 10,000,000 | 2023 | Mar 23 | Acer suffered a data breach when a server was hacked, with threat actors selling 160GB of stolen data. The company said the incident hadn't impacted customer info. | tech | hacked | 1 | Slashdot | https://it.slashdot.org/story/23/03/07/1459230/acer-confirms-breach-after-hacker-offers-to-sell-stolen-data?utm_source=feedly1.0mainlinkanon&utm_medium=feed | https://www.bleepingcomputer.com/news/security/acer-confirms-breach-after-160gb-of-data-for-sale-on-hacking-forum/ | 441 | ||||
| MSI | 10,000,000 | 2023 | Apr 23 | Money Message ransomware group claims to have stolen MSI's source code, demanding $4 million to prevent leaks. MSI downplays impact and hasn't confirmed paying ransom, assuring no user data was affected but advises software downloads only from official sources. | tech | hacked | 1 | Slashdot | https://it.slashdot.org/story/23/04/07/152242/msi-confirms-breach-as-ransomware-gang-claims-responsibility?utm_source=feedly1.0mainlinkanon&utm_medium=feed | https://uk.pcmag.com/security/146322/msi-confirms-breach-as-ransomware-gang-claims-responsibility | 440 | ||||
| T-Mobile | 37,000,000 | 2023 | Jan 23 | T-Mobile's system was exploited by 'bad actors' from November 2022 to January 2023, exposing customer data. It's their ninth hack since 2018, with a 2021 breach affecting 49 million customers. | telecoms | hacked | 2 | Ars Technica | https://arstechnica.com/information-technology/2023/05/t-mobile-discloses-2nd-data-breach-of-2023-this-one-leaking-account-pins-and-more/ | 439 | |||||
| T-Mobile | 836 | 2023 | Mar 23 | T-Mobile faced its second 2023 data breach, exposing PINs and data from Feb to Mar. Though way smaller than the first 2023 breach (only affecting 836 customers), it adds to the $350mil 2021 settlement and erodes customer trust. | telecoms | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/t-mobile-discloses-second-data-breach-since-the-start-of-2023/ | 438 | |||||
| ChatGPT | 101,000 | 2023 | Mar 23 | Over 101,000 ChatGPT accounts were stolen by malware last year. Breakdown: Asia-Pacific 40,999, Middle-East/Africa 24,925, Europe 16,951, Latin America 12,314, North America 4,737. Malware extracts browser credentials from SQLite databases, using CryptProtectData function to decrypt stored data. | tech | hacked | y | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/over-100-000-chatgpt-accounts-stolen-via-info-stealing-malware/ | 437 | ||||
| TIAA | The Teachers Insurance and Annuity Association of America | 2,300,000 | 2023 | May 23 | This US retirement fund for teachers faced a data breach exposing client details. A former teacher-client is suing for inadequate cybersecurity and leaving data unencrypted on a vulnerable platform. | finance | hacked, poor security | 2 | ClassAction | https://www.classaction.org/news/teachers-insurance-and-annuity-association-of-america-hit-with-class-action-over-may-2023-data-breach#:~:text=Teachers%20Insurance%20and%20Annuity%20Association%20of%20America%20faces%20a%20class,of%20approximately%202.3%20million%20individuals. | https://news.slashdot.org/story/23/06/30/2038234/schools-say-us-teachers-retirement-fund-was-breached-by-moveit-hackers?utm_source=feedly1.0mainlinkanon&utm_medium=feed | 436 | |||
| Microsoft | 30,000,000 | 2023 | Jun 23 | Anonymous Sudan hacked Microsoft, accessed customer data, and caused outages. They offered the database for $50,000. But Microsoft claims no evidence of compromised customer data. | web | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/microsoft-denies-data-breach-theft-of-30-million-customer-accounts/ | 435 | |||||
| Microsoft | 10,000,000 | 2023 | May 23 | China-backed hackers stole a cryptographic key from Microsoft, undetected for a month, accessing 25 organizations, including government. Microsoft's postmortem cites past system vulnerabilities. | web | hacked | 3 | unknown | NYT | https://www.nytimes.com/2023/07/11/us/politics/china-hack-us-government-microsoft.html?smid=nytcore-ios-share | https://www.wired.com/story/china-backed-hackers-steal-microsofts-signing-key-post-mortem/ | 434 | |||
| Roblox | 4,000 | 2020 | Dec 20 | Data identifying Roblox creators was breached at a developers' conference, undisclosed for 2 years due to a third-party security issue. | gaming | poor security | 2 | The Verge | https://www.theverge.com/2023/7/21/23802742/roblox-data-breach-leak-developer-personal-information-exposed | 433 | |||||
| Discord.io | 760,000 | 2023 | Aug 23 | Unidentified person listed user data for sale on darknet. Discord.io enables custom Discord invites. | gaming | hacked | 1 | Stackdiary | https://stackdiary.com/the-data-of-760000-discord-io-users-was-put-up-for-sale-on-the-darknet// | 432 | |||||
| Clorox | 10,000,000 | 2023 | Aug 23 | Clorox detected unauthorized IT activity in August 2023. By September, the contained hack led to slower production and a 2% stock drop. Specific affected files undisclosed | retail | hacked | 1 | unknown | Slashdot | https://it.slashdot.org/story/23/10/04/1917217/clorox-security-breach-linked-to-group-behind-casino-hacks?utm_source=feedly1.0mainlinkanon&utm_medium=feed | 431 | ||||
| Latitude Financial | 14,000,000 | 2023 | Apr 23 | 14 million customer records, including driver's licence numbers, passport numbers and financial statements, stolen in a cyber-attack that was worse than the company initially reported. | finance | hacked | 2 | Privacy Commissioner | https://www.privacy.org.nz/publications/statements-media-releases/new-zealands-biggest-data-breach-shows-retention-is-the-sleeping-giant-of-data-security/ | 430 | |||||
| Toyota | 296,019 | 2022 | Oct 22 | An access key to a data server storing customer email addresses and management numbers was mistakenly published publically on GitHub for five years. | transport | poor security | 2 | Slashdot | https://yro.slashdot.org/story/22/10/10/2032250/toyota-discloses-data-leak-after-access-key-exposed-on-github?utm_source=feedly1.0mainlinkanon&utm_medium=feed | 429 | |||||
| Shein | 39,000,000 | 2022 | Oct 22 | Online fast fashion retailer suffered a breach of its login credentials in 2018 but failed to notify its customers | retail | hacked | 2 | Tech Crunch | https://techcrunch.com/2022/10/13/shein-zoetop-fined-1-9m-data-breach/?guccounter=1 | 428 | |||||
| Indonesia's health agency | BPJS Kesehatan | 279,000,000 | 2022 | May 21 | The ID numbers, salary and phone numbers of every single man, woman and child in the country was stolen. | government | hacked | y | 3 | Kr Asia | https://kr-asia.com/shoddy-data-protection-in-indonesia-threatens-personal-security-of-citizens | 427 | |||
| CoinSquare | 50,000 | 2022 | Nov 22 | Major Canadian Crypto Exchange. company claims customer assets are “secure in cold storage and are not at risk.” | tech | hacked | 1 | Coin Desk | https://www.coindesk.com/tech/2022/11/26/major-canadian-crypto-exchange-coinsquare-says-client-data-breached/ | 426 | |||||
| Indian Railways | 30,000,000 | 2022 | Dec 22 | Stolen data includes usernames, emails, phone numbers, gender, city, state, invoices | transport | hacked | 2 | Techlo Media | https://techlomedia.in/2022/12/data-of-30-million-indian-railways-users-is-up-for-sale-on-a-dark-forum-96589/ | 425 | |||||
| Indonesian SIM cards | 1,000,000,000 | 2022 | Oct 22 | A vast data hack of 1.3 bn SIM registrations evealing national identity numbers, phone numbers, and more. | telecoms | hacked | 3 | 1.3bn | Rest of World | https://restofworld.org/2022/indonesia-hacked-sim-bjorka/ | 424 | ||||
| LastPass | 33,000,000 | 2022 | Aug 22 | Popular password manager breached; basic account info exposed. Sensitive vault data like usernames and passwords remained safely encrypted. | web | hacked | 2 | Tech Crunch | https://techcrunch.com/2022/12/14/parsing-lastpass-august-data-breach-notice/ | https://www.forbes.com/sites/daveywinder/2023/03/03/why-you-should-stop-using-lastpass-after-new-hack-method-update/ | 423 | ||||
| 200,000,000 | 2022 | Dec 22 | Over 200 million Twitter emails were stolen and posted online, possibly before Musk's 2022 takeover. | web | hacked | 1 | Wired | https://www.wired.com/story/twitter-leak-200-million-user-email-addresses/ | 422 | ||||||
| City of Amagasaki, Japan | 500,000 | 2022 | Jun 2022 | An unnamed government official lost his bag after a night's drinking. It contained a USB stick with sensitive data of the entire city's residents. USB stick was encrypted and passworded. | government | oops! | 3 | BBC | https://www.bbc.co.uk/news/world-asia-61921222 | 421 | |||||
| Shanghai Police | 500,000,000 | 2022 | Jul 2022 | A database containing records of over a billion Chinese civilians – allegedly stolen from the Shanghai Police. Addresses, police records and national ID numbers. Potentially one of the largest data breaches in history. Details repressed and censored by Chinese media. | government | hacked | 5 | "one billion" | The Register | https://www.theregister.com/2022/07/05/shanghai_police_database_for_sell/ | 420 | ||||
| 5,400,000 | 2021 | Dec 2021 | Zero day vulnerability allowed a threat actor to create profiles of 5.4 million Twitter users inc. a verified phone number or email address, and scraped public information, such as follower counts, screen name, login name, etc | web | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/twitter-confirms-zero-day-used-to-expose-data-of-54-million-accounts/ | 419 | ||||||
| Plex | 15,000,000 | 2022 | Aug 2022 | Intruders access password data, usernames, and emails for at least half of its 30 million users. | web | hacked | 1 | Ars technica | https://arstechnica.com/information-technology/2022/08/plex-imposes-password-reset-after-hackers-steal-data-for-15-million-users/ | 418 | |||||
| Dubai Real Estate Leak | 800,000 | 2022 | May 2022 | Data leak exposes how criminals, officials, and sanctioned politicians poured money into Dubai real estate including more than 100 members of Russia's political elite, public officials, or businesspeople close to the Kremlin, as well as dozens of Europeans implicated in money laundering and corruption | finance | inside job | y | 1 | E24 | https://e24.no/internasjonal-oekonomi/i/Bj97B0/dubai-uncovered-data-leak-exposes-how-criminals-officials-and-sanctioned-politicians-poured-money-into-dubai-real-estate | 417 | ||||
| Heroku | 50,000 | 2022 | Apr 2022 | A compromised token was used by attackers to exfiltrate customers' hashed and salted passwords from "a database." on the Salesforce-owned cloud platform. | tech | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/heroku-admits-that-customer-credentials-were-stolen-in-cyberattack/ | 416 | |||||
| Mailchimp | 106,586 | 2022 | Apr 2022 | Hackers gained access to internal customer support and account management tools of the email marketing company to steal audience data and conduct phishing attacks. | tech | hacked | 1 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/hackers-breach-mailchimps-internal-tools-to-target-crypto-customers/ | 415 | |||||
| PayHere | 1,580,249 | 2022 | Mar 2022 | Sri Lankan payment gateway PayHere suffered a data breach exposing more than 65GB of payment records including over 1.5M unique email addresses. (IP and physical addresses, names, phone numbers, purchase histories and partially obfuscated credit card data (card type, first 6 and last 4 digits plus expiry date). | finance | hacked | 3 | Pay Here | https://blog.payhere.lk/ensuring-integrity-on-payhere-cybersecurity-incident/ | 414 | |||||
| CDEK | 18,218,203 | 2022 | Mar 2022 | UNVERIFIED. Russian courier service CDEK was hacked by Ukrainian hacker group "IT Army" - including 19M unique email addresses along with names and phone numbers. | retail | hacked | 3 | 19m | Have I Been Pwned | https://twitter.com/haveibeenpwned/status/1504343470072549377?lang=en | 413 | ||||
| Washington State Dpt of Licensing | 257,000 | 2022 | Feb 2022 | The Washington State Department of Licensing said the personal information of potentially millions of licensed professionals may have been exposed after it detected suspicious activity on its online licensing system. | government | hacked | 3 | Seattle Times | https://www.seattletimes.com/business/breach-at-state-licensing-agency-may-have-exposed-data-from-1000s-of-professionals/ | 412 | |||||
| Red Cross | 500,000 | 2022 | Jan 2022 | A network intrusion at the International Committee for the Red Cross (ICRC) in January led to the theft of personal information on more than 500,000 people receiving assistance from the group. KrebsOnSecurity has learned that the email address used by a cybercriminal actor who offered to sell the stolen ICRC data also was used to register multiple domain names the FBI says are tied to a sprawling media influence operation originating from Iran. | misc | hacked | 4 | Arsetechnia | https://arstechnica.com/information-technology/2022/01/red-cross-hack-compromises-the-personal-data-of-515k-highly-vulnerable-people/ | 411 | |||||
| Open Subtitles | 100,000 | 2022 | Jan 2022 | web | hacked | 1 | Open Subtitles | https://forum.opensubtitles.org/viewtopic.php?t=17685 | 410 | ||||||
| FlexBooker | 3,700,000 | 2022 | Jan 2022 | appointment scheduling service | web | hacked | 3 | 3.7m | Bleeping Computer | https://www.bleepingcomputer.com/news/security/flexbooker-discloses-data-breach-over-37-million-accounts-impacted/ | 409 | ||||
| LINE Pay | 133,000 | 2021 | Dec 2021 | finance | poor security | 2 | The Register | https://www.theregister.com/2021/12/07/line_pay_leaks_around_133000/ | 408 | ||||||
| Robinhood | 5,000,937 | 2021 | Nov 2021 | a malicious hacker had socially engineered a customer service representative over the phone November 3 to get access to customer support systems. That allowed the hacker to obtain customer names and email addresses, but also the additional full names, dates of birth and ZIP codes of 310 customers. | finance | hacked | 2 | 5m | Tech Crunch | https://techcrunch.com/2021/11/09/robinhood-data-breach/?guccounter=1 | 407 | ||||
| GoDaddy | 1,200,000 | 2021 | Nov 2021 | Security Incident Affecting Managed WordPress Servic | web | hacked | 1 | SEC | https://techcrunch.com/2021/11/09/robinhood-data-breach/?guccounter=1 | 406 | |||||
| Travelio | 471,376 | 2021 | Nov 2021 | The Indonesian real estate website Travelio suffered a data breach of over 470k customer accounts. The data included email addresses, names, password hashes, phone numbers and for some accounts, dates of birth, physical address and Facebook auth tokens. | misc | hacked | 2 | 470K | HaveIBeenPwned | https://www.riskbasedsecurity.com/2021/12/14/dark-web-roundup-november-2021/ | 405 | ||||
| Acer | 3,000,000 | 2021 | Oct 2021 | tech | hacked | 1 | Hot Hardware | https://hothardware.com/news/acer-confirms-hacked-again-60gb-stolen-customer-data | 404 | ||||||
| Brewdog | 200,000 | 2021 | Oct 2021 | BrewDog, one of the world's largest craft beer brewers, has exposed personally identifiable information (PII) belonging to more than 200,000 of its shareholders and customers, | retail | poor security | 1 | Tech Radar | https://www.techradar.com/news/brewdog-exposes-data-of-200000-customers-and-shareholders | 403 | |||||
| Experian SA | South Africa | 24,000,000 | 2020 | Jul 2020 | Handed over personal information of their South African customers to a fraudulent client. | web | oops! | 3 | Uni of Hawaii | https://westoahu.hawaii.edu/cyber/global-weekly-exec-summary/experian-security-breach-in-south-africa/#:~:text=Experian%20disclosed%20the%20data%20breach,local%20businesses%20(Cimpanu%202020). | 402 | ||||
| Nvidia | 100,000 | 2021 | Mar 2021 | tech | hacked | 2 | CNN Business | https://edition.cnn.com/2022/03/01/tech/nvidia-information-leak/ | https://it.slashdot.org/story/22/03/01/1523248/nvidia-says-employee-company-information-leaked-online-after-cyber-attack?utm_source=feedly1.0mainlinkanon&utm_medium=feed | 401 | |||||
| Okta | 100,000 | 2021 | Jan 2021 | Identity and access management provider Okta | tech | hacked | 1 | The Verge | https://www.theverge.com/2022/4/20/23034360/okta-lapsus-hack-investigation-breach-25-minutes | https://twitter.com/BillDemirkapi/status/1508527487655067660/ | 399 | ||||
| Royal Enfield | 420,873 | 2020 | Jan 2020 | Motorcycle maker Royal Enfield left a database publicly exposed that resulted in the inadvertent publication of over 400k customers. (Email and physical addresses, names, motorcycle information, social media profiles, passwords, and other personal information) | transport | poor security | 3 | The Quint | https://www.thequint.com/news/india/royal-enfield-exposed-database-containing-450000-customer-data-cyber-security-expert | 398 | |||||
| Avvo | 4,101,101 | 2019 | Dec 2019 | A data breach of the lawyer directory service released 4.1M unique email addresses alongside SHA-1 hashes, most likely representing user passwords. | misc | hacked | 1 | 4.1m | HaveIBeenPwned | https://www.troyhunt.com/breach-disclosure-blow-by-blow-heres-why-its-so-hard/ | 397 | ||||
| Aimware | 305,470 | 2019 | May 2019 | Video game cheats website "Aimware" suffered a data breach of subscribers' personal information (email and IP addresses, usernames, forum posts, private messages, website activity and passwords stored as salted MD5 hashes) | gaming | hacked | 3 | HaveIBeenPwned | 396 | ||||||
| Twitch | 10,000,000 | 2021 | Oct 2021 | Full source code breach of the streaming gaming site revealed a trove of internal data & documents including core config packages, devtools, and payments to top streamers. | gaming | hacked | y | 4 | unknown | BBC | https://www.bbc.co.uk/news/technology-58817658 | 395 | |||
| Syniverse | 500,000,000 | 2021 | Sep 2021 | "A company that is a critical part of the global telecommunications infrastructure used by AT&T, T-Mobile, Verizon and several others around the world such as Vodafone and China Mobile, quietly disclosed that hackers were inside its systems for years, impacting more than 200 of its clients and potentially millions of cellphone users worldwide." | telecoms | hacked | 4 | unknown | Vice | https://www.vice.com/en/article/z3xpm8/company-that-routes-billions-of-text-messages-quietly-says-it-was-hacked | 394 | ||||
| Pandora Papers | 11,900,000 | 2021 | Oct 2021 | Millions of documents reveal offshore deals and assets of more than 100 billionaires, 30 world leaders and 300 public officials | government | hacked | y | 4 | Guardian | https://www.theguardian.com/news/2021/oct/03/pandora-papers-biggest-ever-leak-of-offshore-data-exposes-financial-secrets-of-rich-and-powerful | 393 | ||||
| Neiman Marcus | 4,600,000 | 2021 | Sep 2021 | Occurred sometime in May 2020 after "an unauthorized party" obtained the personal information of some Neiman Marcus customers from their online accounts. | retail | hacked | 3 | Ars Technica | https://arstechnica.com/information-technology/2021/10/neiman-marcus-data-breach-impacts-4-6-million-customers/ | 392 | |||||
| Epik | 15,000,000 | 2021 | Sep 2021 | An Internet-services company for concealing online identities, popular with the far right | retail | hacked | y | 5 | Ars Technica | https://arstechnica.com/information-technology/2021/09/epik-data-breach-impacts-15-million-users-including-non-customers/ | 391 | ||||
| Thailand visitors | 100,000,000 | 2021 | Sep 2021 | Any foreigner who has travelled to Thailand in the last decade ‘might have had their information exposed’ | government | poor security | 2 | 100m | South China Morning Post | https://www.scmp.com/news/asia/southeast-asia/article/3149475/details-some-100-million-visitors-thailand-exposed-online | 390 | ||||
| T-Mobile | 76,000,000 | 2021 | Aug 2021 | Exposed the names, date of birth, Social Security number and driver’s license/ID information of more than 40 million current, former or prospective customers who applied for credit with the company. T-mobile paid a $500m settlement. | telecoms | hacked | 3 | Krebson Security | https://krebsonsecurity.com/2021/08/t-mobile-breach-exposed-ssn-dob-of-40m-people/ | 389 | |||||
| Contact tracing data | 38,000,000 | 2021 | Aug 2021 | A thousand web apps mistakenly exposed 38 million records on the open internet, including data from a number of Covid-19 contact tracing platforms, vaccination sign-ups, job application portals, and employee databases. | telecoms | hacked | 3 | 38m | Wired | https://www.wired.com/story/microsoft-power-apps-data-exposed/ | 388 | ||||
| Estonian gov | 280,000 | 2021 | Jul 2021 | A hacker was able to obtain over 280,000 personal identity photos following an attack on the state information system last Friday. | government | hacked | 4 | News ERR | https://news.err.ee/1608291072/hacker-downloads-close-to-300-000-personal-id-photos | 387 | |||||
| Guntrader | UK firearms sales website | 111,000 | 2021 | Jul 2021 | Criminals have hacked into a Gumtree-style website used for buying and selling firearms, making off with a 111,000-entry database containing names, mobile phone numbers, email addresses, user geolocation data, and more including bcrypt-hashed passwords used by gun shops across the UK. | retail | hacked | 2 | The Register | https://www.theregister.com/2021/07/23/guntrader_hacked_111k_users_sql_database/ | 386 | ||||
| 700,000,000 | 2021 | Jul 2021 | The hacker appears to have misused the official LinkedIn API to scrape the data, the same method used in a similar breach back in April. User details, but no passwords. | web | hacked | 1 | 700m | 9 to 5 mac | https://9to5mac.com/2021/06/29/linkedin-breach/ | 385 | |||||
| VW | 3,300,000 | 2021 | Jun 2021 | Phone numbers, email addresses and some sensitive credit data. Nearly all those impacted were current or potential customers of Audi, one of the German automaker's luxury brands | transport | hacked | 2 | Reuters | https://www.reuters.com/business/autos-transportation/vw-says-data-breach-vendor-impacted-33-million-people-north-america-2021-06-11/ | 384 | |||||
| MacDonalds | 10,000,000 | 2021 | Jun 2021 | Unknown detail | retail | hacked | 2 | unknown | Wall St Journal | https://www.wsj.com/articles/mcdonalds-hit-by-data-breach-in-south-korea-taiwan-11623412800 | 383 | ||||
| Air India | 4,500,000 | 2021 | May 2021 | Passenger’s name, date of birth, contact information, passport information, ticket information, frequent flyer data and credit card information. | transport | hacked | 2 | Indian Express | https://indianexpress.com/article/explained/air-india-sita-data-breach-explained-7325501/ | 382 | |||||
| Omiai dating app | Japanese dating app | 1,710,000 | 2021 | May 2021 | Addresses and dates of birth from identification, including passports, drivers’ licenses and health insurance cards, provided to the company. | web | hacked | 2 | Japan Times | https://www.japantimes.co.jp/news/2021/05/22/business/tech/omiai-dating-app-hack-japan/ | 381 | ||||
| Amazon Reviews | 13,124,962 | 2021 | May 2021 | Database exposing an organized fake reviews scam affecting Amazon. The server contained a treasure trove of direct messages between Amazon vendors and customers willing to provide fake reviews in exchange for free products | web | poor security | y | 2 | Safety Detectives | https://www.safetydetectives.com/blog/amazon-reviews-leak-report/ | 380 | ||||
| Peloton | 3,000,000 | 2021 | May 2021 | tech | poor security | 2 | Ars Technica | https://arstechnica.com/gadgets/2021/05/peloton-takes-3-months-to-fix-flaw-that-exposed-users-private-information/#p3 | 379 | ||||||
| Digital Ocean | 10,000,000 | 2021 | Apr 2021 | tech | poor security | unknown | Tech Crunch | https://techcrunch.com/2021/04/28/digitalocean-customer-billing-data-breach/ | 378 | ||||||
| Park Mobile | mobile parking app | 21,000,000 | 2021 | Apr 2021 | Customer email addresses, dates of birth, phone numbers, license plate numbers, hashed passwords and mailing addresses. | transport | hacked | 2 | Krebson Security | https://krebsonsecurity.com/2021/04/parkmobile-breach-exposes-license-plate-data-mobile-numbers-of-21m-users/ | 377 | ||||
| Ubiquiti | 16,000,000 | 2021 | Feb 2021 | Unknown amount of user data breached | tech | hacked | 2 | ZDNet | https://www.zdnet.com/article/ubiquiti-tells-customers-to-change-passwords-after-security-breach/ | 376 | |||||
| Meet Mindful | 2,240,000 | 2021 | Feb 2021 | Dating site user data includes real names, phone numbers, Facebook account codes, latitude & longtitude. Thankfully private messages were not leaked. | tech | hacked | 4 | ZDnet | https://www.zdnet.com/article/hacker-leaks-data-of-2-28-million-dating-site-users/ | 375 | |||||
| Experian Brazil | 220,000,000 | 2021 | Feb 2021 | Details hazy | finance | hacked | 2 | 220m | ZDNet | https://www.zdnet.com/article/experian-challenged-over-massive-data-leak-in-brazil/ | 374 | ||||
| Gab | 4,000,000 | 2021 | Mar 2021 | Over 70GB of data from the far-right social media site was hacked. Alll posts, messages, passwords from all users were breached. | tech | hacked | y | 3 | 100K | Wired | https://www.wired.com/story/gab-hack-data-breach-ddosecrets/ | 373 | |||
| Star Alliance | 16,000,000 | 2021 | Mar 2021 | The Star Alliance of airlines including Singapore Airlines, Lufthansa and United, said on Thursday it had been the victim of a cyber attack leading to a breach of passenger data. Lufthansa, Cathay Pacific and Air New Zealand were also affected. Breached data was limited to "name, tier status and membership number” | transport | hacked | 1 | The Guardian | https://www.theguardian.com/world/2021/mar/05/airline-data-hack-hundreds-of-thousands-of-star-alliance-passengers-details-stolen | 372 | |||||
| 533,000,000 | 2021 | Mar 2021 | Phone numbers, full names, locations, email addresses, and biographical information on 533 million users from 106 countries. Scraped due to a vulnerability "patched in 2019". | tech | hacked | y | 1 | 533m | Business Insider | https://www.businessinsider.com/stolen-data-of-533-million-facebook-users-leaked-online-2021-4?r=US&IR=T | 371 | ||||
| Ledger | 270,000 | 2020 | Dec 2020 | A threat actor has leaked the stolen email and mailing addresses for Ledger cryptocurrency wallet users on a hacker forum for free. | finance | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/physical-addresses-of-270k-ledger-owners-leaked-on-hacker-forum/ | 370 | |||||
| T-mobile | 200,000 | 2020 | Dec 2020 | The information exposed in this breach includes phone numbers, call records, and the number of lines on an account. | telecoms | hacked | 1 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/t-mobile-data-breach-exposed-phone-numbers-call-records/ | 369 | |||||
| The Hospital Group | 1,000,000 | 2020 | Dec 2020 | Hackers compromised the plastic surgery firm and threatened to release over 900 gigabytes of private surgery photographs. | health | hacked | y | 4 | BBC | https://www.bbc.co.uk/news/technology-55439190 | 368 | ||||
| SolarWinds | 50,000,000 | 2020 | Dec 2020 | Suspected Russian hackers compromised network monitoring software used by the Pentagon, intelligence agencies, nuclear labs and many Fortune 500 companies. A tainted software update acted as a trojan horse. An unknown number of companies and individuals might be affected. | web | hacked | y | 3 | New York Times | https://www.nytimes.com/2020/12/14/us/politics/russia-hack-nsa-homeland-security-pentagon.html | 367 | ||||
| Ho Mobile | 2,500,000 | 2020 | Dec 2020 | Italian mobile operator owned by Vodaphone is now taking the rare step of offering to replace the SIM cards of all affected customers. Data hacked full names, telephone numbers, social security numbers, email addresses, dates and places of birth, nationality, and home addresses. | telecoms | hacked | 2 | ZD Net | https://www.zdnet.com/article/italian-mobile-operator-offers-to-replace-sim-cards-after-massive-data-breach/ | 366 | |||||
| Spotify | 500,000 | 2020 | Dec 2020 | Undisclosed number of users had their email addresses and passwords left open online. Spotify said the vulnerability existed as far back as April 9 but wasn’t discovered until November 12. | web | oops! | 1 | Tech Crunch | https://techcrunch.com/2020/12/10/spotify-resets-user-passwords-after-a-bug-exposed-private-account-information/?guccounter=1&guce_referrer=aHR0cHM6Ly9pdC5zbGFzaGRvdC5vcmcv&guce_referrer_sig=AQAAAMGNMpm00iWQgE4Zhw1q6_5FoeBsJUbWyKEniavHxaZR-X1oBrnXuFtvr9B4IYBK1C6x9AfEqEZwzfJaZhhINvaBZltXd-DF036LVwwnAhWAMQpD98Lahw3sni-Z2bS6qEIjPgodPdZHV3DRJWLrNt0bOoohuh_DWM8-IngVnCl6 | 365 | |||||
| Drizly | 2,400,000 | 2020 | Sep 2020 | Alcohol delivery service hacked with email addresses, DOB, hashed passwords and some home addresses leaked. | web | hacked | 2 | Tech Crunch | https://techcrunch.com/2020/07/28/drizly-data-breach/ | 364 | |||||
| GEDmatch | 1,400,000 | 2020 | Sep 2020 | DNA data on up to 1.4m users of this geneaology site may have been hacked. | misc, health | hacked | y | 5 | New York Times | https://www.nytimes.com/2020/08/01/technology/gedmatch-breach-privacy.html?referringSource=articleShare | 363 | ||||
| Call of Duty / Activision | 500,000 | 2020 | Sep 2020 | Login data for users of the popular video games may have compromised. Activision refutes the claim. | gaming | hacked | 1 | Forbes | https://www.forbes.com/sites/daveywinder/2020/09/21/activision-accounts-hacked-500000-call-of-duty-players-could-be-affected-report/?sh=7ca04e0f7bbe | 362 | |||||
| Zhenhua | 2,400,000 | 2020 | Sep 2020 | Personal details of millions of notable people around the world found in a leaked database compiled by a Chinese tech company with reported links to the country’s military and intelligence networks. Mostly compiled from social media profiles. | misc | oops! | y | 1 | The Guardian | https://www.theguardian.com/world/2020/sep/14/zhenhua-data-full-list-leak-database-personal-details-millions-china-tech-company | 361 | ||||
| Cense AI | 2,500,000 | 2020 | Aug 2020 | Medical records from an artificial intelligence company were left open online. | tech, health | poor security | 4 | PC Mag | https://uk.pcmag.com/encryption/128228/report-ai-company-leaks-over-25m-medical-records | 360 | |||||
| Nintendo | 300,000 | 2020 | Apr 2020 | Unauthorised access to thousands of Nintendo Switch accounts. Hackers were able to use saved payment details to make purchases. | gaming | hacked | 3 | 300K | Tech Crunch | https://techcrunch.com/2020/06/09/nintendo-accounts-affected-breach/?guccounter=1&guce_referrer=aHR0cHM6Ly9nYW1lcy5zbGFzaGRvdC5vcmcvc3RvcnkvMjAvMDYvMDkvMTg0MjIzNy9uaW50ZW5kby1ub3ctc2F5cy0zMDAwMDAtYWNjb3VudHMtYnJlYWNoZWQtYnktaGFja2Vycz91dG1fc291cmNlPXJzczEuMG1haW5saW5rYW5vbiZ1dG1fbWVkaXVtPWZlZWQ&guce_referrer_sig=AQAAAIXC8IvaFgPdt5t-CUm7yPEhKblsmme4097SUtEWdSkjyrdsxVYiQBfbdpekm_Y29T7evb-5zNNl2-ZHfNSmVkKFnE5vClvpvsaPYykOO8WtAX76dZoL2EUkVL8XfmMQBVlNF43T5MATGNeSnwn6Ta6ELVBXnf_ZTsmVaemjk1Vf | 359 | ||||
| Pakistani mobile operators | 115,000,000 | 2020 | Apr 2020 | Personal details stolen from Jazz and other mobile networks were put up for sale for $2.1m in bitcoin. | telecoms | hacked | 2 | 115m | ZDNet | https://www.zdnet.com/article/details-of-44m-pakistani-mobile-users-leaked-online-part-of-bigger-115m-cache/ | 358 | ||||
| US Marshals Service | 387,000 | 2020 | May 2020 | Prisoners had sensitive personal data stolen in December 2019. They were notified five months later. | government | hacked | 2 | 287K | NextGov | https://www.nextgov.com/cybersecurity/2020/05/us-marshals-service-breach-exposed-personal-data-387000-prisoners/165305/ | 357 | ||||
| db8151dd | "mystery breach" | 22,000,000 | 2020 | May 2020 | Aggregated data from multiple websites was discovered in an open database. It included addresses, job titles, phone numbers and social media profiles. The breach was dubbed 'db8151dd'. | web | hacked | 2 | 22m | 9 to 5 Mac | https://9to5mac.com/2020/05/15/db8151dd/ | 356 | |||
| EasyJet | 9,000,000 | 2020 | May 2020 | The airline became aware of a hack in January, but didn't notify customers until April. Email addresses, travel details and credit card details were stolen. | transport | hacked | 3 | 9m | BBC | https://www.bbc.co.uk/news/technology-52722626 | 355 | ||||
| Microsoft | 250,000,000 | 2020 | Jan 2020 | Customer support records spanning 14 years were left online without password protection. | web | poor security | 1 | 250m | Forbes | https://www.forbes.com/sites/daveywinder/2020/01/22/microsoft-security-shocker-as-250-million-customer-records-exposed-online/#91076484d1b3 | 354 | ||||
| Dutch Government | 6,900,000 | 2020 | Mar 2020 | Two hard drives with data from 6.9m registered organ donors went missing. They contained contact details, ID numbers & signatures. | government | lost device | 4 | 6.9m | ZDNet | https://www.zdnet.com/article/dutch-government-loses-hard-drives-with-data-of-6-9-million-registered-donors/ | 353 | ||||
| Virgin Media | 900,000 | 2020 | Mar 2020 | A poorly-configured database left names, email addresses and phone numbers exposed for 10 months. | retail | poor security | 1 | 900K | BBC | https://www.bbc.co.uk/news/business-51760510 | 352 | ||||
| Boots Advantage Card | 150,000 | 2020 | Mar 2020 | Hackers accessed Advantage Card records, but no financial data was stolen. Payment using points was suspended. | retail | hacked | 1 | 150K | Which | https://www.which.co.uk/news/2020/03/boots-advantage-card-tesco-clubcard-both-suffer-data-breaches-in-same-week/ | 351 | ||||
| Tesco Clubcard | 600,000 | 2020 | Mar 2020 | Details of accrued loyalty points were accessed, but financial details weren't exposed. | retail | hacked | 1 | 600K | Tech Radar | https://www.techradar.com/uk/news/tesco-clubcard-holders-warned-of-major-security-issue | 350 | ||||
| Marriott Hotels | 5,200,000 | 2020 | Mar 2020 | Guest records were accessed using the logins of two employees between mid-Jan and end of Feb. | retail | inside job | 2 | 5.2m | Marriott | https://news.marriott.com/news/2020/03/31/marriott-international-notifies-guests-of-property-system-incident | 349 | ||||
| Zoom | 500,000 | 2020 | Apr 2020 | Email addresses, passwords and personal meeting URLs were sold on the dark web. It led to a host of zoom-bombing pranks. | web | hacked | 1 | 500K | We Live Security | https://www.welivesecurity.com/2020/04/16/half-million-zoom-accounts-sale-dark-web/ | 348 | ||||
| Israeli government | 6,500,000 | 2020 | Feb 2020 | Names, addresses, and ID card numbers of every Israeli voter were found on an insecure website belonging to Elector, a political communications app. | government | poor security | 2 | 6.5m | NYTimes | https://www.nytimes.com/2020/02/10/world/middleeast/israeli-voters-leak.html?action=click&module=News&pgtype=Homepage | 347 | ||||
| MGM Hotels | 10,600,000 | 2020 | Feb 2020 | Data stolen during an 2019 hack of an MGM server was published on a hacking forum. | retail | hacked | 2 | 10.6m | ZDNet | https://www.zdnet.com/article/exclusive-details-of-10-6-million-of-mgm-hotel-guests-posted-on-a-hacking-forum/ | 346 | ||||
| Buchbinder Car Rentals | 5,000,000 | 2020 | Jan 2020 | Correspondence, invoices and contracts containing personal details were left exposed on an unsecured company server. | transport | poor security | 2 | 5m | Teller Report | https://www.tellerreport.com/news/2020-01-22---big-data-leak--media--at-buchbinder-car-rental-company--customer-data-was-open-.BJ-S5Jk8Z8.html | 345 | ||||
| Wawa | fuel & convenience store chain | 30,000,000 | 2019 | Dec 2019 | Card-stealing malware was installed, and remained undiscovered for nine months. | retail | hacked | 3 | 30m | Krebs on Security | https://krebsonsecurity.com/2020/01/wawa-breach-may-have-compromised-more-than-30-million-payment-cards/ | 344 | |||
| Desjardins Group | 4,200,000 | 2019 | Jun 2019 | An employee of the Canadian financial firm leaked customer information outside the organisation: names, addresses, birthdates, social insurance numbers & transaction habits. | finance | inside job | 2 | CBC | https://www.cbc.ca/news/canada/montreal/desjardins-data-breach-1.5344216 | 343 | |||||
| US Customs and Border Protection | 100,000 | 2019 | Jun 2019 | Photos of faces and license plates taken at an US border crossing were stolen in a cyberattack on a surveillance contractor. | government | hacked | y | 2 | Washington Post | https://www.washingtonpost.com/technology/2019/06/10/us-customs-border-protection-says-photos-travelers-into-out-country-were-recently-taken-data-breach/?utm_term=.69c66aaf152f | 342 | ||||
| Quest Diagnostics | 20,000,000 | 2019 | Jun 2019 | For an 8 month period, a hacker group stole personal and payment information from a firm providing billing services for the US healthcare sector. | health | poor security | 4 | ZDNet | https://www.zdnet.com/article/amca-data-breach-has-now-gone-over-the-20-million-mark/ | 341 | |||||
| Australian National University | 200,000 | 2019 | Jun 2019 | A hacker accessed personal information including addresses, bank account details, payroll information and academic records. Staff, students and visitors were affected. | academia | hacked | 4 | Guardian | https://www.theguardian.com/australia-news/2019/jun/04/australian-national-university-hit-by-huge-data-breach | 340 | |||||
| Canva | 139,000,000 | 2019 | May 2019 | Names, email addresses and location data belonging to users of an Australian graphic design service were stolen by a hacker. | web | hacked | 2 | 139m | ZDNet | https://www.zdnet.com/article/australian-tech-unicorn-canva-suffers-security-breach/ | 339 | ||||
| Chtrbox | Instagram Influencers | 49,000,000 | 2019 | May 2019 | Contact details for millions of Instagram influencers, celebrities and brand accounts was left exposed in an online database for at least six days. | misc | poor security | y | 1 | Techcrunch | https://techcrunch.com/2019/05/20/instagram-influencer-celebrity-accounts-scraped/ | 337 | |||
| WiFi Finder | A hotspot finder app | 2,000,000 | 2019 | Apr 2019 | An Android app for finding local WiFi passwords inadvertently provided access to the entire database, including domestic WiFi points. | web | poor security | 1 | Techcrunch | https://techcrunch.com/2019/04/22/hotspot-password-leak/ | 336 | ||||
| Toyota | 3,100,000 | 2019 | Apr 2019 | A security breach of Toyota subsidiaries' IT systems may have leaked personal customer information. | transport | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/toyota-security-breach-exposes-personal-info-of-31-million-clients/ | https://global.toyota/jp/newsroom/corporate/27465617.html | 335 | ||||
| Unknown | Open database in China | 1,800,000 | 2019 | Mar 2019 | A Dutch researcher found women's personal information in an open Chinese database. It included phone numbers, addressed and their "BreedReady" status, whatever that might be. | web | poor security | y | 4 | The Guardian | https://www.theguardian.com/world/2019/mar/11/china-database-lists-breedready-status-of-18-million-women | 334 | |||
| Vårdguiden | Sweden's healthcare hotline | 2,700,000 | 2019 | Feb 2019 | 170,000 hours of sensitive calls to Sweden's healthcare hotline were stored on an open web server with no encryption or authentication. The breach was blamed on subcontractor Medicall. | health | poor security | y | 5 | ComputerSweden | https://computersweden.idg.se/2.2683/1.714787/inspelade-samtal-1177-vardguiden-oskyddade-internet | https://thenextweb.com/eu/2019/02/18/2-7-million-patient-calls-to-swedish-healthcare-hotline-left-unprotected-online/# | 333 | ||
| Dubsmash | 162,000,000 | 2019 | Feb 2019 | Part of the theft of 617 million online account details from 16 hacked websites, put up for sale on the dark web. | web | hacked | 1 | 162m | The Register | https://www.theregister.co.uk/2019/02/11/620_million_hacked_accounts_dark_web/ | 332 | ||||
| ShareThis | 41,000,000 | 2019 | Feb 2019 | Part of the theft of 617 million online account details from 16 hacked websites, put up for sale on the dark web. | web | hacked | 1 | The Register | https://www.theregister.co.uk/2019/02/11/620_million_hacked_accounts_dark_web/ | 331 | |||||
| HauteLook | 28,000,000 | 2019 | Feb 2019 | Part of the theft of 617 million online account details from 16 hacked websites, put up for sale on the dark web. | retail | hacked | 1 | The Register | https://www.theregister.co.uk/2019/02/11/620_million_hacked_accounts_dark_web/ | 330 | |||||
| Animoto | 25,000,000 | 2019 | Feb 2019 | Part of the theft of 617 million online account details from 16 hacked websites, put up for sale on the dark web. | web | hacked | 1 | The Register | https://www.theregister.co.uk/2019/02/11/620_million_hacked_accounts_dark_web/ | 329 | |||||
| EyeEm | 22,000,000 | 2019 | Feb 2019 | Part of the theft of 617 million online account details from 16 hacked websites, put up for sale on the dark web. | web | hacked | 1 | The Register | https://www.theregister.co.uk/2019/02/11/620_million_hacked_accounts_dark_web/ | 328 | |||||
| 8fit | 20,000,000 | 2019 | Feb 2019 | Part of the theft of 617 million online account details from 16 hacked websites, put up for sale on the dark web. | web | hacked | 1 | The Register | https://www.theregister.co.uk/2019/02/11/620_million_hacked_accounts_dark_web/ | 327 | |||||
| Whitepages | 18,000,000 | 2019 | Feb 2019 | Part of the theft of 617 million online account details from 16 hacked websites, put up for sale on the dark web. | web | hacked | 1 | The Register | https://www.theregister.co.uk/2019/02/11/620_million_hacked_accounts_dark_web/ | 326 | |||||
| Fotolog | 16,000,000 | 2019 | Feb 2019 | Part of the theft of 617 million online account details from 16 hacked websites, put up for sale on the dark web. | web | hacked | 1 | The Register | https://www.theregister.co.uk/2019/02/11/620_million_hacked_accounts_dark_web/ | 325 | |||||
| Armor Games | 11,000,000 | 2019 | Feb 2019 | Part of the theft of 617 million online account details from 16 hacked websites, put up for sale on the dark web. | gaming | hacked | 1 | The Register | https://www.theregister.co.uk/2019/02/11/620_million_hacked_accounts_dark_web/ | 324 | |||||
| BookMate | 8,000,000 | 2019 | Feb 2019 | Part of the theft of 617 million online account details from 16 hacked websites, put up for sale on the dark web. | web | hacked | 1 | The Register | https://www.theregister.co.uk/2019/02/11/620_million_hacked_accounts_dark_web/ | 323 | |||||
| CoffeeMeetsBagel | 6,000,000 | 2019 | Feb 2019 | Part of the theft of 617 million online account details from 16 hacked websites, put up for sale on the dark web. | web | hacked | 1 | The Register | https://www.theregister.co.uk/2019/02/11/620_million_hacked_accounts_dark_web/ | 322 | |||||
| Artsy | 1,000,000 | 2019 | Feb 2019 | Part of the theft of 617 million online account details from 16 hacked websites, put up for sale on the dark web. | web | hacked | 1 | The Register | https://www.theregister.co.uk/2019/02/11/620_million_hacked_accounts_dark_web/ | 321 | |||||
| DataCamp | 700,000 | 2019 | Feb 2019 | Part of the theft of 617 million online account details from 16 hacked websites, put up for sale on the dark web. | web | hacked | 1 | The Register | https://www.theregister.co.uk/2019/02/11/620_million_hacked_accounts_dark_web/ | 320 | |||||
| Ixigo | 18,000,000 | 2019 | Feb 2019 | Part of the theft of 127 million online account details from 8 hacked websites. They were put up for sale on the dark web 1 week after a similar tranche of 617 million records from 16 other websites. | transport | poor security | 1 | Techcrunch | https://techcrunch.com/2019/02/14/hacker-strikes-again/ | 319 | |||||
| YouNow | 40,000,000 | 2019 | Feb 2019 | Part of the theft of 127 million online account details from 8 hacked websites. They were put up for sale on the dark web 1 week after a similar tranche of 617 million records from 16 other websites. | web | hacked | 1 | Techcrunch | https://techcrunch.com/2019/02/14/hacker-strikes-again/ | 318 | |||||
| Houzz | 57,000,000 | 2019 | Feb 2019 | Part of the theft of 127 million online account details from 8 hacked websites. They were put up for sale on the dark web 1 week after a similar tranche of 617 million records from 16 other websites. | retail | hacked | 2 | Techcrunch | https://techcrunch.com/2019/01/31/houzz-data-breach/ | 317 | |||||
| Ge.tt | 1,800,000 | 2019 | Feb 2019 | Part of the theft of 127 million online account details from 8 hacked websites. They were put up for sale on the dark web 1 week after a similar tranche of 617 million records from 16 other websites. | web | hacked | 1 | Techcrunch | https://techcrunch.com/2019/02/14/hacker-strikes-again/ | 316 | |||||
| Coinmama | 450,000 | 2019 | Feb 2019 | Part of the theft of 127 million online account details from 8 hacked websites. They were put up for sale on the dark web 1 week after a similar tranche of 617 million records from 16 other websites. | finance | hacked | 1 | Techcrunch | https://techcrunch.com/2019/02/14/hacker-strikes-again/ | 315 | |||||
| Roll20 | 4,000,000 | 2019 | Feb 2019 | Part of the theft of 127 million online account details from 8 hacked websites. They were put up for sale on the dark web 1 week after a similar tranche of 617 million records from 16 other websites. | gaming | hacked | 1 | Techcrunch | https://techcrunch.com/2019/02/14/hacker-strikes-again/ | 314 | |||||
| Stronghold Kingdoms | 5,000,000 | 2019 | Feb 2019 | Part of the theft of 127 million online account details from 8 hacked websites. They were put up for sale on the dark web 1 week after a similar tranche of 617 million records from 16 other websites. | gaming | hacked | 1 | Techcrunch | https://techcrunch.com/2019/02/14/hacker-strikes-again/ | 313 | |||||
| Petflow | 1,000,000 | 2019 | Feb 2019 | Part of the theft of 127 million online account details from 8 hacked websites. They were put up for sale on the dark web 1 week after a similar tranche of 617 million records from 16 other websites. | retail | poor security | 1 | Techcrunch | https://techcrunch.com/2019/02/14/hacker-strikes-again/ | 312 | |||||
| 500px | 14,800,000 | 2019 | Feb 2019 | A July 2018 hack exposed the personal information of all 500px users, including names, usernames, email addresses, encrypted passwords, location, birth date, and gender. | web | hacked | 2 | PetaPixel | https://petapixel.com/2019/02/13/500px-hacked-personal-data-stolen-from-all-14-8-million-users/ | 311 | |||||
| Blur | password manager | 2,400,000 | 2019 | Jan 2019 | A server belonging to the password manager service contained a freely accessible file with users' email addresses, names and encrypted passwords. | tech | oops! | 1 | ZDNet | https://www.zdnet.com/article/data-of-2-4-million-blur-password-manager-users-left-exposed-online/ | 310 | ||||
| Blank Media Games | 7,600,000 | 2019 | Jan 2019 | A hacker stole usernames, email addresses and encrypted passwords belonging to players of the game "Town of Salem" from an insecure server. | gaming | hacked | 1 | ZDNet | https://www.zdnet.com/article/town-of-salem-game-suffers-data-breach-exposing-7-6-million-user-details/ | 309 | |||||
| Indian citizens | 275,265,298 | 2019 | May 2019 | The discovery of a huge, unprotected MongoDB database containing personal information of Indian citizens, including their education, resume and current salary. | web | poor security | 2 | 275m | Bleeping Computer | https://www.bleepingcomputer.com/news/security/over-275-million-records-exposed-by-unsecured-mongodb-database/ | 308 | ||||
| Bulgarian National Revenue Agency | 5,000,000 | 2019 | Jul 2019 | A hacker stole personal details of Bulgarian citizens from 110 government databases. 5m records, out of a total population of 7m. | government | hacked | 2 | ZDNet | https://www.zdnet.com/article/hacker-steals-data-of-millions-of-bulgarians-emails-it-to-local-media/ | 307 | |||||
| Capital One | 100,000,000 | 2019 | Jul 2019 | The massive data breach included personal information from credit card applications over a 14-year period. A former Amazon employee, Paige Thompson, 36, was found guilty of wire fraud. | finance | hacked | 3 | 100m | Forbes | https://www.forbes.com/sites/rachelsandler/2019/07/29/capital-one-says-hacker-breached-accounts-of-100-million-people-ex-amazon-employee-arrested/#2a5cb36b41d2 | 306 | ||||
| Suprema | biometrics security company | 27,800,000 | 2019 | Aug 2019 | A biometric security company stored unencrypted usernames and passwords, fingerprints and facial recognition information on a publicly accessible database. | tech | poor security | 5 | Guardian | https://www.theguardian.com/technology/2019/aug/14/major-breach-found-in-biometrics-system-used-by-banks-uk-police-and-defence-firms | 305 | ||||
| 419,000,000 | 2019 | Sep 2019 | Several unprotected databases were found to contain the phone numbers of around 20% of all Facebook users, with (in some cases) names and locations. | web | poor security | 2 | 420m | Fast Company | https://www.fastcompany.com/90399734/the-phone-numbers-of-419-million-facebook-accounts-have-been-leaked | 304 | |||||
| DoorDash | food delivery company | 4,900,000 | 2019 | Sep 2019 | Users who joined the platform before April 2018 had their names, email addresses, order history, phone numbers and encrypted passwords stolen in a hack. | transport | hacked | 2 | 4.9m | Techcrunch | https://techcrunch.com/2019/09/26/doordash-data-breach/ | 303 | |||
| BriansClub | site selling stolen card data | 26,000,000 | 2019 | Oct 2019 | A site selling stolen payment card data was hacked and 26 million records were leaked. Banks were able to invalidate those cards, taking around 1/3 of the world's stolen cards out of circulation. | web | hacked | 3 | 26m | Ars Technica | https://arstechnica.com/information-technology/2019/10/data-for-a-whopping-26-million-stolen-payment-cards-leaked-in-hack-of-fraud-bazaar/ | 302 | |||
| OxyData | 380,000,000 | 2019 | Nov 2019 | Information compiled by a data aggregation firm were found on an insecure server. It included complete scrapes of LinkedIn data, including recruiter information. | tech | poor security | 2 | 380m | Dataviper | https://www.dataviper.io/blog/2019/pdl-data-exposure-billion-people/ | 300 | ||||
| Click2Gov | 300,000 | 2018 | Dec 2018 | Vulnerabilities in government payment software allowed hackers to access financial records and personal data across 46 US cities. | finance | hacked | 3 | Fortune | http://fortune.com/2018/12/18/click2gov-local-government-portals-hackers-credit-card-breach/ | 299 | |||||
| SingHealth | 1,500,000 | 2018 | Jul 2018 | Hackers stole personal details of 1.5 million patients, as well as the prescription details of 160,000 people, including prime minister Lee Hesien Loong. | health | hacked | 4 | Straits Times | https://www.straitstimes.com/singapore/personal-info-of-15m-singhealth-patients-including-pm-lee-stolen-in-singapores-most | 298 | |||||
| GovPayNow.com | Government Payment Service Inc | 14,000,000 | 2018 | Sep 2018 | A company used by US government agencies to accept online payments exposed personal records via a standard web browser, including addresses, phone numbers and credit card digits. | finance | poor security | 2 | Krebs on Security | https://krebsonsecurity.com/2018/09/govpaynow-com-leaks-14m-records/ | 297 | ||||
| Cathay Pacific Airways | 94,000,000 | 2018 | Oct 2018 | Stolen data included names, nationalities, birth dates, phone numbers, addresses, passport & identity card numbers & expired credit card numbers. | transport | hacked | 3 | ABC News | https://www.abc.net.au/news/2018-10-25/cathay-pacific-data-breach-affects-9.4-million-customers/10429878 | 296 | |||||
| Chinese resume leak | 202,000,000 | 2018 | Dec 2018 | Information thought to have been scraped from Chinese jobseeking websites was found in an insecure database. It included resumes, phone numbers, height, weight, driving license & literacy level. | web | poor security | 2 | 202m | HackenProof | https://blog.hackenproof.com/industry-news/202-million-private-resumes-exposed | 295 | ||||
| Google+ | 52,500,000 | 2018 | Dec 2018 | A vulnerability exposed users' personal details to developers, even if their profiles were set to private. As a result, Google shut down the consumer version of the social network 4 months early. | web | poor security | 2 | The Verge | https://www.theverge.com/2018/12/10/18134541/google-plus-privacy-api-data-leak-developers | 294 | |||||
| Quora | 100,000,000 | 2018 | Dec 2018 | Login details and private messages were compromised by "a malicious third party". | web | hacked | 1 | 100m | NY Times | https://www.nytimes.com/2018/12/04/technology/quora-hack-data-breach.html | 293 | ||||
| Marriott International | 383,000,000 | 2018 | Nov 2018 | Hackers breached the reservation system of all Starwood hotels, including Sheraton, Westin and Le Meridien. Personal information, credit card details and passport info dating back to 2014 was stolen. | retail | hacked | 3 | 383m | NY Times, CNET | https://www.nytimes.com/2018/11/30/business/marriott-data-breach.html | https://www.cnet.com/news/marriott-says-hackers-stole-more-than-5-million-passport-numbers/ | 292 | |||
| NMBS | Belgian national railway operator | 700,000 | 2018 | Dec 2018 | Customer names, gender, birth dates, email and postal address data were left on a publicly searchable server belonging to the Belgian rail authority. Caused by a data worker “clicking on the wrong button”. | transport | oops! | y | 2 | Flanders Today | http://www.flanderstoday.eu/business/nmbs-data-leak-was-breach-privacy | 291 | |||
| 50,000,000 | 2018 | Mar 2018 | Cambridge Analytica, headed at the time by Steve Bannon, harvested profiles in early 2014 to build a system that could profile US voters and target them with political adverts. | web | hacked | y | 1 | 50m | Guardian | https://www.theguardian.com/news/2018/mar/17/cambridge-analytica-facebook-influence-us-election?CMP=twt_gu | 290 | ||||
| Panerabread | 37,000,000 | 2018 | Apr 2018 | Customer records, including loyalty card numbers, were available via the bakery chain's website for at least 8 months. The firm claims 10k records were leaked. Security researchers put the figure at over 37 million. | retail | poor security | 2 | Krebsonsecurity, Medium | https://krebsonsecurity.com/2018/04/panerabread-com-leaks-millions-of-customer-records/ | https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-security-seriously-bf078027f815 | 289 | ||||
| Dixons Carphone | 10,000,000 | 2018 | Jun 2018 | The firm admitted that hackers were able to access the details of 10m customers and 6m payment cards. | telecoms | hacked | 1 | BBC | https://www.bbc.co.uk/news/business-45016906 | 288 | |||||
| MyHeritage | 92,283,889 | 2018 | Jun 2018 | The genealogy site received a message from a researcher who had discovered over 92m email addresses and encrypted passwords on an external server. | web | hacked | 1 | Bloomberg | https://www.bloombergquint.com/technology/hack-of-dna-website-exposes-data-from-92-million-user-accounts | 287 | |||||
| Saks and Lord & Taylor | Both owned by Hudson's Bay Company | 5,000,000 | 2018 | Apr 2018 | A known ring of cybercriminals implanted software into store cash registers, siphoning off credit card details from readers. | retail | hacked | y | 3 | NYTimes | https://www.nytimes.com/2018/04/01/technology/saks-lord-taylor-credit-cards.html | 286 | |||
| Careem | Dubai-born ride hailing service | 14,000,000 | 2018 | Apr 2018 | The Dubai-based ride hailing service admitted that names, email addresses, phone numbers and trip data had been accessed in what it called a "cyber incident". | web | hacked | 2 | Khaleej Times | https://www.khaleejtimes.com/nation/dubai//dubais-careem-admits-to-data-breach-of-14-million-users | 285 | ||||
| Texas voter records | 14,800,000 | 2018 | Aug 2018 | A single file containing 14.8 million voter records was found on an unsecured server. It was thought to have been originally compiled by Data Trust, a Republican-focused data analytics firm. | web | poor security | 2 | TechCrunch | https://techcrunch.com/2018/08/23/millions-of-texas-voter-records-exposed-online/ | 284 | |||||
| British Airways | 380,000 | 2018 | Sep 2018 | The personal and financial details of customers who booked flights in a two-week period over the summer were compromised. | transport | hacked | 4 | Guardian | https://www.theguardian.com/business/2018/sep/06/british-airways-customer-data-stolen-from-its-website | 283 | |||||
| T-Mobile | 2,000,000 | 2018 | Aug 2018 | Personal data along with passwords encrypted by a notoriously weak algorithm (MD5) were stolen. The firm initially failed to disclose the password breach, "because they were encrypted". | telecoms | hacked | 1 | Motherboard | https://motherboard.vice.com/en_us/article/a3qpk5/t-mobile-hack-data-breach-api-customer-data | 282 | |||||
| MyFitnessPal | UnderArmour | 150,000,000 | 2018 | Mar 2018 | A breach of usernames, email addresses, and hashed passwords belonging to users of the fitness app. | web | hacked | 1 | 150m | Guardian | https://www.theguardian.com/technology/2018/mar/30/hackers-steal-data-150m-myfitnesspal-app-users-under-armour | 281 | |||
| Helse Sør-Øst RHF | Health authority responsible for 10 Norwegian counties. | 3,000,000 | 2018 | Feb 2018 | Patient records of more than half of Norway's population were stolen. The hack is thought to have happened via old computers running Windows XP. | health | hacked | 4 | It Governance | https://www.itgovernance.eu/blog/en/breach-at-norways-largest-healthcare-authority-was-a-disaster-waiting-to-happen | 280 | ||||
| Nametests | Facebook quiz app owned by Social Sweethearts | 120,000,000 | 2018 | Jun 2018 | A security failure in a "personality test" app on Facebook left millions of people’s data publicly exposed for almost two years – even after they had deleted the app. | web | poor security | y | 1 | 120m | Medium | https://medium.com/@intideceukelaire/this-popular-facebook-app-publicly-exposed-your-data-for-years-12483418eff8 | 279 | ||
| Ticketmaster | 40,000 | 2018 | Jun 2018 | The data was stolen via an attack on a third-party customer support firm. It was likely to have affected UK customers who bought tickets between Feb and Jun 2018. | web | hacked | 3 | BBC News | https://www.bbc.co.uk/news/technology-44628874 | 278 | |||||
| Firebase | A service from Google | 100,000,000 | 2018 | Jun 2018 | Misconfigured databases used by app developers were found to be exposing 113GB of personal data, accumulated by thousands of iOS and Android mobile apps. | web | poor security | 5 | 100m | Bleeping Computer | https://www.bleepingcomputer.com/news/security/thousands-of-apps-leak-sensitive-data-via-misconfigured-firebase-backends/ | 277 | |||
| Aadhaar | India's national, biometric government ID database | 550,000,000 | 2018 | Mar 2018 | India's biometric database was breached via a leak at a state-owned utility company. All registered Indian citizens were affected; their names, identity numbers and bank details were exposed. Data later found for sale on WhatsApp for less than £6. | government | poor security | 4 | 1.1bn | ZDNet | http://www.zdnet.com/article/another-data-leak-hits-india-aadhaar-biometric-database/ | 276 | |||
| Grindr | 3,000,000 | 2018 | Mar 2018 | A third-party tool that allows users to see who had blocked them was able to access non-public personal info, including locations of users who had opted out of location sharing. | web | poor security | 3 | NBC News | https://www.nbcnews.com/feature/nbc-out/security-flaws-gay-dating-app-grindr-expose-users-location-data-n858446 | 275 | |||||
| Orbitz | 880,000 | 2018 | Mar 2018 | An legacy version of the travel website was hacked, exposing personal details and payment card info of people who'd made purchases in 2016 and 2017. Orbitz is now owned by Expedia. | web | hacked | 3 | US News | https://www.usnews.com/news/business/articles/2018-03-20/orbitz-legacy-travel-booking-platform-likely-hacked | 274 | |||||
| MBM Company | Limogés Jewellery | 1,300,000 | 2018 | Mar 2018 | An insecure customer database belonging to the jewellery firm exposed postal addresses, email addresses, IP addresses and plain-text passwords. | retail | poor security | 4 | NextWeb | https://thenextweb.com/security/2018/03/14/jewelry-site-accidentally-leaks-personal-details-plaintext-passwords-1-3m-users/ | 273 | ||||
| LocalBlox | datasearch service | 48,000,000 | 2018 | May 2018 | A cloud storage repository was left publically accessible. Data included names, addresses, DOBs, and other information scraped from social media websites including Facebook. | web | poor security | 2 | UpGuard | https://www.upguard.com/breaches/s3-localblox | 272 | ||||
| 330,000,000 | 2018 | May 2018 | A glitch caused some passwords to be stored in readable text that was visible on Twitter's internal computer system. | tech | poor security | 1 | 330m | Reuters | https://www.reuters.com/article/us-twitter-passwords/twitter-urges-all-users-to-change-passwords-after-glitch-idUSKBN1I42JG | 271 | |||||
| ViewFines | South African traffic fines database | 934,000 | 2018 | May 2018 | Data originating with a South African traffic fine payment firm was leaked online. It included names, national ID numbers, cell numbers, email addresses and plain text passwords. | transport | oops! | 4 | iAfrikan | https://www.iafrikan.com/2018/05/23/just-under-1-million-personal-records-of-south-africans-leaked-online/ | 270 | ||||
| TicketFly | 27,000,000 | 2018 | May 2018 | Names, addresses, email addresses and phone numbers were stolen from the ticketing firm. Ransom demands were made. The FBI indicted a suspect in February 2020. | web | hacked | 2 | The Verge | https://www.theverge.com/2018/6/7/17438516/ticketfly-hack-personal-information-26-million-customers-leaked | 269 | |||||
| Amazon | 5,000,000 | 2018 | Nov 2018 | A "technical issue" inadvertently caused customer names & email addresses to be posted to the Amazon website just prior to Black Friday. | retail | oops! | 1 | Guardian | https://www.theguardian.com/technology/2018/nov/21/amazon-hit-with-major-data-breach-days-before-black-friday | 268 | |||||
| Urban Massage | Home massage app | 309,000 | 2018 | Nov 2018 | An online database with no password protection contained thousands of customer records, including names, email addresses, phone numbers and sexual misconduct complaints. | web | poor security | 2 | Tech Crunch | https://techcrunch.com/2018/11/27/urban-massage-data-exposed-customers-creepy-clients/?guccounter=1 | 267 | ||||
| Dell | 100,000 | 2018 | Nov 2018 | Dell detected and disrupted unauthorized attempts to extract customer names, email addresses & hashed passwords. The number of affected customers was not disclosed. | tech | hacked | 1 | ZD Net | https://www.zdnet.com/article/dell-announces-security-breach/ | 266 | |||||
| High Tail Hall | erotic role-playing site | 411,000 | 2018 | Nov 2018 | Hackers obtained email addresses, names, order histories, hashed passwords, physical and IP addresses for users of an "erotic role-playing game". | web | hacked | 2 | Daily Mail | https://www.dailymail.co.uk/sciencetech/article-6415441/Furry-erotica-site-hit-data-breach-exposed-hundreds-thousands-users-information.html | 265 | ||||
| SKY Brasil | 32,000,000 | 2018 | Nov 2018 | Poorly configured servers exposed customer details – including payment methods – for long enough to make their theft "likely". | telecoms | poor security | 1 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/sky-brasil-exposes-32-million-customer-records/ | 264 | |||||
| Vision Direct | UK opticians | 16,300 | 2018 | Nov 2018 | A 5-day data breach saw attackers steal personal information, passwords and CVV security codes. | retail | hacked | 4 | BBC | https://www.bbc.co.uk/news/technology-46261209 | 263 | ||||
| Medicare & Medicaid | Centers for Medicare & Medicaid Services | 93,689 | 2018 | Nov 2018 | "Sensitive" information on applicants for US healthcare plans was hacked. It included names, birth dates, addresses, expected income & health insurance status. | health | hacked | 2 | HCA News | https://www.hcanews.com/news/update-94k-hit-in-cms-data-breach | 262 | ||||
| 29,000,000 | 2018 | Oct 2018 | The biggest hack in Facebook's history to date. Names, birth dates, phone numbers, search history and location data was stolen by hackers masquerading as a digital marketing company. | web | hacked | 2 | Business Insider, Facebook | https://www.businessinsider.com.au/facebook-thinks-spammers-responsible-hack-stole-info-from-29-million-users-2018-10?r=US&IR=T | https://newsroom.fb.com/news/2018/10/update-on-security-issue/ | 261 | |||||
| Newegg | 45,000,000 | 2018 | Sep 2018 | Hackers injected 15 lines of card skimming code on the online retailer's payments page. It remained online for more than a month. | retail | hacked | y | 3 | TechCrunch | https://techcrunch.com/2018/09/19/newegg-credit-card-data-breach/ | 260 | ||||
| Mount Olympus | mortgage lender | 1,100 | 2016 | Mar 2016 | An employee stole client information and loan files and took them with him when he went to work for a competitor. Mount Olympus later awarded $25m in damages. | finance | inside job | 5 | 188K | Housing Wire | https://www.housingwire.com/articles/36597-guaranteed-rate-ordered-to-pay-25m-to-mount-olympus-mortgage-for-data-theft/ | 259 | |||
| Apollo | intelligence firm | 200,000,000 | 2018 | May 2018 | Data scraping company left a database exposed online, revealing 200 million contacts, 10 million companies and 9 billion "data points". | tech | poor security | 1 | 200m | Wired | https://www.wired.com/story/apollo-breach-linkedin-salesforce-data/ | 258 | |||
| Disqus | 17,500,000 | 2017 | Dec 2017 | Hackers stole 17.5m email addresses in 2012. About a third of those records included passwords hashed using a weak algorithm. | web | hacked | 4 | ZD Net | http://www.zdnet.com/article/disqus-confirms-comments-tool-hacked/ | 257 | |||||
| RootsWeb | 300,000 | 2017 | Dec 2017 | Data on a "leaky server" belonging to Ancestry.com's community-driven site RootsWeb was exposed. Passwords, email addresses and usernames were leaked. | web | poor security | y | 4 | Threat Post | https://threatpost.com/leaky-rootsweb-server-exposes-some-ancestry-com-user-data/129248/ | 256 | ||||
| Yahoo | 32,000,000 | 2017 | Mar 2017 | For two years, hackers used forged cookies to log into millions of Yahoo accounts without a password. | web | hacked | 4 | CNet | https://www.cnet.com/news/yahoo-says-forged-cookie-attack-accessed-about-32m-accounts/ | 255 | |||||
| Uber | 57,000,000 | 2017 | Nov 2017 | Uber concealed an October 2016 leak of personal information for more than a year. They paid hackers $100,000 to delete the stolen data. The chief security officer resigned. | web | hacked | y | 1 | 57m | Bloomberg | https://www.bloomberg.com/news/articles/2017-11-21/uber-concealed-cyberattack-that-exposed-57-million-people-s-data | 254 | |||
| Wonga | 270,000 | 2017 | Apr 2017 | The firm reported unauthorised access to names, addresses, phone numbers and bank account details relating to British and Polish customers. | finance | hacked | 4 | The Guardian | https://www.theguardian.com/business/2017/apr/09/wonga-data-breach-could-affect-250000-uk-customers?CMP=Share_iOSApp_Other | 253 | |||||
| Snapchat | 1,700,000 | 2017 | Apr 2017 | Indian hackers leaked records after taking umbrage at comments made by Snapchat's CEO about their country. | web | hacked | y | 1 | BGR | http://www.bgr.in/news/indian-hacker-group-leaks-data-of-1-7-million-snapchat-users-after-ceos-poor-country-comments-report/ | 252 | ||||
| Spambot | 520,000,000 | 2017 | Aug 2017 | A misconfigured spambot leaked email addresses and passwords. "Almost one address for every single man, woman and child in all of Europe." The set included some fake or repeated accounts. | web | poor security | 4 | 711m | The Guardian | https://www.theguardian.com/technology/2017/aug/30/spambot-leaks-700m-email-addresses-huge-data-breach-passwords | 251 | ||||
| CEX | 2,000,000 | 2017 | Aug 2017 | The second-hand games seller fell victim to a security breach. An 'unauthorised third party' accessed systems holding personal information. | retail | oops! | 3 | PC Mag | https://uk.pcmag.com/cex/90937/cex-hack-up-to-2m-customers-potentially-affected | 250 | |||||
| Al.type | 31,000,000 | 2017 | Dec 2017 | The developer of the customisable keyboard app failed to secure its database server. 577GB of user records were exposed. | web | poor security | 4 | ZDNet | http://www.zdnet.com/article/popular-virtual-keyboard-leaks-31-million-user-data/ | 249 | |||||
| Cellebrite | 3,000,000 | 2017 | Jan 2017 | Cellebrite's main product is a device that rips data from mobile phones. 900GB of data was stolen from Cellebrite. The hackers got hacked. The number of records taken is unknown. | tech | hacked | y | 2 | Vice | https://www.vice.com/en_us/article/3daywj/hacker-steals-900-gb-of-cellebrite-data | 248 | ||||
| Waterly | App for paying water bills | 1,000,000 | 2017 | Jan 2017 | An app which allows Israelis to pay water bills contained a vulnerability in the sign-in process. It could reveal payment history, personal ID information and credit card details. | web | poor security | 3 | Data Breaches | https://www.databreaches.net/waterly-app-potentially-exposed-up-to-1-million-israelis-details-researcher/ | 247 | ||||
| Swedish Transport Agency | 3,000,000 | 2017 | Jul 2017 | All Swedish driving license data was made available to Czech IT workers. The question of whether national security was harmed was censored in the official report. | government | poor security | y | 5 | The Local | https://www.thelocal.se/20170717/swedish-authority-handed-over-keys-to-the-kingdom-in-it-security-slip-up | 246 | ||||
| Hong Kong Registration & Electoral Office | 3,700,000 | 2017 | Mar 2017 | Two laptop computers were stolen at the backup venue for the election of the leader of Hong Kong. The names of electors and personal information of the city's voters was compromised. | government | lost device | 2 | SCMP | http://www.scmp.com/news/hong-kong/politics/article/2082566/laptops-containing-37-million-hong-kong-voters-data-stolen | 245 | |||||
| River City Media | Spam operator | 340,000,000 | 2017 | Mar 2017 | One of the world's largest spam operations accidentally leaked a backup of its database of over a billion email addresses, along with real names, IP and physical addresses. | web | oops! | 2 | 340m | Guardian | https://www.theguardian.com/technology/2017/mar/06/email-addresses-spam-leak-river-city-media | 244 | |||
| DaFont | Font sharing site | 700,000 | 2017 | May 2017 | The font site's database was targeted by a hacker who had seen it being traded elsewhere. The flaw was "easy to find". Usernames, email addresses and passwords were stolen. | web | hacked | 4 | ZD Net | http://www.zdnet.com/article/font-sharing-site-dafont-hacked-thousands-of-accounts-stolen/ | 243 | ||||
| Bell | 1,900,000 | 2017 | May 2017 | Email addresses and information about customers and contractors was leaked after being stolen from an insecure database. The company was threatened with further leaks. | telecoms | hacked | 1 | CBC | http://www.cbc.ca/beta/news/technology/bell-data-breach-customer-names-phone-numbers-emails-leak-1.4116608 | 242 | |||||
| Zomato | Restaurants & events | 17,000,000 | 2017 | May 2017 | Stolen email addresses and hashed passwords were being sold on the dark web for just over $1000. | web | hacked | 4 | HackRead | https://www.hackread.com/zomato-hacked-17-million-accounts-sold-on-dark-web/ | 241 | ||||
| Imgur | 1,700,000 | 2017 | May 2017 | Stolen email addresses and hashed passwords were being sold on the dark web for just over $1000. | web | hacked | 4 | Imgur | https://blog.imgur.com/2017/11/24/notice-of-data-breach/ | 240 | |||||
| TIO Networks | Owned by Paypal | 1,600,000 | 2017 | Dec 2017 | A Paypal subsidiary providing bill payment services suffered a "security incident". Personal information and financial details were likely to have been breached. | finance | hacked | 4 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/paypal-says-1-6-million-customer-details-stolen-in-breach-at-canadian-subsidiary/ | 239 | ||||
| Malaysian telcos & MVNOs | 46,200,000 | 2017 | Oct 2017 | Phone numbers, customer details, addresses and SIM card information from over a dozen Malaysian mobile providers was discovered online after being stolen in 2014. | telecoms | hacked | 4 | LowYat | https://www.lowyat.net/2017/146339/46-2-million-mobile-phone-numbers-leaked-from-2014-data-breach/ | 238 | |||||
| Malaysian medical practitioners | 81,309 | 2017 | Oct 2017 | Databases belonging to the Malaysian Medical Council, the Malaysian Medical Association and the Malaysian Dental Association were discovered online after being stolen in 2014. | health | hacked | 4 | Silicon | https://www.silicon.co.uk/cloud/data-breach-mobile-numbers-malaysia-224079 | 237 | |||||
| 6,000,000 | 2017 | Sep 2017 | A bug in Instagram's API exposed users' contact details. The data was placed online in a searchable database, with a charge of $10 per search. | web | hacked | 1 | The Verge | https://www.theverge.com/2017/9/1/16244304/instagram-hack-api-bug-doxagram-selena-gomez | 236 | ||||||
| Viacom | 3,000,000 | 2017 | Sep 2017 | A misconfigured server exposed 1Gb of Viacom's credentials – enough, say researchers, to take down the firm's internal IT infrastructure. | web | hacked | 4 | The Hacker News | https://thehackernews.com/2017/09/viacom-amazon-server.html | 235 | |||||
| Equifax | 143,000,000 | 2017 | Sep 2017 | A breach of the health insurance firm's database exposed the names, social security numbers, birth dates, addresses, driver's license numbers and credit card information of US, UK and Canadian citizens. | finance, health | hacked | y | 4 | 143m | UK Gov | https://www.consumer.ftc.gov/blog/2017/09/equifax-data-breach-what-do | 234 | |||
| SVR Tracking | Vehicle tracking | 540,000 | 2017 | Sep 2017 | Personal data and vehicle details were exposed. Customer passwords were stored using an easily-crackable algorithm. | web | poor security | 4 | The Hacker News | https://thehackernews.com/2017/09/hacker-track-car.html | 233 | ||||
| 117,000,000 | 2016 | May 2016 | A massive batch of login credentials was discovered on the black market after being stolen by hackers. The breach dated from 2012, when the firm's password security policies were weak. | web | hacked | 1 | 117m | CNN | http://money.cnn.com/2016/05/19/technology/linkedin-hack/ | https://money.cnn.com/2012/06/06/technology/linkedin-password-hack/?iid=EL | 232 | ||||
| Tumblr | 65,000,000 | 2016 | May 2016 | A three year old data breach came to light. Millions of email addresses and hashed passwords had been stolen. | web | hacked | 1 | Vice | https://www.vice.com/en_us/article/8q88k5/hackers-stole-68-million-passwords-from-tumblr-new-analysis-reveals | 231 | |||||
| Yahoo | 500,000,000 | 2016 | Sep 2016 | At the time, the largest ever data breach from a single website. It was stolen, according to Yahoo, by a "state-sponsored actor". It included names, dates of birth and security information. | web | hacked | 2 | 500m | CNBC | https://www.cnbc.com/2016/09/22/yahoo-data-breach-is-among-the-biggest-in-history.html | 230 | ||||
| Mossack Fonseca | Panamanian law firm | 11,500,000 | 2016 | Apr 2016 | A hacker took 2.6TB of data from the Panamanian law firm. It included emails, contracts, scanned documents, transcripts and sensitive information relating to many politicians and public figures. | misc | hacked | y | 5 | PanamaPapers | http://panamapapers.sueddeutsche.de/articles/56febff0a1bb8d3c3495adf4/ | 229 | |||
| Philippines’ Commission on Elections | COMELEC | 55,000,000 | 2016 | Apr 2016 | After a message was posted on the COMELEC website by hackers from Anonymous, warning the government of its weak election security, the entire database of voters was stolen and posted online. | government | hacked | 5 | Trend Micro | http://blog.trendmicro.com/trendlabs-security-intelligence/55m-registered-voters-risk-philippine-commission-elections-hacked/ | 228 | ||||
| Syrian government | 274,477 | 2016 | Apr 2016 | Hacking outfit calling itself 'Cyber Justice Team' leaked 10GB of data from multiple Syrian government and private websites. Much of it was duplicated from previously known hacks. | government | hacked | 1 | Softpedia | http://news.softpedia.com/news/syrian-government-hacked-43-gb-of-data-spilled-online-by-hacktivists-502765.shtml | 227 | |||||
| Minecraft | Lifeboat' community | 7,000,000 | 2016 | Apr 2016 | Players using Minecraft's Lifeboat service had their email addresses and passwords leaked. The passwords were very weakly hashed. | gaming | hacked | 1 | BBC | https://www.bbc.co.uk/news/technology-36168860 | 226 | ||||
| Turkish citizenship database | 49,611,709 | 2016 | Apr 2016 | An entire database of voter records, originally stolen back in 2008, was leaked online. | government | hacked | 2 | Business Insider | http://www.businessinsider.com/turkish-citizenship-database-allegedly-hacked-and-leaked-2016-4?r=UK&IR=T | 225 | |||||
| Banner Health | 3,700,000 | 2016 | Aug 2016 | Hackers gained access to payment card data that was used to buy food and drink at Banner Health outlets. In 2019, Banner agreed to a $6m settlement over the breach. | health | hacked | 3 | Healthcare Informatics | https://www.healthcare-informatics.com/news-item/cybersecurity/breaking-massive-cyber-attack-banner-health-affects-37m-individuals | 224 | |||||
| Mail. ru | Game-related forums | 25,000,000 | 2016 | Aug 2016 | Two hackers attacked three game-related forums hosted by the Russian company Mail.ru. They stole email addresses, scrambled passwords and birthdates. | web | hacked | 2 | ZD Net | http://www.zdnet.com/article/over-25-million-accounts-stolen-after-mail-ru-forums-raided-by-hackers/ | 223 | ||||
| PayAsUGym | 300,000 | 2016 | Dec 2016 | The fitness website was hacked. Email addresses and passwords were published online. | web | hacked | 1 | BBC News | http://www.bbc.co.uk/news/technology-38350987 | 222 | |||||
| Lynda.com | owned by LinkedIn | 9,500,000 | 2016 | Dec 2016 | Hackers breached a database holding contact information and interest in online courses. Lynda's owners, LinkedIn, said that 55,000 user passwords were also breached. | web | hacked | 1 | Neowin | https://www.neowin.net/news/microsoft-owned-linkedin-is-sending-emails-to-users-about-a-lyndacom-data-breach | 221 | ||||
| Linux Ubuntu forums | 2,000,000 | 2016 | Jul 2016 | 2 million usernames, email addresses, and IP addresses were compromised via a vulnerability in the forum software. | web | hacked | 1 | ZDnet | https://www.zdnet.com/article/ubuntu-forums-hack-exposes-two-million-users/ | 220 | |||||
| Wendy's | Restaurant chain | 1,025 | 2016 | Jul 2016 | Malware installed in 1025 point of sale systems was used to steal credit card data from customers. It's not known how many individuals were impacted. | retail | hacked | y | 3 | Forbes | https://www.forbes.com/sites/moneybuilder/2016/07/08/this-week-in-credit-card-news-wendys-data-breach-affects-1000-stores-card-fraud-dropping/#260a2f727bab | 219 | |||
| Clinton campaign | 5,000,000 | 2016 | Jul 2016 | The computer network used by Hillary Clinton's campaign team was hacked as part of a broader cyber attack on Democratic political organizations. | government | hacked | 2 | Reuters | http://news.trust.org/item/20160729204542-r98dj | 218 | |||||
| uTorrent | 35,000 | 2016 | Jun 2016 | Access to user data was gained via a third party. Uncertain as to what exactly had been stolen, the firm advised its users to change their passwords. | web | hacked | 1 | Torrent Freak | https://torrentfreak.com/utorrent-forums-hacked-passwords-compromised-160608/ | 217 | |||||
| World Check | Run by Thompson Reuters | 2,200,000 | 2016 | Jun 2016 | A database of suspected terrorists and criminals used by global banks and intelligence agencies was leaked online. Access is normally granted via a strict vetting process. | misc | poor security | 3 | The Stack | https://thestack.com/security/2016/06/29/2-million-person-terror-database-leaked-online/ | 216 | ||||
| Mutuelle Generale de la Police | French police health insurance | 112,000 | 2016 | Jun 2016 | Personal details of French police officers were uploaded to Google Drive by an employee. The leak came two weeks after a gendarme was murdered in an ISIS-inspired attack. | health | inside job | 5 | BBC News | http://www.bbc.co.uk/news/world-europe-36645519 | 215 | ||||
| VK | Russia's Facebook | 171,000,000 | 2016 | Jun 2016 | A database stolen in 2013 from the Russian social network, containing full names, email addresses and passwords, was offered for sale online. | web | hacked | 4 | 100m | Motherboard | http://motherboard.vice.com/read/another-day-another-hack-100-million-accounts-for-vk-russias-facebook | 214 | |||
| KM.ru & Nival | News site and email provider/Videogame maker | 1,500,000 | 2016 | Mar 2016 | A hacker targeted several Russian websites in revenge for the shooting down of flight MH17 over Ukraine. They included videogame firm Nival and email provider KM.ru. | web | hacked | 4 | Motherboard | https://motherboard.vice.com/en_us/article/pgkp57/a-teen-hacker-is-targeting-russian-sites-as-revenge-for-the-mh17-crash | 213 | ||||
| Fling | Dating site | 40,000,000 | 2016 | May 2016 | Data allegedly stolen in 2011 was put up for sale on the dark web. The stash included email addresses, plain text passwords and information on sexual desires & preferences. | web | hacked | 4 | IBTimes | https://www.ibtimes.co.uk/fling-com-breach-passwords-sexual-preferences-40-million-users-sale-dark-web-1558711 | 212 | ||||
| MySpace | 164,000,000 | 2016 | May 2016 | In one of the largest password breaches ever, 360 million MySpace logins were stolen and put on sale for $2,800. | web | hacked | 1 | 164m | Vice | https://www.vice.com/en_us/article/pgkk8v/427-million-myspace-passwords-emails-data-breach | 211 | ||||
| Three | Three mobile company in the UK | 130,000 | 2016 | Nov 2016 | Fraudsters compromised the mobile network's handset upgrade system and ordered new handsets to sell online. Customer details were accessed as part of the breach. | telecoms | hacked | 2 | Three | http://www.threemediacentre.co.uk/news/2017/handsetfraud-update.aspx | 210 | ||||
| Red Cross Blood Service | 550,000 | 2016 | Oct 2016 | Australian donor information was accessed via an unsecured database posted online by a contractor. Information included that of "at-risk sexual behaviour". | health | oops! | 4 | ABC News | http://www.abc.net.au/news/2016-10-28/red-cross-blood-service-admits-to-data-breach/7974036 | 209 | |||||
| Telegram | Instant messaging service | 15,000,000 | 2016 | Aug 2016 | An Iranian hacking group called Rocket Kitten stole millions of phone numbers from Telegram, an instant messaging service which prides itself on strong security. | web | hacked | 1 | Venture Beat | http://venturebeat.com/2016/08/02/hackers-break-into-telegram-revealing-15-million-users-phone-numbers/ | 208 | ||||
| Dailymotion | video sharing site | 85,200,000 | 2016 | Dec 2016 | Users of the video sharing site had their email addresses and usernames stolen. One in five also had their passwords compromised. | web | hacked | 1 | ZDNet | http://www.zdnet.com/article/dailymotion-hack-exposes-millions-of-accounts/ | 207 | ||||
| Weebly | 43,000,000 | 2016 | Oct 2016 | IP addresses, usernames and hashed passwords were stolen from the web design platform. | web | hacked | 4 | Tech Crunch | https://techcrunch.com/2016/10/20/weebly-hacked-43-million-credentials-stolen/ | 206 | |||||
| Interpark | 10,000,000 | 2016 | Jul 2016 | South Korean police blamed North Korea for stealing personal customer data from a shopping mall's server in an attempt to obtain foreign currency. | web | hacked | 2 | NY times | http://www.nytimes.com/2016/07/29/world/asia/north-korea-hacking-interpark.html | 205 | |||||
| Quest Diagnostics | 34,000 | 2016 | Dec 2016 | Healthcare data accessed by an unauthorised third party contained names, dates of birth and lab results. | health | hacked | 4 | Newsroom | http://newsroom.questdiagnostics.com/2016-12-12-Quest-Diagnostics-Provides-Notice-of-Data-Security-Incident#assets_129 | 204 | |||||
| Friend Finder Network | Parent company of Adult Friend Finder , Cams.com and Penthouse.com | 412,000,000 | 2016 | Nov 2016 | Almost every password used on Adult Friend Finder, Cams.com and Penthouse.com was breached. Those passwords were encrypted, but easily crackable. | web | hacked | 1 | 412m | ZDNet | http://www.zdnet.com/article/adultfriendfinder-network-hack-exposes-secrets-of-412-million-users/ | 203 | |||
| Brazzers | Porn site | 790,724 | 2016 | Sep 2016 | A vulnerability in the pornsite's forum software compromised millions of accounts, many of which had identical login details for the site itself. | web | hacked | 4 | Vice | https://www.vice.com/en_us/article/vv7pgd/nearly-800000-brazzers-porn-site-accounts-exposed-in-forum-hack | 202 | ||||
| ClixSense | 6,600,000 | 2016 | Sep 2016 | A service which pays people to view adverts and take surveys was hacked. Stolen information included addresses, banking details and social security numbers. | web | hacked | 5 | Digital trends | http://www.digitaltrends.com/computing/clixsense-hacked/ | 201 | |||||
| Carefirst | Blue Cross, Blue Shield US medical insurer | 1,100,000 | 2015 | May 2015 | Hackers gained access to a database belonging to the healthcare insurer, stealing names, birth dates, email addresses and insurance ID numbers. | health | hacked | 1 | Krebs on Security | https://krebsonsecurity.com/2015/05/carefirst-blue-cross-breach-hits-1-1m/ | 200 | ||||
| Twitch | Gaming site | 10,000,000 | 2015 | Mar 2015 | All users were forced to reset their passwords after unauthorised access to a number of accounts. | health | hacked | 1 | Twitch | http://blog.twitch.tv/2015/03/important-notice-about-your-twitch-account/ | 199 | ||||
| Premera | US healthcare provider | 11,000,000 | 2015 | Mar 2015 | The health insurance firm revealed that its IT systems had been breached, exposing financial and medical records. | health | hacked | 5 | Computer Weekly | https://www.computerweekly.com/news/2240242508/Premera-hack-exposes-11-million-financial-and-medical-records | 198 | ||||
| Uber | 50,000 | 2015 | Feb 2015 | The breach, which occurred in Sep 2014, revealed the names & license plates of 50,000 drivers across the USA. | tech, web | poor security | 1 | TechCrunch | https://techcrunch.com/2015/02/27/uber-database-breach-exposed-information-of-50000-drivers-company-confirms/ | 197 | |||||
| Deep Root Analytics | 198,000,000 | 2015 | Dec 2015 | A insecure database containing US voter information was discovered by a researcher. It contained names, addresses, contact details and party affiliations. | web | poor security | 2 | 198m | Reuters, UpGuard | http://uk.reuters.com/article/us-usa-voters-breach-idUKKBN0UB1E020151229 | https://www.upguard.com/breaches/the-rnc-files | 196 | |||
| Kromtech | MacKeeper software | 13,000,000 | 2015 | Dec 2015 | A security researcher stumbled on an insecure database belonging to the Mac software provider, containing usernames, email addresses and passwords. | web | hacked | 1 | BBC | https://www.bbc.co.uk/news/technology-35100330 | https://www.reddit.com/r/apple/comments/3wq9fc/massive_data_breach/ | 195 | |||
| Invest Bank | United Arab Emirates bank | 40,000 | 2015 | Dec 2015 | A hacker breached the systems of a UAE bank. They demanded a ransom of $3m in bitcoin to stop tweeting data, relating mainly to corporate accounts. | finance | hacked | 4 | Daily Dot | https://www.dailydot.com/debug/invest-bank-hacker-buba/ | 194 | ||||
| Sanrio | Hello Kitty and other franchises | 3,300,000 | 2015 | Dec 2015 | A researcher accessed a database containing login information, password hints and birthdates of fans of the Hello Kitty brand, including many children. | web | poor security | 2 | CSO Online | https://www.csoonline.com/article/3017171/database-leak-exposes-3-3-million-hello-kitty-fans.html | 193 | ||||
| VTech | Toymaker company | 6,400,000 | 2015 | Dec 2015 | The toy maker was targeted by a hacker who stole the private data of millions of children, including names, email addresses and birth dates. | web | hacked | 5 | The Guardian | http://www.theguardian.com/technology/2015/dec/02/vtech-hack-us-hong-kong-investigate-children-exposed | http://www.troyhunt.com/2015/11/when-children-are-breached-inside.html | 192 | |||
| Hacking Team | 500,000 | 2015 | Jul 2015 | An Italian hacking firm which sells digital surveillance software to national security organisations – including those of repressive regimes – was itself hacked, and the data put on BitTorrent. | web | hacked | y | 5 | The Guardian | http://www.theguardian.com/technology/2015/jul/06/hacking-team-hacked-firm-sold-spying-tools-to-repressive-regimes-documents-claim | 191 | ||||
| AshleyMadison.com | US ex-marital affairs site | 37,000,000 | 2015 | Jul 2015 | The online hookup site for extra-marital affairs was severely breached. Personal details and company financial records were threatened with release. | web | hacked | 1 | Krebs on Security | http://krebsonsecurity.com/2015/07/online-cheating-site-ashleymadison-hacked/ | 190 | ||||
| US Office of Personnel Management (2nd Breach) | 21,500,000 | 2015 | Jul 2015 | Hackers with suspected links to China accessed sensitive data on US intelligence and military personnel, leading to concerns about potential blackmail attempts. | government | hacked | 5 | BBC News | http://www.bbc.co.uk/news/world-us-canada-33120405 | http://www.reuters.com/article/2015/07/09/us-cybersecurity-usa-idUSKCN0PJ2M420150709?feedType=RSS&feedName=topNews&utm_source=twitter | 189 | ||||
| US Office of Personnel Management | 4,000,000 | 2015 | Jun 2015 | Hackers gained access to federal employees’ Social Security numbers, job assignments, performance ratings and training information. | government | hacked | 2 | Washington Post | http://www.washingtonpost.com/world/national-security/chinese-hackers-breach-federal-governments-personnel-office/2015/06/04/889c0e52-0af7-11e5-95fd-d580f1c5d44e_story.html?tid=hpModule_04941f10-8a79-11e2-98d9-3012c1cd8d1e | 188 | |||||
| Australian Immigration Department | 30 | 2015 | Mar 2015 | An agency employee inadvertently sent the passport numbers and visa details of all world leaders attending the G20 Brisbane summit to the organisers of the Asian Cup football tournament. | government | oops! | y | 4 | The Guardian | http://www.theguardian.com/world/2015/mar/30/personal-details-of-world-leaders-accidentally-revealed-by-g20-organisers | 187 | ||||
| IRS | US Tax service | 100,000 | 2015 | May 2015 | An organized crime syndicate used the IRS website to steal taxpayers' personal financial information. 15,000 of them were used to claim refunds in other people's names. | government | hacked | 1 | CNN | http://money.cnn.com/2015/05/26/pf/taxes/irs-website-data-hack/index.html | 186 | ||||
| MSpy | kid & partner tracking service | 400,000 | 2015 | May 2015 | A service that claims to help people spy on mobile devices was hacked, exposing emails, text messages, payment and location data. | web | hacked | 2 | Krebs on Security | http://krebsonsecurity.com/2015/05/mobile-spy-software-maker-mspy-hacked-customer-data-leaked/ | 185 | ||||
| Adult Friend Finder | Internet dating & hookup site | 3,900,000 | 2015 | May 2015 | Data found on the dark web included sexual preferences, names, email addresses, usernames, dates of birth and postal codes. It included information of former as well as current users. | web | hacked | 1 | Channel 4 | http://www.channel4.com/news/adult-friendfinder-dating-hack-internet-dark-web | 184 | ||||
| Securus Technologies | Prison phone service provider | 70,000,000 | 2015 | Nov 2015 | An anonymous hacker leaked records of over 70m prisoner phone calls, plus links to recordings, potentially violating constitutional protections. | web | hacked | y | 5 | 70m | The Intercept | https://theintercept.com/2015/11/11/securus-hack-prison-phone-company-exposes-thousands-of-calls-lawyers-and-clients/ | 183 | ||
| TalkTalk | Telecoms provider | 157,000 | 2015 | Nov 2015 | Shares in the telecoms firm plunged by a third after the hack, which exposed the banking details of more than 15,000 people. | telecoms | hacked | 2 | BBC News | https://www.bbc.co.uk/news/business-34743185 | http://www.bbc.co.uk/news/uk-34611857 | 182 | |||
| Experian / T-mobile | 15,000,000 | 2015 | Oct 2015 | The world's biggest data monitoring firm disclosed a massive data breach. It had exposed the details of T-Mobile customers applying for credit checks. | telecoms | hacked | 3 | Reuters | http://www.reuters.com/article/2015/10/02/us-tmobile-dataprotection-idUSKCN0RV5PL20151002 | 181 | |||||
| Slack | software for remote working | 500,000 | 2015 | Mar 2015 | Sometime in February 2015, hackers were able to peruse Slack’s central database for up to four days. That database included usernames, email addresses and encrypted passwords. | web | hacked | 1 | Tech Crunch | http://techcrunch.com/2015/03/27/slack-got-hacked/ | 180 | ||||
| CarPhone Warehouse | UK mobile phone supplier | 2,400,000 | 2015 | Aug 2015 | The breach exposed names, addresses, birth date and bank details. Around 480,000 were TalkTalk Mobile customers; 1.9m were customers of Carphone Warehouse directly. | telecoms | hacked | 3 | The Guardian | http://www.theguardian.com/technology/2015/aug/10/carphone-warehouse-uk-data-watchdog-investigating-customer-hack | 179 | ||||
| British Airways | Frequent flyer accounts | 10,000 | 2015 | Mar 2015 | Hackers accessed tens of thousands of British Airways frequent-flyer accounts. The airline froze the affected accounts while it resolved the issue. | transport | hacked | 1 | The Guardian | http://www.theguardian.com/business/2015/mar/29/british-airways-frequent-flyer-accounts-hacked | 178 | ||||
| Anthem | Second-largest health insurer in the US | 80,000,000 | 2015 | Feb 2015 | A "sophisticated cyberattack" on one of the USA's largest health insurers uncovered names, dates of birth, social security numbers, addresses and employment information. | health | hacked | y | 2 | 80m | NYTimes | https://www.nytimes.com/2015/02/05/business/hackers-breached-data-of-millions-insurer-says.html | 177 | ||
| UCLA Health | 4,500,000 | 2015 | May 2015 | Patient information was exposed in a hack on the network. In 2019, the firm reached a $2 million class-action lawsuit settlement. | health | hacked | 4 | 4.5m | Health IT Security | https://healthitsecurity.com/news/ucla-health-reaches-7.5m-settlement-over-2015-breach-of-4.5m | 176 | ||||
| Neiman Marcus | US retailer | 1,100,000 | 2014 | Jan 2014 | Malware in the firm's IT system leaked customer payment data for several months. | retail | hacked | 2 | NY Times | http://www.nytimes.com/2014/01/24/business/neiman-marcus-breach-affected-1-1-million-cards.html | http://krebsonsecurity.com/2014/08/stealthy-razor-thin-atm-insert-skimmers/ | 175 | |||
| AOL | 2,400,000 | 2014 | Apr 2014 | User accounts were compromised in order to send out spam messages. | web | hacked | 1 | NBC News | https://www.nbcnews.com/tech/security/youve-got-hacked-aol-confirms-significant-number-mail-users-hit-n91701 | 174 | |||||
| Community Health Systems | 4,500,000 | 2014 | Aug 2014 | The US hospital operator suffered a system breach, leaking 5 years worth of data. Details included names, addresses, social security numbers. The goal: identity theft. | health | hacked | y | 2 | CNN | http://money.cnn.com/2014/08/18/technology/security/hospital-chs-hack/ | 173 | ||||
| Privatization Agency of the Republic of Serbia | 5,190,396 | 2014 | Dec 2014 | A text file containing personal data and financial documents relating to almost all adult Serbian citizens was made publically available. | government | oops! | 2 | Poverenik | https://www.poverenik.rs/en/press-releases/1953-povreda-prava-na-zastitu-podataka-o-licnosti-skoro-svih-punoletnih-gradjana-srbije.html | 172 | |||||
| Sony Pictures | 10,000,000 | 2014 | Dec 2014 | Potentially every piece of data held by the company was hacked, including unreleased films, employee social security numbers and sensitive internal documents. North Korea suspected. | misc | hacked | 2 | Buzzfeed | http://www.buzzfeed.com/tomgara/sony-hack | 171 | |||||
| Indiana University | 146,000 | 2014 | Feb 2014 | Students who attended the university between 2011 and 2014 may have had their data accessed by three automated computer data mining applications. | academia | poor security | 2 | Indiana University | http://news.iu.edu/releases/iu/2014/02/data-exposure-disclosure.shtml | http://www.usatoday.com/story/news/nation/2014/02/26/indiana-university-data-breach/5830685/ | 170 | ||||
| Ebay | 145,000,000 | 2014 | May 2014 | Hackers attacked between late February and early March, using the login credentials of three corporate employees. They then accessed a database containing all user records. | web | hacked | y | 1 | 145m | Business Insider | https://www.businessinsider.com/cyber-thieves-took-data-on-145-million-ebay-customers-by-hacking-3-corporate-employees-2014-5?r=US&IR=T | 169 | |||
| UPS | 4,000,000 | 2014 | Aug 2014 | Malware was discovered in the credit & debit card processing systems of 51 UPS branches in 24 states. It was leaking data for as long as eight months. | retail | hacked | 3 | Time | http://time.com/3151681/ups-hack/ | 168 | |||||
| European Central Bank | 4,000,000 | 2014 | Jul 2014 | The ECB received an anonymous call requesting money in return for the stolen data. The bank didn't say how much the blackmailer asked for, but did say that it refused to pay anything. | finance | hacked | 1 | City am | http://www.cityam.com/1406190300/ecb-website-hacked | 167 | |||||
| JP Morgan Chase | 76,000,000 | 2014 | Oct 2014 | A hack of the USA's largest bank began in June, but was not discovered until July, when the hackers had already obtained the highest level of administrative privilege for dozens of servers. | finance | hacked | y | 3 | 76m | Deal Book | http://dealbook.nytimes.com/2014/10/02/jpmorgan-discovers-further-cyber-security-issues/?_php=true&_type=blogs&_r=0 | 166 | |||
| New York Taxis | 52,000 | 2014 | Jun 2014 | A freedom of information request resulted in the release of data on all 173 million journeys undertaken by New York taxis in one year. Unfortunately, the data was not properly anonymised. | transport | poor security | y | 1 | Medium | https://medium.com/@vijayp/f6bc289679a1 | 165 | ||||
| HSBC Turkey | 2,700,000 | 2014 | Nov 2014 | An attack on credit and debit card systems left numbers, account numbers, expiry dates and customer names compromised. | finance | hacked | 4 | Reuters | http://www.reuters.com/article/us-hsbc-turkey-cybersecurity/hsbc-turkey-says-customer-credit-card-data-stolen-idUSKCN0IW1RR20141112 | 164 | |||||
| Japan Airlines | 750,000 | 2014 | Sep 2014 | Japan Airlines confirmed the possible theft of information from up to 750,000 frequent-flier programme members, including names, birth dates, addresses and places of work. | transport | hacked | 2 | WSJ, Japan Airlines | http://online.wsj.com/articles/japan-airlines-reports-hacker-attack-1412053828 | http://www.jal.co.jp/en/info/other/140924.html | 163 | ||||
| Staples | 1,160,000 | 2014 | Dec 2014 | Point of sale systems were infected with malware. Thieves may have used it to steal customer names, payment card numbers, expiration dates and card verification codes. | retail | hacked | 3 | Fortune | http://fortune.com/2014/12/19/staples-cards-affected-breach/ | 162 | |||||
| GMail | 5,000,000 | 2014 | Sep 2014 | Account details and passwords were posted on a Russian Bitcoin forum. Close inspection revealed the user details to be old (3+ years). Gmail itself was not hacked. | web | hacked | y | 1 | The Next Web | http://thenextweb.com/google/2014/09/10/4-93-million-gmail-usernames-passwords-published-google-says-evidence-systems-compromised/ | 161 | ||||
| Home Depot | 56,000,000 | 2014 | Sep 2014 | Malware installed on cash register systems at 2,200 stores syphoned credit card details of up to 56 million customers, which were then sold online. | retail | hacked | y | 3 | Krebs on Security | http://krebsonsecurity.com/2014/09/banks-credit-card-breach-at-home-depot/ | 160 | ||||
| Korea Credit Bureau | 20,000,000 | 2014 | Jan 2014 | An employee was accused of of stealing data from customers of three credit card firms while working as a temporary consultant. | finance | inside job | 5 | Security Week | http://www.securityweek.com/20-million-people-fall-victim-south-korea-data-leak | 159 | |||||
| Dominios Pizzas (France) | 600,000 | 2014 | Jun 2014 | Hackers demanded a ransom of €30,000 (£24,000) from Domino's Pizza after stealing personal data on more than 600,000 of its French and Belgian customers. | retail | hacked | 1 | The Guardian | http://www.theguardian.com/technology/2014/jun/16/dominos-pizza-ransom-hack-data | 158 | |||||
| Mozilla | 76,000 | 2014 | Aug 2014 | After the failure of a "data sanitation" process, Mozilla’s developer community was alerted to an accidental leak of email addresses and encrypted passwords. | web | poor security | 2 | The Guardian | http://www.theguardian.com/technology/2014/aug/05/mozilla-leak-developer-email-addresses-passwords-firefox | 157 | |||||
| Massive American business hack | 7-Eleven, JC Penney, Hannaford, Heartland, JetBlue, Dow Jones, Euronet, Visa Jordan, Global Payment, Diners Singapore and Ingenicard | 160,000,000 | 2013 | Jul 2013 | For more than seven years a hacking ring targeted banks, payment processors and chain stores to steal more than 160 million credit and debit card numbers. | finance | hacked | y | 5 | 160m | Technology Review | https://www.technologyreview.com/s/517551/prosecutors-describe-massive-breach-of-credit-card-data/ | 156 | ||
| Affinity Health Plan, Inc. | 344,579 | 2013 | Aug 2013 | A rented photocopier used to copy health records did not have its hard-drive wiped before its return, exposing personal data. | health | lost device | y | 4 | Proskauer | https://privacylaw.proskauer.com/2013/08/articles/identity-theft/a-1-2-million-photocopier-mistake-health-plan-settles-with-hhs-in-hipaa-breach-case/ | 155 | ||||
| Citigroup | 150,000 | 2013 | Jul 2013 | The bank failed to redact court records before they were placed on a publicly accessible system. The personal information of customers entering bankruptcy between 2007-2011 was exposed. | finance | oops! | y | 2 | Softpedia | http://news.softpedia.com/news/Citi-Exposes-Details-of-150-000-Individuals-Who-Went-into-Bankruptcy-369979.shtml | 154 | ||||
| Tianya | Usernames, clear tect passwords and email addresses hacked. | 40,000,000 | 2013 | Jul 2013 | China's biggest online forum confirmed that private information for 40 million users had been breached back in 2011. | web | hacked | 1 | Computer World, Hacker News | http://www.scmagazine.com.au/News/349585,28-million-clear-text-passwords-found-after-tianya65279-hack.aspx | https://thehackernews.com/2011/12/tianya-chinas-biggest-online-forum-40.html | 153 | |||
| Scribd | "world's largest online library" | 500,000 | 2013 | Apr 2013 | A website billing itself as the "world's largest online library" was hacked. 1% of its users had passwords compromised. | web | hacked | 1 | Naked Security, NBC News | http://nakedsecurity.sophos.com/2013/04/05/scribd-worlds-largest-online-library-admits-to-network-intrusion-password-breach/ | http://www.nbcnews.com/technology/scribd-hack-exposes-thousands-users-1B9239618 | 152 | |||
| Living Social | special offers website | 50,000,000 | 2013 | Apr 2013 | Hackers gained access to names, e-mail addresses, dates of birth & encrypted passwords for 50 million users of an online offers site part-owned by Amazon. | web | hacked | 1 | Naked Security, New York Times | http://nakedsecurity.sophos.com/2013/04/27/livingsocial-hacked-50-million-affected/ | http://bits.blogs.nytimes.com/2013/04/26/living-social-hack-exposes-data-for-50-million-customers/ | 151 | |||
| Yahoo | 550,000,000 | 2013 | Dec 2016 | A 2013 attack was eventually disclosed in 2016. Stolen data included names, telephone numbers, birth dates, passwords and security questions. | web | hacked | 2 | 1bn | NY Times, BBC | http://www.nytimes.com/2016/12/14/technology/yahoo-hack.html?action=Click&contentCollection=BreakingNews&contentID=64651831&pgtype=Homepage&_r=0 | https://www.bbc.co.uk/news/business-41493494 | 150 | |||
| SnapChat | 4,600,000 | 2013 | Jan 2014 | Hackers abused an exploit to siphon off usernames and phone numbers, which were then posted online. | web, tech | hacked | 2 | BBC News | https://www.bbc.co.uk/news/technology-25572661 | 149 | |||||
| University of Delaware | 74,000 | 2013 | Aug 2013 | Confidential personal information on past and current employees of the University of Delaware was stolen when a software vulnerability was exploited. | academia | hacked | 2 | University of Delaware | http://www1.udel.edu/udaily/2014/jul/resources073013.html | 148 | |||||
| Central Hudson Gas & Electric | 110,000 | 2013 | Feb 2013 | Customer banking information and other personal information may have been accessed when systems belonging to the energy supplier were hacked. | misc | hacked | 3 | eSecurity Planet | https://www.esecurityplanet.com/network-security/central-hudson-gas-and-electric-hacked.html | 147 | |||||
| 250,000 | 2013 | Feb 2013 | A Java vulnerability gave hackers access to some user information including usernames, email addresses, session tokens and encrypted/salted versions of passwords. | web | hacked | 1 | CNN | https://edition.cnn.com/2013/02/01/tech/social-media/twitter-hacked/index.html | 146 | ||||||
| Crescent Health Inc., Walgreens | 100,000 | 2013 | Feb 2013 | A stolen laptop exposed private data including names, social security numbers, health insurance information, birth dates, diagnoses and other medical information. | health | lost device | 4 | Healthcare IT News | https://www.healthcareitnews.com/news/walgreens-company-announces-data-breach | 145 | |||||
| Florida Department of Juvenile Justice | 100,000 | 2013 | Jan 2013 | The theft of a mobile device containing youth and employment records exposed 100,000 young people to potential identity theft. | government | lost device | 2 | Data Breaches | https://www.databreaches.net/stolen-florida-dept-of-juvenile-justice-device-contained-records-of-more-than-100000-youth-and-employees/ | 144 | |||||
| Advocate Medical Group | 4,000,000 | 2013 | Aug 2013 | Four unencrypted computers were stolen from an office belonging to the healthcare provider. 4,000,000 patient names, addresses, dates of birth and Social Security numbers were exposed. | health | lost device | y | 2 | Health IT Security | http://healthitsecurity.com/2013/08/27/advocate-medical-group-endures-massive-data-breach/ | 143 | ||||
| OVH | French Internet host | 200,000 | 2013 | Jul 2013 | A hacker gained access to an email account, from where they were able to compromise the firm's internal systems. The European customer database was exposed. | web | hacked | 2 | OVH | http://status.ovh.net/?do=details&id=5070 | 142 | ||||
| Apple | 275,000 | 2013 | Jul 2013 | Apple's developer portal was hacked. "Some" information about 275,000 3rd-party developers was potentially stolen. | tech, web | hacked | 1 | The Guardian | http://www.guardian.co.uk/technology/2013/jul/22/apple-developer-site-hacked | 141 | |||||
| NASDAQ | Nasdaq OMX Group | 500,000 | 2013 | Jul 2013 | Cybercriminals targeted the Nasdaq online forum, stealing email addresses and passwords. | finance | hacked | y | 1 | Reuters | https://uk.reuters.com/article/net-us-nasdaq-cybercrime-website/nasdaq-forum-website-hacked-passwords-compromised-idUSBRE96H1F520130718 | 140 | |||
| UbiSoft | games company | 58,000,000 | 2013 | Jul 2013 | The video games publisher revealed that user names, email addresses and encrypted passwords had been "illegally accessed". | gaming | hacked | 2 | BBC News | https://www.bbc.co.uk/news/technology-23159997 | 139 | ||||
| Ubuntu | The discussion forum for the popular alternative, open-source operating system | 2,000,000 | 2013 | Jul 2013 | The discussion forum for the operating system was hacked, exposing personal details and weakly-hashed passwords. | tech, web | hacked | y | 3 | Ars Technica | http://arstechnica.com/security/2013/07/hack-exposes-e-mail-addresses-password-data-for-2-million-ubuntu-forum-users/ | 138 | |||
| Nintendo | Japan's Club Nintendo service | 4,000,000 | 2013 | Jun 2013 | Names, phone numbers, home and email addresses of Japanese members of Club Nintendo were stolen after a website breach. | gaming | hacked | 2 | ZDNet | https://www.zdnet.com/article/club-nintendo-site-hacked-customer-data-exposed/ | 137 | ||||
| National Security Agency | 1,500,000 | 2013 | Jun 2013 | Edward Snowden, an intelligence contractor in Hawaii, downloaded up to 1.5 million files. He then flew to Hong Kong to meet journalists Glenn Greenwald and Laura Poitras before fleeing to Moscow. | government | inside job | y | 5 | Business Insider | http://uk.businessinsider.com/snowden-leaks-timeline-2016-9 | 136 | ||||
| 6,000,000 | 2013 | Jun 2013 | By using the network's "Download Your Information" tool, some Facebook members were able to access phone numbers and email addresses of strangers. | web | oops! | 1 | https://www.facebook.com/notes/facebook-security/important-message-from-facebooks-white-hat-program/10151437074840766 | 135 | |||||||
| Evernote | online note-taking site | 50,000,000 | 2013 | Mar 2013 | Evernote asked all its users to reset their passwords, following the discovery of unauthorised access of personal details. | web | hacked | 1 | Wired, Digital Trends | http://www.wired.co.uk/news/archive/2013-03/04/evernote-hacked | http://www.digitaltrends.com/mobile/evernote-hack-50-million-users-forced-to-reset-passwords/ | 134 | |||
| Kirkwood Community College | Hacked online database | 125,000 | 2013 | Apr 2013 | Hackers accessed data relating to applications made between February 2006 and March 2013, including names, birth dates, race, contact information and Social Security numbers. | academia | hacked | 2 | eSecurity Planet | https://www.esecurityplanet.com/hackers/kirkwood-community-college-hacked.html | 133 | ||||
| Yahoo Japan | 22,000,000 | 2013 | May 2013 | 22 million Yahoo user IDs may have been leaked after Yahoo detected an unauthorized attempt to access the administrative system of its Yahoo Japan portal. | tech, web | hacked | 1 | Reuters | https://www.reuters.com/article/us-yahoojapan/yahoo-japan-suspects-22-million-user-ids-leaked-kyodo-idUSBRE94G0P620130517 | 132 | |||||
| Drupal | open-source content management platform | 1,000,000 | 2013 | May 2013 | Malicious files were placed on the servers of the content management platform. They exposed usernames, e-mail addresses and cryptographically hashed passwords. | web | hacked | 1 | Ars Technica | http://arstechnica.com/security/2013/05/drupal-org-resets-login-credentials-after-hack-exposes-password-data/ | 131 | ||||
| TerraCom & YourTel | 170,000 | 2013 | May 2013 | Journalists discovered the personal data of over 170,000 customers on a publicly accessible server. Hilariously, the firms branded the journalists "hackers". | telecoms | oops! | y | 2 | Boing Boing, Wired | http://boingboing.net/2013/05/23/terracom-and-yourtel-threaten.html | http://www.wired.co.uk/news/archive/2013-05/23/reporter-google-breach-hacker | 130 | |||
| Washington State court system | Administrative offices | 160,000 | 2013 | May 2013 | Social Security numbers and a million driver's license numbers may have been accessed by hackers exploiting weaknesses in old server software. | government | hacked | 2 | Reuters, Privacy Rights | https://www.reuters.com/article/us-usa-hack-washingtonstate-idUSBRE9480YY20130509 | http://www.privacyrights.org/data-breach | 129 | |||
| MacRumours.com | 860,000 | 2013 | Nov 2013 | A moderator account on the forum was logged into by the hacker, who then was able to escalate privileges. All users were advised to change their passwords. | web | hacked | 1 | Wired | http://www.wired.co.uk/news/archive/2013-11/13/mac-rumours-forums-hacked | 128 | |||||
| Court Ventures | Experian | 200,000,000 | 2013 | Oct 2013 | A 24 year old Vietnamese national, Hieu Minh Ngo, ran an identity theft service from his bedroom. A deal he struck with Experian gave him access to the personal and financial data of American citizens. | finance | inside job | 2 | 200m | NY Times, Gov Tech | https://krebsonsecurity.com/2014/03/experian-lapse-allowed-id-theft-service-to-access-200-million-consumer-records/ | http://www.govtech.com/security/San-Diego-Sues-Experian-Over-Alleged-2010-Breach.html | 127 | ||
| Vodafone | 2,000,000 | 2013 | Sep 2013 | An IT contractor for the firm used his access to the telecom giant's system to steal customer details, including bank account numbers and sort codes. | telecoms | inside job | y | 3 | Security Week | http://www.securityweek.com/attacker-steals-data-2-million-vodafone-germany-customers | 126 | ||||
| Adobe | 38,000,000 | 2013 | Oct 2013 | Hackers obtained access to a swathe of Adobe customer IDs, encrypted passwords & sensitive information including encrypted credit and debit card numbers. Plus source code. | tech | hacked | y | 3 | 38m | Adobe | https://www.bbc.co.uk/news/technology-24740873 | 125 | |||
| D&B, Altegrity | 1,000,000 | 2013 | Sep 2013 | Hackers stole millions of social security numbers from a number of large US data brokers, intending to steal identities. | tech | hacked | 3 | USA Today; Reuters | http://www.usatoday.com/story/cybertruth/2013/09/26/lexisnexis-dunn--bradstreet-altegrity-hacked/2878769/ | http://www.reuters.com/article/2013/09/26/us-cyberattacks-databrokers-idUSBRE98P03220130926 | 124 | ||||
| ssndob.ms | 4,000,000 | 2013 | Sep 2013 | Teenage hackers collected data for exposed.su, a site that charged people to search for the social security numbers, birthdays, phone numbers and addresses of celebrities. | web | hacked | y | 2 | Krebs on Security | http://krebsonsecurity.com/2013/09/data-broker-giants-hacked-by-id-theft-service/ | 123 | ||||
| Target | 70,000,000 | 2013 | Dec 2013 | Investigators believe that personal data was obtained via software installed on card-swiping machines at Target stores. | retail | hacked | y | 3 | Huffington Post | http://www.huffingtonpost.com/2013/12/19/target-hacked-customer-credit-card-data-accessed_n_4471672.html?utm_hp_ref=mostpopular | 122 | ||||
| China Software Developer Network | 6,000,000 | 2012 | Mar 2012 | A man surnamed Zeng was arrested on suspicion of leaking personal information belonging to users of the China Software Developer Network (CSDN). | web | hacked | 1 | ZDNet | http://www.zdnet.com/blog/security/chinese-hacker-arrested-for-leaking-6-million-logins/11064 | 121 | |||||
| Global Payments | Credit, debit and check processing for merchants (Visa, Mastercard, etc) | 1,500,000 | 2012 | Apr 2012 | Hackers gained unauthorised access to systems of the payment processing firm, exposing over a million credit card numbers. | finance | hacked | 3 | Washington Post | http://www.washingtonpost.com/business/technology/faq-the-global-payments-hack/2012/04/02/gIQAIHLLrS_story.html | 120 | ||||
| South Carolina Government | South Carolina Department of Health and Human Services | 228,000 | 2012 | Apr 2012 | A man was arrested for sending confidential information on Medicaid beneficiaries to his personal email address. | health | inside job | 4 | The State | https://www.infosecurity-magazine.com/news/data-breach-hits-228000-south-carolina-medicaid/ | 119 | ||||
| Three Iranian banks | Saderat, Eghtesad Novin, & Saman | 3,000,000 | 2012 | Apr 2012 | After finding a security flaw in Iran's banking system, Khosrow Zarefarid sent a formal report to the CEOs of all affected banks. When they ignored him, he hacked 3m bank accounts to prove his point. | finance | hacked | y | 5 | ZD Net | http://www.zdnet.com/blog/security/3-million-bank-accounts-hacked-in-iran/11577 | 118 | |||
| California Department of Child Support Services | 800,000 | 2012 | Apr 2012 | California child support records were lost in transit during a "disaster preparedness" exercise. | government | lost device | 2 | Business Insider | https://www.businessinsider.com/california-child-support-data-breach-2012-4?IR=T | 117 | |||||
| Emory Healthcare | hospital system in Atlanta | 315,000 | 2012 | Apr 2012 | The company 'misplaced' 10 backup discs containing sensitive patient information, including social security numbers. | health | lost device | 4 | Emory | http://news.emory.edu/stories/2012/04/ehc_missing_data/campus.html | 116 | ||||
| Office of the Texas Attorney General | 6,500,000 | 2012 | Apr 2012 | The office of Texas Attorney General Greg Abbott mistakenly gave attorneys access to a database containing millions of Social Security numbers. | government | oops! | 2 | Raw Story | http://www.rawstory.com/rs/2012/04/26/texas-attorney-general-exposes-millions-of-voters-social-security-numbers/ | 115 | |||||
| Medicaid | US health program for low income people and families | 780,000 | 2012 | Apr 2012 | Hackers operating out of Eastern Europe circumvented server security at the Utah Health Department, stealing the Social Security numbers of Medicaid claimants. | government, health | hacked | y | 5 | Reuters | https://www.reuters.com/article/us-usa-hackers-utah/european-hackers-suspected-in-utah-medicaid-files-breach-idUSBRE83404G20120405 | 114 | |||
| Blizzard | Activision, Battle.net | 14,000,000 | 2012 | Aug 2012 | Scrambled passwords, e-mail addresses, and personal security answers were stolen from Blizzard's internal network. Blizzard would not elaborate on the size of the hack ("millions"). | gaming | hacked | 2 | Forbes | https://www.forbes.com/sites/erikkain/2012/08/09/its-official-blizzard-hacked-account-information-stolen/#6dfbcdc355d1 | 113 | ||||
| New York State Electric & Gas | 1,800,000 | 2012 | Jan 2012 | An employee from a software consulting firm was able to grant unauthorized access to the energy supplier's database. | misc | inside job | 2 | Data Breaches | https://www.databreaches.net/nyseg-and-rge-notify-customers-of-unauthorized-access-to-customer-data/ | 112 | |||||
| Memorial Healthcare System | Florida | 102,153 | 2012 | Apr 2012 | For more than a year, an employee of an affiliated physician’s office accessed patient information through a web portal: names, dates of birth and Social Security numbers. | health | lost device | 2 | Modern Healthcare | https://www.databreaches.net/more-breaches-you-may-not-have-known-about/ | 111 | ||||
| Zappos | 24,000,000 | 2012 | Jan 2012 | The Amazon-owned e-commerce firm was the target of a cyber attack on its internal network, exposing names, e-mail addresses, phone numbers,addresses, and encrypted passwords. | web | hacked | 2 | Forbes | http://www.forbes.com/sites/andygreenberg/2012/01/15/zappos-says-hackers-accessed-24-million-customers-account-details/ | 110 | |||||
| Formspring | Interest-based social Q&A website | 420,000 | 2012 | Jul 2012 | 420,000 hashed passwords were posted to a security forum. Formspring immediately forced users to reset their passwords. | web | hacked | y | 1 | CNet | http://news.cnet.com/8301-1009_3-57469944-83/formspring-disables-user-passwords-in-security-breach/?tag=mncol;txt | 109 | |||
| KT Corp. | Korean mobile carrier | 8,700,000 | 2012 | Jul 2012 | Two suspects earned an estimated $877,000 by selling the contact information and plan details of 8.7 million subscribers to Korea's second largest mobile phone network. | telecoms | hacked | 2 | Korea Times, CNet | http://www.koreatimes.co.kr/www/news/biz/2012/07/113_116143.html | http://news.cnet.com/8301-1009_3-57482215-83/hackers-accused-of-stealing-data-from-9m-korean-mobile-users/ | 108 | |||
| Yahoo Voices | 450,000 | 2012 | Jul 2012 | Usernames and passwords thought to be related to Yahoo's Voice service were dumped online, after being accessed in a database hack. | tech, web | hacked | 1 | Slashdot | https://www.helpnetsecurity.com/2012/07/12/nearly-half-a-million-yahoo-passwords-leaked-following-hack/ | 107 | |||||
| Last.fm | Owned by CBS | 43,500,000 | 2012 | Sep 2016 | Usernames, email addresses and other internal records, such as newsletter sign-ups and ad-related data, were stolen in a 2012 hack. | web | hacked | 1 | ZD Net | http://www.zdnet.com/article/hackers-stole-43-million-last-fm-account-details-in-2012-breach/ | https://www.zdnet.com/article/last-fm-investigating-security-issue-passwords-leaked/ | 106 | |||
| LinkedIn, eHarmony, Last.fm | 8,000,000 | 2012 | Jun 2012 | Hacker 'dwdm' uploaded a file containing 6.5 million passwords to a Russian hacker forum. Soon after, another 1.5 million passwords were discovered in another file on the forum. | web | hacked | 1 | Cnet | http://news.cnet.com/8301-1009_3-57449325-83/what-the-password-leaks-mean-to-you-faq/?tag=mncol;txt | 105 | |||||
| Gamigo | 8,000,000 | 2012 | Jul 2012 | 4 months after the gaming site Gamigo warned users about a hacker intrusion, more than 8 million usernames, emails & encrypted passwords from the site were published on the web. | web | hacked | 1 | Forbes | http://www.forbes.com/sites/andygreenberg/2012/07/23/eight-million-passwords-spilled-from-gaming-site-gamigo-months-after-breach/ | 104 | |||||
| Militarysingles.com | Online dating network for, you guessed it, military singles | 163,792 | 2012 | Mar 2012 | Hacking group LulzSec released a database of 163,792 names, usernames, e-mail addresses, IP addresses, and passwords of "single" military personnel. | web, military | hacked | 1 | PC World | http://www.pcworld.com/article/252647/reborn_lulzsec_claims_hack_of_dating_site_for_military_personnel.html | 103 | ||||
| "Apple" | 12,367,232 | 2012 | Mar 2012 | Millions of Apple Unique Device Identifiers (UDIDs) were leaked online. A hacking group claimed it had hacked an FBI laptop, but a software firm called BlueToad was found to be the source. | tech, retail | oops! | y | 2 | CNET | http://news.cnet.com/8301-1009_3-57505330-83/antisec-claims-to-have-snatched-12m-apple-device-ids-from-fbi/ | http://news.cnet.com/8301-1009_3-57509595-83/udid-leak-source-idd-bluetoad-mobile-firm-says-it-was-hacked/ | 102 | |||
| Greek government | 9,000,000 | 2012 | Nov 2012 | A computer programmer was arrested in Greece for allegedly stealing the identity information of 83% of the country's population. The 35-year-old was suspected of trying to sell it on. | government | hacked | 2 | Wired | http://www.wired.co.uk/news/archive/2012-11/22/greece-id-theft | 101 | |||||
| South Carolina State Dept. of Revenue | 3,600,000 | 2012 | Oct 2012 | A server containing social security numbers and credit card data was breached by an international hacker. | government | hacked | 1 | Information Week | http://www.infoworld.com/article/2615754/cyber-crime/south-carolina-reveals-massive-data-breach-of-social-security-numbers--credit-cards.html | 100 | |||||
| Dropbox | 68,700,000 | 2012 | Aug 2016 | User credentials were stolen in a 2012 hack, but the number affected only came to light four years later. Dropbox reset any passwords that had been unchanged since 2012. | web | hacked | 1 | 68.7m | The Telegraph | https://www.bbc.co.uk/news/technology-37232635 | 99 | ||||
| New York City Health & Hospitals Corp. | New York City Health & Hospitals Corporation's North Bronx Healthcare Network | 1,700,000 | 2011 | Feb 2011 | Computer backup tapes from the New York provider were stolen from a truck that was transporting them to a secure storage location. | health | lost device | 4 | InfoRisk | https://www.inforisktoday.com/new-york-breach-affects-17-million-a-3349 | 98 | ||||
| Seacoast Radiology, PA | 231,400 | 2011 | Jan 2011 | Computer gamers hacked a server in search of more bandwidth to play Call of Duty. In the process they gained access to personal records of more than 230,000 patients. | health | hacked | y | 2 | Fosters | http://www.fosters.com/apps/pbcs.dll/article?AID=/20110120/GJNEWS_01/701209744 | 97 | ||||
| South Shore Hospital, Massachusetts | 800,000 | 2011 | Sep 2011 | South Shore Hospital hired a contractor to destroy files no longer in use. The firm lost the shipment. It contained social security numbers, medical records and banking details. | health | lost device | 5 | Boston Globe | https://www.infosecurity-magazine.com/news/south-shore-hospital-data-breach-may-affect-up-to/ | 96 | |||||
| Betfair | UK gambling site | 2,300,000 | 2011 | May 2011 | Betfair waited 18 months to report the breach of their online gambling site, alarming banking institutions and security experts. The breach involved user names, addresses and account details. | web | hacked | 3 | FT | https://www-ft-com.libezproxy.open.ac.uk/content/819f5b1c-eb80-11e0-a576-00144feab49a | 95 | ||||
| Ankle & foot Center of Tampa Bay, Inc. | 156,000 | 2011 | Jan 2011 | Names, social security numbers, date of birth, home addressees, account numbers, healthcare services and diagnostics were hacked. | health | hacked | 4 | Phi Privacy | https://www.databreaches.net/ankle-foot-center-of-tampa-bay-breach-affecting-156000-included-social-security-numbers-as-well-as-phi/ | 94 | |||||
| Yale University | 43,000 | 2011 | Aug 2011 | The names and Social Security numbers of 43,000 people affiliated with the university were publicly viewable on Google for 10 months. | academia | oops! | 2 | NBC News | http://www.nbcnews.com/id/44235153/ns/technology_and_science-security/t/data-breach-hits-yale-university/ | 93 | |||||
| Morgan Stanley Smith Barney | 34,000 | 2011 | Jul 2011 | Morgan Stanley mailed two CDRs containing sensitive data about investors to the New York State Department of Taxation and Finance. When it arrived at the relevant desk, the CDs were missing. | finance | lost device | y | 3 | ABC News | https://abcnews.go.com/Business/morgan-stanley-smith-barney-breach-losing-client-data/story?id=14008632 | 92 | ||||
| State of Texas | 3,500,000 | 2011 | Apr 2011 | 3.5 million records were accidentally published online including people's names, mailing addresses and social security numbers. They were there for a year. | government | oops! | 2 | Dallas News | https://uk.pcmag.com/news/105457/texas-security-breach-exposes-35m-records | 91 | |||||
| Epsilon | Marketing email provider | 3,000,000 | 2011 | Apr 2011 | Names & email addresses of customers of Barclaycard US, Capital One, JP Morgan, Citigroup & other firms were stolen via a breach in an email system. | web | hacked | 1 | Guardian | https://www.theguardian.com/technology/2011/apr/04/epsilon-email-hack | 90 | ||||
| Sony PSN | 77,000,000 | 2011 | Apr 2011 | Rounding off a thoroughly unhappy year for Sony, their third breach saw a breach of 76,000,000 Sony PSN and Qriocity user accounts. They were offline for 23 days. | gaming | hacked | y | 1 | Mashable | https://blog.playstation.com/archive/2011/04/28/playstation-network-and-qriocity-outage-faq/ | 89 | ||||
| US Law Enforcement | 123,461 | 2011 | Aug 2011 | "AntiSec" hackers published a huge trove of personal information from 70 different US law enforcement agencies. | government | hacked | 3 | PC World | http://www.pcmag.com/article2/0,2817,2390683,00.asp | 88 | |||||
| University of Wisconsin - Milwaukee | 73,000 | 2011 | Aug 2011 | A malware attack on a database server exposed the names and social security numbers of students and staff, past and present. | academia | hacked | 2 | ZDNet | https://www.zdnet.com/article/university-of-wisconsin-hacked-75000-social-security-numbers-student-names-exposed/ | 87 | |||||
| Stratfor | geopolitical intelligence firm | 935,000 | 2011 | Dec 2011 | Hacking collective Anonymous published what they claimed was Stratfor's confidential client list, along with credit card details and passwords. In fact, it was a list of subscribers to Stratfor's online publication. | military | hacked | 3 | NYTimes | https://https://en.wikipedia.org/wiki/Stratfor_email_leak | 86 | ||||
| Chinese gaming sites | 10,000,000 | 2011 | Dec 2011 | Several major Chinese gaming sites were hacked, breaching millions of user records. | web | hacked | 1 | eHacking News | http://www.ehackingnews.com/2011/12/hackers-compromised-38-million-chinese.html | 85 | |||||
| Southern California Medical-Legal Consultants | 300,000 | 2011 | Jun 2011 | Electronic files containing names and social security numbers of approximately 300,000 individuals who have applied for workers’ compensation benefits were left unsecured. | health | hacked | 2 | Data Breaches | https://www.databreaches.net/southern-california-medical-legal-consultants-reveals-that-300000-workers-compensation-applicants-names-and-social-security-numbers-were-exposed-on-internet/ | 84 | |||||
| Writerspace.com | Website design and hosting for writers | 62,000 | 2011 | Jun 2011 | Hacker group LulzSec released a stash of e-mails and passwords, 12,000 of which were confirmed to originate from Writerspace.com. | web | hacked | 1 | PC Mag | http://www.pcmag.com/article2/0,2817,2387186,00.asp | 83 | ||||
| Bethesda Game Studios | US video game company (Elder Scrolls, Fallout 3) | 200,000 | 2011 | Jun 2011 | Hacking collective Lulzsec claimed to have stolen the account information of 200,000 users. | gaming | hacked | 1 | PC World | https://venturebeat.com/2011/06/13/lulzsec-bethesda-hack/ | 82 | ||||
| Sega | 1,290,755 | 2011 | Jun 2011 | Information registered as part of the Sega Pass system was stolen, including names, birth dates, e-mail addresses and passwords. | gaming | hacked | 2 | ZDNet | http://www.zdnet.com/blog/gamification/sega-1-3-million-customer-records-hacked-lulzsec-promises-retribution/481 | 81 | |||||
| Citigroup | 210,000 | 2011 | Jun 2011 | A breach of the bank's online web portal compromised the information of around 1% of Citbank card holders. | finance | hacked | 3 | PC World | http://www.pcworld.com/article/229891/Citigroup_Hack_Nets_Over_200k_in_Stolen_Customer_Details.html | 80 | |||||
| Sony Pictures | 1,000,000 | 2011 | Jun 2011 | The LulzSec hacking collective accessed unencrypted user information. They claimed that they didn't have the resources to steal everything they were able to access. | web | hacked | y | 1 | Mashable | http://mashable.com/2011/06/02/sony-pictures-hacked/ | 79 | ||||
| Accendo Insurance Co. | 175,350 | 2011 | Jun 2011 | Mismailed letters allowed some lines of sensitive information (medication name, date of birth, and member ID) to be visible through the envelope window. | health | poor security | 2 | Data Breaches | http://www.databreaches.net/?p=19198 | 78 | |||||
| Washington Post | 1,270,000 | 2011 | Jul 2011 | Unknown hackers broke into The Washington Post's jobs website, stealing user IDs and email addresses. | misc | hacked | 2 | PC Mag | http://www.pcmag.com/article2/0,2817,2388200,00.asp | 77 | |||||
| Health Net - IBM | Data lost from HN servers managed by IBM | 1,900,000 | 2011 | Mar 2011 | As many as nine server drives containing personal information of former and current employees went missing from an IBM data center in California. | health | lost device | 3 | IEEE Spectrum | https://spectrum.ieee.org/riskfactor/computing/it/health-net-data-breaches-affects-19-million-people | 76 | ||||
| Eisenhower Medical Center | California hospital | 514,330 | 2011 | Apr 2011 | A computer stolen from the hospital contained patients' names, ages, dates of birth, medical record numbers and the last four digits of their social security numbers. | health | lost device | 4 | Data Breach Info | http://databreachinvestigation.blogspot.com/2011/04/thief-gets-away-with-eisenhower-medical.html | 75 | ||||
| Spartanburg Regional Healthcare System | 400,000 | 2011 | May 2011 | A computer stolen from an employee's car contained a password-protected file with Social Security numbers as well as names, addresses, dates of birth and medical billing codes. | health | lost device | 4 | GoUpstate | https://www.inforisktoday.com/400000-affected-by-stolen-pc-a-3853 | 74 | |||||
| NHS | UK's national health service, govt funded | 8,600,000 | 2011 | Jun 2011 | A laptop holding the unencrypted records of eight million patients went missing from an NHS store room and wasn't reported until 3 weeks later. | health | lost device | y | 4 | Alphr | https://www.alphr.com/news/security/368062/nhs-loses-laptop-holding-8m-patient-records | 73 | |||
| San Francisco Public Utilities Commission | 180,000 | 2011 | Jun 2011 | A server storing customer data was found to be a) unsecured, and b) infected with viruses. | government | hacked | 1 | CNET | http://news.cnet.com/8301-27080_3-20068386-245/sf-utilities-agency-warns-of-potential-breach/ | 72 | |||||
| Sony Online Entertainment | 24,600,000 | 2011 | May 2011 | Hackers may have taken personal information from accounts in Austria, Germany, The Netherlands and Spain, including over 12,000 credit card accounts and 10,000 bank accounts. | gaming | hacked | 3 | Computer Weekly | https://privacyrights.org/data-breaches/sony-playstation-network-psn-sony-online-entertainment-soe | 71 | |||||
| Honda Canada | 283,000 | 2011 | May 2011 | Names, addresses and vehicle identification numbers were taken from two of the firms' eCommerce websites, myHonda and myAcura | retail | hacked | y | 2 | Guelph Mercury | http://www.guelphmercury.com/news-story/2200845-honda-canada-hit-by-online-security-breach-283-000-car-owners-personal-data-stolen/ | 70 | ||||
| Massachusetts Government | Massachusetts Executive Office of Labor and Workforce | 210,000 | 2011 | May 2011 | Over 1,500 departmental computers were infected with malware which “downloads additional files, steals information and opens a back door on the compromised computer”. | government | hacked | y | 5 | NBC News | http://www.nbcnews.com/id/43086769/ns/technology_and_science-security/t/huge-data-breach-puts-risk/#.XAfhPhP7TUI | 69 | |||
| Oregon Department of Motor Vehicles | 1,000,000 | 2011 | May 2011 | Detectives arrested Tim Nuss for accessing an old Oregon Department of Motor Vehicles database, including names, addresses, birth dates, gender and ages of people who registered. | government | hacked | 2 | Data Breaches | https://www.databreaches.net/or-deputies-man-used-dmv-database-in-id-theft/ | 68 | |||||
| Steam | gaming portal | 35,000,000 | 2011 | Nov 2011 | Attackers used login details from a forum hack to gain access to a database containing user names, encrypted passwords and credit card info, game purchases and billing addresses. | web | hacked | 3 | SC Mag | http://www.bbc.co.uk/news/technology-15690187 | 67 | ||||
| Restaurant Depot | food, equipment, and supplies for restaurants | 200,000 | 2011 | Nov 2011 | Nov 2011. Cybercrooks presumed to be operating from Russia hacked into the Restaurant Depot database and accessed credit and debit card details. | retail | hacked | 3 | NBC News | https://www.finextra.com/newsarticle/23243/restaurant-depot-hacked-by-russian-cyber-criminals | 66 | ||||
| Nexon Korea Corp | game developer | 13,200,000 | 2011 | Nov 2011 | Personal data of subscribers to the online game Maple Story was breached and subsequently leaked. | web | hacked | 2 | Reuters | https://uk.reuters.com/article/us-korea-hacking-nexon/data-of-13-million-south-korean-online-game-subscribers-hacked-idUSTRE7AP09H20111126 | 65 | ||||
| Nemours Foundation | US children's hospitals | 1,600,000 | 2011 | Oct 2011 | A Florida health care provider responsible for running children’s hospitals lost three data backup tapes, containing 10 years worth of information. | health | lost device | 4 | Law360 | https://www.law360.com/articles/277961/nemours-says-data-breach-affected-1-6m-patients | 64 | ||||
| Sutter Medical Foundation | 4,243,434 | 2011 | Nov 2011 | A stolen laptop contained a database with names, addresses, dates of birth, phone numbers, email addresses, medical record numbers and health insurance plans. | health | lost device | 2 | Trend Micro | https://blog.trendmicro.com/sutter-health-sued-for-1-billion-following-data-breach/ | 63 | |||||
| Tricare | Healthcare service for US Military | 4,901,432 | 2011 | Sep 2011 | Backup tapes containing information for some 4.6 million active and retired military personnel, as well as their families, was stolen from a data contractor's car in San Antonio. | military, health | lost device | 4 | Reuters | http://www.reuters.com/article/us-data-breach-texas-idUSTRE78S5JG20110929 | 62 | ||||
| AvMed, Inc. | 1,220,000 | 2010 | Feb 2010 | Two company laptops containing names, addresses, dates of birth, Social Security numbers and health-related information were stolen from an AvMed facility in Gainesville. | health | lost device | 2 | Hack Notice | https://www.databreachtoday.com/avmed-sued-over-laptop-breach-a-3111 | 61 | |||||
| Blue Cross Blue Shield of Tennessee | US health insurance organization | 1,023,209 | 2010 | May 2010 | A thief stole 57 unencrypted hard drives from the closet of a BlueCross call center in Chattanooga. | health | lost device | y | 2 | Data Breaches | https://www.databreaches.net/bcbs-of-tenn-breach-lessons-learned/ | 60 | |||
| US Military | Wikileaks / Bradley Manning/Cablegate. | 260,000 | 2010 | Nov 2010 | The Wikileaks Embassy Cables, containing over 1/4 of a million dispatches from more than 250 worldwide embassies and consulates. | military | inside job | y | 5 | Guardian | http://www.guardian.co.uk/news/datablog/2010/nov/29/wikileaks-cables-data | 59 | |||
| Gawker.com | US news and gossip blog network including Gawker.com Gizmodo.com Lifehacker.com | 1,500,000 | 2010 | Dec 2010 | The notorious website was hacked. The source code was stolen, along with 1.5 million usernames, emails and passwords. | web | hacked | 2 | Guardian | http://www.guardian.co.uk/technology/2010/dec/13/gawker-hackers-passwords-twitter-wikileaks?INTCMP=SRCH | http://www.mediaite.com/online/gawker-medias-entire-commenter-database-appears-to-have-been-hacked/ | 58 | |||
| Triple-S Salud, Inc. | Puerto-Rican health insurance company | 398,000 | 2010 | Nov 2010 | A competitor accessed restricted areas of the healthcare firm's website without authorisation, compromising client information. | health | lost device | 4 | Data Breaches | https://www.databreaches.net/puerto-rico-dept-of-health-reports-breach-affecting-400000-triple-s-salud-fined-100k/ | 57 | ||||
| Ohio State University | 760,000 | 2010 | Dec 2010 | The breach affected current and former students. It cost the university $4m in expenses related to investigative consulting, breach notification and credit security. | academia | hacked | 2 | The Lantern | https://www.thelantern.com/2010/12/hacked-data-breach-costly-for-ohio-state-victims-of-compromised-info/ | 56 | |||||
| Emergency Healthcare Physicians, Ltd. | A Chicago emergency physician group | 180,111 | 2010 | May 2010 | A stolen portable hard drive contained records from 2003 to 2006, including patient names, addressees, phone numbers, birth dates and Social Security numbers. | health | lost device | 4 | Healthcare Info Security | http://www.healthcareinfosecurity.com/chicago-breach-affects-180000-a-2496 | 55 | ||||
| Colorado government | Department of Health Care Policy & Financing | 105,470 | 2010 | Jul 2010 | State officials discovered the unauthorized removal of a computer hard drive housed at Colorado's Office of Information Technology which contained health insurance information. | health | lost device | 2 | Data Breaches | http://www.databreaches.net/?p=12611 | 54 | ||||
| AT&T | US Telecoms company | 114,000 | 2010 | Jun 2010 | Details of iPad 3G users, thought to include those of White House chief of staff Rahm Emanuel, was stolen from the AT&T website. | telecoms | hacked | y | 1 | Guardian | http://www.guardian.co.uk/technology/2010/jun/10/apple-ipad-security-leak?INTCMP=SRCH | 53 | |||
| Lincoln Medical & Mental Health Center | 130,495 | 2010 | Jun 2010 | Protected health information was exposed after seven CDs were lost in transit with FedEx. | health | lost device | 4 | Alert Boot | https://www.pcworld.idg.com.au/article/351659/new_york_hospital_loses_data_130_000_via_fedex/ | 52 | |||||
| Educational Credit Management Corp | US student loan guarantor | 3,300,000 | 2010 | Mar 2010 | A contractor for the US Department of Education stole a device containing student loan records. The breach affected as many as 5% of all the country's federal student loan borrowers. | finance | lost device | y | 2 | Wall Street Journal | https://www.wsj.com/articles/SB10001424052702304434404575150024174102954 | 51 | |||
| US Federal Reserve Bank of Cleveland | 400,000 | 2010 | Nov 2010 | Nov 2010. A Malaysian man was charged with hacking into major US corporations and stealing 400,000 credit and debit card account numbers. | finance | hacked | 3 | Bank Info Security | https://www.bankinfosecurity.com/cleveland-federal-reserve-hacked-a-3115 | 50 | |||||
| Classified Iraq War documents | 392,000 | 2010 | Oct 2010 | Wikileaks posted classified Iraq War documents on its website. | government | inside job | 2 | Forbes | http://www.forbes.com/sites/andygreenberg/2010/10/22/wikileaks-reveals-the-biggest-classified-data-breach-in-history/ | 49 | |||||
| Heartland | Independent payment processor | 130,000,000 | 2009 | Jan 2009 | Keylogging malware caused a massive data breach. Heartland eventually paid more than $110 million to Visa, MasterCard, American Express and other card associations to settle claims. | finance | hacked | y | 3 | 130m | Dark Reading | https://www.darkreading.com/attacks-and-breaches/heartland-payment-systems-hit-by-data-security-breach/d/d-id/1075770 | 48 | ||
| US National Guard | 131,000 | 2009 | Dec 2009 | A personal laptop owned by an Army Guard contractor was stolen. It contained a database including names, Social Security Numbers, incentive payment amounts and payment dates. | military | lost device | y | 2 | CNN | http://edition.cnn.com/2009/US/12/17/theft.security.breach/index.html | 47 | ||||
| RockYou! | Developer of online games (Zoo World/Zoo World 2) and advertising products | 32,000,000 | 2009 | Dec 2009 | The site did not allow users to use special characters or punctuation in their passwords and e-mailed user passwords in plain text. Hackers took advantage of these security lapses. | web, gaming | hacked | y | 1 | Tech Crunch | http://techcrunch.com/2009/12/14/rockyou-hack-security-myspace-facebook-passwords/ | 46 | |||
| CheckFree Corporation | Provider of online banking, online bill payment and electronic bill payment services for the financial services industry | 5,000,000 | 2009 | Jan 2009 | Criminals took control of the payment service's domains. They redirected traffic to a Ukrainian Web server that used malware to install a password-stealing program on the victim's computer. | finance | hacked | y | 1 | Computer World | https://www.computerworld.com/article/2530152/checkfree-warns-5-million-customers-after-hack.html | 45 | |||
| Network Solutions | Domain name registration business | 573,000 | 2009 | Jul 2009 | A large-scale infection of e-commerce sites with malicious code led to the compromise of thousands of debit and credit cards. | web | hacked | 3 | Washington Post | http://voices.washingtonpost.com/securityfix/2009/07/network_solutions_hack_comprom.html | 44 | ||||
| Virginia Prescription Monitoring Program | 531,400 | 2009 | May 2009 | A prescriptions website with a database containing 8m patient records and 35m prescription records was hacked. The hacker demanded a $10 million ransom for the breach. | health | hacked | y | 2 | Digital Health | https://www.digitalhealth.net/2009/05/virginia-department-of-health-hacked/ | 43 | ||||
| University of California Berkeley | details on students, alumni and others | 160,000 | 2009 | May 2009 | The attackers accessed a computer belonging to the university's health centre. The personal information of current students and alumni was stolen. | academia | hacked | 3 | Cnet | https://www.cnet.com/news/uc-berkeley-computers-hacked-160000-at-risk/ | 42 | ||||
| Health Net | Largest US publicly traded managed health care company | 1,500,000 | 2009 | Nov 2009 | A portable hard drive with seven years worth of personal and medical information was lost for six months before being reported. | health | lost device | y | 4 | Computer World | https://www.computerworld.com/article/2521838/security0/health-net-says-1-5m-medical-records-lost-in-data-breach.html | 41 | |||
| US Military | 76,000,000 | 2009 | Oct 2009 | The National Archives And Records Administration sent a defective, unencrypted hard drive for repair and recycling. It held detailed records on 76 million veterans dating back to 1972. | military | lost device | y | 2 | Wired | http://www.wired.com/threatlevel/2009/10/probe-targets-archives-handling-of-data-on-70-million-vets/ | 40 | ||||
| Compass Bank | 1,000,000 | 2008 | Mar 2008 | A former employee stole a hard drive containing 1m account details between May & July 2007, then used it to defraud cutomers of nearly $32,000. | finance | inside job | y | 3 | Computer Weekly | https://www.computerworld.com/article/2536195/programmer-who-stole-drive-containing-1-million-bank-records-gets-42-months.html | 39 | ||||
| Hannaford Brothers Supermarket Chain | Delhaize Group: Hannaford Bros, Sweetbay, Food Lion, Bloom, Bottom Dollar, Harveys, Kash n' Karry | 4,200,000 | 2008 | Mar 2008 | An estimated 4.2 million credit and debit card numbers were stolen when payment data was intercepted by hackers. | retail | hacked | 3 | NetworkWorld | https://www.networkworld.com/article/2284998/lan-wan/details-emerging-on-hannaford-data-breach.html | 38 | ||||
| University of Miami | 2,100,000 | 2008 | Apr 2008 | Six backup tapes from the medical school containing more than 2 million medical records were stolen from a van that was transporting the data to an off-site facility. | academia | lost device | 3 | Identity Theft | https://www.computerworld.com/article/2536837/thieves-pilfer-backup-tapes-holding-2m-medical-records.html | 37 | |||||
| BNY Mellon Shareowner Services | Wealth management | 4,500,000 | 2008 | May 2008 | An archiving vendor lost a box full of data storage tapes containing sensitive information. | finance | lost device | 1 | Reuters | https://www.reuters.com/article/us-mellon-breach-idUSN2143343820080521 | 36 | ||||
| Countrywide Financial Corp | Employee convicted of downloading millions of borrower files and selling the information to other loan officers. | 2,500,000 | 2008 | Aug 2008 | A senior financial analyst was sentenced to eight months in prison after pleading guilty to downloading millions of borrower files onto thumb drives & selling the information. | finance | inside job | 2 | LATimes | https://www.networkworld.com/article/2274502/security-oversight-may-have-enabled-countrywide-breach.html | 35 | ||||
| UK Home Office | 84,000 | 2008 | Aug 2008 | PA Consulting lost an unencrypted memory stick containing details of high risk, prolific and other offenders. It had its contract terminated after an enquiry. | government | lost device | 2 | Wikipedia | http://news.bbc.co.uk/1/hi/uk_politics/7608155.stm | 34 | |||||
| RBS Worldpay | the U.S. payment processing arm of The Royal Bank of Scotland Group | 1,500,000 | 2008 | Dec 2008 | A hack compromised RBS Worldpay prepay and gift cards. Actual fraud has been committed on approximately 100 cards. The personal information of over 1m people was exposed. | finance | hacked | 5 | The Register | http://www.theregister.co.uk/2008/12/29/rbs_worldpay_breach/ | 33 | ||||
| Auction.co.kr | South Korea's largest online shopping site | 18,000,000 | 2008 | Feb 2008 | South Korea’s largest online shopping site was attacked by a Chinese hacker who made off with user information and a large amount of financial data. | web | hacked | 3 | Dark Reading | https://www.darkreading.com/attacks-breaches/hacker-steals-data-on-18m-auction-customers-in-south-korea/d/d-id/1129325 | 32 | ||||
| GS Caltex | Private oil company | 11,100,000 | 2008 | Sep 2008 | Two multimedia discs containing personal data of Korean customers was found by an office worker in a trash pile in Seoul. Likely to have been stolen by an employee. | misc | inside job | 2 | The Dong-a Ilbo | http://english.donga.com/srv/service.php3?biid=2008090631088 | 31 | ||||
| AT&T | 113,000 | 2008 | Jun 2008 | A laptop containing unencrypted Social Security numbers and bonus/salary info of AT&T employees was stolen from a car. | telecoms | lost device | y | 1 | NetworkWorld | https://www.networkworld.com/article/2344552/security/latest--lost--laptop-holds-treasure-trove-of-unencrypted-at-t-payroll-data.html | 30 | ||||
| Stanford University | 72,000 | 2008 | Jun 2008 | A laptop containing information on tens of thousands of past and current Stanford University employees was stolen. | academia | lost device | 2 | SFGate | http://www.sfgate.com/bayarea/article/Stanford-employees-data-on-stolen-laptop-3281185.php | 29 | |||||
| University of Utah Hospitals & Clinics | stolen data tapes | 2,200,000 | 2008 | Jun 2008 | Petty thieves stole backup data tapes containing billing records from an employee's car. According to police reports the thieves tried - and failed - to view the tapes using a VHS player. | academia | lost device | y | 4 | Salt Lake Tribune | http://archive.sltrib.com/story.php?ref=/ci_9540210 | 28 | |||
| Chile Ministry Of Education | 6,000,000 | 2008 | May 2008 | A computer hacker in Chile published confidential records belonging to six million people to illustrate the weakness of government security. | government | hacked | 1 | BBC News | http://news.bbc.co.uk/2/hi/americas/7395295.stm | http://www.geek.com/articles/news/government-servers-in-chile-hacked-6-million-personal-records-made-public-20080514/ | 27 | ||||
| Texas Lottery | 89,000 | 2008 | Nov 2008 | Data on more than 89,000 lottery winners (including names, Social Security numbers, addresses and prize amounts) were taken from the agency without permission by a former employee. | government | inside job | 2 | Houston Chronicle | https://www.chron.com/news/houston-texas/article/89-000-lottery-winners-affected-by-security-breach-1603025.php | 26 | |||||
| Starbucks | 97,000 | 2008 | Nov 2008 | A laptop containing private information on 97,000 employees was stolen. Employees won a case against the firm before losing in the federal court as they were unable to prove any cognizable harm. | retail | lost device | y | 2 | Info Watch | https://infowatch.com/analytics/leaks_monitoring/1304 | 25 | ||||
| UK Ministry of Defence | 1,700,000 | 2008 | Oct 2008 | A hard drive containing sensitive details of Armed Forces personnel - passport & national insurance numbers, bank details etc - went missing. The loss was revealed during National Identity Fraud Prevention Week. | government | lost device | y | 5 | BBC News | http://news.bbc.co.uk/1/hi/uk_politics/7667507.stm | 24 | ||||
| T-Mobile, Deutsche Telecom | 17,000,000 | 2008 | Oct 2008 | Thieves stole a device containing names, addresses, cell phone numbers, and some birth dates and e-mail addresses for high-profile German citizens. | telecoms | lost device | 1 | FT | https://www.dw.com/en/telekom-says-data-from-17-million-customers-was-stolen/a-3690132 | 23 | |||||
| Norwegian Tax Authorities | 3,950,000 | 2008 | Sep 2008 | Tax authorities accidentally sent CD-ROMs filled with the 2006 tax returns of 4m Norwegian citizens to editorial staff at national newspapers, radios and television stations. | government | oops! | y | 2 | Info Watch | http://infowatch.com/node/1289 | 22 | ||||
| Service Personnel and Veterans Agency (UK) | 50,500 | 2008 | Sep 2008 | Hard drives containing personal information of employees were stolen from a high-security facility. | government | lost device | 2 | BBC News | http://news.bbc.co.uk/1/hi/england/gloucestershire/7639006.stm | 21 | |||||
| Monster.com | Jobs website | 1,600,000 | 2007 | Aug 2007 | A trojan virus harvested user names, e-mail addresses, home addresses and phone numbers. Soon after, phishing e-mails encouraged users to download a Monster Job Seeker Tool, which was in fact malware. | web | hacked | y | 2 | BBC News | http://news.bbc.co.uk/1/hi/6956349.stm | 20 | |||
| Driving Standards Agency | 3,000,000 | 2007 | Dec 2007 | A hard disk with details of UK driving theory test candidates was lost by a contractor while they were in Iowa, USA. | government | lost device | 2 | BBC News | http://news.bbc.co.uk/1/hi/uk_politics/7147715.stm | 19 | |||||
| Fidelity National Information Services | 8,500,000 | 2007 | Jul 2007 | An employee sold customer information to a data broker, including names, addresses, birth dates, bank account and credit card information. | finance | inside job | 3 | PCWorld | http://www.pcworld.com/article/135117/article.html | 18 | |||||
| City and Hackney Teaching Primary Care Trust | 160,000 | 2007 | Dec 2007 | Disks containing children's personal details were lost by couriers. It prompted the agency to introduce disk encryption. | government | lost device | 2 | Computer Weekly | https://www.computerweekly.com/news/2240104003/Hackney-NHS-trust-encrypts-IT-equipment-following-loss-of-child-data | 17 | |||||
| Gap Inc | 800,000 | 2007 | Sep 2007 | A laptop containing data on people who applied for positions at Gap stores between July 2006 and June 2007 was stolen. | retail | lost device | 2 | PC World | http://www.pcworld.com/article/137865/article.html | 16 | |||||
| Dai Nippon Printing | Japanese printing company | 8,637,405 | 2007 | Mar 2007 | A former contractor of the firm stole 8.6 million records containing the personal data of customers. | retail | inside job | 1 | Compare Business Products | https://www.comparebusinessproducts.com/fyi/15-most-massive-data-breaches-history | 15 | ||||
| TK / TJ Maxx | Largest retail breach to date | 94,000,000 | 2007 | Mar 2007 | A Minnesota store wifi network was hacked. Data from the credit and debit cards of shoppers was stolen. | retail | hacked | 3 | 94m | ZD Net | http://www.zdnet.com/wi-fi-hack-caused-tk-maxx-security-breach-3039286991/ | 14 | |||
| JP Morgan Chase | 2,600,000 | 2007 | May 2007 | Personal information was mistakenly identified as trash and thrown out in garbage bags outside five branch offices in New York. | finance | lost device | y | 3 | PC World | http://www.pcworld.com/article/131453/article.html | 13 | ||||
| UK Revenue & Customs | HMRC | 25,000,000 | 2007 | Nov 2007 | A set of discs containing confidential details of 25 million child benefit recipients was lost. | government | lost device | 1 | BBC News | http://news.bbc.co.uk/2/hi/uk_news/7103911.stm | 12 | ||||
| TD Ameritrade | US online broker | 6,300,000 | 2007 | Sep 2007 | The firm settled a class action lawsuit to compensate as many as 6.3 million customers whose data was stolen by hackers. | finance | hacked | 1 | Wired, CBNC | http://www.wired.com/threatlevel/2008/07/ameritrade-hack/ | https://www.cnbc.com/id/20775257 | 11 | |||
| AOL | American Online | 20,000,000 | 2006 | Aug 2006 | AOL released search data for roughly 20 million web queries from 658,000 anonymized users of the service. No one is quite sure why. | web | oops! | y | 1 | Tech Crunch | http://techcrunch.com/2006/08/06/aol-proudly-releases-massive-amounts-of-user-search-data/ | 10 | |||
| US Dept of Vet Affairs | 26,500,000 | 2006 | Jul 2006 | The Veterans Affairs Department agreed to pay $20 million to settle a class action lawsuit over the loss of a laptop. | government, military | lost device | 2 | GCN, US Gov | http://gcn.com/Articles/2009/02/02/VA-data-breach-suit-settlement.aspx | https://www.va.gov/oig/pubs/VAOIG-06-02238-163.pdf | 9 | ||||
| Automatic Data Processing | Business outsourcing, payrolls, benefits | 125,000 | 2006 | Jul 2006 | Automatic Data Processing, one of the world's largest payroll service companies, confirmed that it was swindled by a data thief looking for information on investors. | finance | poor security | 2 | ABC News | http://abcnews.go.com/Technology/story?id=2160425&page=1#.UFcROxgUwaA | 8 | ||||
| KDDI | Japanese telecommunications operator | 4,000,000 | 2006 | Jun 2006 | Tokyo police arrested two men for trying to extort nearly US$90,000. The pair allegedly threatened to disclose the existence of storage media containing personal data. | telecoms | hacked | y | 1 | Computer World | http://www.computerworld.com/s/article/9001150/KDDI_suffers_massive_data_breach | 7 | |||
| Hewlett Packard | 200,000 | 2006 | Mar 2006 | A laptop containing employee data was either lost or stolen. It included names, addresses, Social Security numbers, dates of birth and other employment-related information. | tech, retail | lost device | y | 2 | Computer Weekly | https://www.computerweekly.com/news/2240076956/Personal-data-on-200000-HP-employees-stolen | 6 | ||||
| Ameritrade Inc. | online broker | 200,000 | 2005 | Apr 2005 | A computer backup tape containing the personal information of customers between 2000 and 2003 was lost. | finance | lost device | 2 | NBC | http://www.nbcnews.com/id/7561268/ | 5 | ||||
| Citigroup | 3,900,000 | 2005 | Jun 2005 | A box of computer tapes containing information on 3.9 million customers was lost in transit to a credit reporting agency. | finance | lost device | y | 3 | NY Times | http://www.nytimes.com/2005/06/07/business/07data.html?pagewanted=all&_moc.semityn.www | 4 | ||||
| Cardsystems Solutions Inc. | Third-party payment processor for Visa, Mastercard, Amex, and Discover | 40,000,000 | 2005 | Jun 2005 | An unauthorized entity enabled access to cusomer credit card data. It's not clear how many of the 40 million accounts were stolen. | finance | hacked | y | 3 | Wired | https://www.wired.com/2005/06/cardsystems-data-left-unsecured/ | 3 | |||
| AOL | American Online | 92,000,000 | 2004 | Jun 2004 | A former America Online software engineer stole 92 million screen names and e-mail addresses and sold them to spammers who sent out up to 7 billion unsolicited e-mails. | web | inside job | 1 | 92m | CNN | http://money.cnn.com/2004/06/23/technology/aol_spam/ | 2 |