| A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | ||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | organisation | alternative name | records lost | year | date | story | sector | method | interesting story | data sensitivity | displayed records | source name | 1st source link | 2nd source link | ID | ||||||||||||
2 | visualisation here: https://informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/ pink = new | (use 3m, 4m, 5m or 10m to approximate unknown figures) | year story broke | poor security hacked oops! lost device inside job | 1. Just email address/Online information 2 SSN/Personal details 3 Credit card information 4 Health & other personal records 5 Full details | ||||||||||||||||||||||
3 | Quantas | 5,700,000 | 2025 | Jul 25 | The records of nearly 6 million customers on the platform and Qantas expects a "significant" proportion of the data has been stolen. | transport | hacked | 2 | ABC | https://www.abc.net.au/news/2025-07-02/qantas-cyber-attack-significant-data-stolen/105484720 | 524 | ||||||||||||||||
4 | GiveSendGo | 92,000 | 2022 | Feb 22 | Crowdfunding site that raised funds for the anti-vax “freedom convoy” in Canada was hacked exposing the names and personal details of over 92,000 donors | web | hacked | y | 2 | Vice | https://www.vice.com/en/article/freedom-convoy-givesendgo-donors-leaked/ | 523 | |||||||||||||||
5 | Tea | 72,000 | 2025 | Jul 25 | Web service providing safety for women online dating was breached, exposing over 13K photos of IDs used for account vertification, alongside 56K other images. ID photos were likely geotagged, worsening the severity of the leak | web | hacked | y | 4 | Tech Crunch | https://techcrunch.com/2025/07/26/dating-safety-app-tea-breached-exposing-72000-user-images/ | 522 | |||||||||||||||
6 | Lee Enterprises | 39,000 | 2025 | Feb 25 | Attackers behind a ransomware attack in Feb also stole documents and information on ~40K individuals | misc | hacked | 2 | Beeping Computer | https://www.bleepingcomputer.com/news/security/media-giant-lee-enterprises-says-data-breach-affects-39-000-people/ | 521 | ||||||||||||||||
7 | Cartier | 100,000 | 2025 | Jun 25 | Luxury fashion brand Cartier warned customers of a data breach that exposed customers' personal information. | retail | hacked | 1 | Beeping Computer | https://www.bleepingcomputer.com/news/security/cartier-discloses-data-breach-amid-fashion-brand-cyberattacks/ | 520 | ||||||||||||||||
8 | The North Face | 100,000 | 2025 | Apr 25 | The North Face is warning customers that their personal information was stolen in credential stuffing attacks. | retail | hacked | 2 | Beeping Computer | https://www.bleepingcomputer.com/news/security/the-north-face-warns-customers-of-april-credential-stuffing-attack/ | 519 | ||||||||||||||||
9 | LexisNexis | 364,000 | 2024 | Dec 24 | Data broker giant LexisNexis Risk Solutions states attackers stole personal information of over 364k individuals in Dec. | tech | poor security | 2 | Beeping Computer | https://www.bleepingcomputer.com/news/security/data-broker-lexisnexis-discloses-data-breach-affecting-364-000-people/ | 518 | ||||||||||||||||
10 | Adidas | 100,000 | 2025 | May 25 | German sportswear giant Adidas disclosed attackers hacked a customer service provider and stole some user data. | retail | hacked | 1 | Beeping Computer | https://www.bleepingcomputer.com/news/security/adidas-warns-of-data-breach-after-customer-service-provider-hack/ | 517 | ||||||||||||||||
11 | Coinbase | 69,461 | 2025 | May 25 | Coinbase said, "individuals performing services at our overseas support locations, improperly accessed customer information." | finance | inside job | 3 | Beeping Computer | https://www.bleepingcomputer.com/news/security/coinbase-says-recent-data-breach-impacts-69-461-customers/ | 516 | ||||||||||||||||
12 | UK's Legal Aid Agency | LAA | 2,100,000 | 2025 | May 25 | Criminal records dating back to 2010, as well as personal data was stolen for up to two million people | government | hacked | y | 3 | Beeping Computer | https://www.bleepingcomputer.com/news/security/uk-legal-aid-agency-confirms-applicant-data-stolen-in-data-breach/ | 515 | ||||||||||||||
13 | Nova Scotia Power | 100,000 | 2025 | May 25 | Nova Scotia Power confirms hackers stole sensitive data. The company serves over 500k customers. | misc | hacked | 4 | Beeping Computer | https://www.bleepingcomputer.com/news/security/nova-scotia-power-confirms-hackers-stole-customer-data-in-cyberattack/ | 514 | ||||||||||||||||
14 | ColoCrossing | 7,200 | 2025 | May 25 | Breach impacted users of ColoCloud virtual server although was isolated to their cloud/VPS platform. 7k emails exposed. | web, tech | hacked | 2 | Have I Been Pwned | https://haveibeenpwned.com/Breach/ColoCrossing | 513 | ||||||||||||||||
15 | Free | 13,900,000 | 2024 | Oct 24 | French ISP "Free" suffered a breach which was posted for sale and later, leaked. 14m email, names, addresses etc. exposed. | web | hacked | 3 | Have I Been Pwned | https://haveibeenpwned.com/Breach/FreeMobile | 512 | ||||||||||||||||
16 | Fédération Francaise de Rugby | 282,000 | 2023 | Jul 23 | The French Rugby Federation had a breach and attempted ransom. 282k emails, names, dates of birth and phone numbers. | government | hacked | 1 | Have I Been Pwned | https://haveibeenpwned.com/Breach/FFR | 511 | ||||||||||||||||
17 | TehetségKapu | 54,400 | 2025 | Mar 25 | 55k records breached from the Hungarian education office TehetségKapu. Data was subsequently published to a hacking forum. | government | hacked | 1 | Have I Been Pwned | https://haveibeenpwned.com/Breach/TehetsegKapu | 510 | ||||||||||||||||
18 | Krispy Kreme | 161,676 | 2024 | Nov 24 | U.S. doughnut chain confirmed attackers stole the personal info of over 160k individuals in a cyberattack. | retail | hacked | 3 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/krispy-kreme-says-november-data-breach-impacts-over-160-000-people/ | 509 | ||||||||||||||||
19 | Episource | 5,418,866 | 2025 | Feb 25 | An investigation revealed that hackers accessed and exfiltrated 5.4m records stored on these systems. | health | hacked | 4 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/episource-says-data-breach-impacts-54-million-patients/ | 508 | ||||||||||||||||
20 | Cock.li | 1,023,800 | 2025 | Jun 25 | Email hosting provider confirmed exploited flaws in its retired Roundcube webmail platform exposed over 1m records. | web | poor security | 1 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/hacker-steals-1-million-cockli-user-records-in-webmail-data-breach/ | 507 | ||||||||||||||||
21 | UnitedHealth | 190,000,000 | 2024 | Oct 24 | 190m Americans had their personal and healthcare data stolen in the Change Healthcare ransomware attack. | health | hacked | 4 | 190m | Bleeping Computer | https://www.bleepingcomputer.com/news/security/unitedhealth-now-says-190-million-impacted-by-2024-data-breach/ | 506 | |||||||||||||||
22 | Internet Archive | 33,000,000 | 2024 | Oct 24 | The Archive was hit by two different attacks, a data breach exposing 33m users data and a DDoS attack. | web | hacked | 1 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/internet-archive-hacked-data-breach-impacts-31-million-users/ | 505 | ||||||||||||||||
23 | National Public Data | 1,000,000,000 | 2024 | Aug 24 | 2.7bn records of US citizens used for background checks leaked on a hacking forum, names, social security, physical addresses, and aliases. | government | hacked | 2 | 2.7bn | Bleeping Computer | https://www.bleepingcomputer.com/news/security/hackers-leak-27-billion-data-records-with-social-security-numbers/ | 504 | |||||||||||||||
24 | VeriSource | 4,000,000 | 2024 | Feb 24 | Employee benefits administration firm exposed the personal information of 4m people. | finance | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/verisource-now-says-february-data-breach-impacts-4-million-people/ | 503 | ||||||||||||||||
25 | Baltimore Public Schools | 31,000 | 2025 | Feb 25 | Tens of thousands of employees and students exposed in a breach incident when attackers hacked into its network. | academia | hacked | 3 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/baltimore-city-public-schools-data-breach-affects-over-31-000-people/ | 502 | ||||||||||||||||
26 | Robinsons | 195,600 | 2024 | Jun 24 | Philippine shopping-mall operator suffered a breach via mobile app exposing 195k emails, names, numbers, DOB, genders. | retail | poor security | 2 | Have I Been Pwned | https://haveibeenpwned.com/Breach/RobinsonsMalls | 501 | ||||||||||||||||
27 | Have Fun Teaching | 27,100 | 2021 | Aug 21 | Teaching resources site suffered a breach leaking 80k WooCommerce transactions, and posted to a hacking forum. | academia | hacked | 3 | Have I Been Pwned | https://haveibeenpwned.com/Breach/HaveFunTeaching | 500 | ||||||||||||||||
28 | Ualabee | 472,300 | 2025 | May 25 | South American mobility services platform had 472k records scraped from an interface on their platform. | transport | hacked | 2 | Have I Been Pwned | https://haveibeenpwned.com/Breach/Ualabee | 499 | ||||||||||||||||
29 | Wiredbucks | 918,500 | 2022 | May 22 | Social media influencer platform suffered a data breach exposing over 900k emails, IP addresses, names, usernames, etc. | web | hacked | 2 | Have I Been Pwned | https://haveibeenpwned.com/Breach/WiredBucks | 498 | ||||||||||||||||
30 | Disk Union | 690,700 | 2022 | Jun 22 | Japanese record chain store exposed 690k email, names, postcodes, phone numbers and passwords. | retail | hacked | 2 | Have I Been Pwned | https://haveibeenpwned.com/Breach/DiskUnion | 497 | ||||||||||||||||
31 | Spectos | 216,300 | 2025 | Mar 25 | Data breach of logistics provider, Spectos: 216k emails, names, physical addresses, and purchases. | telecoms | hacked | 2 | Have I Been Pwned | https://haveibeenpwned.com/Breach/SamsungGermany | 496 | ||||||||||||||||
32 | German Doner Kebab | 162,400 | 2025 | Mar 25 | Breched food company leaked 162k unique emails, names, phone numbers and physical addresses. | retail | hacked | 2 | Have I Been Pwned | https://haveibeenpwned.com/Breach/GermanDonerKebab | 495 | ||||||||||||||||
33 | Orange Romania | 556,600 | 2025 | Feb 25 | Published to a hacking forum: 556k emails, phone, subscription, partial credit card data. | telecoms | hacked | 2 | Have I Been Pwned | https://haveibeenpwned.com/Breach/OrangeRomania | 494 | ||||||||||||||||
34 | Thermomix Recipe World Forum | 3,100,000 | 2025 | Jan 25 | Forum for users of the popular food processer was breached, exposing 3.1m records inc. emails, physical address, and DOB. | web | hacked | 2 | Have I Been Pwned | https://haveibeenpwned.com/Breach/Thermomix | 493 | ||||||||||||||||
35 | Kaiser Permanente | 13,400,000 | 2024 | Apr 24 | A leading U.S. healthcare organization transmitted personal information to third-party vendors, including Google, Microsoft Bing, and X (formerly Twitter), including search terms entered in Kaiser's health encyclopedia. | health | oops! | 3 | Bleeping Computer | https://restoreprivacy.com/data-breach-at-kaiser-permanente-affects-13-4-million-people/ | 492 | ||||||||||||||||
36 | Ticketmaster | 560,000,000 | 2024 | Jun 24 | Hacker group ShinyHunters say it stole names, addresses, phone numbers and partial credit cards details from hundreds of millions of Ticketmaster customers around the world. | misc | hacked | y | 3 | 560m | BBC | https://www.bbc.co.uk/news/articles/cw99ql0239wo | 491 | ||||||||||||||
37 | Stanford University | 27,000 | 2023 | May 23 | The Akira ransomware group claims to have stolen 430 GB of data, including names and social security numbers. The breach went unnoticed for four months, suggesting a possible prolonged attacker presence | academia | hacked | 2 | Slashdot | https://yro.slashdot.org/story/24/03/13/2053224/stanford-university-failed-to-detect-ransomware-intruders-for-4-months?utm_source=feedly1.0mainlinkanon&utm_medium=feed | 490 | ||||||||||||||||
38 | Cooler Master | 500,000 | 2024 | May 24 | Threat actor 'Ghostr' hacked the company's Fanzone website, stealing 103 GB of data. Compromised info includes names, emails, phone numbers, birth dates, addresses, product details, employee info, and vendor correspondence. | tech | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/cooler-master-confirms-customer-info-stolen-in-data-breach/ | 489 | ||||||||||||||||
39 | Financial Business and Consumer Solutions | FBCS | 3,200,000 | 2024 | Feb 24 | A U.S. debt collection agency reported a breach Initially affecting 1.9m people but the number has since increased significantly. Stolen data includes names, SSNs, birthdates, account info, and driver's license numbers. | tech | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/collection-agency-fbcs-ups-data-breach-tally-to-32-million-people/ | 488 | |||||||||||||||
40 | Santander | 30,000,000 | 2024 | May 24 | Threat actor 'ShinyHunters' claim to be selling Santander bank data on 30m customers from Chile, Spain and Uruguay. | finance | hacked | 3 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/banco-santander-warns-of-a-data-breach-exposing-customer-info/ | 487 | ||||||||||||||||
41 | Everbridge | 5,600,000 | 2024 | May 24 | The American crisis management software company, serving the U.S. Army, Atlanta Airport, and Norway and Australia, suffered a major data breach. Both business and user data compromised. | tech | hacked | 1 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/everbridge-warns-of-corporate-systems-breach-exposing-business-data/ | 486 | ||||||||||||||||
42 | BBC | 25,000 | 2024 | May 24 | Personal information of BBC Pension Scheme members, including current and former employees, was compromised. Data types include names, National Insurance numbers, birthdates, and home addresses. | misc | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/bbc-suffers-data-breach-impacting-current-former-employees/ | 485 | ||||||||||||||||
43 | First American | 44,000 | 2023 | Dec 23 | The second largest title insurance company in the US did not reveal which personal information was compromissed. | finance | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/first-american-december-data-breach-impacts-44-000-people/ | 484 | ||||||||||||||||
44 | Christie's | 500,000 | 2024 | May 24 | Famous auction house Christie's lost sensitive information on 500,000 clients to the RansomHub extortion gang. This includes full names, physical addresses, and ID details. Ironically, the cybercriminals also auction these stolen files to the highest bidder. | retail | hacked | y | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/christies-confirms-breach-after-ransomhub-threatens-to-leak-data/ | 483 | |||||||||||||||
45 | Sav-Rx | 2,800,000 | 2023 | Oct 23 | Prescription management company Sav-Rx warned over 2.8m people in the US of a data breach. Compromised data includes full names, birthdates, SSNs, emails, addresses, phone numbers, eligibility data, and insurance IDs. | health | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/sav-rx-discloses-data-breach-impacting-28-million-americans/ | 482 | ||||||||||||||||
46 | Cencora | 100,000 | 2024 | Feb 24 | Major drug companies, including Novartis and Bayer, disclosed data breaches after a February 2024 cyberattack at Cencora, their pharmaceutical services partner. Compromised data includes names, addresses, diagnoses, medications, and prescriptions. | health | hacked | 4 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/cencora-data-breach-exposes-us-patient-info-from-11-drug-companies/ | 481 | ||||||||||||||||
47 | WebTPA | 2,400,00 | 2023 | Apr 23 | The breach at this employer service compromised names, contact info, birth/death dates, SSNs, and insurance details. Impacted individuals include customers of The Hartford, Transamerica, and Gerber Life Insurance. | tech | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/webtpa-data-breach-impacts-24-million-insurance-policyholders/ | 480 | ||||||||||||||||
48 | Nissan | Nissan North America | 53;000 | 2023 | Nov 23 | This breach of the car manufacturer exposed personal data (including Social Security numbers) belonging to current and former employees. | transport | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/nissan-north-america-data-breach-impacts-over-53-000-employees/ | 479 | |||||||||||||||
49 | Singing River | Singing River Health System | 895,000 | 2023 | Aug 23 | A healthcare provider in the Gulf Coast region was breached by the Rhysida ransomware gang. Compromised data includes names, birthdates, addresses, SSNs, and medical info. | health | hacked | 4 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/singing-river-health-system-data-of-895-000-stolen-in-ransomware-attack/ | 478 | |||||||||||||||
50 | City of Helsinki | Helsinki | 80,000 | 2024 | Apr 24 | A data breach in Helsinki's education division affected tens of thousands of students, guardians, and personnel. Compromised data includes usernames, emails, IDs, addresses, fee details, education info, welfare requests, and medical certificates. | government | hacked | 4 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/helsinki-suffers-data-breach-after-hackers-exploit-unpatched-flaw/ | https://poliisi.fi/en/-/police-investigate-extensive-data-breach-in-helsinki-city-s-computer-network | 477 | ||||||||||||||
51 | Firstmac | 100,000 | 2024 | Apr 24 | Australia's largest non-bank lender had 500GB of data stolen by the Embargo cyber-extortion group. Stolen data includes names, addresses, emails, phone numbers, birthdates, bank account info, and driver's license numbers. | finance | hacked | 3 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/largest-non-bank-lender-in-australia-warns-of-a-data-breach/ | https://www.cyberdaily.au/security/10487-exclusive-aussie-lender-firstmac-falls-victim-to-embargo-ransomware-gang | 476 | |||||||||||||||
52 | The Post Millennial | 26,000,000 | 2024 | May 24 | A conservative Canadian news magazine was breached leaking data on mailing lists, subscriber info, and details of writers and editors: names, emails, usernames, passwords, IPs, phone numbers, addresses, and genders. | misc | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/the-post-millennial-hack-leaked-data-impacting-26-million-people/ | https://www.mediaite.com/politics/conservative-news-websites-hacked-replaced-with-page-leaking-private-information/ | 475 | |||||||||||||||
53 | Dell | 49,000,000 | 2024 | Apr 24 | The Dell data breach by a threat actor scraped 49m customer records via a partner portal API accessed as a fake company. Data includes customer names, order info, warranty details, service tags, and locations. | tech | oops! | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/dell-api-abused-to-steal-49-million-customer-records-in-data-breach/ | 474 | ||||||||||||||||
54 | UK Ministry of Defense | 270,000 | 2024 | May 24 | A threat actor breached the Ministry of Defence, accessing the Armed Forces payment network. Compromised data includes personal and banking details and a few addresses of active, reserve, and some retired personnel. | government | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/uk-confirms-ministry-of-defence-payroll-data-exposed-in-data-breach/ | https://www.theguardian.com/technology/article/2024/may/06/uk-military-personnels-data-hacked-in-mod-payroll-breach | 473 | |||||||||||||||
55 | Dropbox | Dropbox Sign | 100,000 | 2024 | Apr 24 | A Dropbox service which allows online document signatures, was breached. Hackers accessed authentication tokens, MFA keys, hashed passwords, and customer information. | tech | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/dropbox-says-hackers-stole-customer-data-auth-secrets-from-esignature-service/ | 472 | |||||||||||||||
56 | Panda Restaurants | 47,000 | 2024 | Mar 24 | Information exposed includes names or other personal identifiers and their driver's license numbers or ID card numbers for an undisclosed cohort. | retail | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/panda-restaurants-discloses-a-data-breach-after-corporate-systems-hack/ | 471 | ||||||||||||||||
57 | Philadelphia Inquirer | 25,000 | 2023 | May 23 | A breach at this daily newspaper exposed names, personal identifiers, and financial account or credit/debit card numbers with security codes, passwords, or PINs. The Cuba ransomware gang claimed responsibility. | misc | hacked | 4 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/philadelphia-inquirer-data-of-over-25-000-people-stolen-in-2023-breach/ | 470 | ||||||||||||||||
58 | French government | 43,000,000 | 2024 | Feb 24 | A breach in a French government department - responsible for registering and assisting unemployed people - exposed 20 years of personal data, including names, birthdates, Social Security numbers, travel IDs, emails, postal addresses, and phone numbers. | government | hacked | 2 | 43m | The Register | https://www.theregister.com/2024/03/14/mega_data_breach_at_french/ | 469 | |||||||||||||||
59 | USG | University System of Georgia | 800,000 | 2023 | May 24 | USG, operating 26 public colleges and universities in Georgia, was compromised in the 2023 Clop MOVEit attacks, which impacted thousands of organizations worldwide. Data included full/partial SSNs, birthdates, bank account numbers, and tax documents with Tax IDs. | government | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/university-system-of-georgia-800k-exposed-in-2023-moveit-attack/ | https://www.usg.edu/news/release/notice_of_data_breach | 468 | ||||||||||||||
60 | Ohio Lottery | 538,000 | 2023 | Dec 24 | The DragonForce ransomware gang claimed responsibility for the Christmas Eve attack on the Ohio Lottery. They accessed names, SSNs, and other personal identifiers of affected individuals. | gaming | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/ohio-lottery-ransomware-attack-impacts-over-538-000-individuals/ | 467 | ||||||||||||||||
61 | OmniVision | 100,000 | 2023 | Sep 24 | The Cactus ransomware gang claimed an attack, leaking passport scans, NDAs, contracts, and confidential documents from OmniVision, a subsidiary of Will Semiconductor, designs imaging sensors for various devices. | tech | hacked | 3 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/omnivision-discloses-data-breach-after-2023-ransomware-attack/ | 466 | ||||||||||||||||
62 | Western Sydney University | 7,500 | 2023 | May 24 | Hackers had accessed the University's Microsoft Office 365 environment, including email accounts and SharePoint files. | academia | hacked | 1 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/western-sydney-university-data-breach-exposed-student-data/ | 465 | ||||||||||||||||
63 | AT&T | 73,000,000 | 2024 | Apr 24 | Sensitive 2019 data from 7.6m current AT&T account holders and approximately 65.4m former account holders. Emails, passcodes, social security numbers. | telecoms | hacked | 4 | 73m | Ars Technica | https://arstechnica.com/tech-policy/2024/04/att-acknowledges-data-leak-that-hit-73-million-current-and-former-users/ | 464 | |||||||||||||||
64 | Irish towing company | 512,000 | 2023 | Oct 23 | The driving licences and payment card etails of thousands of motorists who had vehicles towed on behalf of the Irish police | transport | poor security | 3 | Irish independent | https://www.independent.ie/irish-news/thousands-of-drivers-have-sensitive-data-exposed-to-hackers-in-major-it-breach/a1379036136.html | 463 | ||||||||||||||||
65 | Maine Government | 1,300,000 | 2023 | May 23 | Russian ransomware group Clop stole names, dates of birth, Social Security numbers, driver’s license and other state or taxpayer identification numbers. Some individuals had medical and health insurance information taken. | government | hacked | 4 | Tech Crunch | https://techcrunch.com/2023/11/09/maine-government-data-breach-clop-ransomware/ | 462 | ||||||||||||||||
66 | Welltok | 8,500,000 | 2023 | Nov 23 | Patient data was exposed during the breach, including full names, email addresses, physical addresses, and telephone numbers. For some, it also includes Social Security Numbers (SSNs), Medicare/Medicaid ID numbers, and certain Health Insurance information. | health | hacked | 4 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/welltok-data-breach-exposes-data-of-85-million-us-patients/ | 461 | ||||||||||||||||
67 | Maximus | 10,000,000 | 2023 | Jul 23 | Exploit of a zero-day flaw in the MOVEit file transfer application. Data stolen included social security numbers, protected health information. | government | hacked | 4 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/8-million-people-hit-by-data-breach-at-us-govt-contractor-maximus/ | 460 | ||||||||||||||||
68 | Okta | 134 | 2023 | Nov 23 | Names and email addresses of customers of the identity security company. 134 of the company's 18,400 clients were impacted, but that only five instances of successful session hijacking were logged | tech | hacked | 1 | Okta | https://sec.okta.com/harfiles | 459 | ||||||||||||||||
69 | Delta Dental | 7,000,000 | 2023 | May 23 | The dental insurance company suffered unauthorized access by threat actors through the MOVEit file transfer software application exposing full credit card details of customers | health | hacked | 3 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/delta-dental-of-california-data-breach-exposed-info-of-7-million-people/ | 458 | ||||||||||||||||
70 | Xfinity | 36,000,000 | 2023 | Oct 23 | Hackers using the CitrixBleed vulnerability accessed acocunt details like name, last four digits of social security numbers and hashed passwords | telecoms | hacked | 2 | Tech Crunch | https://techcrunch.com/2023/12/19/comcast-xfinity-hackers-36-million-customers/ | 457 | ||||||||||||||||
71 | Atlassian | 13,200 | 2023 | Feb 23 | SiegedSec hacked Atlassian, the owner of Trello and other apps, via a third party office app, leaking employee details and office floor plans after an employee publicly shared credentials. | tech | oops! | y | 1 | Cyberscoop | https://cyberscoop.com/atlassian-hack-employee-data-seigedsec/ | 456 | |||||||||||||||
72 | 100,000 | 2023 | Feb 23 | A phishing attack granted access to Reddit's internal documents and systems, but without breaching main production systems, user passwords, or accounts. | web | hacked | y | 1 | Forbes | https://www.forbes.com/sites/daveywinder/2023/02/10/reddit-confirms-it-was-hacked-recommends-users-set-up-2fa/ | 455 | ||||||||||||||||
73 | Go Daddy | 1,228,000 | 2022 | Dec 23 | GoDaddy faced a multi-year breach (2020-2022) by a single intruder, resulting in stolen source code, user credentials, malware installation, and user redirects to malicious sites. WordPress customers’ email addresses, usernames, passwords, and even their SSL private keys were stolen. | web | hacked | y | 3 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/godaddy-hackers-stole-source-code-installed-malware-in-multi-year-breach/ | 454 | |||||||||||||||
74 | MGM | 10,600,000 | 2023 | Sept 23 | AlphV and Scattered Spider's cyberattack on MGM caused slot machine errors and hotel queues in Las Vegas, stealing pre-March 2019 customer data and inflicting a $100m loss on the company's Q3 results. MGM declined to say if any ransom was paid. | retail | hacked | y | 3 | Reuters | https://www.reuters.com/business/mgm-expects-cybersecurity-issue-negatively-impact-third-quarter-earnings-2023-10-05/ | 453 | |||||||||||||||
75 | Uber | 20,000,000 | 2022 | Dec 22 | Data on 77,000 Uber employees and internal reports were leaked on forums. While Uber denied ownership of the implicated source code, the breach stemmed from their third-party vendor, Teqtivity, which had a security incident earlier that year. | transport | hacked | y | 1 | Restore Privacy | https://restoreprivacy.com/uber-data-leak-breach-third-party-vendor-hacked/ | 452 | |||||||||||||||
76 | X (Twitter) | 200,000,000 | 2023 | Jan 23 | From Nov 2022 to Jan 2023, over 200 million Twitter users' data, including emails and names, was exposed due to repeated security flaw exploitations and posted on hacker forums. But no highly sensitive data was revealed. | web | poor security | 1 | 200m | Firewall Times | https://firewalltimes.com/twitter-data-breach-timeline/ | 451 | |||||||||||||||
77 | CommuteAir | 1,500,000 | 2023 | Jan 23 | Swiss hacker Maia Arson Crimew, stumbled upon a misconfigured AWS server containing TSA's No Fly list and exposed ~250,000 'selectees' (selectees are automatically chosen for additional screening each time they fly) to a hacker forum. | transport | hacked | y | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/us-no-fly-list-shared-on-a-hacking-forum-government-investigating/ | 450 | |||||||||||||||
78 | Yum! | 10,000,000 | 2023 | Jan 23 | The brand owner of KFC, Pizza Hut, and Taco Bell fast food chains saw an undisclosed amount of personal user information stolen during a ransomware attack: names, driver's license numbers, and other ID card numbers. ~300 restaurants were shut down in the UK due to IT system disruptions caused by the attack. | retail | hacked | y | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/kfc-pizza-hut-owner-discloses-data-breach-after-ransomware-attack/ | 449 | |||||||||||||||
79 | PharMerica | 5,800,000 | 2023 | May 23 | Full names, addresses, dates of birth, social security numbers (SSNs), medications, and health insurance information of 5,815,591 people. | health | hacked | 4 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/ransomware-gang-steals-data-of-58-million-pharmerica-patients/ | 448 | ||||||||||||||||
80 | NATO | 8,000 | 2023 | Jul 23 | Hacktivist group, SiegedSec, claimed to have broken into six NATO web portals and stolen >3,000 files and 9GB of data. Threat intel biz CloudSEK analysis revealed 20 unclassified documents and 8,000 personnel records with names, job titles, email addresses, home addresses, and photos. | government | hacked | y | 4 | The Register | https://www.theregister.com/2023/10/04/nato_data_attack/#:~:text=On%20Sunday%2C%20the%20SiegedSec%20crew,)%3B%20the%20Communities%20of%20Interest | 447 | |||||||||||||||
81 | Topgolf Callaway | 1,114,954 | 2023 | Aug 23 | Only full names, shipping and email addresses, phone numbers, order histories, account passwords and answers to security questions were exposed. | retail | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/golf-gear-giant-callaway-data-breach-exposes-info-of-11-million/ | 446 | ||||||||||||||||
82 | Sony | 6,800 | 2023 | Oct 23 | Personal information belonging to current and former employees and their family members was stolen by Clop in a ransomware attack. Details unrevealed by Sony. | tech | hacked | 2 | The Verge | https://www.theverge.com/2023/10/5/23905370/sony-interactive-entertainment-security-breach-confirmation | https://www.bleepingcomputer.com/news/security/sony-confirms-data-breach-impacting-thousands-in-the-us/ | 445 | |||||||||||||||
83 | 23andMe | 6,900,000 | 2023 | Oct 23 | Hackers accessed the genetic site's user data via login guesses and information from DNA relatives (users opt into sharing info through DNA relatives for others to see). Stolen data included personal and some genetic ancestry and health details. After two breaches, one unverified, 23andMe now faces legal action. | health | hacked | y | 4 | 6.9m | Tech Crunch | https://arstechnica.com/tech-policy/2023/12/hackers-stole-ancestry-data-of-6-9-million-users-23andme-finally-confirmed/ | https://www.bleepingcomputer.com/news/security/23andme-hit-with-lawsuits-after-hacker-leaks-stolen-genetics-data/ | 444 | |||||||||||||
84 | Optus | 9,700,000 | 2022 | Sept 2022 | The telecom company faced a 'sophisticated attack' exposing ~10 million accounts including personal details (passport, driver’s licence & Medicare numbers). Hacker demanded $1m ransom but later apologized and claimed data deletion, unverified. | telecoms | hacked | 4 | The Guardian | https://www.theguardian.com/business/2022/sep/29/optus-data-breach-everything-we-know-so-far-about-what-happened | https://www.optus.com.au/about/media-centre/media-releases/2022/09/optus-notifies-customers-of-cyberattack | 443 | |||||||||||||||
85 | PayPal | 34942 | 2023 | Dec 22 | PayPal's breach involved unauthorized account access using credential stuffing (exploiting users reusing the same password for multiple accounts). It wasn't from a direct security lapse and hackers couldn't transact. PayPal reset passwords. | finance | hacked | 2 | Office of the Maine Attorney General | https://apps.web.maine.gov/online/aeviewer/ME/40/766753f1-f9c7-4dc5-9a5c-fe0f3ff51c06.shtml | https://www.bleepingcomputer.com/news/security/paypal-accounts-breached-in-large-scale-credential-stuffing-attack/ | 442 | |||||||||||||||
86 | Acer | 10,000,000 | 2023 | Mar 23 | Acer suffered a data breach when a server was hacked, with threat actors selling 160GB of stolen data. The company said the incident hadn't impacted customer info. | tech | hacked | 1 | Slashdot | https://it.slashdot.org/story/23/03/07/1459230/acer-confirms-breach-after-hacker-offers-to-sell-stolen-data?utm_source=feedly1.0mainlinkanon&utm_medium=feed | https://www.bleepingcomputer.com/news/security/acer-confirms-breach-after-160gb-of-data-for-sale-on-hacking-forum/ | 441 | |||||||||||||||
87 | MSI | 10,000,000 | 2023 | Apr 23 | Money Message ransomware group claims to have stolen MSI's source code, demanding $4 million to prevent leaks. MSI downplays impact and hasn't confirmed paying ransom, assuring no user data was affected but advises software downloads only from official sources. | tech | hacked | 1 | Slashdot | https://it.slashdot.org/story/23/04/07/152242/msi-confirms-breach-as-ransomware-gang-claims-responsibility?utm_source=feedly1.0mainlinkanon&utm_medium=feed | https://uk.pcmag.com/security/146322/msi-confirms-breach-as-ransomware-gang-claims-responsibility | 440 | |||||||||||||||
88 | T-Mobile | 37,000,000 | 2023 | Jan 23 | T-Mobile's system was exploited by 'bad actors' from November 2022 to January 2023, exposing customer data. It's their ninth hack since 2018, with a 2021 breach affecting 49 million customers. | telecoms | hacked | 2 | Ars Technica | https://arstechnica.com/information-technology/2023/05/t-mobile-discloses-2nd-data-breach-of-2023-this-one-leaking-account-pins-and-more/ | 439 | ||||||||||||||||
89 | T-Mobile | 836 | 2023 | Mar 23 | T-Mobile faced its second 2023 data breach, exposing PINs and data from Feb to Mar. Though way smaller than the first 2023 breach (only affecting 836 customers), it adds to the $350mil 2021 settlement and erodes customer trust. | telecoms | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/t-mobile-discloses-second-data-breach-since-the-start-of-2023/ | 438 | ||||||||||||||||
90 | ChatGPT | 101,000 | 2023 | Mar 23 | Over 101,000 ChatGPT accounts were stolen by malware last year. Breakdown: Asia-Pacific 40,999, Middle-East/Africa 24,925, Europe 16,951, Latin America 12,314, North America 4,737. Malware extracts browser credentials from SQLite databases, using CryptProtectData function to decrypt stored data. | tech | hacked | y | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/over-100-000-chatgpt-accounts-stolen-via-info-stealing-malware/ | 437 | |||||||||||||||
91 | TIAA | The Teachers Insurance and Annuity Association of America | 2,300,000 | 2023 | May 23 | This US retirement fund for teachers faced a data breach exposing client details. A former teacher-client is suing for inadequate cybersecurity and leaving data unencrypted on a vulnerable platform. | finance | hacked, poor security | 2 | ClassAction | https://www.classaction.org/news/teachers-insurance-and-annuity-association-of-america-hit-with-class-action-over-may-2023-data-breach#:~:text=Teachers%20Insurance%20and%20Annuity%20Association%20of%20America%20faces%20a%20class,of%20approximately%202.3%20million%20individuals. | https://news.slashdot.org/story/23/06/30/2038234/schools-say-us-teachers-retirement-fund-was-breached-by-moveit-hackers?utm_source=feedly1.0mainlinkanon&utm_medium=feed | 436 | ||||||||||||||
92 | Microsoft | 30,000,000 | 2023 | Jun 23 | Anonymous Sudan hacked Microsoft, accessed customer data, and caused outages. They offered the database for $50,000. But Microsoft claims no evidence of compromised customer data. | web | hacked | 2 | Bleeping Computer | https://www.bleepingcomputer.com/news/security/microsoft-denies-data-breach-theft-of-30-million-customer-accounts/ | 435 | ||||||||||||||||
93 | Microsoft | 10,000,000 | 2023 | May 23 | China-backed hackers stole a cryptographic key from Microsoft, undetected for a month, accessing 25 organizations, including government. Microsoft's postmortem cites past system vulnerabilities. | web | hacked | 3 | unknown | NYT | https://www.nytimes.com/2023/07/11/us/politics/china-hack-us-government-microsoft.html?smid=nytcore-ios-share | https://www.wired.com/story/china-backed-hackers-steal-microsofts-signing-key-post-mortem/ | 434 | ||||||||||||||
94 | Roblox | 4,000 | 2020 | Dec 20 | Data identifying Roblox creators was breached at a developers' conference, undisclosed for 2 years due to a third-party security issue. | gaming | poor security | 2 | The Verge | https://www.theverge.com/2023/7/21/23802742/roblox-data-breach-leak-developer-personal-information-exposed | 433 | ||||||||||||||||
95 | Discord.io | 760,000 | 2023 | Aug 23 | Unidentified person listed user data for sale on darknet. Discord.io enables custom Discord invites. | gaming | hacked | 1 | Stackdiary | https://stackdiary.com/the-data-of-760000-discord-io-users-was-put-up-for-sale-on-the-darknet// | 432 | ||||||||||||||||
96 | Clorox | 10,000,000 | 2023 | Aug 23 | Clorox detected unauthorized IT activity in August 2023. By September, the contained hack led to slower production and a 2% stock drop. Specific affected files undisclosed | retail | hacked | 1 | unknown | Slashdot | https://it.slashdot.org/story/23/10/04/1917217/clorox-security-breach-linked-to-group-behind-casino-hacks?utm_source=feedly1.0mainlinkanon&utm_medium=feed | 431 | |||||||||||||||
97 | Latitude Financial | 14,000,000 | 2023 | Apr 23 | 14 million customer records, including driver's licence numbers, passport numbers and financial statements, stolen in a cyber-attack that was worse than the company initially reported. | finance | hacked | 2 | Privacy Commissioner | https://www.privacy.org.nz/publications/statements-media-releases/new-zealands-biggest-data-breach-shows-retention-is-the-sleeping-giant-of-data-security/ | 430 | ||||||||||||||||
98 | Toyota | 296,019 | 2022 | Oct 22 | An access key to a data server storing customer email addresses and management numbers was mistakenly published publically on GitHub for five years. | transport | poor security | 2 | Slashdot | https://yro.slashdot.org/story/22/10/10/2032250/toyota-discloses-data-leak-after-access-key-exposed-on-github?utm_source=feedly1.0mainlinkanon&utm_medium=feed | 429 | ||||||||||||||||
99 | Shein | 39,000,000 | 2022 | Oct 22 | Online fast fashion retailer suffered a breach of its login credentials in 2018 but failed to notify its customers | retail | hacked | 2 | Tech Crunch | https://techcrunch.com/2022/10/13/shein-zoetop-fined-1-9m-data-breach/?guccounter=1 | 428 | ||||||||||||||||
100 | Indonesia's health agency | BPJS Kesehatan | 279,000,000 | 2022 | May 21 | The ID numbers, salary and phone numbers of every single man, woman and child in the country was stolen. | government | hacked | y | 3 | Kr Asia | https://kr-asia.com/shoddy-data-protection-in-indonesia-threatens-personal-security-of-citizens | 427 |