ABCDEFGHIJKLMNOPQRSTUVWXYZ
1
organisationalternative namerecords lostyear datestorysectormethodinteresting storydata sensitivitydisplayed recordssource name1st source link2nd source linkID
2
visualisation here: https://informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/
pink = new
(use 3m, 4m, 5m or 10m to approximate unknown figures) year story brokepoor security
hacked
oops!
lost device
inside job
1. Just email address/Online information
2 SSN/Personal details
3 Credit card information
4 Health & other personal records
5 Full details
3
Quantas5,700,0002025 Jul 25The records of nearly 6 million customers on the platform and Qantas expects a "significant" proportion of the data has been stolen.transporthacked2ABChttps://www.abc.net.au/news/2025-07-02/qantas-cyber-attack-significant-data-stolen/105484720524
4
GiveSendGo92,0002022Feb 22Crowdfunding site that raised funds for the anti-vax “freedom convoy” in Canada was hacked exposing the names and personal details of over 92,000 donorswebhackedy2Vicehttps://www.vice.com/en/article/freedom-convoy-givesendgo-donors-leaked/523
5
Tea72,0002025 Jul 25Web service providing safety for women online dating was breached, exposing over 13K photos of IDs used for account vertification, alongside 56K other images. ID photos were likely geotagged, worsening the severity of the leakwebhackedy4Tech Crunchhttps://techcrunch.com/2025/07/26/dating-safety-app-tea-breached-exposing-72000-user-images/522
6
Lee Enterprises 39,0002025 Feb 25Attackers behind a ransomware attack in Feb also stole documents and information on ~40K individualsmischacked2Beeping Computerhttps://www.bleepingcomputer.com/news/security/media-giant-lee-enterprises-says-data-breach-affects-39-000-people/521
7
Cartier 100,0002025 Jun 25Luxury fashion brand Cartier warned customers of a data breach that exposed customers' personal information.retailhacked1Beeping Computerhttps://www.bleepingcomputer.com/news/security/cartier-discloses-data-breach-amid-fashion-brand-cyberattacks/520
8
The North Face100,0002025 Apr 25The North Face is warning customers that their personal information was stolen in credential stuffing attacks.retailhacked2Beeping Computerhttps://www.bleepingcomputer.com/news/security/the-north-face-warns-customers-of-april-credential-stuffing-attack/519
9
LexisNexis364,0002024 Dec 24Data broker giant LexisNexis Risk Solutions states attackers stole personal information of over 364k individuals in Dec.techpoor security2Beeping Computerhttps://www.bleepingcomputer.com/news/security/data-broker-lexisnexis-discloses-data-breach-affecting-364-000-people/518
10
Adidas100,0002025 May 25German sportswear giant Adidas disclosed attackers hacked a customer service provider and stole some user data.retailhacked1Beeping Computerhttps://www.bleepingcomputer.com/news/security/adidas-warns-of-data-breach-after-customer-service-provider-hack/517
11
Coinbase69,4612025 May 25Coinbase said, "individuals performing services at our overseas support locations, improperly accessed customer information."financeinside job3Beeping Computerhttps://www.bleepingcomputer.com/news/security/coinbase-says-recent-data-breach-impacts-69-461-customers/516
12
UK's Legal Aid Agency LAA2,100,0002025 May 25Criminal records dating back to 2010, as well as personal data was stolen for up to two million peoplegovernmenthackedy3Beeping Computerhttps://www.bleepingcomputer.com/news/security/uk-legal-aid-agency-confirms-applicant-data-stolen-in-data-breach/515
13
Nova Scotia Power 100,0002025 May 25Nova Scotia Power confirms hackers stole sensitive data. The company serves over 500k customers.mischacked4Beeping Computerhttps://www.bleepingcomputer.com/news/security/nova-scotia-power-confirms-hackers-stole-customer-data-in-cyberattack/514
14
ColoCrossing7,2002025May 25Breach impacted users of ColoCloud virtual server although was isolated to their cloud/VPS platform. 7k emails exposed.web, techhacked2Have I Been Pwnedhttps://haveibeenpwned.com/Breach/ColoCrossing513
15
Free13,900,0002024Oct 24French ISP "Free" suffered a breach which was posted for sale and later, leaked. 14m email, names, addresses etc. exposed.webhacked3Have I Been Pwnedhttps://haveibeenpwned.com/Breach/FreeMobile512
16
Fédération Francaise de Rugby282,0002023Jul 23The French Rugby Federation had a breach and attempted ransom. 282k emails, names, dates of birth and phone numbers.governmenthacked1Have I Been Pwnedhttps://haveibeenpwned.com/Breach/FFR511
17
TehetségKapu54,4002025Mar 2555k records breached from the Hungarian education office TehetségKapu. Data was subsequently published to a hacking forum.governmenthacked1Have I Been Pwnedhttps://haveibeenpwned.com/Breach/TehetsegKapu510
18
Krispy Kreme 161,6762024 Nov 24U.S. doughnut chain confirmed attackers stole the personal info of over 160k individuals in a cyberattack.retailhacked3Bleeping Computerhttps://www.bleepingcomputer.com/news/security/krispy-kreme-says-november-data-breach-impacts-over-160-000-people/509
19
Episource 5,418,8662025 Feb 25An investigation revealed that hackers accessed and exfiltrated 5.4m records stored on these systems.healthhacked4Bleeping Computerhttps://www.bleepingcomputer.com/news/security/episource-says-data-breach-impacts-54-million-patients/508
20
Cock.li1,023,8002025 Jun 25Email hosting provider confirmed exploited flaws in its retired Roundcube webmail platform exposed over 1m records.webpoor security1Bleeping Computerhttps://www.bleepingcomputer.com/news/security/hacker-steals-1-million-cockli-user-records-in-webmail-data-breach/507
21
UnitedHealth 190,000,0002024 Oct 24190m Americans had their personal and healthcare data stolen in the Change Healthcare ransomware attack.healthhacked4190mBleeping Computerhttps://www.bleepingcomputer.com/news/security/unitedhealth-now-says-190-million-impacted-by-2024-data-breach/506
22
Internet Archive33,000,0002024 Oct 24The Archive was hit by two different attacks, a data breach exposing 33m users data and a DDoS attack.webhacked1Bleeping Computerhttps://www.bleepingcomputer.com/news/security/internet-archive-hacked-data-breach-impacts-31-million-users/505
23
National Public Data1,000,000,0002024 Aug 242.7bn records of US citizens used for background checks leaked on a hacking forum, names, social security, physical addresses, and aliases.governmenthacked22.7bnBleeping Computerhttps://www.bleepingcomputer.com/news/security/hackers-leak-27-billion-data-records-with-social-security-numbers/504
24
VeriSource 4,000,0002024 Feb 24Employee benefits administration firm exposed the personal information of 4m people. financehacked2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/verisource-now-says-february-data-breach-impacts-4-million-people/503
25
Baltimore Public Schools 31,0002025 Feb 25Tens of thousands of employees and students exposed in a breach incident when attackers hacked into its network.academiahacked3Bleeping Computerhttps://www.bleepingcomputer.com/news/security/baltimore-city-public-schools-data-breach-affects-over-31-000-people/502
26
Robinsons195,6002024 Jun 24Philippine shopping-mall operator suffered a breach via mobile app exposing 195k emails, names, numbers, DOB, genders.retailpoor security2Have I Been Pwnedhttps://haveibeenpwned.com/Breach/RobinsonsMalls501
27
Have Fun Teaching27,1002021 Aug 21Teaching resources site suffered a breach leaking 80k WooCommerce transactions, and posted to a hacking forum. academiahacked3Have I Been Pwnedhttps://haveibeenpwned.com/Breach/HaveFunTeaching500
28
Ualabee472,3002025 May 25South American mobility services platform had 472k records scraped from an interface on their platform.transporthacked2Have I Been Pwnedhttps://haveibeenpwned.com/Breach/Ualabee499
29
Wiredbucks918,5002022 May 22Social media influencer platform suffered a data breach exposing over 900k emails, IP addresses, names, usernames, etc.webhacked2Have I Been Pwnedhttps://haveibeenpwned.com/Breach/WiredBucks498
30
Disk Union690,7002022 Jun 22Japanese record chain store exposed 690k email, names, postcodes, phone numbers and passwords.retailhacked2Have I Been Pwnedhttps://haveibeenpwned.com/Breach/DiskUnion497
31
Spectos216,3002025 Mar 25Data breach of logistics provider, Spectos: 216k emails, names, physical addresses, and purchases.telecomshacked2Have I Been Pwnedhttps://haveibeenpwned.com/Breach/SamsungGermany496
32
German Doner Kebab162,4002025 Mar 25Breched food company leaked 162k unique emails, names, phone numbers and physical addresses.retailhacked2Have I Been Pwnedhttps://haveibeenpwned.com/Breach/GermanDonerKebab495
33
Orange Romania556,6002025 Feb 25Published to a hacking forum: 556k emails, phone, subscription, partial credit card data.telecomshacked2Have I Been Pwnedhttps://haveibeenpwned.com/Breach/OrangeRomania494
34
Thermomix Recipe World Forum3,100,0002025 Jan 25Forum for users of the popular food processer was breached, exposing 3.1m records inc. emails, physical address, and DOB. webhacked2Have I Been Pwnedhttps://haveibeenpwned.com/Breach/Thermomix493
35
Kaiser Permanente13,400,0002024 Apr 24A leading U.S. healthcare organization transmitted personal information to third-party vendors, including Google, Microsoft Bing, and X (formerly Twitter), including search terms entered in Kaiser's health encyclopedia.healthoops!3Bleeping Computerhttps://restoreprivacy.com/data-breach-at-kaiser-permanente-affects-13-4-million-people/492
36
Ticketmaster560,000,0002024 Jun 24Hacker group ShinyHunters say it stole names, addresses, phone numbers and partial credit cards details from hundreds of millions of Ticketmaster customers around the world.mischackedy3560mBBChttps://www.bbc.co.uk/news/articles/cw99ql0239wo491
37
Stanford University27,0002023 May 23The Akira ransomware group claims to have stolen 430 GB of data, including names and social security numbers. The breach went unnoticed for four months, suggesting a possible prolonged attacker presenceacademiahacked 2Slashdothttps://yro.slashdot.org/story/24/03/13/2053224/stanford-university-failed-to-detect-ransomware-intruders-for-4-months?utm_source=feedly1.0mainlinkanon&utm_medium=feed490
38
Cooler Master500,0002024 May 24Threat actor 'Ghostr' hacked the company's Fanzone website, stealing 103 GB of data. Compromised info includes names, emails, phone numbers, birth dates, addresses, product details, employee info, and vendor correspondence.techhacked2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/cooler-master-confirms-customer-info-stolen-in-data-breach/489
39
Financial Business and Consumer SolutionsFBCS3,200,0002024 Feb 24A U.S. debt collection agency reported a breach Initially affecting 1.9m people but the number has since increased significantly. Stolen data includes names, SSNs, birthdates, account info, and driver's license numbers.techhacked2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/collection-agency-fbcs-ups-data-breach-tally-to-32-million-people/488
40
Santander30,000,0002024 May 24Threat actor 'ShinyHunters' claim to be selling Santander bank data on 30m customers from Chile, Spain and Uruguay. financehacked3Bleeping Computerhttps://www.bleepingcomputer.com/news/security/banco-santander-warns-of-a-data-breach-exposing-customer-info/487
41
Everbridge5,600,0002024 May 24The American crisis management software company, serving the U.S. Army, Atlanta Airport, and Norway and Australia, suffered a major data breach. Both business and user data compromised.techhacked1Bleeping Computerhttps://www.bleepingcomputer.com/news/security/everbridge-warns-of-corporate-systems-breach-exposing-business-data/486
42
BBC25,0002024 May 24Personal information of BBC Pension Scheme members, including current and former employees, was compromised. Data types include names, National Insurance numbers, birthdates, and home addresses.mischacked2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/bbc-suffers-data-breach-impacting-current-former-employees/485
43
First American44,0002023 Dec 23The second largest title insurance company in the US did not reveal which personal information was compromissed. financehacked2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/first-american-december-data-breach-impacts-44-000-people/484
44
Christie's500,0002024 May 24Famous auction house Christie's lost sensitive information on 500,000 clients to the RansomHub extortion gang. This includes full names, physical addresses, and ID details. Ironically, the cybercriminals also auction these stolen files to the highest bidder.retailhackedy2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/christies-confirms-breach-after-ransomhub-threatens-to-leak-data/483
45
Sav-Rx2,800,0002023 Oct 23Prescription management company Sav-Rx warned over 2.8m people in the US of a data breach. Compromised data includes full names, birthdates, SSNs, emails, addresses, phone numbers, eligibility data, and insurance IDs.healthhacked2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/sav-rx-discloses-data-breach-impacting-28-million-americans/482
46
Cencora100,0002024 Feb 24Major drug companies, including Novartis and Bayer, disclosed data breaches after a February 2024 cyberattack at Cencora, their pharmaceutical services partner. Compromised data includes names, addresses, diagnoses, medications, and prescriptions.healthhacked4Bleeping Computerhttps://www.bleepingcomputer.com/news/security/cencora-data-breach-exposes-us-patient-info-from-11-drug-companies/481
47
WebTPA2,400,002023 Apr 23The breach at this employer service compromised names, contact info, birth/death dates, SSNs, and insurance details. Impacted individuals include customers of The Hartford, Transamerica, and Gerber Life Insurance.techhacked2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/webtpa-data-breach-impacts-24-million-insurance-policyholders/480
48
NissanNissan North America53;0002023 Nov 23This breach of the car manufacturer exposed personal data (including Social Security numbers) belonging to current and former employees. transporthacked2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/nissan-north-america-data-breach-impacts-over-53-000-employees/479
49
Singing RiverSinging River Health System895,0002023 Aug 23A healthcare provider in the Gulf Coast region was breached by the Rhysida ransomware gang. Compromised data includes names, birthdates, addresses, SSNs, and medical info.healthhacked4Bleeping Computerhttps://www.bleepingcomputer.com/news/security/singing-river-health-system-data-of-895-000-stolen-in-ransomware-attack/478
50
City of HelsinkiHelsinki80,0002024 Apr 24A data breach in Helsinki's education division affected tens of thousands of students, guardians, and personnel. Compromised data includes usernames, emails, IDs, addresses, fee details, education info, welfare requests, and medical certificates.governmenthacked4Bleeping Computerhttps://www.bleepingcomputer.com/news/security/helsinki-suffers-data-breach-after-hackers-exploit-unpatched-flaw/https://poliisi.fi/en/-/police-investigate-extensive-data-breach-in-helsinki-city-s-computer-network477
51
Firstmac100,0002024 Apr 24Australia's largest non-bank lender had 500GB of data stolen by the Embargo cyber-extortion group. Stolen data includes names, addresses, emails, phone numbers, birthdates, bank account info, and driver's license numbers.financehacked3Bleeping Computerhttps://www.bleepingcomputer.com/news/security/largest-non-bank-lender-in-australia-warns-of-a-data-breach/https://www.cyberdaily.au/security/10487-exclusive-aussie-lender-firstmac-falls-victim-to-embargo-ransomware-gang476
52
The Post Millennial26,000,0002024 May 24A conservative Canadian news magazine was breached leaking data on mailing lists, subscriber info, and details of writers and editors: names, emails, usernames, passwords, IPs, phone numbers, addresses, and genders.
mischacked2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/the-post-millennial-hack-leaked-data-impacting-26-million-people/https://www.mediaite.com/politics/conservative-news-websites-hacked-replaced-with-page-leaking-private-information/475
53
Dell49,000,0002024 Apr 24The Dell data breach by a threat actor scraped 49m customer records via a partner portal API accessed as a fake company. Data includes customer names, order info, warranty details, service tags, and locations.techoops!2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/dell-api-abused-to-steal-49-million-customer-records-in-data-breach/474
54
UK Ministry of Defense270,0002024 May 24A threat actor breached the Ministry of Defence, accessing the Armed Forces payment network. Compromised data includes personal and banking details and a few addresses of active, reserve, and some retired personnel.governmenthacked2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/uk-confirms-ministry-of-defence-payroll-data-exposed-in-data-breach/https://www.theguardian.com/technology/article/2024/may/06/uk-military-personnels-data-hacked-in-mod-payroll-breach473
55
DropboxDropbox Sign100,0002024 Apr 24A Dropbox service which allows online document signatures, was breached. Hackers accessed authentication tokens, MFA keys, hashed passwords, and customer information.techhacked2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/dropbox-says-hackers-stole-customer-data-auth-secrets-from-esignature-service/472
56
Panda Restaurants47,0002024 Mar 24Information exposed includes names or other personal identifiers and their driver's license numbers or ID card numbers for an undisclosed cohort.retailhacked2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/panda-restaurants-discloses-a-data-breach-after-corporate-systems-hack/471
57
Philadelphia Inquirer25,0002023 May 23A breach at this daily newspaper exposed names, personal identifiers, and financial account or credit/debit card numbers with security codes, passwords, or PINs. The Cuba ransomware gang claimed responsibility.mischacked4Bleeping Computerhttps://www.bleepingcomputer.com/news/security/philadelphia-inquirer-data-of-over-25-000-people-stolen-in-2023-breach/470
58
French government43,000,0002024 Feb 24A breach in a French government department - responsible for registering and assisting unemployed people - exposed 20 years of personal data, including names, birthdates, Social Security numbers, travel IDs, emails, postal addresses, and phone numbers.governmenthacked243mThe Registerhttps://www.theregister.com/2024/03/14/mega_data_breach_at_french/469
59
USGUniversity System of Georgia 800,0002023 May 24USG, operating 26 public colleges and universities in Georgia, was compromised in the 2023 Clop MOVEit attacks, which impacted thousands of organizations worldwide. Data included full/partial SSNs, birthdates, bank account numbers, and tax documents with Tax IDs.governmenthacked2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/university-system-of-georgia-800k-exposed-in-2023-moveit-attack/https://www.usg.edu/news/release/notice_of_data_breach468
60
Ohio Lottery538,0002023 Dec 24The DragonForce ransomware gang claimed responsibility for the Christmas Eve attack on the Ohio Lottery. They accessed names, SSNs, and other personal identifiers of affected individuals.gaminghacked2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/ohio-lottery-ransomware-attack-impacts-over-538-000-individuals/467
61
OmniVision100,0002023 Sep 24The Cactus ransomware gang claimed an attack, leaking passport scans, NDAs, contracts, and confidential documents from OmniVision, a subsidiary of Will Semiconductor, designs imaging sensors for various devices. techhacked3Bleeping Computerhttps://www.bleepingcomputer.com/news/security/omnivision-discloses-data-breach-after-2023-ransomware-attack/466
62
Western Sydney University7,5002023 May 24Hackers had accessed the University's Microsoft Office 365 environment, including email accounts and SharePoint files.academiahacked1Bleeping Computerhttps://www.bleepingcomputer.com/news/security/western-sydney-university-data-breach-exposed-student-data/465
63
AT&T73,000,0002024 Apr 24Sensitive 2019 data from 7.6m current AT&T account holders and approximately 65.4m former account holders. Emails, passcodes, social security numbers.telecomshacked473mArs Technicahttps://arstechnica.com/tech-policy/2024/04/att-acknowledges-data-leak-that-hit-73-million-current-and-former-users/464
64
Irish towing company512,0002023 Oct 23The driving licences and payment card etails of thousands of motorists who had vehicles towed on behalf of the Irish policetransportpoor security3Irish independenthttps://www.independent.ie/irish-news/thousands-of-drivers-have-sensitive-data-exposed-to-hackers-in-major-it-breach/a1379036136.html463
65
Maine Government1,300,0002023 May 23Russian ransomware group Clop stole names, dates of birth, Social Security numbers, driver’s license and other state or taxpayer identification numbers. Some individuals had medical and health insurance information taken.governmenthacked4Tech Crunchhttps://techcrunch.com/2023/11/09/maine-government-data-breach-clop-ransomware/462
66
Welltok8,500,0002023 Nov 23Patient data was exposed during the breach, including full names, email addresses, physical addresses, and telephone numbers. For some, it also includes Social Security Numbers (SSNs), Medicare/Medicaid ID numbers, and certain Health Insurance information.health hacked4Bleeping Computerhttps://www.bleepingcomputer.com/news/security/welltok-data-breach-exposes-data-of-85-million-us-patients/461
67
Maximus10,000,0002023 Jul 23Exploit of a zero-day flaw in the MOVEit file transfer application. Data stolen included social security numbers, protected health information.governmenthacked4Bleeping Computerhttps://www.bleepingcomputer.com/news/security/8-million-people-hit-by-data-breach-at-us-govt-contractor-maximus/460
68
Okta1342023 Nov 23Names and email addresses of customers of the identity security company. 134 of the company's 18,400 clients were impacted, but that only five instances of successful session hijacking were loggedtechhacked1Oktahttps://sec.okta.com/harfiles459
69
Delta Dental7,000,0002023 May 23The dental insurance company suffered unauthorized access by threat actors through the MOVEit file transfer software application exposing full credit card details of customershealth hacked3Bleeping Computerhttps://www.bleepingcomputer.com/news/security/delta-dental-of-california-data-breach-exposed-info-of-7-million-people/458
70
Xfinity36,000,0002023 Oct 23Hackers using the CitrixBleed vulnerability accessed acocunt details like name, last four digits of social security numbers and hashed passwordstelecomshacked2Tech Crunchhttps://techcrunch.com/2023/12/19/comcast-xfinity-hackers-36-million-customers/457
71
Atlassian13,2002023 Feb 23SiegedSec hacked Atlassian, the owner of Trello and other apps, via a third party office app, leaking employee details and office floor plans after an employee publicly shared credentials.techoops!y1Cyberscoophttps://cyberscoop.com/atlassian-hack-employee-data-seigedsec/456
72
Reddit100,0002023 Feb 23A phishing attack granted access to Reddit's internal documents and systems, but without breaching main production systems, user passwords, or accounts.webhackedy1Forbeshttps://www.forbes.com/sites/daveywinder/2023/02/10/reddit-confirms-it-was-hacked-recommends-users-set-up-2fa/455
73
Go Daddy1,228,0002022 Dec 23GoDaddy faced a multi-year breach (2020-2022) by a single intruder, resulting in stolen source code, user credentials, malware installation, and user redirects to malicious sites. WordPress customers’ email addresses, usernames, passwords, and even their SSL private keys were stolen.webhackedy3Bleeping Computerhttps://www.bleepingcomputer.com/news/security/godaddy-hackers-stole-source-code-installed-malware-in-multi-year-breach/454
74
MGM10,600,0002023Sept 23AlphV and Scattered Spider's cyberattack on MGM caused slot machine errors and hotel queues in Las Vegas, stealing pre-March 2019 customer data and inflicting a $100m loss on the company's Q3 results. MGM declined to say if any ransom was paid. retailhackedy3Reutershttps://www.reuters.com/business/mgm-expects-cybersecurity-issue-negatively-impact-third-quarter-earnings-2023-10-05/453
75
Uber20,000,0002022 Dec 22Data on 77,000 Uber employees and internal reports were leaked on forums. While Uber denied ownership of the implicated source code, the breach stemmed from their third-party vendor, Teqtivity, which had a security incident earlier that year.transporthackedy1Restore Privacyhttps://restoreprivacy.com/uber-data-leak-breach-third-party-vendor-hacked/452
76
X (Twitter)200,000,0002023 Jan 23From Nov 2022 to Jan 2023, over 200 million Twitter users' data, including emails and names, was exposed due to repeated security flaw exploitations and posted on hacker forums. But no highly sensitive data was revealed.webpoor security1200mFirewall Timeshttps://firewalltimes.com/twitter-data-breach-timeline/451
77
CommuteAir1,500,0002023 Jan 23Swiss hacker Maia Arson Crimew, stumbled upon a misconfigured AWS server containing TSA's No Fly list and exposed ~250,000 'selectees' (selectees are automatically chosen for additional screening each time they fly) to a hacker forum.transporthackedy2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/us-no-fly-list-shared-on-a-hacking-forum-government-investigating/450
78
Yum!10,000,0002023 Jan 23The brand owner of KFC, Pizza Hut, and Taco Bell fast food chains saw an undisclosed amount of personal user information stolen during a ransomware attack: names, driver's license numbers, and other ID card numbers. ~300 restaurants were shut down in the UK due to IT system disruptions caused by the attack. retailhackedy2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/kfc-pizza-hut-owner-discloses-data-breach-after-ransomware-attack/449
79
PharMerica5,800,0002023 May 23Full names, addresses, dates of birth, social security numbers (SSNs), medications, and health insurance information of 5,815,591 people.health hacked4Bleeping Computerhttps://www.bleepingcomputer.com/news/security/ransomware-gang-steals-data-of-58-million-pharmerica-patients/448
80
NATO8,0002023 Jul 23Hacktivist group, SiegedSec, claimed to have broken into six NATO web portals and stolen >3,000 files and 9GB of data. Threat intel biz CloudSEK analysis revealed 20 unclassified documents and 8,000 personnel records with names, job titles, email addresses, home addresses, and photos.governmenthackedy4The Registerhttps://www.theregister.com/2023/10/04/nato_data_attack/#:~:text=On%20Sunday%2C%20the%20SiegedSec%20crew,)%3B%20the%20Communities%20of%20Interest447
81
Topgolf Callaway1,114,9542023 Aug 23Only full names, shipping and email addresses, phone numbers, order histories, account passwords and answers to security questions were exposed. retailhacked2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/golf-gear-giant-callaway-data-breach-exposes-info-of-11-million/446
82
Sony6,8002023 Oct 23Personal information belonging to current and former employees and their family members was stolen by Clop in a ransomware attack. Details unrevealed by Sony.techhacked2The Vergehttps://www.theverge.com/2023/10/5/23905370/sony-interactive-entertainment-security-breach-confirmationhttps://www.bleepingcomputer.com/news/security/sony-confirms-data-breach-impacting-thousands-in-the-us/445
83
23andMe6,900,0002023 Oct 23Hackers accessed the genetic site's user data via login guesses and information from DNA relatives (users opt into sharing info through DNA relatives for others to see). Stolen data included personal and some genetic ancestry and health details. After two breaches, one unverified, 23andMe now faces legal action.health hackedy46.9mTech Crunchhttps://arstechnica.com/tech-policy/2023/12/hackers-stole-ancestry-data-of-6-9-million-users-23andme-finally-confirmed/https://www.bleepingcomputer.com/news/security/23andme-hit-with-lawsuits-after-hacker-leaks-stolen-genetics-data/444
84
Optus9,700,0002022Sept 2022The telecom company faced a 'sophisticated attack' exposing ~10 million accounts including personal details (passport, driver’s licence & Medicare numbers). Hacker demanded $1m ransom but later apologized and claimed data deletion, unverified.telecomshacked4The Guardianhttps://www.theguardian.com/business/2022/sep/29/optus-data-breach-everything-we-know-so-far-about-what-happenedhttps://www.optus.com.au/about/media-centre/media-releases/2022/09/optus-notifies-customers-of-cyberattack443
85
PayPal 349422023 Dec 22PayPal's breach involved unauthorized account access using credential stuffing (exploiting users reusing the same password for multiple accounts). It wasn't from a direct security lapse and hackers couldn't transact. PayPal reset passwords.financehacked2Office of the Maine Attorney Generalhttps://apps.web.maine.gov/online/aeviewer/ME/40/766753f1-f9c7-4dc5-9a5c-fe0f3ff51c06.shtmlhttps://www.bleepingcomputer.com/news/security/paypal-accounts-breached-in-large-scale-credential-stuffing-attack/442
86
Acer10,000,0002023 Mar 23Acer suffered a data breach when a server was hacked, with threat actors selling 160GB of stolen data. The company said the incident hadn't impacted customer info.techhacked1Slashdothttps://it.slashdot.org/story/23/03/07/1459230/acer-confirms-breach-after-hacker-offers-to-sell-stolen-data?utm_source=feedly1.0mainlinkanon&utm_medium=feedhttps://www.bleepingcomputer.com/news/security/acer-confirms-breach-after-160gb-of-data-for-sale-on-hacking-forum/441
87
MSI10,000,0002023 Apr 23Money Message ransomware group claims to have stolen MSI's source code, demanding $4 million to prevent leaks. MSI downplays impact and hasn't confirmed paying ransom, assuring no user data was affected but advises software downloads only from official sources.techhacked1Slashdothttps://it.slashdot.org/story/23/04/07/152242/msi-confirms-breach-as-ransomware-gang-claims-responsibility?utm_source=feedly1.0mainlinkanon&utm_medium=feedhttps://uk.pcmag.com/security/146322/msi-confirms-breach-as-ransomware-gang-claims-responsibility440
88
T-Mobile37,000,0002023 Jan 23T-Mobile's system was exploited by 'bad actors' from November 2022 to January 2023, exposing customer data. It's their ninth hack since 2018, with a 2021 breach affecting 49 million customers.telecomshacked2Ars Technicahttps://arstechnica.com/information-technology/2023/05/t-mobile-discloses-2nd-data-breach-of-2023-this-one-leaking-account-pins-and-more/439
89
T-Mobile8362023 Mar 23T-Mobile faced its second 2023 data breach, exposing PINs and data from Feb to Mar. Though way smaller than the first 2023 breach (only affecting 836 customers), it adds to the $350mil 2021 settlement and erodes customer trust.telecomshacked2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/t-mobile-discloses-second-data-breach-since-the-start-of-2023/438
90
ChatGPT101,0002023 Mar 23Over 101,000 ChatGPT accounts were stolen by malware last year. Breakdown: Asia-Pacific 40,999, Middle-East/Africa 24,925, Europe 16,951, Latin America 12,314, North America 4,737. Malware extracts browser credentials from SQLite databases, using CryptProtectData function to decrypt stored data.techhackedy2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/over-100-000-chatgpt-accounts-stolen-via-info-stealing-malware/437
91
TIAAThe Teachers Insurance and Annuity Association of America2,300,0002023 May 23This US retirement fund for teachers faced a data breach exposing client details. A former teacher-client is suing for inadequate cybersecurity and leaving data unencrypted on a vulnerable platform.financehacked, poor security2ClassActionhttps://www.classaction.org/news/teachers-insurance-and-annuity-association-of-america-hit-with-class-action-over-may-2023-data-breach#:~:text=Teachers%20Insurance%20and%20Annuity%20Association%20of%20America%20faces%20a%20class,of%20approximately%202.3%20million%20individuals.https://news.slashdot.org/story/23/06/30/2038234/schools-say-us-teachers-retirement-fund-was-breached-by-moveit-hackers?utm_source=feedly1.0mainlinkanon&utm_medium=feed436
92
Microsoft30,000,0002023 Jun 23Anonymous Sudan hacked Microsoft, accessed customer data, and caused outages. They offered the database for $50,000. But Microsoft claims no evidence of compromised customer data.webhacked2Bleeping Computerhttps://www.bleepingcomputer.com/news/security/microsoft-denies-data-breach-theft-of-30-million-customer-accounts/435
93
Microsoft10,000,0002023 May 23China-backed hackers stole a cryptographic key from Microsoft, undetected for a month, accessing 25 organizations, including government. Microsoft's postmortem cites past system vulnerabilities.webhacked3unknownNYThttps://www.nytimes.com/2023/07/11/us/politics/china-hack-us-government-microsoft.html?smid=nytcore-ios-sharehttps://www.wired.com/story/china-backed-hackers-steal-microsofts-signing-key-post-mortem/434
94
Roblox4,0002020 Dec 20Data identifying Roblox creators was breached at a developers' conference, undisclosed for 2 years due to a third-party security issue.gamingpoor security2The Vergehttps://www.theverge.com/2023/7/21/23802742/roblox-data-breach-leak-developer-personal-information-exposed433
95
Discord.io760,0002023 Aug 23Unidentified person listed user data for sale on darknet. Discord.io enables custom Discord invites.gaminghacked1Stackdiaryhttps://stackdiary.com/the-data-of-760000-discord-io-users-was-put-up-for-sale-on-the-darknet//432
96
Clorox10,000,0002023 Aug 23Clorox detected unauthorized IT activity in August 2023. By September, the contained hack led to slower production and a 2% stock drop. Specific affected files undisclosedretailhacked1unknownSlashdothttps://it.slashdot.org/story/23/10/04/1917217/clorox-security-breach-linked-to-group-behind-casino-hacks?utm_source=feedly1.0mainlinkanon&utm_medium=feed431
97
Latitude Financial14,000,0002023 Apr 2314 million customer records, including driver's licence numbers, passport numbers and financial statements, stolen in a cyber-attack that was worse than the company initially reported.financehacked2Privacy Commissionerhttps://www.privacy.org.nz/publications/statements-media-releases/new-zealands-biggest-data-breach-shows-retention-is-the-sleeping-giant-of-data-security/430
98
Toyota296,0192022 Oct 22An access key to a data server storing customer email addresses and management numbers was mistakenly published publically on GitHub for five years.transportpoor security 2Slashdothttps://yro.slashdot.org/story/22/10/10/2032250/toyota-discloses-data-leak-after-access-key-exposed-on-github?utm_source=feedly1.0mainlinkanon&utm_medium=feed429
99
Shein39,000,0002022 Oct 22Online fast fashion retailer suffered a breach of its login credentials in 2018 but failed to notify its customersretailhacked2Tech Crunchhttps://techcrunch.com/2022/10/13/shein-zoetop-fined-1-9m-data-breach/?guccounter=1428
100
Indonesia's health agencyBPJS Kesehatan279,000,0002022 May 21The ID numbers, salary and phone numbers of every single man, woman and child in the country was stolen.governmenthackedy3Kr Asiahttps://kr-asia.com/shoddy-data-protection-in-indonesia-threatens-personal-security-of-citizens427