Security News

Cybersecurity news aggregator

INFO News Huntress

27 Biggest Data Breaches in History: Famous Examples

  • What: Overview of major data breaches in history
  • Impact: Highlights the risks of data exposure and the importance of security measures.
Read Full Article →

Home Blog 27 Biggest Data Breaches in History & What They Teach Us Last Updated: June 25, 2026 27 Biggest Data Breaches in History & What They Teach Us By: Brenda Buckman Summarize with AI Summarize ChatGPT Claude Perplexity Google AI Remember when your biggest online privacy concern was your parents friending you on Facebook? Ah, simpler times. Now, we're navigating a digital minefield where giants like Yahoo, Equifax, and, yes, Facebook have made personal data a hot commodity on the dark web. These biggest data breaches in history offer critical lessons for any business looking to avoid becoming the next famous data breach headline. To make it on this list of the biggest data breaches, the attacks include both a massive number of records exposed and a wide range of data accessed by threat actors. Each data breach example below reveals common patterns in how the largest data breaches unfold—and what could have prevented them. Keep reading to learn more about the biggest global data breaches, what they have in common, and how to prevent them at your organization. The 27 biggest data breaches in history From big names in the credit card game like Capital One to shopping sites like eBay, anyone can fall victim to a data breach, especially if the right protections aren't in place. These famous data breaches show that no industry or company size is immune. It’s important to note that while the term data breach is commonly used to describe any sort of incident involving data, this list actually includes three distinct types of data threats: Data breaches: These are traditional, unauthorized infiltrations of a secure system. Data leaks: This often refers to an unintentional exposure of data due to a misconfiguration issue, such as the storage of unencrypted passwords . Data scraping: This is the automated extraction of large amounts of data, often publicly available, but done in a massive, unauthorized way that violates terms of service. Here’s an overview of some of the largest data incidents of the past 20 years. Breach Location Records exposed Data accessed Chinese Surveillance Network China 4 billion WeChat data, bank details, Alipay profile information, phone numbers, home addresses, and behavioral profiles Yahoo Global 3 billion Names, email addresses, dates of birth, phone numbers, and encrypted or unencrypted security questions and answers National Public Data US, UK, and Canada 2.9 billion Full names, dates of birth, addresses, phone numbers, and Social Security numbers Real Estate Wealth Network United States 1.5 billion Names, addresses, phone numbers, mortgage information, and tax identification numbers River City Media United States 1.4 billion Email and IP addresses, full names, and physical addresses Aadhaar India 1.1 billion Names, addresses, photos, phone numbers, emails, and biometric data Alibaba China 1.1 billion User IDs and phone numbers First American Financial United States 885 million Social Security numbers, bank account details, mortgage and tax records, wire transfer receipts, and driver's license photos LinkedIn Global 700 million Names, email addresses, phone numbers, location, and gender Sina Weibo China 538 million Names, usernames, phone numbers, location, and gender Facebook Global 533 million Names, Facebook IDs, locations, dates of birth, and phone numbers Marriott International (Starwood) Global 500 million Names, mailing addresses, phone numbers, email addresses, passport numbers, dates of birth, other travel details, and encrypted payment card information for a smaller number of people Adult FriendFinder Global 412 million Usernames, email addresses, dates of last visits, passwords, and IP addresses 14. MySpace Global 360 million Email addresses, usernames, and passwords 15. Exactis United States 340 million Full names, email addresses, phone numbers, home addresses, plus the number, age, and gender of a person's children, their interests, and their estimated income 16. NetEase China 235 million Usernames, passwords, and security question answers 17. Zynga Global 218 million Usernames, email addresses, passwords, Facebook IDs, and phone numbers 18. Court Ventures (Experian) United States 200 million Names, addresses, dates of birth, and Social Security numbers 19. Dubsmash United States 162 million Usernames, email addresses, geographic locations, and passwords 20. Equifax US, UK, and Canada 159 million Names, Social Security numbers, dates of birth, addresses, and driver's license numbers 21. Adobe Global 153 million Names, email addresses, and encrypted passwords 22. eBay Global 145 million Names, encrypted passwords, email addresses, physical addresses, phone numbers, and dates of birth 23. Heartland Payment Systems Primarily US 130 million Credit and debit card numbers 24. Capital One US and Canada 100 million Names, addresses, dates of birth, self-reported income for applicants, Social Security numbers, and linked bank account numbers 25. JPMorgan Chase United States 76 million households and 7 million small businesses Names, addresses, phone numbers, and email addresses 26. Home Depot US and Canada 56 million Card numbers, expiration dates, and the three-digit Card Verification Value (CVV) codes 27. Microsoft Global 250,000 servers Business emails, passwords, and administrative privileges 1. Chinese Surveillance Network Date: June 2025 Location: China (primarily) Records exposed: 4 billion personal records Types of data: WeChat data, bank details, Alipay profile information, phone numbers, home addresses, and behavioral profiles A massive data leak in China, discovered by Bob Dyachenko at SecurityDiscovery.com and the Cybernews research team, exposed a database of 4 billion records containing sensitive personally identifiable information (PII). The 631-gigabyte database was found without a password, making it easily accessible. The researchers said they believed the data was likely intentionally gathered to build comprehensive profiles of nearly every Chinese citizen. The leak, which primarily affected Chinese users, is considered one of the largest data leaks to ever occur in China. 2. Yahoo Date: August 2013 L ocation: Global Records exposed: 3 billion user accounts Types of data: Names, email addresses, dates of birth, phone numbers, and encrypted or unencrypted security questions and answers Widely considered one of the biggest data breaches in history, the August 2013 Yahoo incident wasn’t disclosed until December 2016. The breach compromised all 3 billion of Yahoo's user accounts. The breach resulted in a significant financial and reputational loss for Yahoo, including fetching a lower price when sold to Verizon. 3. National Public Data Date: December 2023 Location: US, UK, and Canada Records exposed: 2.9 billion Types of data: Full names, dates of birth, addresses, phone numbers, and Social Security numbers The National Public Data (NPD) breach, which the company did not confirm until August 2024, was caused by a security lapse that allowed a threat actor to access and steal data. The compromised information was later put up for sale on a dark web forum, with the threat actor claiming it included the Social Security numbers of over 272 million people. The breach was not a traditional hack, but a failure of security on the part of NPD and a sister site, which had a publicly accessible file containing plain-text usernames and passwords, including ones reportedly belonging to the site’s administrator . The incident ultimately led to numerous class-action lawsuits against NPD and their parent company, causing them to go out of business completely. 4. Real Estate Wealth Network Date: December 2023 Location: United States Records exposed: 1.5 billion Types of data: Names, addresses, phone numbers, mortgage information, and tax identification numbers The Real Estate Wealth Network (REWN) breach resulted from an unsecured database, totaling 1.16 terabytes, that was left open without a password. The exposed information was meticulously organized into categories like property history, motivated sellers, and tax records, and included sensitive details on millions of people, including celebrities and politicians. A cybersecurity researcher discovered the vulnerability and notified REWN, who then secured the database. While it's unknown how long the data was exposed or if malicious actors accessed it, the leak highlights the severe risks of unprotected databases, including the potential for identity theft, fraud, and a significant invasion of privacy. 5. River City Media Date: March 2017 Location: United States Records exposed: 1.4 billion Types of data: Email and IP addresses, full names, and physical addresses The River City Media data leak involved a spam operation, where the spam email operators were masquerading as a legitimate email marketing firm. The data was left on a backup server without any password protection, making it accessible to anyone who knew where to look. The leak was discovered by a security researcher—a hero, if you ask us—who found the open repository and then notified law enforcement and anti-spam organizations. The incident revealed the inner workings of a large-scale spam operation and served as a clear reminder of how easily sensitive data can be compromised thanks to simple configuration errors. 6. Aadhaar Date: January 2018 Location: India Records exposed: 1.1 billion Types of data: Names, addresses, photos, phone numbers, emails, and biometric data This breach came to light when a reporter from an Indian newspaper claimed to have bought access to a portal for a small fee, which allowed them to get the details of over a billion Aadhaar cardholders. While the Unique Identification Authority of India (UIDAI)—which manages Aadhaar—denied a breach of their central database, it was later revealed that the leak was likely due to vulnerabilities in the systems of third-party government websites and utility companies that had access to Aadhaar data. The

Share this article