← The Breach Files

Case Files

How the breaches that mattered actually happened

The archive tells you what was taken. These tell you how — the unpatched server, the contractor's password, the API nobody put a login on — and what happened to the people in the file afterwards. Written from regulatory findings, court records and company disclosures, and sourced at the foot of every page.

49Case files
19Years covered
178Sources cited

2024 onwards

The third-party era. The intrusion is rarely at the company whose name ends up in the headline — it is at a supplier, a cloud tenant, or on an employee's home computer.

2019 – 2023

Cloud misconfiguration, ransomware crews with a publicity operation, and the first breaches measured in whole national populations.

2023 · Genetic testing

23andMe, 2023: 14,000 accounts opened the door to 6.9 million people

The clearest case of one person's weak password exposing thousands of strangers — and of ancestry data being used to build targeting lists.

about 6.9 million people, from 14,000 compromised accounts Read the case file →
2023 · Hospitality

MGM Resorts, 2023: a ten-minute phone call to the help desk

No exploit, no malware on the way in. A phone call, a name from LinkedIn, and a help desk doing what help desks are measured on: being helpful quickly.

Personal data of customers who transacted with MGM before March 2019 Read the case file →
2023 · Supply chain

MOVEit, 2023: one file transfer product, 2,700 organisations

The clearest example of supply-chain leverage: attack the software everyone uses to move sensitive files, and you attack everyone at once.

over 2,700 organisations; more than 90 million individuals Read the case file →
2022 · Password manager

LastPass, 2022: the vaults were stolen, and then attacked offline

Encryption held, mostly. But a stolen vault can be attacked forever, offline, with no rate limit and nobody watching.

backups of customer vaults, affecting tens of millions of accounts Read the case file →
2022 · Health insurance

Medibank, 2022: the company said no, and the data went up anyway

A contractor's credential with no second factor, 9.7 million customers, and an extortion campaign designed around shame rather than fraud.

9.7 million current and former customers; health claims data for about 480,000 Read the case file →
2022 · Telecommunications

Optus, 2022: an API with no lock on it, and 9.8 million Australians

No password, no token, no rate limit. The breach that rewrote Australian privacy law and put a price on identity documents.

9.8 million customers; about 2.1 million with identity document numbers Read the case file →
2022 · Phishing campaign

0ktapus, 2022: one text message, one hundred and thirty companies

The difference between the companies that fell and the one that did not was not training, vigilance or luck. It was the type of second factor they used.

~9,900 accounts and ~5,400 one-time codes captured across 130+ organisations Read the case file →
2022 · Social network

Twitter, 2022: an API that confirmed which account owned which email

The damage was not stolen passwords. It was the link between a real identity and an anonymous account — which cannot be undone.

5.4 million accounts confirmed; a larger compilation circulated later Read the case file →
2021 · Telecommunications

T-Mobile, 2021: an exposed router, and 76 million people who were mostly not customers

The carrier that has been breached more often than any other, and the year it lost the Social Security numbers of people who were never customers.

over 76 million records, including about 40 million former and prospective customers Read the case file →
2021 · Aviation

Air India, 2021: ten years of passengers, lost by a supplier

One supplier, many airlines. Passengers who had never heard of SITA had their passport details taken from its systems.

about 4.5 million passengers Read the case file →
2021 · Energy

Colonial Pipeline, 2021: one leaked password, and the fuel stopped

Not a breach of personal data — a breach of everyday life. The case that turned ransomware from an IT problem into a national security one.

Operational shutdown; a limited number of personal records also taken Read the case file →
2021 · Social network

Facebook, 2021: 533 million phone numbers that were never "hacked"

A feature, not a flaw — until it produced a free file of 533 million phone numbers matched to names. The case that made scraping a regulatory matter.

533 million users across 106 countries Read the case file →
2021 · India · Disputed

MobiKwik, 2021: the breach that was denied while people searched their own KYC files

Users found their own identity documents in a searchable portal while the company was publicly denying that anything had been taken. It has never confirmed a breach.

Alleged 99 million users and 8.2 TB of data — never confirmed by the company Read the case file →
2021 · Supply chain

Accellion FTA, 2021: the rehearsal for MOVEit

The vendor had been telling customers to migrate for years. The ones who had not were breached through a product that was already scheduled to die.

Dozens of organisations; the Washington State Auditor alone reported 1.6 million individuals Read the case file →
2020 · Supply chain

SolarWinds, 2020: 18,000 organisations installed the backdoor themselves

The update was signed, the checksum matched and the vendor was reputable. Every control that was supposed to catch this passed it through.

~18,000 organisations downloaded the backdoor Read the case file →
2020 · Surveillance

Clearview AI, 2020: three billion faces, scraped and sold

Every photo in it was already public. That was the company's entire legal argument, and regulators across four continents rejected it.

Over 3 billion images scraped; later reported by the company as more than 30 billion Read the case file →
2019 · Banking

Capital One, 2019: a firewall misconfiguration and 106 million applicants

The breach that changed how cloud metadata works. One misconfigured firewall, one request to an internal address, and fourteen years of applications.

about 100 million US and 6 million Canadian applicants Read the case file →
2019 · Credential aggregate

Collection #1, 2019: 773 million addresses, and nobody was breached

The file that explained credential stuffing to the public. No company was breached to create it — it was thousands of older breaches, merged into one attack tool.

772,904,991 unique email addresses; 21,222,975 unique passwords Read the case file →

2014 – 2018

The years that produced the regulation. Mega-breaches that ended careers, moved share prices and wrote the rules everyone now works under.

2018 · Hospitality

Marriott and Starwood, 2018: a breach that came with the acquisition

Four years of guest records, five million unencrypted passport numbers, and a compromise that was already running when the company was bought.

about 339 million guest records Read the case file →
2018 · Airline

British Airways, 2018: twenty-two lines of JavaScript

Nothing was stolen from a database. The card numbers were copied out of the browser, one keystroke at a time, before BA ever received them.

About 429,612 customers and staff Read the case file →
2018 · Data misuse

Cambridge Analytica, 2018: the breach that was not a breach

About 270,000 people took a personality quiz. The API of the day let the quiz collect their friends too, and the friends were never asked.

Up to 87 million Facebook users Read the case file →
2018 · National identity

Aadhaar, 2018: what the reported exposures actually showed

A disputed case, deliberately included. The exposure was in the ecosystem around the identity system rather than in its central database — which is where large identity systems usually fail.

Disputed; reports covered access to demographic details and third-party systems holding Aadhaar numbers Read the case file →
2016 · Ride-hailing

Uber, 2016: the breach that was paid to disappear

The data loss was ordinary. The response — payment, non-disclosure agreements, silence, and eventually a criminal conviction for the security chief — was not.

57 million riders and drivers; 600,000 driver's licence numbers Read the case file →
2017 · Credit bureau

Equifax, 2017: 147 million people, one unpatched web form

A patch released in March. An intrusion in May. Discovery in July, because a certificate on the monitoring appliance had been expired for ten months.

147.9 million people Read the case file →
2017 · Destructive attack

NotPetya, 2017: the update that cost ten billion dollars

It looked like ransomware and was not. There was no way to pay and no way to recover — the decryption key it offered had never existed.

No data stolen — an estimated $10 billion in destroyed systems Read the case file →
2013–2014 · Web portal

Yahoo, 2013–2014: three billion accounts, and three years of silence

Two intrusions, every account Yahoo had ever issued, and a disclosure that arrived three years late and mid-acquisition. Still the largest breach on record.

3 billion accounts Read the case file →
2012 · Cloud storage

Dropbox, 2012: an employee reused a password, and 68 million accounts followed

The textbook demonstration that one company's breach becomes another company's breach, carried across by a single reused password.

68.6 million accounts Read the case file →
2008 · Social network

MySpace, 2016: 360 million accounts from a website nobody used any more

Dead site, live passwords. The largest breach on record at the time, and a lesson in why abandoning an account is not the same as closing it.

about 360 million accounts Read the case file →
2015 · Children's data

VTech, 2015: six million children in a toy company's database

Names, dates of birth, genders and the parents they linked to. For some children, also the photographs and messages they had sent.

Around 4.9 million parent accounts and 6.4 million child profiles Read the case file →
2015 · Telecoms

TalkTalk, 2015: a nineteen-year-old and a webpage nobody owned

The vulnerable pages came with a company TalkTalk bought in 2009. Nobody had looked at them since, and the attack that worked was fifteen years old.

156,959 customers, including 15,656 bank account numbers Read the case file →
2015 · Dating

Ashley Madison, 2015: when the data itself was the weapon

Good password hashing, catastrophic everything else. The breach that proved some data is dangerous purely because of what it implies about a person.

32 million user records Read the case file →
2015 · Government

OPM, 2015: 21.5 million security clearance files, fingerprints included

Not identity theft. Counterintelligence. The SF-86 form exists to record everything that could be used to pressure someone, and all of it was taken.

21.5 million background investigation records, 4.2 million personnel records, 5.6 million fingerprints Read the case file →
2015 · Health insurance

Anthem, 2015: 78.8 million health records and one query that looked wrong

Found because one employee questioned a query he did not recognise. The largest US health data breach of its time, and the largest HIPAA penalty.

78.8 million people Read the case file →
2014 · Film studio

Sony Pictures, 2014: the breach that destroyed the computers on the way out

Theft, destruction and publication in one operation, aimed at a company over a film. The first breach treated as a national security incident.

about 47,000 individuals' details, plus the company's internal correspondence Read the case file →
2014 · Banking

JPMorgan Chase, 2014: one server without two-factor authentication

The rollout of two-factor authentication across the estate was complete except for one server. The attackers found the exception.

76 million households and 7 million small businesses Read the case file →
2014 · Retail

Home Depot, 2014: 56 million cards through a supplier's login

Employees had warned for years that the tills were running outdated protection. The breach ran from April to September before a bank spotted the pattern.

56 million payment cards and 53 million email addresses Read the case file →
2014 · Marketplace

eBay, 2014: 145 million users and a notice nobody saw

No card data was taken, which eBay said often. What was taken was everything needed to impersonate 145 million people convincingly.

145 million user records Read the case file →
2014 · Insider

Morrisons, 2014: the auditor who published the payroll

He had legitimate access, a legitimate reason to use it, and a disciplinary record he was angry about. No control in the company was designed to stop that.

99,998 employees Read the case file →

Before 2014

The foundational cases. Almost everything the industry believes about passwords, card data and disclosure was learned here, expensively.

2013 · Retail

Target, 2013: 40 million cards, and the air-conditioning contractor

The breach that made "third-party risk" a board-level phrase. The way in was a heating and air-conditioning contractor's password.

40 million payment cards, 70 million customer records Read the case file →
2013 · Software

Adobe, 2013: 153 million records and the world's worst crossword

A masterclass in how not to store passwords: one encryption key, no salt, and a plaintext hint column that gave the answers away.

153 million records Read the case file →
2012 · Professional network

LinkedIn, 2012: 6.5 million hashes that turned into 165 million accounts

Unsalted SHA-1, a forum post asking for help cracking it, and four years later the rest of the database. The breach that compromised other companies.

165 million accounts (117 million with passwords) Read the case file →
2011 · Gaming

PlayStation Network, 2011: 77 million accounts and 23 days offline

Sony said the passwords were not stored in plain text. It took a week to say what they were stored as, and by then the damage to trust was done.

77 million PSN accounts, plus 24.6 million Sony Online Entertainment accounts Read the case file →
2009 · Social apps

RockYou, 2009: the 32 million plaintext passwords that became a wordlist

Small breach, enormous legacy. The file that taught everyone what people actually choose as a password — and that still ships with every penetration testing distribution.

32.6 million accounts Read the case file →
2008 · Payments

Heartland, 2008: 130 million cards from a company that had just passed its audit

Compliant and breached. The case that separated "passed the audit" from "is actually secure", permanently.

about 130 million card numbers Read the case file →
2007 · Retail

TJX, 2007: the wireless network in the car park

The first mega-breach of the card era. Weak wireless encryption, eighteen months of undetected access, and the reason PCI DSS grew teeth.

45.7 million cards confirmed; court filings suggested up to 94 million Read the case file →

Every case file is sourced. Where a headline figure was later revised — and it usually is — these pages use the number the organisation or its regulator finally settled on, and say what it was first reported as. Claims that remain disputed are labelled as disputed.

The live breach archive → Guides →