How the breaches that mattered actually happened
The archive tells you what was taken. These tell you how — the unpatched server, the contractor's password, the API nobody put a login on — and what happened to the people in the file afterwards. Written from regulatory findings, court records and company disclosures, and sourced at the foot of every page.
2024 onwards
The third-party era. The intrusion is rarely at the company whose name ends up in the headline — it is at a supplier, a cloud tenant, or on an employee's home computer.
National Public Data, 2024: a company you never used, holding everything about you
Nobody in this file signed up for anything. The case that made data brokers a mainstream concern — and showed how meaningless a headline record count can be.
advertised as 2.9 billion rows; researchers identified about 134 million unique email addresses Read the case file → 2024 · TelecommunicationsAT&T, 2024: who called whom, for nearly every customer
Metadata is not "less than" content. A complete record of who contacted whom identifies relationships that no message body would reveal.
call and text metadata for nearly all mobile customers, about 109 million accounts Read the case file → 2024 · Cloud dataSnowflake, 2024: 165 companies breached without anyone touching Snowflake
No vulnerability, no intrusion at the platform. Just passwords harvested from employees' machines and accounts that accepted a password alone.
around 165 customer tenants; hundreds of millions of individual records Read the case file → 2024 · Healthcare paymentsChange Healthcare, 2024: one login, and American healthcare stopped billing
The largest health data breach in US history, and a month in which pharmacies could not tell patients what their prescriptions cost.
about 190 million people Read the case file →2019 – 2023
Cloud misconfiguration, ransomware crews with a publicity operation, and the first breaches measured in whole national populations.
23andMe, 2023: 14,000 accounts opened the door to 6.9 million people
The clearest case of one person's weak password exposing thousands of strangers — and of ancestry data being used to build targeting lists.
about 6.9 million people, from 14,000 compromised accounts Read the case file → 2023 · HospitalityMGM Resorts, 2023: a ten-minute phone call to the help desk
No exploit, no malware on the way in. A phone call, a name from LinkedIn, and a help desk doing what help desks are measured on: being helpful quickly.
Personal data of customers who transacted with MGM before March 2019 Read the case file → 2023 · Supply chainMOVEit, 2023: one file transfer product, 2,700 organisations
The clearest example of supply-chain leverage: attack the software everyone uses to move sensitive files, and you attack everyone at once.
over 2,700 organisations; more than 90 million individuals Read the case file → 2022 · Password managerLastPass, 2022: the vaults were stolen, and then attacked offline
Encryption held, mostly. But a stolen vault can be attacked forever, offline, with no rate limit and nobody watching.
backups of customer vaults, affecting tens of millions of accounts Read the case file → 2022 · Health insuranceMedibank, 2022: the company said no, and the data went up anyway
A contractor's credential with no second factor, 9.7 million customers, and an extortion campaign designed around shame rather than fraud.
9.7 million current and former customers; health claims data for about 480,000 Read the case file → 2022 · TelecommunicationsOptus, 2022: an API with no lock on it, and 9.8 million Australians
No password, no token, no rate limit. The breach that rewrote Australian privacy law and put a price on identity documents.
9.8 million customers; about 2.1 million with identity document numbers Read the case file → 2022 · Phishing campaign0ktapus, 2022: one text message, one hundred and thirty companies
The difference between the companies that fell and the one that did not was not training, vigilance or luck. It was the type of second factor they used.
~9,900 accounts and ~5,400 one-time codes captured across 130+ organisations Read the case file → 2022 · Social networkTwitter, 2022: an API that confirmed which account owned which email
The damage was not stolen passwords. It was the link between a real identity and an anonymous account — which cannot be undone.
5.4 million accounts confirmed; a larger compilation circulated later Read the case file → 2021 · TelecommunicationsT-Mobile, 2021: an exposed router, and 76 million people who were mostly not customers
The carrier that has been breached more often than any other, and the year it lost the Social Security numbers of people who were never customers.
over 76 million records, including about 40 million former and prospective customers Read the case file → 2021 · AviationAir India, 2021: ten years of passengers, lost by a supplier
One supplier, many airlines. Passengers who had never heard of SITA had their passport details taken from its systems.
about 4.5 million passengers Read the case file → 2021 · EnergyColonial Pipeline, 2021: one leaked password, and the fuel stopped
Not a breach of personal data — a breach of everyday life. The case that turned ransomware from an IT problem into a national security one.
Operational shutdown; a limited number of personal records also taken Read the case file → 2021 · Social networkFacebook, 2021: 533 million phone numbers that were never "hacked"
A feature, not a flaw — until it produced a free file of 533 million phone numbers matched to names. The case that made scraping a regulatory matter.
533 million users across 106 countries Read the case file → 2021 · India · DisputedMobiKwik, 2021: the breach that was denied while people searched their own KYC files
Users found their own identity documents in a searchable portal while the company was publicly denying that anything had been taken. It has never confirmed a breach.
Alleged 99 million users and 8.2 TB of data — never confirmed by the company Read the case file → 2021 · Supply chainAccellion FTA, 2021: the rehearsal for MOVEit
The vendor had been telling customers to migrate for years. The ones who had not were breached through a product that was already scheduled to die.
Dozens of organisations; the Washington State Auditor alone reported 1.6 million individuals Read the case file → 2020 · Supply chainSolarWinds, 2020: 18,000 organisations installed the backdoor themselves
The update was signed, the checksum matched and the vendor was reputable. Every control that was supposed to catch this passed it through.
~18,000 organisations downloaded the backdoor Read the case file → 2020 · SurveillanceClearview AI, 2020: three billion faces, scraped and sold
Every photo in it was already public. That was the company's entire legal argument, and regulators across four continents rejected it.
Over 3 billion images scraped; later reported by the company as more than 30 billion Read the case file → 2019 · BankingCapital One, 2019: a firewall misconfiguration and 106 million applicants
The breach that changed how cloud metadata works. One misconfigured firewall, one request to an internal address, and fourteen years of applications.
about 100 million US and 6 million Canadian applicants Read the case file → 2019 · Credential aggregateCollection #1, 2019: 773 million addresses, and nobody was breached
The file that explained credential stuffing to the public. No company was breached to create it — it was thousands of older breaches, merged into one attack tool.
772,904,991 unique email addresses; 21,222,975 unique passwords Read the case file →2014 – 2018
The years that produced the regulation. Mega-breaches that ended careers, moved share prices and wrote the rules everyone now works under.
Marriott and Starwood, 2018: a breach that came with the acquisition
Four years of guest records, five million unencrypted passport numbers, and a compromise that was already running when the company was bought.
about 339 million guest records Read the case file → 2018 · AirlineBritish Airways, 2018: twenty-two lines of JavaScript
Nothing was stolen from a database. The card numbers were copied out of the browser, one keystroke at a time, before BA ever received them.
About 429,612 customers and staff Read the case file → 2018 · Data misuseCambridge Analytica, 2018: the breach that was not a breach
About 270,000 people took a personality quiz. The API of the day let the quiz collect their friends too, and the friends were never asked.
Up to 87 million Facebook users Read the case file → 2018 · National identityAadhaar, 2018: what the reported exposures actually showed
A disputed case, deliberately included. The exposure was in the ecosystem around the identity system rather than in its central database — which is where large identity systems usually fail.
Disputed; reports covered access to demographic details and third-party systems holding Aadhaar numbers Read the case file → 2016 · Ride-hailingUber, 2016: the breach that was paid to disappear
The data loss was ordinary. The response — payment, non-disclosure agreements, silence, and eventually a criminal conviction for the security chief — was not.
57 million riders and drivers; 600,000 driver's licence numbers Read the case file → 2017 · Credit bureauEquifax, 2017: 147 million people, one unpatched web form
A patch released in March. An intrusion in May. Discovery in July, because a certificate on the monitoring appliance had been expired for ten months.
147.9 million people Read the case file → 2017 · Destructive attackNotPetya, 2017: the update that cost ten billion dollars
It looked like ransomware and was not. There was no way to pay and no way to recover — the decryption key it offered had never existed.
No data stolen — an estimated $10 billion in destroyed systems Read the case file → 2013–2014 · Web portalYahoo, 2013–2014: three billion accounts, and three years of silence
Two intrusions, every account Yahoo had ever issued, and a disclosure that arrived three years late and mid-acquisition. Still the largest breach on record.
3 billion accounts Read the case file → 2012 · Cloud storageDropbox, 2012: an employee reused a password, and 68 million accounts followed
The textbook demonstration that one company's breach becomes another company's breach, carried across by a single reused password.
68.6 million accounts Read the case file → 2008 · Social networkMySpace, 2016: 360 million accounts from a website nobody used any more
Dead site, live passwords. The largest breach on record at the time, and a lesson in why abandoning an account is not the same as closing it.
about 360 million accounts Read the case file → 2015 · Children's dataVTech, 2015: six million children in a toy company's database
Names, dates of birth, genders and the parents they linked to. For some children, also the photographs and messages they had sent.
Around 4.9 million parent accounts and 6.4 million child profiles Read the case file → 2015 · TelecomsTalkTalk, 2015: a nineteen-year-old and a webpage nobody owned
The vulnerable pages came with a company TalkTalk bought in 2009. Nobody had looked at them since, and the attack that worked was fifteen years old.
156,959 customers, including 15,656 bank account numbers Read the case file → 2015 · DatingAshley Madison, 2015: when the data itself was the weapon
Good password hashing, catastrophic everything else. The breach that proved some data is dangerous purely because of what it implies about a person.
32 million user records Read the case file → 2015 · GovernmentOPM, 2015: 21.5 million security clearance files, fingerprints included
Not identity theft. Counterintelligence. The SF-86 form exists to record everything that could be used to pressure someone, and all of it was taken.
21.5 million background investigation records, 4.2 million personnel records, 5.6 million fingerprints Read the case file → 2015 · Health insuranceAnthem, 2015: 78.8 million health records and one query that looked wrong
Found because one employee questioned a query he did not recognise. The largest US health data breach of its time, and the largest HIPAA penalty.
78.8 million people Read the case file → 2014 · Film studioSony Pictures, 2014: the breach that destroyed the computers on the way out
Theft, destruction and publication in one operation, aimed at a company over a film. The first breach treated as a national security incident.
about 47,000 individuals' details, plus the company's internal correspondence Read the case file → 2014 · BankingJPMorgan Chase, 2014: one server without two-factor authentication
The rollout of two-factor authentication across the estate was complete except for one server. The attackers found the exception.
76 million households and 7 million small businesses Read the case file → 2014 · RetailHome Depot, 2014: 56 million cards through a supplier's login
Employees had warned for years that the tills were running outdated protection. The breach ran from April to September before a bank spotted the pattern.
56 million payment cards and 53 million email addresses Read the case file → 2014 · MarketplaceeBay, 2014: 145 million users and a notice nobody saw
No card data was taken, which eBay said often. What was taken was everything needed to impersonate 145 million people convincingly.
145 million user records Read the case file → 2014 · InsiderMorrisons, 2014: the auditor who published the payroll
He had legitimate access, a legitimate reason to use it, and a disciplinary record he was angry about. No control in the company was designed to stop that.
99,998 employees Read the case file →Before 2014
The foundational cases. Almost everything the industry believes about passwords, card data and disclosure was learned here, expensively.
Target, 2013: 40 million cards, and the air-conditioning contractor
The breach that made "third-party risk" a board-level phrase. The way in was a heating and air-conditioning contractor's password.
40 million payment cards, 70 million customer records Read the case file → 2013 · SoftwareAdobe, 2013: 153 million records and the world's worst crossword
A masterclass in how not to store passwords: one encryption key, no salt, and a plaintext hint column that gave the answers away.
153 million records Read the case file → 2012 · Professional networkLinkedIn, 2012: 6.5 million hashes that turned into 165 million accounts
Unsalted SHA-1, a forum post asking for help cracking it, and four years later the rest of the database. The breach that compromised other companies.
165 million accounts (117 million with passwords) Read the case file → 2011 · GamingPlayStation Network, 2011: 77 million accounts and 23 days offline
Sony said the passwords were not stored in plain text. It took a week to say what they were stored as, and by then the damage to trust was done.
77 million PSN accounts, plus 24.6 million Sony Online Entertainment accounts Read the case file → 2009 · Social appsRockYou, 2009: the 32 million plaintext passwords that became a wordlist
Small breach, enormous legacy. The file that taught everyone what people actually choose as a password — and that still ships with every penetration testing distribution.
32.6 million accounts Read the case file → 2008 · PaymentsHeartland, 2008: 130 million cards from a company that had just passed its audit
Compliant and breached. The case that separated "passed the audit" from "is actually secure", permanently.
about 130 million card numbers Read the case file → 2007 · RetailTJX, 2007: the wireless network in the car park
The first mega-breach of the card era. Weak wireless encryption, eighteen months of undetected access, and the reason PCI DSS grew teeth.
45.7 million cards confirmed; court filings suggested up to 94 million Read the case file →Every case file is sourced. Where a headline figure was later revised — and it usually is — these pages use the number the organisation or its regulator finally settled on, and say what it was first reported as. Claims that remain disputed are labelled as disputed.