101+ Data Breach Statistics – The Big Scary Online

Written by Nick Galov • Edited by Jordan T. Prodanoff
• 16 min read

On March 18, 1990, two men in police uniforms entered an art museum in Boston. They performed the largest fine art theft in the history. 13 paintings of world famous artists were stolen that day.

To this day, their frames remain empty on the walls of the museum.

Now, 1990 also saw the dawn of another kind of robbery. Storing data on the internet is one of the greatest technological advancements and we have all enjoyed it immensely.

It came at a price though…

Since the advent of the global network, robberies have become much more subtle, as these comprehensive data breach statistics curated by Webtribunal can tell you.

The modern ways of stealing are harder to track and can affect a lot more people.

Let’s look at some quick data breach facts first.

Scary Data Breach Statistics (Editor’s Choice):

  • In 2025, about 278.8 million people in the US received breach notices, down from roughly 1.37 billion in 2024.
  • Worldwide information security spending reached about $213 billion in 2025.
  • The global average cost of a breach is $4.99 million, and $11.5 million in the US.
  • It takes 247 days on average to identify and contain a breach.

Cybersecurity issues are as real as physical thefts.

Today we ask:

How much do you know about data breach statistics?

Different Types of Data Breaches and Their Impact

  • Identity theft – the leading type of data breach for years. In 2018, 83% of all stolen records involved identity theft (a 2018 figure, kept here as historical context). (Source: Gemalto Breach Level Index)
  • Cyber attack – the often-quoted "new attack every 39 seconds" comes from a 2007 University of Maryland study that counted automated attacks on internet-connected test machines. It is not a census of global cyberattacks, and it is not a current figure. (Source: University of Maryland)

Data Breaches Risks and Impact Stats

  • In 2017, 36% of all compromised data was in the form of names, birthdays, and gender (2017 figure). (Source: Varonis)
  • In 2018, more than 70 million records were either accessed or stolen, due to poorly configured S3 buckets. (Source: Symantec)
  • In 2018, supply chain attacks increased by 78%. (Source: Symantec)
  • Across all industries, the mean time to identify and contain a breach is now 247 days, according to IBM's 2026 Cost of a Data Breach report. That single lifecycle figure has replaced the older split between discovery and containment, so it is not directly comparable with the 139-day and 53-day numbers this page used to carry. (Source: Varonis)

Cost of Data Breaches for Companies

  • In 2025, the Identity Theft Resource Center recorded 3,322 data compromises in the US, the highest count it has ever logged, and those produced about 278.8 million victim notices. Note the direction of travel: more incidents, far fewer notices than the roughly 1.37 billion in 2024, when a handful of mega-breaches dominated the total. (Source: Statista)
  • The global average cost of a data breach is $4.99 million, while the US average is $11.5 million, more than double the global figure (IBM, 2026). (Source: IBM-Ponemon Institute)
  • A massive data breach with 1 million affected records had an average total cost of $40 million in the 2018 study. (Source: IBM-Ponemon Institute)
  • In the same 2018 study, organisations with fully deployed security automation paid about 35% less per breach, $2.88 million against $4.43 million. (Source: IBM-Ponemon Institute)
  • For historical comparison, the average cost per data breach rose 6.4% between 2017 and 2018. (Source: IBM-Ponemon Institute)
  • Healthcare is still the most expensive industry, averaging $6.64 million per breach, its 13th consecutive year at the top (IBM, 2026). Note the change of unit: this is cost per breach, not the $408 per record this page used to quote, and the two cannot be converted without knowing the average breach size. (Source: Hipaa Journal)
  • The average cost per lost or stolen record has risen to roughly $173, based on 2024 data. (Source: IBM-Ponemon Institute)
  • The biggest component in a data breach cost was lost business, according to the 2018 study. (Source: IBM-Ponemon Institute)
  • A strong incident response team had the most positive effect on data breach cost in the 2018 study. (Source: IBM-Ponemon Institute)
  • Investing in an incident response team was worth up to $14 per breached record in the 2018 study. (Source: IBM-Ponemon Institute)
  • Target paid $19 million because of a data breach in 2013. (Source: Fortune)

Data Breach Preventions Stats

  • In 2018, 17% of IT security specialists said information security accounts for the largest budget increase. (Source: Zdnet)
  • In 2018, 80% of companies plan on expanding their security budget. (Source: Zdnet)

Biggest Data Breaches by Categories

Hearing about a new data breach today is like just another day on the internet!

Let’s do a 2020 recap of the data breach statistics from the last 15 years.

Government Data Breaches

Aadhaar (Indian identity database)

(Source: Moneylife, Business Insider)

  • India’s national ID database has suffered several data breaches so far.
  • More than 1.1 billion citizens have Aadhar ID cards. That’s more than 90% of the population.
  • In March 2018, a breach was discovered – it had compromised every account in the database.
  • The time and date of the breach remain unknown.
  • The leaked information contains data such as names of residents, their 12-digit ID numbers, and bank account numbers.

Health Care Data Breaches

21st Century Oncology

(Sources: Health IT Security, The National Law Review)

  • The 21st Century Oncology data breach from October 2015 affected the confidentiality of over 2.2 million patients’ personal records.
  • Personal information like social security numbers, physicians, diagnoses, treatments, as well as insurance was breached.
  • The breach was announced 5 months after the hacking. The FBI was involved in the investigation.

Anthem

(Source: Digital Sentinel)

  • The second largest health insurance company in the US was breached in January 2015.
  • 78.8 million customers and employees were affected in the Anthem data breach.
  • The company publicly admitted about the cyber attack 20 days after it occurred.
  • The compromised data included medical IDs, social security numbers, and physical addresses.

Tech and Web Data Breaches

Yahoo

(Source: CNBC, Statista)

  • Between 2013 and 2016, there were several Yahoo data breaches.
  • In 2013, all 3 billion user accounts were compromised.
  • In 2014, yet another data breach affected over 500 million user accounts.
  • Both security breaches were made public in 2016.
  • Because of the breach, Yahoo’s sale price fell by $350 million.
  • In 2017, Verizon acquired Yahoo for $4.48 billion. Verizon’s offer before the information of the breaches became public, was $4.8 billion. (For reference: Facebook acquired Instagram in 2012 for $1 billion, and WhatsApp in 2014 for $19 billion.)
  • Yahoo remains one of the largest confirmed breaches of a single company. Bigger record totals have been reported since, but those are compilations assembled from many sources rather than one company losing one dataset, so they are not directly comparable.
  • Yahoo received a $35 million fine for not reporting the massive data breach.

AOL

(Source: CNN)

  • In 2004, AOL suffered an extensive data breach.
  • It was reported that the breach was an inside job.
  • A former America Online software engineer stole 92 million screen names and email addresses and sold them to an online marketer.
  • The AOL data breach was one of the biggest data breaches in history.

Facebook

(Source: Investorplace)

  • In September 2018, Facebook’s database was breached.
  • More than 50 million accounts were compromised because of poor security.
  • The social network suffered another data breach as recently as March 2019. This time there were considerably more than 50 million. The latest Facebook data breach exposed more than 540 million user accounts.

Sony PlayStation

(Source: Reuters)

  • In 2011 there was a data breach in Sony’s video game network.
  • The data of 77 million accounts were affected by the Sony data breach.
  • All sorts of information were accessed – from email addresses and birth names to logins, usernames, and security questions.
  • This was one of the largest ever security cyber break-ins.

eBay

(Source: Bank Info Security, Business Insider)

  • The 2014 eBay data breach compromised the account information of 145 million users.
  • The breach occurred in the period February – March 2014 but was detected as late as May 2014.
  • The cyber attack occurred after the login information of 3 corporate employees was hacked.
  • The hackers had full access to the eBay database for 229 days.

My Space

(Source: SaaSAddict)

  • In May 2016, the social network MySpace suffered one of the largest data breaches in history.
  • The usernames of almost 120 million users were stolen, as well as 69 million secondary passwords.

LinkedIn

(Source: Fortune)

  • This is one of the biggest data breaches to this day.
  • Initially, the official report claimed only 6.5 million accounts were breached during the LinkedIn data breach.
  • Later on, the full extent of the damage done revealed that the 2012 LinkedIn hack led to unauthorized entities having access to 117 million account usernames and passwords. #LeakedIn

Blizzard Entertainment

(Source: Data Breach Today)

  • 14 million users accounts were hacked.
  • The breach occurred in 2012 on Battle.net.
  • User information like email passwords cryptographically scrambled passwords and authentication information was accessed.

Uber

(Sources: Forbes, Tech Crunch)

  • The 2014 Uber data breach affected only 50,000 accounts. It was because of poor security.
  • However, there was another security breach in 2016 which was a big one: it affected 50 million riders and 7 million drivers.
  • It also included around 600,000 drivers licenses.

Compilations: bigger record counts, different kind of event

(Sources: Cybernews, IBM)

  • In January 2024, researchers found a 12-terabyte database holding roughly 26 billion records, nicknamed the “Mother of All Breaches”. It was assembled from thousands of earlier leaks rather than being a fresh hack, so the record count is not a count of 26 billion different people.
  • In June 2025, researchers reported about 16 billion login records spread across roughly 30 credential datasets, much of it from infostealer malware logs and previously exposed data. Again, this is a collection of datasets, not one centralised breach.
  • Claims around the National Public Data incident cited roughly 2.7 to 2.9 billion rows of personal data including social security numbers. The number of unique people affected was never established, so the row count should not be read as a victim count.
  • The useful lesson from all three: record counts and victim counts are different measures, and compilations inflate the first without telling you much about the second.

Financial Data Breaches

Equifax

(Sources: Federal Trade Commission, Lifelock)

  • The 2017 Equifax data breach affected 143 million consumers.
  • This identity theft occurred due to poor security.
  • The breach was discovered on July 29 but was reported in September.
  • The information that was affected included birth dates, social security numbers, physical addresses, and driver’s license numbers.
  • The breach has cost Equifax about $1.38 billion in cleanup and settlement costs.

Heartland

(Sources: The Guardian, Computerworld)

  • In 2009, cybercriminals stole the user details of 130 million customers.
  • The breach cost the company $140 million in breach-related expenses.

My Fitness Pal

(Source: BBC, Fortune, Business Insider)

  • The popular nutrition app owned by Under Armor was breached in February 2018.
  • The attack was not discovered until March 25.
  • About 150 million user accounts were affected.
  • The hackers, responsible for the Under Armor data breach, had access to social security and driver’s license numbers.

Quora

(Source: CNN, Business Insider, PC World)

  • The question-and-answer website suffered a cyber attack in November 2018.
  • One of the big data breaches in recent years led to 100 million compromised and stolen user accounts.
  • The affected data included usernames, email addresses, and encrypted passwords.

Retail Data Breaches

Target Corporation

(Source: USA Today, Arxiv)

  • Target’s data breach in 2013 was one of the largest in the retail industry.
  • The cyber attack on Target affected 41 million customers and their card accounts.
  • The information leak was made possible through the use of malware.
  • The consequence: the retail giant had to pay an $18.5 million data breach settlement.
  • The affected customers also received free credit monitoring services.

Home Depot

(Source: Forbes)

  • The home improvement supplies giant Home Depot suffered a big data breach in September 2014.
  • 56 million cards compromised because of the hacking.

Data Breaches in Airlines, Hotels, and Restaurants

Marriott

(Source: Techcrunch)

  • In 2018, Marriott International suffered a massive data breach.
  • The Starwood hotel in the US was affected due to the hacking.
  • 50 million unencrypted passwords were stolen. (Some say more than 500 million customers were affected…)

Cathay Pacific

(Source: Business Insider)

  • In March 2018, a large data breach in the airline’s security was discovered.
  • Personal information of 9.4 million passengers was accessed.
  • The company stated that 860,000 passport numbers and 245,000 Hong Kong ID numbers were accessed during the breach.

Chipotle

(Sources: Lifelock, Reuters)

  • The Mexican grill restaurant suffered a payment card security breach in April 2017.
  • The Chipotle data breach affected most of the company’s 2,250 restaurants.
  • The stolen information included account numbers and internal verification codes.

Telecom Data Breaches

Experian T-Mobile US

(Source: Reuters)

  • The Experian data breach was hacked in 2015.
  • The cybercriminals accessed 15 million user accounts.
  • The data breach claimed personal information, even personal records from the US government.

Military Data Breaches

US Army

(Sources: Forbes, Spiegel Online, The Guardian)

  • In 2010, the US Army suffered a massive data breach.
  • Around 400,000 classified documents were posted on Wikileaks.
  • The massive leak of American military documents exposed confidential information from the Iraq and Afghanistan wars.

US Department of Veteran Affairs

(Sources: EPIC, govinfo, Data Breach Today)

  • In 2006, the data of more than 26 million US veterans was stolen.
  • The issue of data security occurred due to stolen equipment.
  • This affected both non-active and active military officers. The stolen data consisted of family information, social security numbers, and disability records.

US Office of Personnel Management

(Sources: Wired, ABC News)

  • The OPM data breaches from 2014 and 2015 were caused by malware and by allowing a hacker in the physical building of the Office.
  • The number of stolen records is estimated to be no less than 21.5 million.
  • The stolen documents had a high clearance level and contained information about foreign contacts and psychological information.
  • The theft remained undetected for a year.

Responsible and Irresponsible Companies in the Times of Data Breaches

Data breaches alone are nasty enough. They can become even more dangerous if companies fail to inform their users and decide to keep the information for themselves.

Time is a key factor after a cyber attack has occurred. Every time a personal user account is breached, the user must be informed immediately.

As we will see in a moment, though, that almost never happens…

Here is a list that will shed some light on the response times for various data breaches:

Companies which Informed Their Customers Swiftly

(Source: Varonis, Investor Place)

  • Sony – After the Sony PlayStation data breach, the company took less than a week to inform its customers about the attack.
  • Target – The company did an amazing job with the detection of the data breach. It took them 16 days to detect and 20 days to inform the customers.
  • Facebook – Super professional in how quickly they informed the public. Not that professional, considering the breach happened because they had been storing hundreds of thousands of user IDs and passwords in plain text for years before the incident.

Companies that Took Forever to Inform Customers

(Sources: Techcrunch, Forbes, Inc.)

  • Yahoo! – With the pending sale to Verizon, the company decided to remain quiet and keep its sale price.
  • Uber – The company informed the public almost 1 year after the incident of 2016.
  • Marriott – It took 2 months to inform customers their accounts have been attacked.

Recap

So, here we are, guys.

Now we have seen the ugly face of Cyber Attack Cerberus, and what he is capable of.

And he seems to know what he’s doing out there, terrorizing the village…

After all, if we just google how many data breaches took place in just 2018, we’ll come up with the mindblowing number of 945. Cerberus isn’t for the faint of heart.

Still, data breach statistics do have some good news to tell us. Namely, those companies are having more and more success in stopping those attacks. Their incentive is two-fold – they appreciate having their customers’ trust… as well as paying less money in case settlements.

Whatever the reason for this progress – we, the users, will take it.

Cloud adoption, good security practices, and raising the overall awareness about the global IT security threats all contribute to a safer future.

About Nick Galov

Author

Unaware that life beyond the internet exists, Nick is poking servers and control panels, playing with WordPress add-ons, and helping people get the hosting that suits them.

View all posts by Nick Galov →

About Jordan T. Prodanoff

Editor

A wayfarer by heart, Jordan fancies journeying into foreign lands with a camera in hand almost as much as he enjoys roving the online world. He spends his time poking at letters and pixels, trying to transmogrify them into something cool.

View all posts by Jordan T. Prodanoff →