Nearly every major U.S. sector has suffered a breach large enough to reshape how it handles customer data. Some were driven by nation-state hackers, others by an unsecured cloud folder.
This list orders the 20 largest U.S. data breaches by records or people affected. A few totals are contested or revised, and those are flagged.
1. Yahoo (2013 to 2014)
- Affected records: 3 billion accounts across two separate intrusions.
- Date of breach: 2013 and Dec. 2014.
- Date of disclosure: Sept. 2016 (500 million), Dec. 2016 (1 billion), Oct. 2017 (revised to 3 billion).
- Attack method: State-sponsored intrusion, forged authentication cookies.
- Data exposed: Names, phone numbers, email addresses, dates of birth, hashed passwords, and encrypted and unencrypted security questions and answers.
The Attack
Two intrusions, years apart, touched every Yahoo account, though the full scope wasn’t confirmed until 2017. These are separate attacks, but they’re put together because of the disclosure timeline and according to Yahoo’s updates.
The Aftermath
The SEC fined Altaba $35 million in 2018, and a class action closed at $117.5 million.
2. National Public Data (2024)
- Affected records: ~2.9 billion records claimed, but heavily disputed.
- Date of breach: Dec. 2023 to Aug. 2024.
- Date of disclosure: Aug. 2024.
- Attack method: Unauthorized access.
- Data exposed: Full names, Social Security numbers, current and historical physical addresses, phone numbers, email addresses, and information about relatives.
The Attack
National Public Data compiled records on Americans who never agreed to it, resulting in one of the largest known exposures of Social Security numbers in U.S. history.
The Aftermath
Parent company Jerico Pictures filed for bankruptcy and operations ceased.
3. Salesloft Drift and Salesforce Campaign (2025)
- Affected records: 1.5 billion Salesforce records claimed across ~760 companies. This is an unverified attacker claim.
- Date of breach: March to Aug. 2025.
- Date of disclosure: Aug. 2025; notices into 2026.
- Attack method: Stolen OAuth tokens combined with social engineering to authorize a rogue app.
- Data exposed: Salesforce accounts, contacts, support cases, embedded credentials, API keys, and tokens found inside case text.
The Attack
Attackers stole API credentials tied to the Drift chatbot to pull data from connected Salesforce customers.
The Aftermath
Salesforce refused to negotiate; the group opened a leak site.
4. River City Media (2017)
- Affected records: 1.37 billion email records.
- Date of breach: Discovered Jan. 2017.
- Date of disclosure: March 2017.
- Attack method: Unprotected backup server, leaving the whole database publicly downloadable.
- Data exposed: Email addresses, full names, IP addresses, physical addresses, and the operator’s internal chat logs, business plans, and infrastructure documentation.
The Attack
River City Media left its own database open on an unpassworded server.
The Aftermath
The operation collapsed, and Spamhaus blacklisted it.
5. First American Financial (2019)
- Affected records: 885 million documents.
- Date of breach: Since 2014; discovered May 2019.
- Date of disclosure: May 24, 2019.
- Attack method: Web flaw letting anyone edit a document URL to view unrelated files.
- Data exposed: Social Security numbers, bank details, and mortgage records.
The Attack
First American’s own testing had flagged this months earlier, but the risk was dismissed.
The Aftermath
The SEC fined the company ~$488,000 in 2021, and New York added $1 million in 2023.
6. Ticketmaster / Live Nation (2024)
- Affected records: 560 million claimed by attackers.
- Date of breach: April to May 2024.
- Date of disclosure: May 27, 2024.
- Attack method: Stolen Snowflake credentials; no MFA.
- Data exposed: Names, addresses, phone numbers, order info and history, event info and history, and partial card data.
The Attack
Ticketmaster was the most visible casualty of a 2024 wave of attacks on unprotected Snowflake accounts.
The Aftermath
Parent company Live Nation Entertainment faced intense regulatory scrutiny, SEC filings, and multiple consumer class-action lawsuits concerning its cybersecurity posture and data protection practices.
7. Facebook / Meta (2019 to 2021)
- Affected records: 533 million users; Cambridge Analytica separately touched 87 million.
- Date of breach: Scraped before Sept. 2019.
- Date of disclosure: Partial in 2019; full dataset posted in 2021.
- Attack method: Contact-lookup API abuse matching phone numbers to accounts.
- Data exposed: Phone numbers, full names, email addresses, location data, relationship status, and employer.
The Attack
Meta called this scraping, not a breach; regulators disagreed.
The Aftermath
The FTC handed down a record $5 billion penalty in 2019, and a $725 million class action followed in 2023.
8. Marriott International / Starwood (2014 to 2018)
- Affected records: Up to 339 million guest records.
- Date of breach: July 2014 to Sept. 2018.
- Date of disclosure: Nov. 30, 2018.
- Attack method: A prolonged, undetected breach of Starwood’s legacy guest reservation system, generally linked to hackers backed by the Chinese state, that went unnoticed. Even as Marriott absorbed Starwood in its 2016 acquisition.
- Data exposed: Names, mailing addresses, phone numbers, email addresses, passport numbers, Starwood loyalty account information, dates of birth, gender, arrival and departure information, and encrypted payment card numbers.
The Attack
Intruders sat inside Starwood’s systems two years before Marriott’s acquisition, and two more years after.
The Aftermath
The FTC ordered a security overhaul in 2024, and 49 states added a $52 million settlement.
9. Exactis (2018)
- Affected records: 340 million records, including about 230 million U.S. consumers.
- Date of breach: Discovered June 2018.
- Date of disclosure: June 2018.
- Attack method: Database on a public server with no firewall.
- Data exposed: Names, phone numbers, and about 400 profiling attributes per person. This includes religion, smoking habits, pet ownership, children’s ages and genders, and personal interests.
The Attack
Exactis had built profiles on nearly every American adult before a researcher found the data exposed.
The Aftermath
The company pulled the database offline and faced a class action.
10. Instructure / Canvas LMS (2026)
- Affected records: 275 million users from close to 9,000 schools.
- Date of breach: April 25 to May 7, 2026.
- Date of disclosure: May 1, 2026; second intrusion disclosed May 7.
- Attack method: Free-tier signup abuse, followed by ~3.65 TB exfiltration.
- Data exposed: Student and faculty names, emails, student ID numbers, course enrolment information, and private messages.
The Attack
This is the largest education-sector breach on record, given how widely Canvas is used.
The Aftermath
Instructure says it destroyed the files after striking a deal, though the reported ransom is unconfirmed.
11. Twitter / X (2021 to 2023)
- Affected records: 200+ million records in a Jan. 2023 dataset; a related dataset claimed 400 million. Both are scraped compilations rather than a database theft, and the exact unique count is disputed.
- Date of breach: June 2021 to Jan. 2022.
- Date of disclosure: Jan. 2023.
- Attack method: API flaw matching phone numbers or emails to accounts.
- Data exposed: Emails tied to usernames and account creation dates.
The Attack
The risk was what the data enabled: linking a real email to an anonymous account.
The Aftermath
Twitter / X disputes that the attack ever happened, but did not explain how their users’ email addresses were linked to their accounts in this collection of data.
12. Deep Root Analytics / RNC Voter Files (2017)
- Affected records: 198 million U.S. voters.
- Date of breach: Discovered June 12, 2017.
- Date of disclosure: June 19, 2017.
- Attack method: Open Amazon S3 bucket with no password.
- Data exposed: Personal details such as names, birthdates, home addresses, phone numbers, and voter registration records, along with estimated ethnicity and religion, plus predicted scores gauging where individual voters likely stood on issues like gun control, abortion, and stem cell research.
The Attack
Compiled for the RNC, this is the largest known leak of voter data in U.S. history.
The Aftermath
Deep Root Analytics took public responsibility, though no regulator acted, since federal law doesn’t cover political data.
13. Change Healthcare / UnitedHealth Group (2024)
- Affected records: 192.7 million individuals, revised more than three times. Initially, this was reported to HHS OCR as “more than 500,” then 100 million in October 2024, 190 million in Jan. 2025, and 192.7 million on July 31, 2025.
- Date of breach: Access Feb. 12, 2024; ransomware Feb. 21, 2024.
- Date of disclosure: Feb. 2024; final count July 2025.
- Attack method: ALPHV/BlackCat ransomware via an MFA-less Citrix portal.
- Data exposed: Social Security numbers, health information, and billing records.
The Attack
This is the largest healthcare breach on record, and it froze the country’s claims clearinghouse.
The Aftermath
Parent company UnitedHealth Group reported total incident costs exceeding $3 billion, alongside paying a reported $22 million ransom in bitcoin.
14. LinkedIn (2012 and 2021)
- Affected records: 165 million accounts (2012); a separate 2021 scrape covered up to 700 million profiles.
- Date of breach: June 2012; scraped data published 2021.
- Date of disclosure: 2016 (2012 scope); 2021 (scraping).
- Attack method: 2012 network intrusion; 2021 mass API scraping.
- Data exposed: Emails and password hashes (2012); full names, email addresses, phone numbers, geolocation, job titles, employer details, and social media handles (2021).
The Attack
The unsalted 2012 passwords were cracked quickly, fueling years of follow-on attacks.
The Aftermath
LinkedIn settled a class action for $1.25 million, and the hacker drew an 88-month sentence.
15. Adobe (2013)
- Affected records: 153 million user records, up from an initial report of 2.9 million.
- Date of breach: Sept. 2013.
- Date of disclosure: Oct. 2013.
- Attack method: Network intrusion exposing source code.
- Data exposed: Internal IDs, email addresses, usernames, encrypted passwords, password hints in plaintext, and encrypted payment card details for approximately 3 million customers.
The Attack
Adobe’s encryption produced identical output for identical passwords, and plaintext hints made cracking easy.
The Aftermath
Adobe settled with 15 states for ~$1 million in 2015.
16. Under Armour / MyFitnessPal (2018)
- Affected records: 150 million MyFitnessPal accounts.
- Date of breach: Feb. 2018; Nov. 2025 (Everest listing).
- Date of disclosure: March 2018; Jan. 2026.
- Attack method: Unauthorized database access.
- Data exposed: Hashed passwords (2018).
The Attack
The Under Armour MyFitnessPal data breach in February 2018 compromised the account information of approximately 150 million users.
The Aftermath
Under Armour worked with external security firms and law enforcement to improve database defenses.
17. Equifax (2017)
- Affected records: 147 million consumers, including 145.5 million Social Security numbers.
- Date of breach: May to July 2017.
- Date of disclosure: Sept. 7, 2017.
- Attack method: Unpatched Apache Struts vulnerability (CVE-2017-5638) for which a fix was available. Equifax could not see the exfiltration traffic for 76 days because of an expired TLS certificate.
- Data exposed: Social Security numbers, addresses, and driver’s license numbers.
The Attack
A credit bureau lost data on people who never chose to be its customers, due to an unapplied patch.
The Aftermath
Equifax settled for up to $700 million with regulators and states, and the DOJ indicted four Chinese hackers.
18. eBay (2014)
- Affected records: 145 million users.
- Date of breach: Late Feb. to early March 2014.
- Date of disclosure: May 21, 2014.
- Attack method: Stolen employee credentials.
- Data exposed: Names, encrypted passwords, email addresses, physical addresses, phone numbers, and dates of birth. eBay said that financial data was stored on PayPal systems and was not accessed.
The Attack
eBay sat on the news for two months, then asked all users to reset passwords at once.
The Aftermath
No major fine followed, and a class action was dismissed.
19. Heartland Payment Systems (2008 to 2009)
- Affected records: Roughly 130 million payment cards.
- Date of breach: Throughout 2008; discovered Jan. 2009.
- Date of disclosure: Jan. 20, 2009.
- Attack method: SQL injection plus malware intercepting unencrypted card data.
- Data exposed: Payment card details, including card numbers, expiration dates, and cardholder names.
The Attack
This was the largest card breach on record at the time, run by the group behind the TJX breach.
The Aftermath
Heartland paid ~$145 million to issuers, and its ringleader received a 20-year sentence.
20. Target (2013)
- Affected records: 40 million card records plus data on up to 70 million customers, cited as 110 million.
- Date of breach: Nov. 27 to Dec. 18, 2013.
- Date of disclosure: Dec. 19, 2013.
- Attack method: Stolen HVAC credentials used to install POS malware.
- Data exposed: Payment card details, names, mailing addresses, phone numbers, and email addresses.
The Attack
This breach hit during the busiest shopping weeks of the year, and Target’s alerts had flagged it.
The Aftermath
Total costs exceeded $200–$290 million, resulting in an $18.5 million multi-state attorney general settlement and major shifts in retail cybersecurity standards (such as adopting chip-enabled card terminals).
A note on disputed figures
Several entries involve numbers that are estimated or unverified, notably Salesloft Drift, Ticketmaster, and Instructure Canvas. Totals can also change after disclosure, as with Marriott and Adobe.
What these breaches mean for cybersecurity in 2026
The biggest data breaches show that serious exposures do not always require sophisticated attacks. An unpatched server, missing MFA setting, exposed database, or unmonitored vendor integration can be enough to turn a security gap into a large-scale incident. Basic security hygiene and continuous monitoring remain essential, but businesses also need to know whether those controls actually hold up against an attacker.
The challenge is finding those vulnerabilities before an attacker does. Penetration testing provides an independent way to evaluate how applications, APIs, cloud environments, and infrastructure withstand real-world attack techniques, not simply whether they pass an automated scan.
If you’re ready to see what an attacker could find in your environment, talk to our team to discuss a penetration test tailored to your technology, attack surface, and security goals.