Major Data Leaks by Country | The Complete 2026 Breach Tracker

Knowledge Hub
Major Data Leaks by Country

Data leaks have exposed the personal records of billions of people worldwide, from national ID databases in Pakistan and China to airline, banking, and health insurance systems across India, the United States, the UK, and Australia. This tracker breaks down the largest confirmed and reported incidents by country, what data was exposed, and how to check whether your own information is part of one.

Data Leak vs. Data Breach vs. Data Hack

The terms are often used interchangeably, but they describe different events. A data breach is any confirmed incident in which protected information is accessed without authorization, regardless of the method. A data leak specifically refers to information becoming exposed or publicly accessible, whether through a hack, an unsecured database, or human error; no active break-in is required. A data hack implies a deliberate intrusion by an attacker, using stolen credentials, malware, or a software vulnerability to gain access. In practice, a hack usually causes a breach, and a breach often results in a leak once the stolen data surfaces on a forum or the dark web.

How Dark Web Monitoring Detects Leaks Early

Most stolen data doesn’t stay with the original attacker; it gets posted, sold, or traded on dark web forums and Telegram channels, often weeks or months before the affected company even knows a breach occurred. Dark web monitoring tools continuously scan these marketplaces and paste sites for identifiers tied to a specific person, domain, or organization, email addresses, phone numbers, card numbers, or ID numbers, and issue an alert the moment a match appears. This is often the fastest way to learn about exposure, since many breaches, particularly government ones, are disclosed months after the fact or denied outright by the affected agency.

Pakistan Data Leaks, Timeline & Exposure Details

Pakistan has experienced a string of data exposure incidents tied to its national identity system, telecom networks, and government agencies, several of which involved insider access rather than external hacking alone.

Pakistan Data Leaks

Notable Pakistani Data Leak Incidents

In 2021, cybersecurity researchers found a dump of 115 million Pakistani mobile subscriber records for sale on a dark web forum. In 2024, a Joint Investigation Team formed to probe the theft from Pakistan’s National Database and Registration Authority (NADRA) confirmed that the credentials of 2.7 million citizens had been compromised between 2019 and 2023, and that NADRA subsequently terminated several employees, including insiders, over their alleged roles. In mid-2025, a separate dark web listing surfaced offering what a threat actor claimed was a database of 602 million Pakistani citizens sourced from NADRA, including CNIC numbers and authentication hashes, a claim NADRA has not confirmed. Pakistan’s national CERT also warned in 2025 that login credentials for more than 180 million internet users tied to Pakistani services had appeared in a global infostealer-malware compilation.

What Data Was Exposed and Who Was Affected

Across these incidents, the exposed data has typically included CNIC (national ID) numbers, names, addresses, dates of birth, phone numbers, and in some cases biometric or family-tree data drawn from NADRA’s civil registry. Confirmed exposure has affected millions of citizens rather than the entire population, though the scale of the unverified 602-million-record claim, if accurate, would represent nearly the whole country. NADRA has repeatedly disputed the larger claims as unsubstantiated while confirming smaller, insider-driven incidents, which is a common pattern with government identity databases worldwide: official acknowledgment tends to lag well behind the data’s appearance on criminal forums.

Russia–Ukraine Cyber Conflict Data Leaks

The war between Russia and Ukraine has produced a steady stream of cyber operations on both sides, including hacks of military systems, government databases, and, increasingly, disinformation dressed up as leaked data.

Russia–Ukraine

Russian Hackers Leak Ukrainian Defense Ministry Data (1.7M Casualty Records)

In August 2025, pro-Russian hacking groups, including one calling itself Beregini, claimed to have breached Ukraine’s General Staff database and obtained records showing 1.7 million Ukrainian soldiers killed or missing since 2022. It’s important to be direct about this one: independent fact-checkers, Ukraine’s Center for Countering Disinformation, and a trust-and-safety firm that analyzed the groups involved all concluded the claim is very likely fabricated. Ukraine has never fielded a standing army near 1.7 million people, and the figure is far above any independent casualty estimate, including those from the UN and Western intelligence assessments. The episode is a useful case study in how genuine-sounding “leak” claims are sometimes manufactured for disinformation purposes rather than pulled from a real breach.

Anonymous and State-Linked Russian Leak Incidents

Separately from the disputed casualty claim, both pro-Ukrainian hacktivist collectives and state-linked Russian groups have carried out and claimed a wide range of genuine leaks throughout the conflict, targeting government ministries, military contractors, and financial institutions on both sides. These operations are typically harder to independently verify than corporate breaches, since neither government tends to confirm details for operational security reasons, which is exactly why claims from this conflict warrant more scrutiny before being treated as fact than a typical corporate breach disclosure would.

China’s Largest Data Leaks, 1 Billion+ Records Exposed

China’s centralized approach to citizen data collection has produced some of the largest single-incident data leaks ever recorded, with the 2022 Shanghai police database leak likely a record holder.

China's Largest Data Leaks

The Alleged Chinese Police Database Hack (Shanghai Leak)

In July 2022, a hacker using the alias “ChinaDan” advertised more than 23 terabytes of data for sale on a cybercrime forum for 10 bitcoin (about $200,000 at the time), claiming it was stolen from the Shanghai National Police database hosted on Alibaba’s cloud infrastructure. Journalists at Reuters, the Associated Press, and Vice independently contacted individuals listed in released data samples, several of whom confirmed the accuracy of the records, including police case details that would be difficult to source elsewhere. The scale, if fully accurate, would make it one of the largest breaches of government data in history, exposing names, addresses, national ID numbers, phone numbers, and case records for roughly a billion residents.

Citizen & Population Data Exposure Incidents

The Shanghai leak wasn’t an isolated event. Chinese national ID data has repeatedly surfaced in breach compilations sold on cybercrime forums, including a separate 2024 dataset that researchers estimated contained national ID numbers covering nearly a tenth of China’s population after duplicates were removed. Chinese police, health, and municipal databases have been named in leak claims with regularity, a pattern researchers attribute to the sheer volume of citizen data Chinese authorities collect combined with inconsistent security practices across the vendors and cloud providers that host it.

Corporate and Social Data-Scraping Leaks

Separate from government-sourced leaks, China-based platforms have also been the source of large-scale data scraping incidents, in which information that is technically public on social profiles is harvested and compiled into resellable databases. These scraping-based leaks are generally considered less severe than direct database breaches because much of the underlying data was already publicly available. Still, the aggregation itself creates new risk by linking previously scattered details- a phone number here, a workplace there- into a single exploitable profile.

India Data Leak Incidents, Government & Corporate

India has recorded some of the highest-volume data leaks of any country, spanning its national biometric ID system, its flagship airline, and several of its largest consumer platforms, often within the same twelve-month stretch.

India Data Leak Incidents

Air India Passenger Data Breach

Air India disclosed in May 2021 that a breach at SITA, a Swiss company that manages the passenger reservation system used by Star Alliance airlines, exposed the personal data of more than 4.5 million passengers who had booked flights between August 2011 and February 2021. The exposed data included names, dates of birth, passport information, ticket details, frequent flyer numbers, and payment card data. However, Air India confirmed that passwords and card verification codes were not affected. The same SITA breach also hit at least ten other Star Alliance carriers, including Singapore Airlines, Lufthansa, and Malaysia Airlines, making it one of the broadest supply-chain breaches in aviation history.

Aadhaar Biometric Data Exposure

India’s Aadhaar system, which holds biometric and demographic data on more than 1.1 billion enrolled citizens, has faced repeated exposure incidents since 2018, when a journalist demonstrated that a government grievance-redressal search tool could be misused to look up any citizen’s Aadhaar details for a small fee. UIDAI, the authority that runs Aadhaar, has consistently denied that its central database itself was ever breached, characterizing incidents instead as misuse of legitimate access or third-party vendor failures. The largest recent claim surfaced in October 2023, when a threat actor advertised 815 million Aadhaar and passport records on a hacking forum; a security firm that acquired and tested a 400,000-record sample confirmed the data was accurate by contacting listed individuals directly.

Domino’s India and Mobikwik Leak Cases

In early 2021, security researchers found that KYC data belonging to roughly 110 million users of the digital wallet MobiKwik, including Aadhaar and card details, was being sold on a dark web forum, a claim MobiKwik disputed despite pressure from India’s central bank to investigate. Weeks later, a linked hacker reportedly used similar techniques to breach Domino’s India’s parent company, exposing details from over 180 million orders and roughly a million payment card records, according to findings from cybersecurity researchers at Hudson Rock. Both incidents, along with a separate Air India breach disclosure the same year, prompted a formal petition to the Delhi High Court demanding a government-led investigation into the wave of 2021 Indian corporate breaches.

American Data Leaks, Corporate & Financial Exposure

Financial services firms have been the source of two of the most significant American data exposure incidents in recent years, one from a hacked third-party vendor and one from a company’s own unsecured website.
American Data Leaks

American Express Data Leak

In March 2024, American Express notified customers that account numbers, names, and card expiration dates had been exposed through a breach at an unnamed third-party merchant processor used by numerous retailers, rather than through any compromise of Amex’s own systems. The company has not disclosed how many customers were affected. Still, it has confirmed the incident to regulators in Massachusetts and elsewhere, advising affected cardholders to monitor their statements for 12 to 24 months. The case illustrates a recurring theme in payment card leaks: the breached organization is frequently not the bank or card issuer itself, but a processor or vendor several steps removed from the customer relationship.

First American Financial Corp Leak

In May 2019, security journalist Brian Krebs revealed that title insurance giant First American Financial had left approximately 885 million sensitive documents publicly accessible on its own website, dating back to 2003, due to a flaw that let anyone view another customer’s records simply by changing a digit in the browser URL. The exposed files included bank account numbers, Social Security numbers, wire transfer receipts, and mortgage records, a rare case where no hacking was required at all, since the documents were sitting on the open internet without authentication. U.S. regulators later fined the company roughly $500,000 over its handling of the exposure, and the incident remains one of the largest confirmed single-source data exposures in U.S. history by document count.

Data Leaks Around the World

Beyond the largest national incidents, several other countries have recorded breaches significant enough to reshape local data protection enforcement.

UK Biobank and Government Data Incidents

In April 2026, UK Biobank, a major medical research charity that links genetic and health data to hundreds of thousands of volunteer participants, disclosed a breach in which the sensitive genetic, biological, and health records of approximately 500,000 people were accessed without authorization and reportedly offered for sale on platforms based in China. UK lawmakers on the Science, Innovation and Technology Committee called the incident evidence that earlier government assurances about improved data-handling standards had not translated into practice. Health and genetic data carry particular long-term risk compared to financial data, since unlike a password or card number, a person’s genetic information cannot be reset or reissued once exposed.

Australia and South Africa Data Leak Cases

Australia experienced back-to-back mega-breaches in 2022: telecom provider Optus exposed the personal data, including passport and driver’s license numbers, of up to 9.8 million current and former customers through an unsecured public API, followed weeks later by health insurer Medibank, where attackers who breached the network via stolen contractor credentials published sensitive health claims data for around 480,000 people after Medibank refused to pay a ransom. In South Africa, credit bureau TransUnion confirmed in 2022 that at least 3 million consumers had their names, ID numbers, and financial details exposed after attackers compromised a server using a client’s stolen credentials, with the country’s information regulator later citing the company for inadequate safeguards.

Dubai Property and Real Estate Data Exposure

Rather than a criminal hack, Dubai’s most consequential data exposure came through investigative journalism. In 2022, the OCCRP and international media partners published “Dubai Uncovered,” built from leaked property records covering roughly 274,000 owners across 800,000 properties, of which about 191,000 belonged to foreign nationals. The dataset, sourced from Dubai’s land registry and utility records, revealed extensive property ownership by politically exposed individuals, sanctioned figures, and alleged criminals using Dubai real estate as a store of value, illustrating that not every major “data leak” involves stolen credentials or malware; some are compiled from records that were simply never meant to be cross-referenced and published at scale.

How to Check If Your Data Was Leaked

Given how many of these incidents go undisclosed for months or are only ever partially confirmed, the most reliable way to know whether you’re affected is to check directly rather than wait for a notification that may never come.

How to Check If Your Data Was Leaked

Dark Web Monitoring Tools

Dark web monitoring services scan breach dumps, criminal forums, and paste sites in real time for your email address, phone number, or ID number, and alert you the moment a match appears, often long before a company issues an official breach notice, if it ever does. This is particularly valuable for the government and third-party breaches described above, where the source organization frequently denies or downplays the incident rather than promptly confirming it.

Steps to Take After a Confirmed Leak

If you confirm exposure, change the password on the affected account immediately, and on any other account that reuses that password, enable two-factor authentication wherever it’s offered, and place a fraud alert or credit freeze with the major credit bureaus if financial or ID data was involved. For government ID leaks like Aadhaar or CNIC exposure, monitor for unfamiliar accounts or loan applications opened in your name, since these identifiers can’t be changed as easily as a password. Continued monitoring matters even after the initial response, since leaked data is often resold and recirculated on new forums months or years after the original incident.

Frequently Asked Questions (FAQ’s)

How Often Do Major Data Leaks Happen?

Incidents affecting millions of records now surface somewhere in the world nearly monthly. However, the pace of disclosure varies enormously by country and sector; corporate breaches in the U.S. and EU tend to surface within weeks under mandatory reporting laws. At the same time, government-sourced leaks can take months or years to be officially acknowledged, if they ever are.

Which Countries Are Most Affected by Data Leaks?

Countries with large, centralized national ID or biometric systems, including China, India, and Pakistan, have recorded some of the highest-volume single incidents, since a single compromised database can expose data covering hundreds of millions or even over a billion people at once. Countries with smaller populations but concentrated financial or health sectors, such as Australia and South Africa, have instead seen breaches that affect a much larger share of their total population per incident, even when the raw record count is lower.

Free Dark Web Report

Keep reading

No results found.