Data leaks have hit a record pace: U.S. organizations reported 3,332 data compromises in 2025 alone, the highest annual total ever tracked and a 79% jump in just five years, according to the Identity Theft Resource Center, marking a record total that represents a 79% increase in just five years. This page tracks the recent data leaks that matter most, organized by year, so you can quickly check what happened, who was affected, and what to do if your own information was exposed.
A data leak occurs whenever sensitive information, passwords, financial details, medical records, or personal identifiers, becomes accessible to people who were never meant to see it, whether through a hack, a misconfigured database, or an insider error. Some incidents make headlines for their scale, like the 2025 discovery of over 16 billion exposed login credentials, described by researchers as the largest credential exposure in recorded history. Others fly under the radar despite affecting millions of people. Below, you’ll find every major leak worth knowing about, from the most recent incidents in 2026 back through the past decade.
What Counts as a Data Leak? (Definition & Context)
A data leak is any incident where sensitive information becomes exposed to unauthorized viewers without necessarily involving an active attack, think an unsecured database left open on the internet, rather than a hacker breaking through a firewall. It’s one of three related but distinct terms security researchers use to describe how personal data ends up in the wrong hands.
Data Leak vs. Data Breach vs. Data Exposure
These three terms get used interchangeably in headlines, but they describe different events. A data breach involves an active, unauthorized intrusion, someone deliberately hacking in and stealing data. A data leak is passive: information is left accessible through a misconfiguration, human error, or a forgotten backup file, with no hacker required to access it. A data exposure is the broader umbrella term covering both, describing any situation where protected data is visible to someone who shouldn’t see it. Industry trackers such as the Identity Theft Resource Center group all three under a single reporting category, data compromises, precisely because the resulting risk to affected individuals is the same regardless of which mechanism caused it. That distinction matters less for the person checking whether their information is at risk, and more for security teams diagnosing how an incident happened and how to prevent the next one.
How Data Leaks Are Discovered and Reported
Most data leaks aren’t discovered by the company that caused them, they’re found by independent security researchers, journalists, or dark web monitoring services scanning for exposed databases and leaked credential dumps. Once identified, U.S. companies are generally required to notify affected individuals and relevant state attorneys general, though the timeline varies significantly by state and industry. That reporting gap can be substantial in practice: one 2025 breach saw notification letters reach affected consumers nearly a month after the breach date, a delay severe enough to become the focus of subsequent class action filings. This lag is part of why year-over-year totals often get revised upward months after they’re first reported, a leak disclosed in early 2026, for instance, may have actually occurred, and gone undetected, in late 2025.
2026 Data Leaks So Far
2026 has already produced some of the most geopolitically charged data leaks in recent memory, with state-linked hacking groups and whistleblowers driving several of the year’s biggest incidents rather than ordinary cybercriminals chasing a payday. The scale in a few cases has been staggering: one alleged breach this year involved a hacker claiming to have stolen over 10 petabytes of data from a Chinese supercomputing hub serving roughly 6,000 government, research, and defense clients.

Notable Incidents (Lockheed Martin/Handala, ICE, NSCC Tianjin, China)
In late March 2026, the Iran-linked hacking group Handala claimed to have breached U.S. defense contractor Lockheed Martin, and separately published the personal data of 28 senior American engineers working on sensitive programs including the F-35, F-22, and THAAD missile defense system. A related threat actor offered a much larger, unverified dataset for sale, claiming to have exfiltrated a cache of Lockheed Martin data offered for more than $598 million, allegedly including F-35 blueprints and Pentagon contracts. Lockheed Martin has stated it has found no evidence supporting the larger breach claims.
That same January, a separate leak hit closer to home for U.S. immigration enforcement: the personal information of roughly 4,500 Border Patrol and ICE employees was leaked to a public accountability website, days after a fatal shooting by an ICE agent in Minneapolis. The dataset reportedly included names, work emails, phone numbers, roles, and résumé details, and was described as likely the largest-ever breach of Department of Homeland Security staff data.
On the state-actor side, a hacker or small group operating under the alias FlamingChina claimed in February to have spent six months quietly extracting more than 10 petabytes of data from China’s National Supercomputing Center in Tianjin, including alleged defense documents, missile schematics, and aerospace research tied to major state entities. Chinese authorities have not confirmed or denied the incident.
Emerging Trends This Year
A clear pattern has emerged across 2026’s biggest leaks so far: attackers are increasingly targeting people, not just databases. Rather than dumping raw records for resale, groups like Handala have paired data theft with direct intimidation, contacting individuals named in leaked datasets and issuing personal threats, a shift from financially-motivated crime toward what researchers are calling psychological and geopolitical operations. Nation-state and hacktivist involvement has also become harder to separate from criminal activity, with several 2026 incidents attributed to groups that blend genuine espionage motives with the appearance of ordinary ransomware or resale schemes. Verification has become a recurring problem as well: multiple headline claims this year, including the largest Lockheed Martin figures, remain unconfirmed months after being posted, underscoring how much of the “leak economy” now runs on unverified claims designed to generate attention and leverage before any data is proven authentic.
2025 Data Leaks
2025 was defined by two very different kinds of data leak: audacious, headline-grabbing crypto thefts and quieter but massive third-party breaches that rippled through entire corporate supply chains. Between the two, the year produced 425.7 million breached accounts worldwide, working out to roughly 810 breaches every minute.

Financial & Crypto Breaches (Kraken, Bybit, Ledger, Coupang)
Crypto exchanges took the hardest hits of the year. In February 2025, North Korea’s Lazarus Group pulled off the largest cryptocurrency theft in history, stealing approximately $1.5 billion in Ethereum from Dubai-based exchange Bybit by compromising a third-party tool used to move funds between wallets, a theft the FBI later formally attributed to North Korean state actors. Kraken faced a different kind of exposure that same year: rather than a system-level hack, two insider incidents saw roughly 2,000 customer accounts, about 0.02% of its user base, exposed after support staff were recruited by criminals to leak internal data, no funds or credentials were compromised. Ledger customers were caught up in a separate incident in early January 2026, when a misconfigured API key at e-commerce partner Global-e exposed customer names, addresses, and order details, though no payment data or wallet recovery phrases were affected.
The most consequential breach of the cluster, though, hit a very different kind of financial target: South Korean e-commerce giant Coupang. A former employee retained privileged system access after leaving the company and, over several months, accessed data tied to approximately 33.7 million customer accounts, later confirmed as one of the largest breaches in Korean corporate history, prompting a resignation, criminal investigation, and a compensation package worth roughly 1.69 trillion won.
Corporate & Enterprise Leaks (Salesforce, Delve, Kaikatsu Club)
Enterprise software supply chains were the year’s other major weak point. Starting in mid-2025, a hacking collective known as Scattered LAPSUS$ Hunters ran a months-long extortion campaign against Salesforce customers, using stolen OAuth tokens and social-engineering phone calls to access CRM data across dozens of major brands; by October, the group claimed to be selling nearly 1 billion stolen records and launched a dedicated dark web leak site to pressure victims into paying. Companies including Qantas, Vietnam Airlines, and Google were confirmed among those affected.
Not every “leak” in this cluster involved stolen data in the traditional sense. In March 2026, AI compliance startup Delve, a Y Combinator-backed platform used by over 1,000 companies, came under fire after a whistleblower alleged the company had fabricated audit evidence and routed clients through unaccredited certification mills, with identical auditor language appearing across 533 compliance reports covering 455 companies. The incident exposed a newer category of “leak”: not personal data spilling out, but false assurances of security spilling into hundreds of companies’ compliance postures.
Elsewhere, Japan’s Kaikatsu Club chain suffered one of its country’s largest breaches of the year when a 17-year-old attacker used a self-built, ChatGPT-assisted program to extract roughly 7.25 million customer records from the internet café chain’s application server, temporarily disrupting service before the attacker was arrested nearly a year later, a case that’s since become a reference point for how accessible sophisticated attack tooling has become, even to unskilled actors.
2024 Data Leaks
2024 was the year data leaks stopped being isolated incidents and started looking like aggregation at scale, old breaches repackaged, cross-referenced, and resold as single mega-datasets. The year opened with the discovery of a leak containing 26 billion records across 3,800 folders, each corresponding to a separate historical breach, quickly dubbed the “Mother of All Breaches.”

Consumer Platforms Affected (Trello, Venmo, eBay, Hulu, Nintendo)
Project management platform Trello was hit in January 2024 when a threat actor scraped roughly 15.1 million user records, containing emails, usernames, and full names, and listed the data for sale on a dark web hacking forum. Trello’s parent company Atlassian confirmed it wasn’t a direct system breach, the attacker had matched a pre-existing list of email addresses against publicly accessible Trello profiles rather than hacking Trello’s infrastructure. Venmo faced a related but distinct issue: its transaction data has long been exposed by default through public API settings, and elements of Venmo user data were swept into the broader Mother of All Breaches dataset that surfaced in January 2024. eBay and Hulu customer records have similarly circulated within these large aggregated 2024 leak compilations, though, as with much of the MOAB dataset, a significant share consists of previously-circulated data recompiled rather than a single fresh, confirmed breach at either company. Nintendo, meanwhile, continued to deal with the long tail of its earlier internal-data leaks throughout the year, a reminder that a single major leak can keep generating “new” exposure headlines for years after the original incident.
The National Public Data Breach, Why It Was Historic
If one incident defined 2024, it was the breach at National Public Data (NPD), a background-check data broker most consumers had never heard of. A hacker calling themselves USDoD first listed the stolen dataset for sale in April 2024, and the company later confirmed 2.9 billion records had been obtained, though it was still working to determine the total number of individuals affected. Analysis of the full dump found around 272 million unique individuals affected, with virtually all U.S. and Canadian Social Security numbers exposed, making it one of the largest SSN exposures ever recorded. The breach was historic less for its raw size than for what it revealed about the data broker industry: NPD had compiled its records by scraping public and court sources without most affected individuals’ knowledge or consent, and the fallout, over a dozen class-action lawsuits and NPD’s eventual Chapter 11 bankruptcy filing, helped accelerate state and federal momentum toward regulating data brokers directly. We cover the full breakdown of what was exposed and how to check your own exposure on our National Public Data breach page.
SSN and Social Security Exposure Incidents
The NPD breach wasn’t an isolated SSN event, it was the largest entry in a year that saw Social Security numbers surface repeatedly across unrelated incidents, from healthcare and financial-sector breaches to smaller regional exposures folded into aggregated leak databases. What made 2024’s SSN exposures particularly damaging wasn’t just volume but permanence: unlike a password, a Social Security number can’t be reset, meaning individuals exposed in the NPD breach and similar incidents face an elevated identity-theft risk that persists for years rather than resolving once a company patches its systems. Security researchers who reviewed the leaked NPD data found approximately 900 million unique Social Security numbers within the dataset, with many entries also including full names, current and prior addresses, and phone numbers, the combination that makes synthetic identity fraud and targeted phishing significantly easier to pull off.
2017–2023: A Look Back at Earlier Major Leaks
Not every major data leak happened in the last two years, some of the incidents that shaped how companies and governments handle personal data today go back nearly a decade. Looking at these earlier leaks side by side, one pattern is hard to miss: the average cost of a data breach in 2023 alone reached $4.24 million and took 287 days to contain, and that number has only climbed since, making these older breaches useful benchmarks for just how much worse the problem has gotten.

2023, FourKites, Tesla, OpenAI
2023 produced two very different lessons about where leak risk actually lives: inside a company’s own workforce, and inside the software it runs. Tesla learned the first the hard way when two former employees shared the personal information of 75,735 current and former employees, including names, addresses, phone numbers, and Social Security numbers, with a German media outlet, a pure insider leak with no external hacker involved at all. OpenAI’s incident that same year illustrated the second: a bug in an open-source caching library caused ChatGPT to briefly reveal other users’ chat history titles and, during a nine-hour window, expose the names, email addresses, and partial payment card details of about 1.2% of ChatGPT Plus subscribers, prompting Italy’s data protection authority to temporarily ban the service, the first such action against a major AI provider by a Western regulator.
2021–2022, Medicare, Shanghai Police Database, T-Mobile
T-Mobile’s August 2021 breach remains one of the most-cited telecom leaks on record. A hacker exploited an exposed network gateway and ultimately stole data on roughly 47.8 million current, former, and prospective customers, including names, dates of birth, Social Security numbers, and driver’s license information. Government data proved just as vulnerable that period: in 2022, a Medicare subcontractor’s ransomware attack exposed the personal information of roughly 254,000 Medicare beneficiaries, prompting CMS to issue replacement Medicare cards with new identification numbers. The largest government-data incident of the stretch happened overseas, in mid-2022, a hacker put up for sale more than one billion Chinese residents’ records from the Shanghai police database, including names, addresses, national ID numbers, and case details, totaling over 23 terabytes of data, demanding 10 bitcoin for the full dataset.
2017–2020, Aadhaar, Wattpad, Blizzard, EA, TripAdvisor, Shadow Brokers/EternalBlue
This earlier stretch produced some of the largest-scale exposures ever recorded, alongside one leak that reshaped cybersecurity itself. India’s Aadhaar national ID database was repeatedly compromised starting in 2017, with journalists in January 2018 finding that criminals were selling unrestricted access to any of the database’s 1.1 billion citizen records for about $7 through anonymous WhatsApp groups. Storytelling platform Wattpad suffered a similarly massive breach in June 2020, when attackers exposed almost 270 million user records including names, usernames, email addresses, birth dates, and bcrypt-hashed passwords, later sold and then leaked for free on a hacking forum. Gaming companies weren’t spared either: both Blizzard and EA experienced high-profile security incidents during this period, and travel platform TripAdvisor faced its own user-data exposure concerns, reflecting how broadly consumer platforms across entertainment, gaming, and travel were targeted throughout the late 2010s.
But the single most consequential event of this era wasn’t a corporate breach at all, it was a leak of government cyberweapons. In April 2017, a group calling itself the Shadow Brokers released a trove of classified NSA cyber tools, including the EternalBlue exploit, which within a month powered the global WannaCry ransomware attack that crippled hospitals, banks, and businesses across more than 150 countries. EternalBlue’s aftermath is a reminder that not every “leak” exposes personal data directly, some expose the very tools that make every subsequent breach on this page possible, which is part of why the exploit is still detected in active attacks years after Microsoft patched the underlying vulnerability.
How Many Data Leaks Happen Each Year? (Trend Analysis)
The honest answer is: more every year, and by a wide margin. U.S. organizations reported a record 3,332 data compromises in 2025, a 79% increase in just five years and the third consecutive year with more than 3,000 recorded incidents.

Year-Over-Year Breach Volume
The trend line has been almost uninterrupted for half a decade. 2025’s total marked a 4% increase from the previous record set in 2024, meaning U.S. data compromises have now broken their own record for multiple years running. Not every year tells the same story, though, while the number of incidents keeps climbing, the number of individuals affected doesn’t always move in lockstep. Notably, the number of individuals affected by data compromises in 2025 actually fell to its lowest annual total since 2014, even as the incident count hit an all-time high. That combination, more breaches, fewer people affected per breach on average, points to a shift toward smaller, more targeted incidents rather than the sprawling mega-leaks that once defined the “biggest breach ever” headlines, alongside continued underreporting that makes true year-over-year comparisons harder than the raw numbers suggest.
Industries Most Frequently Targeted
No sector is safe, but some get hit far more consistently than others. Recent industry data shows, financial services, healthcare, and professional services as the sectors recording the most data breaches, driven largely by the volume and sensitivity of the personal information they store. Healthcare in particular carries an outsized burden relative to its breach count: the sector consistently posts the highest average cost per breach of any industry, at $7.42 million, and the longest time to detect and contain an incident at 279 days. Supply chain and third-party vendor breaches have also become a much larger share of the problem in recent years, the number of entities affected by these cascading, vendor-caused incidents nearly doubled between 2024 and 2025, growing from 660 to 1,251 affected entities, which helps explain why so many of the leaks on this page originate not from the named company itself, but from a payment processor, HR platform, or CRM vendor it relies on.
Types of Data Most Commonly Leaked
Data leaks don’t expose one uniform type of information, they typically fall into a handful of categories, each carrying a different level of long-term risk. The most damaging by far are identifiers that can’t be changed, like Social Security numbers, since a single breach such as the 2024 National Public Data incident exposed around 272 million unique SSNs, with virtually all U.S. and Canadian numbers affected, a scale that shows just how concentrated this risk has become.

SSNs and Government ID Numbers
Social Security numbers and other government-issued IDs sit at the top of the risk hierarchy because, unlike a password, they can’t simply be reset after a leak. A person’s SSN, passport number, or national ID typically follows them for life, which is what made incidents like the Aadhaar breach so consequential: India’s national ID database exposed the biometric and identity records of roughly 1.1 billion citizens, a scale of permanent-identifier exposure that has few parallels anywhere in the world. Once numbers like these are circulating, they’re commonly bundled with names and addresses to enable synthetic identity fraud, fraudulent tax filings, and new-account fraud that can surface years after the original leak. We break down what to do if your own SSN turns up in a leak on our dedicated SSN on the dark web guide.
Credit Card and Financial Data
Financial data leaks tend to be more immediately actionable for criminals but also easier to contain, since banks can cancel and reissue a card number within days. Even so, the scale can be significant: the underground market value of stolen personal data exceeded $9.1 billion in just the first quarter of 2025 alone, much of it tied to payment card and banking credentials. Not every “financial” leak involves full card numbers, either, several major 2025 and 2026 incidents, including Ledger’s and Kraken’s breaches, specifically involved order histories, billing addresses, and partial card details rather than full payment information, which limits direct financial loss but still fuels highly convincing follow-up phishing attempts. For a closer look at how these leaks unfold and how to respond, see our credit card data breach page.
Login Credentials and Email Addresses
Usernames, email addresses, and passwords are the most frequently leaked data type simply because they’re the most widely collected, nearly every online account requires them. The scale here dwarfs other categories: the largest credential exposure ever recorded surfaced in 2025, when researchers uncovered 30 datasets containing more than 16 billion login credentials, compiled from years of prior breaches and malware-infected devices rather than a single new hack. Because so many people reuse passwords across services, a single leaked credential set can unlock accounts far beyond the site it was originally stolen from, a technique called credential stuffing that remains one of the most common ways leaked data turns into an actual account takeover.
What to Do If Your Data Was Leaked
If your information turns up in a data leak, the right response is quick, specific, and proportional to what was actually exposed, not panic, and not inaction either. Given that U.S. data compromises hit a record 3,322 incidents in 2025 alone, the odds that your data has appeared in at least one leak are now higher than most people realize, which makes knowing the actual steps worth more than worrying about the exposure itself.

How to Check If You’re Affected
The first step is confirming whether your data was actually part of a known leak, rather than assuming the worst from a headline. Free breach-lookup tools let you search your email address or phone number against known leaked datasets, and most major breach disclosures, including the ones covered on this page, get indexed within days of becoming public. It’s worth checking multiple identifiers, not just one email address, since a single person is often exposed under several different accounts across unrelated breaches; the National Public Data breach alone affected around 272 million individuals, meaning a large share of U.S. adults have reason to check their exposure even if they never interacted with the company directly. If you’re specifically concerned about a phone number surfacing in a leak, our phone number dark web guide walks through how to check and what the exposure actually means.
Immediate Protective Steps
Once you’ve confirmed exposure, the response depends on what type of data was involved, but a few actions apply almost universally. Change the password on the affected account immediately, and on any other account where you reused that same password, credential reuse is exactly what turns one leak into several account takeovers. Enable multi-factor authentication wherever it’s offered, since it blocks the vast majority of automated account-takeover attempts even when a password is already compromised. If financial or government ID data was exposed, place a fraud alert or credit freeze with the major credit bureaus, and monitor your accounts for unfamiliar activity for months afterward rather than just the first few weeks, leaked data is frequently held and resold before it’s actively used. Finally, be skeptical of unexpected calls, texts, or emails referencing the leak itself, since scammers routinely pose as the breached company’s support team to extract even more information from people who are already on alert. For a broader walkthrough of dark web monitoring and ongoing protection, see our dark web scan guide.
How DeXpose Helps You Stay Ahead of Data Leaks
Checking whether you’ve been part of a past leak is useful, but the more valuable protection is catching exposure the moment it happens, not months later once the data is already circulating. That’s the gap DeXpose’s dark web monitoring is built to close, continuous visibility instead of a one-time lookup, which matters given that reported data breaches took an average of 212 days to contain in 2025, plenty of time for exposed data to spread before most people even know it’s out there.

Real-Time Dark Web Monitoring
Rather than waiting for a company to publicly disclose a breach, which, as this page has shown, can happen weeks or months after the actual incident, DeXpose’s dark web monitoring scans dark web markets, malware logs, and leaked databases on an ongoing basis to flag exposure as it surfaces. This matters most for organizations, since a single compromised employee credential or leaked vendor database can expose an entire company’s attack surface long before a formal breach notification ever gets filed. For a quick, no-commitment starting point, the free dark web report gives an instant snapshot of exposure across dark web markets and public breach sources.
Alerts for New Breach Disclosures
Beyond passive monitoring, DeXpose’s breaches monitoring service tracks newly disclosed incidents as they’re confirmed, so individuals and organizations don’t have to manually check breach-notification sites or wait for a company’s own disclosure timeline. This is particularly valuable given how often 2025 and 2026’s biggest leaks, Coupang, Salesforce, Ledger, originated at a third-party vendor rather than the primary brand itself; supply chain monitoring extends that same alerting to the vendors and partners an organization depends on, closing a blind spot that traditional breach-notification systems routinely miss. Anyone wanting to check a specific email address against known breach data directly can do so through the email data breach scan.
Frequently Asked Questions (FAQ’s)
What’s the difference between a data leak and a data breach?
A breach involves someone actively hacking in to steal information, while a leak often happens passively, through a misconfigured database, an unsecured API, or human error, with no intrusion required. Both result in the same outcome for the people affected: their personal information ends up somewhere it shouldn’t be. Industry trackers frequently group both terms under the broader label “data compromise” for exactly this reason.
How do I know if my information was exposed?
Free lookup tools let you search an email address or phone number against known leaked datasets, and most major incidents get indexed within days of becoming public. It’s worth checking more than one identifier, since a single person is often exposed across several unrelated incidents. Confirming exposure first helps you respond proportionally instead of guessing.
Can leaked Social Security numbers be changed?
Not easily, the Social Security Administration only issues a new number in rare, severe cases, which is why SSN exposure carries more lasting risk than a leaked password. Most people whose SSN is exposed instead rely on credit monitoring, fraud alerts, and credit freezes to limit the damage. This is also why SSN-related leaks tend to generate the most sustained public concern.
Why do so many recent leaks involve third-party vendors instead of the company itself?
Modern organizations rely on dozens of outside vendors, payment processors, HR platforms, CRM tools, each holding a slice of customer or employee data. A single vendor breach can expose customer data across many unrelated companies at once, which is exactly what happened in several of 2025 and 2026’s largest incidents. This is a major reason supply chain risk has become a growing focus for security teams.
Is it safe to click links in emails claiming to be from a breached company?
Not without verifying first, scammers routinely send phishing emails posing as official breach notifications to extract even more personal information from people who are already alert to the situation. Legitimate breach notifications rarely ask you to click a link and re-enter sensitive details. When in doubt, go directly to the company’s official website rather than clicking through an email.



