Skip to main content

Worst Data Breaches

By Every Day Story16 items
Share

About this list

Online commerce thrives on trust. Companies must trust customers, and customers must trust companies with personal and financial information. But the internet's accessibility also makes it vulnerable. Despite meticulous coding, a single hacker can exploit a flaw and put everyone at risk. Human error is another weakness - a plausible email or message can trick an employee into opening a malicious attachment, giving hackers access. Government-sponsored hackers are particularly sophisticated. As a result, companies of all kinds fall victim to cyberattacks, exposing customer information to malicious actors. The public backlash is often severe. In fact, most people have had their personal data stolen online, with the FBI estimating $12.5 billion in losses to Internet fraud in American businesses alone in 2023. The biggest cyber attacks of the 21st century are highlighted here, but they're just the tip of the iceberg - cyber fraud runs deep, and vigilance is essential.

Crowd-ranked
Business
updating live16 items
  • 1
    Ticketmaster

    Ticketmaster appears in the list of worst data breaches.2024

    Ticketmaster exposed credit card numbers, expiration dates, and customer fraud details.A lawsuit against Ticketmaster claimed these details were stolen.Experts claim Ticketmaster did not steal banking or medical information.No banking or medical information was stolen.Ticketmaster stole no banking or medical information.

    560 million Ticketmaster customers were affected.560 million Ticketmaster customers were affected.

    A lawsuit against Live Nation and Ticketmaster claimed the stolen data sold for $500,000 on the dark web.A lawsuit against Live Nation and Ticketmaster claimed the stolen information had a $500,000 asking price on the dark web.

  • 2
    LinkedIn Corporation

    20212021

    User information was exposed.A hacker named Tom Liner got user information by scraping LinkedIn’s application programming interface, the software marketing companies use to reach users.

    About 700 million LinkedIn users were affected.LinkedIn has about 700 million users.

    Tom Liner tried to sell his database access for $5K a pop, but LinkedIn dismissed the incident as a security risk.Tom Liner tried selling database access for $5K a pop, but LinkedIn...LinkedIn dismissed the incident as a security risk.LinkedIn noted Liner built the database from public data, but did so much faster and more efficiently than a normal computer user.

  • 3
    Capital One

    20192019

    Payment information for customers and credit card applicants was exposed, including 100,000 Social Security numbers and 80,000 bank account numbers.Payment information for customers and credit card applicants was exposed, including 100,000 Social Security numbers and 80,000 bank account numbers.

    More than 100 million customers in the US and Canada were affected.More than 100 million customers in the US and Canada.

    Capital One paid about $250 million in damages to Capital One and its customers from the hack.It is estimated the hack cost Capital One and its customers about $250 million in damages. In 2022, ex-Amazon employee Paige A. Thompson was convicted for the hack.Paige A. ThompsonThe Justice Department said Paige A. Thompson was convicted for the hack.Thompson used Amazon Web Services to build a hacking tool that scanned for “misconfigured accounts.” Capital One paid banking regulators $80 million in fines and $190 million in a class-action settlement.Thompson used Amazon Web Services to create a hacking tool that scanned for “misconfigured accounts.” Capital One paid banking regulators $80 million in fines and another $190 million in a class-action settlement.

    Business
  • 4
    Facebook

    2019The hack occurred in 2019 and was revealed in April 2021 because Facebook refused to tell its users about the hack.

    Full names of Facebook account holders, locations, email addresses, phone numbers, and other personal details were exposed.Facebook holds full names of account holders, locations, email addresses, phone numbers, and other personal details.

    533 million Facebook users were affected in 106 countries. 533 million Facebook users in 106 countries.This data exists in 106 countries.

    Facebook had to admit the breach.Facebook later denied responsibility for the hack. Facebook did pay a $5 billion settlement to the FTC that same year for mishandling user data.$5 billion settlementFacebook chose to hide the hack. However, a database of stolen account info appeared on the dark web in March 2021. Facebook had to admit the breach occurred because a 'malicious actor' used an old feature letting users find each other by phone number. Facebook later denied fault but paid a $5 billion settlement.$5 billion settlementFacebook paid the FTC $5 billion for mishandling user data that year.

  • 5
    Equifax

    147 million Americans and 14 million British citizens were affected.Equifax announced the hack in September 2017.

    In February 2020, the Department of Justice indicted Equifax.The breach exposed names, addresses, home phone numbers, dates of birth, Social Security numbers, driver’s license numbers, and credit card numbers.

    Who Was Affected: 147 million Americans and 14 million British citizens.

    The Aftermath:In February 2020, the Department of Justice...indictedFour Chinese hackers from the People’s Liberation Army executed the hack using Wu Zhiyong, Wang Qian, Xu Ke, and Liu Lei. The Department of Justice stated these hackers exploited a weakness in Equifax’s dispute resolution system. Equifax agreed to a global class-action settlement totaling $425 million.$425 million.

  • 6
    Marriott International

    When It Happened:2018

    What Was Exposed: Hotel guests’ personal data, including names, credit cards, addresses, and sometimes passports.Hotel guests’ personal data, including names, credit cards, addresses, and sometimes passports.

    Who Was Affected:About 500 million guests visited Marriott properties between 2014 and 2018 and used the company’s Starwood system to register. These properties included the Sheraton, Westin, W Hotels, St. Regis, Four Points, Aloft, Le Méridien, Tribute, Design Hotels, Element, and the Luxury Collection, but excluded the Residence Inn or the Ritz Carlton.

    The Aftermath:Marriott took a proactive approach to the breach. Marriott set up a special website and call center to help customers. They also offered a one-year subscription to Web Watcher, a service that tracks where users' personal data goes online, but only for customers in the US, Canada, and Great Britain. The US government later determined the hackers were linked to the Chinese Ministry of State Security, making them nearly impossible to prosecute.The company adopted a proactive approach to the breach. They set up a special website and call center to help customers. They also offered a one-year subscription to Web Watcher, which tracks where personal data goes online, but only for customers in the US, Canada, and Great Britain. The US government later determined the hackers were linked to the Chinese Ministry of State Security, making successful prosecution difficult.to the breach, establishing a special website and call center to help customers, as well as offering a one-year subscription to a service called Web Watcher, which helps users keep track of where their personal data goes online, but only to customers in the US, Canada, and Great Britain. The US government laterdeterminedthat the hackers were affiliated with the Chinese Ministry of State Security, which means they’re pretty much impossible to prosecute successfully.

  • 7

    When It Happened:2016

    What Was Exposed: Emails and passwords, dates of last visits, browsing information, IP addresses, and site membership status.Emails and passwords, dates of last visits, browsing information, IP addresses, and site membership status.

    Who Was Affected: 412 million accounts, including around 16 million that had already been deleted.

    The Aftermath: This was AdultFriendFinder's second hack in two years; the 2015 hack exposed data for about 4 million users. A white hat hacker named “Revolver” found a security flaw in the company’s Local File Inclusion procedure. In 2016, AdultFriendFinder reportedly waited a week to warn users about the breach and then told them to change their passwords. Subsequent reviews found the hack happened because AdultFriendFinder used 1996-era security protocols.reviewsfound that the hack happened because AdultFriendFinder used 1996-era security protocols.

    Business
  • 8
    Ashley Madison

    When It Happened: July 2015

    What Was Exposed:Account information, including names, passwords, addresses, phone numbers, and credit card transactions for over 37 million users37 million usersAdmittedly, many of these accounts were fake or weren’t used for successful adultery.

    Who Was Affected: It’s unknown how many lives and relationships were impacted by the leaks, but at least two people allegedly died by suicide over them, including 56-year-old Louisiana pastor John GibsonJohn Gibson.

    The Aftermath: According to company officer Evan Back, the leak was just a temporary setback for Ashley Madison. After the leaks, the company spent “tens of millions” of dollars on security, doubling its membership in the decade since. The site, and adultery, is alive and well.Evan Back, the leak was just a temporary setback for Ashley Madison. In the wake of the leaks, the company invested “tens of millions” of dollars in security, doubling its membership in the near decade since. The site, and adultery, is alive and well.

    Business
  • 9
    Home Depot

    When It Happened: A hacker acted as a vendor between April and September 2014. This hacker used point-of-sale malware to skim data.

    What Was Exposed: Customers' payment info, including 56 million credit and debit card numbers.

    Who Was Affected: About 40 million Home Depot customerswho used self-service checkouts in the US and Canada.

    The Aftermath:Home Depotspentabout $62 million shoring up its cyber security. In 2020, the company paid a $17.5 millionsettlementto customers in 46 states and the District of Columbia (which doesn’t include its Canadian victims). Nobody knows who did the hack, though the malware had some Russian code—this does not prove the hackers are Russian.

  • 10
    JPMorgan Chase

    When It Happened: It began in June 2014 and was not found until July 2014.

    What Was Exposed:Names, addresses, phone numbers, and emails of JPMorgan Chase customers, but no money from accounts.

    Who Was Affected: 76 million households and 7 million small businesses.

    The Aftermath:Though the attacks seemed like they came from Russia, the actual reason was simple greed. In November 2015, the Justice Department indictedthree men for their part in the data breach: Gery Shalon, Ziv Orenstein, and Joshua Samuel Aaron. These three allegedly ran a stock pump-and-dump scheme and only hacked JPMorgan Chase to get a list of targets. Using 75 shell companies and hundreds of people, the trio allegedly made over $100 million before police caught them.

  • 11
    eBay

    When It Happened:The online auction site eBay was hacked in February 2014, and they announced the hack in May of the same year.

    What Was Exposed:Customers’ names, physical addresses, e-mail addresses, phone numbers, and payment and account passwords.

    Who Was Affected: 145 million users.

    The Aftermath: The site faced criticism for not announcing the hack until three months later, after asking users to change passwords. A federal judge then tosseda class-action suit against the company.

  • 12
    Adobe Systems

    When It Happened:2013

    What Was Exposed:Usernames, passwords, payment information, and source code for Adobe programsincludingAcrobat, Reader, Photoshop, and ColdFusion.

    Who Was Affected: About 2.9 million customers saw their payment information and other software use data exposed, while 35.1 million users saw their user IDs exposed.

    The Aftermath: In November 2016, attorneys general from 15 states won a class-action lawsuitagainst Adobe that forced the company to pay $1 million in damages, equaling about $1.80 per victim.

  • 13
    Sony Corporation

    When It Happened: November 2014

    What Was Exposed:47,000 Social Security numbers, plus a collection of internal company emails and spreadsheets. Many showed Sony executives like Amy Pascal and producers like Scott Rudin looking bad. Check what they said about President Obama.

    Who Was Affected:Thousands of Sony employees and millions of movie-goers were involved.

    The Aftermath:By June 2015, the Obama Administration prepared to announce its belief that a North Korean hacking group namedGuardians of Peacewas responsible. The hackers allegedly attacked in retaliation for the Seth Rogen comedyThe InterviewThe movie featured the comedian's character helping assassinate Kim Jong-un. Sony released the movie digitally instead of in theaters.

  • 14
    MySpace

    When It Happened:The breach happened in 2013, but it surfaced in2016.

    What Was Exposed:Usernames and email addresses forMySpace accounts.

    Who Was Affected:360 million account holders.

    The Aftermath:MySpace lost its leading social media spot around 2008. Still, its user data mattered. The site relaunched in 2013 with better security, but hundreds of millions of old accounts kept simple, easy passwords—and no defense against repeated guessing attacks. MySpacechoseto change all known account passwords and tell users their accounts were compromised.

    Business
  • 15
    Target

    When It Happened:The hack hit in November 2013. Target officials learned about it the next month when the Justice Department told the company Target customer data appeared online.

    What Was Exposed:Payment information and customers’ personal details.

    Who Was Affected:Forty million credit and debit card numberswere exposed, plusdata for up to 70 million customers, with some overlap.

    The Aftermath:Target triedto calm customers by giving a 10% discount store-wide during the Christmas shopping season. Its profits dropped 46% for that time, costing the company an estimated $200 million. Also, in 2017, Target paid $18.5 million in a class-action lawsuit.

    Investigators later found the hack happened because an employee at a third-party vendor for HVAC equipment wrongly opened a phishing email that put the Citadel Trojan into the system.

  • 16
    Yahoo!

    When It Happened:2013 and 2014

    What Was Exposed:User names, email addresses, phone numbers, birth dates, hashed passwords, and security questions and answers—but not credit card info.

    Who Was Affected:The first hack hit all of Yahoo’sthree billion subscribers. The second hack affected about 500 million subscribers.

    The Aftermath:This one is complex.. In 2017, Yahoo claimed the two hacks had no connection. ANew York Times report that year showed the first hack hitting three billion Yahoo users came from a “hacking collective based in Eastern Europe.” In 2016, that user data sold on the dark web, with three buyers reportedly paying $300k for a database copy. The first hack remains unsolved.

    But officials know more about the second hack, at leastaccording to the FBIIn 2017, the FBI charged four people over the 2014 hack that took 500 million user accounts. The FBI indictment states Russian FSB officers Dmitry Dokuchaev and Igor Suschin hired Alexsey Belan and then Karim Baratov, a Canadian. These Russian intelligence officers allegedly sought user data for Russian journalists and Russian and foreign government officials. They hired Belan, a known Russian cybercriminal, for the task. Belan allegedly hacked Yahoo’s User Database and its Account Management Tool to access the 500 million accounts. Belan allegedly gave this data to the FSB officers but kept data for 30 million Yahoo users for his own phishing campaign.

Comments (0)

Join the conversation

Sign in to share your take and reply to others.

First take? Share what stood out to you.

More like this