Biggest Data Breaches in History
22 of the most costly and impactful data breaches ever recorded. Real companies, real costs, real consequences.
$5.1B
Largest single breach (Facebook FTC fine)
3B
Records in Yahoo breach (2016)
2024
Change Healthcare — largest US healthcare breach
$4.88M
Global average breach cost (IBM 2024)
| Company | Year | Records (M) | Est. Cost | Type |
|---|---|---|---|---|
| 2019 | 540M | $5.1B | Data Exposure | |
MOVEit / Progress Software | 2023 | 77M | $2.7B | Zero-Day Exploit |
Change Healthcare (UnitedHealth) | 2024 | 190M | $2.5B | Ransomware |
Equifax | 2017 | 147M | $1.4B | Vulnerability Exploit |
JPMorgan Chase | 2014 | 83M | $1.0B | Malicious Attack |
Yahoo | 2016 | 3B | $350M | Credential Theft |
T-Mobile | 2021 | 77M | $350M | Credential Theft |
T-Mobile | 2023 | 37M | $350M | API Abuse |
Capital One | 2019 | 106M | $300M | Cloud Misconfiguration |
Target | 2013 | 110M | $292M | POS Malware |
Anthem | 2015 | 78M | $260M | Credential Theft |
Marriott / Starwood | 2018 | 500M | $200M | Malicious Attack |
eBay | 2014 | 145M | $200M | Credential Theft |
Home Depot | 2014 | 56M | $198M | POS Malware |
Sony PlayStation Network | 2011 | 77M | $171M | Malicious Attack |
Twitter / X | 2022 | 200M | $150M | API Vulnerability |
Uber | 2016 | 57M | $148M | Credential Theft |
LastPass | 2022 | 33M | $100M | Malicious Attack |
SolarWinds | 2020 | 18M | $90M | Supply Chain Attack |
Medibank | 2022 | 9.7M | $35M | Ransomware |
| 2021 | 700M | $2M | Data Scraping | |
Adobe | 2013 | 153M | $1M | Credential Theft |
Costs include settlements, fines, remediation, and estimated business impact. Sources: SEC filings, regulatory disclosures, IBM reports, court documents.
Common Root Causes
- ● Stolen or compromised credentials (most common)
- ● Unpatched vulnerabilities / zero-days
- ● Third-party / supply chain access
- ● Cloud misconfigurations (S3 buckets, APIs)
- ● Phishing and social engineering
- ● Ransomware via email / RDP
Aftermath Patterns
- ● C-suite exits common (Target, Equifax, Uber)
- ● Class action settlements take 2–5 years
- ● Stock prices drop avg 7.5% in 3 months
- ● Regulatory scrutiny intensifies for years
- ● Security budgets double post-breach
- ● Some breaches take 1–4 years to detect
Could your organization be next?
Calculate your estimated breach cost and see what it would take for your organization to appear on this list.
Calculate Your Breach Cost →