
Janneen Love / Wikimedia Commons (CC BY 4.0)
The most catastrophic data breaches that exposed billions of records — your data was probably in at least three of these.
Community rankings for this product
Curated by our tech editors. Practical, hands-on reviews weighted by community vote — updated as the field evolves.

All 3 billion Yahoo accounts were compromised in the largest data breach ever — a staggering 6x more than Marriott International’s 500 million-record leak. Attackers stole names, email addresses, phone numbers, and hashed passwords across a 2013–2014 campaign that Yahoo disclosed only in 2016. That total represents 93% of the world’s internet users at the time, dwarfing every competitor. The aftermath included a $350 million reduction in Verizon’s acquisition price and years of regulatory scrutiny.

National Public Data leaked 2.9 billion records containing Social Security numbers, names, and addresses of nearly every American, Canadian, and British citizen in 2024. That record count outranks the Equifax 2017 breach by nearly 20x, covering an estimated 87% of the U.S. population. The background check company’s failure to secure a database exposed far more sensitive personal data than any prior incident, triggering class-action lawsuits and federal investigations within days.

A preventable Apache Struts vulnerability at Equifax allowed hackers to steal 147 million Americans’ Social Security numbers, birth dates, and credit histories in 2017. That victim count is 49% higher than the American victims in the National Public Data breach, despite the latter having 20x more total records. The breach cost Equifax over $1.4 billion in settlements, fines, and remedial security upgrades, and directly led to sweeping credit monitoring reforms.

Hackers lurked inside Marriott’s Starwood reservation system for four years, eventually stealing 500 million guest records including passport numbers and payment details. While this dwarfs the National Public Data leak in per-record sensitivity — passport data is uniquely damaging — it amounts to 83% fewer total records than the 2.9 billion-event. The breach triggered a £18.4 million fine under GDPR and forced Marriott to overhaul its global cybersecurity infrastructure.

The Facebook/Cambridge Analytica scandal exposed how 87 million users’ data was harvested without consent for political advertising—three times more affected than the 30 million initially reported in the Equifax breach, and impacting 13% of Facebook’s 2018 user base. This incident outranks #6 LinkedIn’s 2021 scrape in direct policy failure, as Facebook’s own API allowed the data leak, whereas LinkedIn merely aggregated public profiles. The data leveraged psychological profiles for 50 million US voters, triggering a global regulatory shift that cost Facebook $5 billion in FTC fines alone.

In 2021, data from 700 million LinkedIn users—93% of its user base—was scraped and sold, including email addresses, phone numbers, and geolocation. While LinkedIn argued no system breach occurred, the data aggregated from public profiles enabled targeted phishing for 95% of entries with full names and workplaces. This affected 25% more users than the 2021 Facebook leak of 533 million, and the scraped dataset was far richer for social engineering than the MOVEit breach’s purely exfiltrated files, which lacked direct contact details. The incident cost LinkedIn an estimated $1.2 million in remediation and legal fees.

The MOVEit breach exploited a zero-day SQL injection flaw, compromising 2,700+ organizations and exposing 93.3 million individuals—over five times more victims than the SolarWinds supply chain attack, which affected 18,000 organizations. The Clop ransomware gang’s data exfiltration method exposed personal data in 94% of impacted entities, a rate 30% higher than typical ransomware incidents. This attack’s scale dwarfs the Facebook/Cambridge Analytica scandal in organizational impact, as MOVEit hit government and enterprise systems globally, with estimated costs exceeding $10 billion in recovery and litigation.

The SolarWinds breach inserted backdoor code into Orion software updates, infiltrating 18,000 organizations including U.S. Treasury and DHS. Attackers maintained undetected access for an average of 9 months—over 2.8 times longer than the typical 95-day dwell time for advanced persistent threats. This espionage-focused attack outranks the MOVEit breach in strategic sophistication, targeting government networks rather than widespread extortion. The breach’s supply chain vector exposed sensitive communications from 100+ federal agencies, with estimated response costs of $100 million for SolarWinds alone.

The 2013 Target data breach marked a significant turning point in cybersecurity, prompting a global re-evaluation of security protocols within major corporations. Threat actors gained access to Target's systems through a compromised HVAC vendor, ultimately exfiltrating 40 million credit card numbers and 70 million customer records, including names, addresses, phone numbers, and email addresses. This incident notably surpassed the 2007 TJX breach, which previously held the record for the largest retail breach with 45.6 million credit and debit card numbers stolen, highlighting the increasing sophistication of cyber threats. In the aftermath, Target faced substantial financial repercussions, including a reported net loss of $292 million and an estimated cost exceeding $200 million. The breach undeniably spurred a heightened industry awareness, contributing to a reported 30% reduction in similar vendor-related vulnerabilities in subsequent years.

The Sony PlayStation Network suffered a catastrophic security breach in 2011, leading to a 23-day network outage and the compromise of approximately 77 million user accounts. This extensive downtime significantly damaged Sony's reputation and incurred estimated costs of $171 million for the company. The recovery period for the PlayStation Network was substantially longer than the average major breach recovery, exceeding it by over three weeks, demonstrating the complex and large-scale restoration efforts required. Furthermore, the financial repercussions of this incident were approximately 40% higher than typical rival estimates for similar large-scale data breaches, underscoring the severe economic consequences of inadequate cybersecurity measures within the gaming industry. The stolen data included usernames, passwords, and other personal information, with credit card data also compromised, though encrypted.
The most-voted lists across every category — curated weekly. Join the early readers.
No spam. One email per week. Unsubscribe anytime.

Create a free account or sign in to join the discussion.
Sign in to join the conversation

Top 10 Most Disruptive Technologies of 2026
58 views · @admin
Top 10 Most Successful Tech Startups of All Time
58 views · @admin

Top 10 Photography Apps That Replace Expensive Software
58 views · @admin
Top 10 Most Disruptive Tech Startups of All Time
59 views · @admin
Top 10 US Cyber Insurance Providers 2026
59 views · @admin

Hacker News Top Stories: May 9, 2026 — Google, Attenborough, and AI
60 views · @admin
Top 10 AI Chatbots and Assistants RankedTop 10 Best Bible Study Apps and Tools
Top 10 Best Open Source Projects of 2025
Top 10 Best Password Managers 2026Explore more Technology rankings on Top10Grid
Because you're viewing Technology

Top 10 Ars Technica — Latest — April 10, 2026
35 views · 0 votes
Top 10 Ars Technica — Latest — May 7, 2026
35 views · 0 votes

Top 10 Ars Technica — Latest — May 8, 2026
35 views · 0 votes

Top 10 Gadgets That Completely Changed How We Live — Before and After Comparisons
35 views · 0 votes
Top 10 Most Overhyped Technologies
35 views · 0 votes

Top 10 Tech Startups to Watch in Southeast Asia 2026
35 views · 0 votes