Recommended Free Tools
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
By CSO Online’s June 12, 2025 ranking, the largest listed event is a Chinese surveillance database containing 4 billion records. Yahoo’s 2013 breach follows with 3 billion accounts. Those figures are not directly interchangeable: the ranking mixes records, accounts and people, and some totals are estimates or disputed. The list below preserves CSO Online’s order while identifying exactly what each number measures.
How the ranking defines “biggest”
CSO Online ranks incidents by users affected, records exposed or accounts compromised. It excludes accidental exposures for which there is no significant evidence of misuse. A “record” may describe one database entry, while an “account” or “person” may be counted differently; none of the totals should be read as a count of unique individuals without that qualification.
The incident date also matters. Some entries use the date attackers got in, others the date a company discovered or disclosed the event. Yahoo and LinkedIn appear twice because the source treats separate incidents as separate breaches. The Privacy Rights Clearinghouse chronology provides wider context, covering more than 75,000 reported breaches since 2005.
The 20 biggest breaches in CSO Online’s 2025 ranking
| Rank | Incident and date | Reported scale and unit | What was exposed | How it happened and what is known |
|---|---|---|---|---|
| 1 | Chinese surveillance database — June 2025 | 4 billion records | WeChat data, bank details, Alipay profiles, phone numbers, addresses and behavioral profiles | An open 631GB database was found by Bob Dyachenko and Cybernews and taken offline. Researchers said the volume and variety suggested a centralized aggregation point for surveillance, profiling or data enrichment. |
| 2 | Yahoo — August 2013 incident | 3 billion accounts | Account information and security questions | Yahoo revised its original estimate to 3 billion. The report says plaintext passwords and payment-card or bank data were not stolen. |
| 3 | Real Estate Wealth Network — December 2023 | 1.5 billion records | Property histories, financial records, tax IDs, court judgments and other personal information | A misconfigured 1.16TB database was exposed. The total is a record count, not a count of people. |
| 4 | Aadhaar — January 2018 | About 1.1 billion Indian citizens | Names, addresses, photos, phone numbers, email addresses, fingerprints and iris scans | An API lacked effective access controls, allowing exposure of national identity data. The figure refers to citizens, although duplicate or stale entries cannot be ruled out. |
| 5 | Alibaba/Taobao — November 2019 | 1.1 billion pieces of user data | Usernames and mobile numbers | An affiliate-marketing developer scraped data for eight months. The developer and employer were each sentenced to three years in prison. |
| 6 | LinkedIn — June 2021 | 700 million users | Scraped email addresses, phone numbers, geolocation and gender | The dataset was offered on a dark-web forum. LinkedIn described the event as a violation of its terms rather than a conventional intrusion. |
| 7 | Sina Weibo — March 2020 | 538 million accounts | Real names, usernames, gender, location and phone numbers | The information was reportedly obtained and sold. Weibo said passwords were not affected. |
| 8 | Facebook — April 2019 disclosure | 533 million users | Phone numbers, account names and Facebook IDs | Publicly exposed datasets were later posted for free. The disclosure date is used here, not necessarily the date the data was first collected. |
| 9 | Marriott/Starwood — September 2018 discovery | 500 million customers | Names, addresses, phone numbers, email addresses, passport numbers, loyalty data, birth dates and reservation details; some payment-card data was encrypted | Unauthorized access had persisted since 2014. The UK Information Commissioner’s Office ultimately fined Marriott £18.4 million. |
| 10 | Yahoo — 2014 incident | 500 million accounts | Names, email addresses, phone numbers, hashed passwords and birth dates | Yahoo attributed the theft to state-sponsored actors. This is separate from Yahoo’s 2013 incident ranked second. |
| 11 | Adult Friend Finder/FriendFinder Network — October 2016 | 412.2 million accounts | Data from six databases spanning roughly 20 years | Most passwords used weak SHA-1 hashing and were reportedly cracked, making account takeover and password reuse especially dangerous. |
| 12 | MySpace — 2013 | 360 million accounts | Email addresses, usernames and passwords for older accounts | MySpace invalidated affected passwords. The records largely concerned legacy accounts. |
| 13 | NetEase — October 2015 | 235 million accounts reported | Email addresses and plaintext passwords were offered for sale | The source and Have I Been Pwned classify this incident as unverified, so the reported total should not be treated as confirmed. |
| 14 | Court Ventures/Experian — October 2013 | 200 million personal records | Personal information obtained from a database | Hieu Minh Ngo impersonated a private investigator to obtain access and sell the information. He later pleaded guilty in the United States. |
| 15 | LinkedIn — June 2012 | About 165 million users | Email addresses and passwords; the initial disclosure involved 6.5 million unsalted SHA-1 hashes | The later 165-million-record dataset expanded the known scope beyond LinkedIn’s first announcement. |
| 16 | Dubsmash — December 2018 | 162 million accounts | Email addresses, usernames, PBKDF2 password hashes and birth dates | Stolen data was offered on a dark-web market. Hashed passwords still required defensive resets because reused credentials could be attacked elsewhere. |
| 17 | Adobe — October 2013 | 153 million records | Username/password pairs and encrypted payment-card records | Adobe first reported nearly 3 million encrypted card records and an uncertain account count, then 38 million active users. Later analysis indicated more than 150 million username/hash pairs. |
| 18 | National Public Data — December 2023 | About 270 million people and an estimated 2.9 billion records | Names, Social Security numbers, addresses, email addresses and phone numbers | Data was sold or leaked; much appeared outdated or inaccurate, and the initial access method remained unconfirmed. The people and record totals are estimates, not equivalent measures. |
| 19 | Equifax — 2017 | About 159 million records | Names, Social Security numbers, birth dates, addresses, driver’s-license data and some payment-card data | Attackers exploited an unpatched Apache Struts vulnerability. US authorities charged four Chinese military members. |
| 20 | eBay — 2014 | About 145 million accounts | Names, encrypted passwords, email and mailing addresses, phone numbers and birth dates | Compromised employee credentials opened access to the corporate network. PayPal financial data was stored separately. |
Which breach affected the most people?
The answer depends on the unit. The Chinese database has the largest reported number, 4 billion records, but that is not a verified count of people. Yahoo’s 2013 incident is the largest confirmed account compromise in this ranking at 3 billion accounts. Aadhaar’s approximately 1.1 billion figure is expressed as Indian citizens, while National Public Data is estimated at about 270 million people alongside an estimated 2.9 billion records. These numbers cannot be added together or ranked as if they measured the same population.
#1 Best Overall
What information was exposed?
Identity and contact data
Names, addresses, phone numbers, email addresses, dates of birth and account identifiers recur throughout the list. These fields support convincing phishing, impersonation and account-recovery fraud even when no payment card is present.
Credentials and authentication data
Yahoo, MySpace, Adult Friend Finder, LinkedIn, Dubsmash, Adobe and eBay involved passwords or password-derived data. Hashing reduces direct exposure but does not protect users who reuse a password, especially where older or weak algorithms were used. Security questions in Yahoo’s 2013 incident could also aid account recovery attacks.
Government identifiers and biometrics
Aadhaar exposed fingerprints and iris scans as well as identity details. Equifax and National Public Data included Social Security numbers or comparable identity records, which are difficult to replace and therefore carry long-term identity-theft risk.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Financial, travel and behavioral information
Real-estate and court records, bank or payment profiles, Marriott reservation and passport data, and the Chinese database’s behavioral profiles can reveal finances, movements, relationships or habits. Encrypted card fields are not the same as unprotected card numbers, but they still warrant monitoring.
How these mega-breaches happened
Open or misconfigured databases
The Chinese surveillance database and Real Estate Wealth Network demonstrate how a database reachable from the internet can expose enormous volumes without a sophisticated exploit. A missing authentication layer or incorrect cloud permission can be enough.
Unpatched software
Equifax shows the classic patch-management failure: attackers used a known Apache Struts vulnerability that had not been fixed. Asset inventories, emergency patching and verification are as important as choosing a security product.
Stolen credentials and excessive access
eBay’s attackers used employee credentials, while Court Ventures involved impersonation to obtain legitimate database access. Strong multifactor authentication, least privilege and monitoring for unusual administrator activity limit the damage from valid accounts.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsInsecure APIs and third parties
Aadhaar’s API lacked adequate access controls. Taobao’s incident involved an affiliate-marketing developer, and several other cases show how partners, old systems and data aggregators can expand the exposure perimeter.
Best Value
Scraping and public re-use
LinkedIn and Facebook illustrate a different path: data can be collected through poorly controlled interfaces or public datasets and later redistributed. Even when a company calls the activity scraping or a terms-of-service violation, the resulting phone numbers and identifiers can still fuel fraud.
Long dwell times
Marriott’s unauthorized access continued from 2014 until its September 2018 discovery. The gap between intrusion and detection allowed attackers to collect more records and illustrates why continuous logging, anomaly detection and tested incident response matter.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Yahoo, Facebook, Marriott, Equifax and eBay: the practical differences
- Yahoo: two separate incidents dominate the account-count rankings. The 2013 event involved account information and security questions at unprecedented scale; the 2014 event involved names, contact details, birth dates and hashed passwords and was attributed to state-sponsored actors.
- Facebook: the 2019 disclosure centered on phone numbers, names and Facebook IDs in datasets that became freely available, making phishing and phone-based impersonation the principal concern rather than stolen payment records.
- Marriott: the defining issue was persistence. Attackers remained in the Starwood environment for years, and the exposed reservation, passport and loyalty data created travel-identity risks. The ICO’s £18.4 million penalty was a major regulatory consequence.
- Equifax: the breach was driven by an unpatched public-facing component and exposed highly durable identity data, including Social Security numbers and birth dates.
- eBay: employee-account compromise enabled network access, but PayPal financial information was kept separately. Password changes and phishing vigilance were still necessary because contact and birth-date data were exposed.
What organizations did after discovery
Typical remediation included invalidating or forcing resets for passwords, taking exposed databases offline, replacing vulnerable systems, notifying affected users, investigating access logs and cooperating with regulators or law enforcement. The consequences varied: Adult Friend Finder users faced cracked legacy hashes; Marriott faced a UK regulatory fine; and the Court Ventures perpetrator was criminally prosecuted. A breach notification does not mean every field was misused, but it identifies data that should be treated as potentially available to attackers.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What to do if your information appears in a breach
- Confirm the notice. Use the organization’s official website or a trusted notice, not a link in an unexpected email or text. Check which service, dates and data fields are named.
- Change the affected password immediately. Use a unique, long password stored in a password manager. Change it anywhere else you reused it, beginning with email, banking and social accounts.
- Enable multifactor authentication. Prefer an authenticator app or security key where offered; review and remove unfamiliar recovery email addresses, phone numbers and active sessions.
- Protect financial accounts. Review statements and card alerts. In the United States, place a credit freeze with Equifax, Experian and TransUnion or add a fraud alert; use the equivalent credit-report protections available in your country.
- Watch for targeted scams. Breach data makes believable password-reset, delivery, tax and banking messages easier to write. Do not disclose one-time codes or approve an unexpected login request.
- Handle identity documents carefully. If a Social Security number, passport number, driver’s-license data or biometric information was exposed, follow the notifying organization’s identity-restoration guidance and contact the issuing authority about replacement or monitoring options.
- Document and report fraud. Save notices, dates, transaction records and suspicious messages. Report identity theft to your national fraud-reporting service, financial institution and local law enforcement as appropriate.
Important limits on the ranking
Totals may be revised as investigations uncover older data or remove duplicates. NetEase is explicitly unverified. The National Public Data figures are estimates, and some records appeared outdated or inaccurate. LinkedIn and Yahoo are listed twice because their incidents were separate. Finally, an exposed record is evidence of availability, not proof that every record was downloaded or misused; the practical risk depends on the fields involved, whether credentials were protected, how long access lasted and how quickly the organization contained it.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

