Learn what to do when your personal information is exposed in a data breach β and understand that it is often NOT your fault.
β οΈ Important: Breaches Happen to Companies β Not Just Individuals
Even if you are careful online, your data can be stolen when companies that hold your information get hacked. Banks, hospitals, insurance companies, and even the government have all been breached. Being in a breach does not mean you did anything wrong.
These are all real events. Hackers attacked businesses, hospitals, police departments, the U.S. government, and even the water supply β not just individuals.
147 million affected
Social Security numbers, birth dates, addresses, credit card numbers
3 billion affected
Emails, passwords, security questions and answers, phone numbers
54 million affected
Names, Social Security numbers, phone numbers, addresses, driver's license info
533 million affected
Phone numbers, full names, locations, email addresses, birthdates
700 million affected
Email addresses, phone numbers, geolocation data, work history
73 million affected
Social Security numbers, account numbers, passcodes, mailing addresses
190 million affected
Medical records, insurance info, Social Security numbers, payment information
40 million affected
Credit/debit card numbers, names, addresses, phone numbers, email addresses
500 million affected
Passport numbers, names, addresses, phone numbers, credit card info, travel history
78 million affected
Social Security numbers, medical IDs, income data, home addresses, employment info
106 million affected
Credit card applications, Social Security numbers, bank account numbers
56 million affected
Credit/debit card numbers stolen from in-store payment terminals
1.1 million affected
Credit and debit card numbers, including security codes
145 million affected
Names, addresses, dates of birth, email addresses, passwords
3 million affected
Names, Social Security numbers, credit scores, and address history
22 million affected
Fingerprints, Social Security numbers, security clearance records, background investigation files of federal employees
612,000 affected
Names, addresses, Social Security numbers, Medicare numbers of elderly patients
6 million affected
Driver's license numbers, Social Security numbers, vehicle registration data
3.5 million affected
Driver's license numbers, Social Security numbers β stolen via a software vendor breach
500,000+ affected
Student Social Security numbers, grades, disciplinary records, health info
400 hospitals shut down affected
400 hospitals across the U.S. lost access to computer systems. Staff used paper and pencil for days. Patient care was delayed.
Entire East Coast affected
Ransomware shut down 5,500 miles of gas pipeline. Gas stations ran out of fuel across the East Coast for 6 days. The company paid $4.4 million in ransom.
Entire city's water supply affected
Hackers remotely increased sodium hydroxide levels to dangerous amounts. An operator caught it in time. This could have poisoned the water supply.
Entire city government affected
Ransomware shut down Atlanta city systems. Police could not look up criminal records. Residents couldn't pay water bills online. Cost $17 million to fix.
Entire city government affected
City paid $600,000 in Bitcoin to hackers after ransomware encrypted all city data including police records.
Patients diverted away affected
Ransomware forced the hospital to turn away emergency patients. A woman who needed urgent care died after being rerouted to a distant hospital.
U.S. beef supply disrupted affected
Ransomware shut down beef processing plants across the U.S., Canada, and Australia. The company paid $11 million in ransom to restore operations.
U.S. Federal Government affected
Russian hackers secretly accessed emails at the U.S. Treasury, Pentagon, State Department, and dozens of other agencies for 9 months undetected.
Entire country's healthcare affected
Ransomware shut down Ireland's entire national healthcare computer system. Cancer appointments and surgeries were cancelled nationwide for weeks.
230,000 residents affected
Russian hackers shut off electricity for 230,000 people in the middle of winter. First confirmed cyberattack to knock out a power grid.
Phishing Attacks on Employees
A company employee receives a fake email and clicks a malicious link. Hackers use that one employee's computer to access company servers.
Weak or Reused Passwords
Hackers buy stolen passwords from other breaches and try them on other websites. If a company employee reuses passwords, one stolen password unlocks everything.
Unpatched Software
Companies fail to update their computer systems. Hackers exploit known security holes in old software to break in.
Insider Threats
A disgruntled employee or contractor intentionally leaks or steals data. This accounts for about 20% of all breaches.
Misconfigured Cloud Storage
Companies store your data in the cloud but accidentally leave it publicly accessible. Anyone who finds the link can download millions of records.
Third-Party Vendor Hacks
A company's supplier or partner gets hacked. Because they have access to the company's systems, hackers get in through the back door.