Our Repository
Real-time insights into global data breaches. Explore patterns, risks, and trends to stay informed.
785
Total Breaches
11.63B
Exposed Records
5.19B
Unique Emails
836.0M
Exposed Passwords
Key Statistics
As of , the XposedOrNot data breach repository indexes 785 data breaches totalling 11,626,299,217 exposed records, including 5,193,759,555 unique email addresses and 835,955,029 exposed passwords.
The most affected industry is Entertainment with 222 breaches, followed by Information Technology (131) and Retail (109). Just 14 breaches account for 50% of all exposed records. The largest single breach, 1.4BillionRecords, exposed 1,114,303,554 records.
Key Insights
Live DataTop Contributors
14
breaches account for 50% of all records
Verified Breaches
751
95.7% of all breaches verified
Searchable
733
breaches available for lookup
Industries Affected
20
distinct sectors impacted
Yearly Breach Trend
| Year | Breaches |
|---|---|
| 2007 | 1 |
| 2008 | 2 |
| 2009 | 2 |
| 2010 | 3 |
| 2011 | 15 |
| 2012 | 14 |
| 2013 | 27 |
| 2014 | 41 |
| 2015 | 57 |
| 2016 | 77 |
| 2017 | 36 |
| 2018 | 53 |
| 2019 | 70 |
| 2020 | 78 |
| 2021 | 59 |
| 2022 | 51 |
| 2023 | 32 |
| 2024 | 53 |
| 2025 | 36 |
| 2026 | 78 |
Password Security Risk
| Risk level | Breaches |
|---|---|
| Plaintext | 84 |
| Easy to crack | 210 |
| Hard to crack | 157 |
| Unknown | 334 |
Most Exposed Data Types
| Data type | Share of breaches |
|---|---|
| Email Addresses | 100% |
| Passwords | 66% |
| Names | 52% |
| Usernames | 50% |
| Phone Numbers | 35% |
| IP Addresses | 35% |
| Physical Addresses | 28% |
| Dates of Birth | 25% |
Breach Size Distribution
Mega (100M+)
24
62.2% of records
Large (10M-100M)
107
28.2% of records
Medium (1M-10M)
279
8.5% of records
Small (100K-1M)
285
1.1% of records
Tiny (<100K)
90
0.04% of records
Identity Theft Risk Combinations
Full Identity Exposure
Name + DOB + Address + Phone combined
59
Breaches
1.13B
Records
Email + Government ID
High-risk for account takeover and fraud
24
Breaches
166.9M
Records
Email + Financial Data
Credit cards, SSN, account info exposed
8
Breaches
40.9M
Records
Breaches by Industry
Top 10 Largest Breaches
| Logo | Breach | Description | Records |
|---|---|---|---|
![]() | 1.4 Billion Records | 4iQ, a cybersecurity company, uncovered a massive credential collection in 2017 containing more than 1.4B unique username and password combinations along with email addresses and IP addresses. The dataset was widely circulated on dark web marketplaces and represented data aggregated from multiple prior breaches rather than a single incident. | 1.11B |
![]() | Collection #1 | Collection #1 is the name of a collection of email addresses and passwords that appeared on the dark web around January 2019. The database contains over 773 million unique email addresses, resulting in more than 2.7 billion email/password sets. | 790.8M |
![]() | Verifications | Verifications.io, a comprehensive email verification service, suffered a severe data breach in 2019 that compromised a vast array of personal user data. The exposed data included email addresses, phone numbers, dates of birth, and other personal details, which presented a considerable privacy and security risk to the affected users. | 762.6M |
![]() | Exploit.in | Exploit.IN was a hacking forum and marketplace that was hacked in 2016. The hacker gained access to the site's database, which contained over 590 million user accounts with email addresses, usernames, IP addresses, and hashed passwords. The database was subsequently made available for free download on a popular hacking forum. | 592.9M |
![]() | Anti Public Combo | The Anti Public Combo List, an aggregate collection consisting of data from various breaches, was made public on 2016.This compilation predominantly contained email addresses and passwords from multiple sources, thereby amplifying the potential risks to affected individuals. | 457.4M |
![]() | Alien Stealer Logs | ALIEN TXTBASE, a stealer log collection, was exposed in February 2025 when 23 billion rows of logs were obtained from a Telegram channel, revealing 299M unique email addresses along with the websites they were entered into and the passwords used. | 299.6M |
![]() | Alleged-SOCRadar | SOCRadar faced allegations from a threat actor, identified as USDoD, claiming a leak of over 330 million email addresses. However, SOCRadar's investigation revealed no breach of its internal systems. The actor had legitimately acquired access to SOCRadar's platform and utilized its capabilities to gather publicly available email addresses from Telegram channels. SOCRadar confirmed that no customer data or sensitive internal information was compromised. | 283.0M |
![]() | Wattpad | Wattpad, a self-publishing platform that claims to be “the world’s most-loved social storytelling platform,” suffered a data breach exposing all of its users. The leaked database included more than 270 million records with more than 268 million unique email address and password combinations. Exposed data includes email address, date of birth, gender if provided, IP address upon sign up, if signed up before 2017, display name, account name, and salted and cryptographically hashed passwords. | 268.1M |
![]() | Deezer | Deezer, a music streaming service, suffered a data breach that was made public in November 2022 but originally occurred in 2019. The breach exposed the personal details of 240 million users, including first and last names, dates of birth, email addresses, gender, location data, join date, user ID, session IP addresses, and language. | 244.0M |
![]() | NetEase | NetEase, a Chinese internet technology company, suffered a data breach in 2015, where personal information of around 200 million users was exposed, including email addresses, usernames, and hashed passwords. | 232.9M |
Recent Breaches
| Logo | Breach | Description | Records |
|---|---|---|---|
![]() | Chess (2026) | Chess.com, an online chess platform, had user data scraped and published online in August 2026, exposing 7.3M records including 4.6M unique email addresses along with usernames, names, countries, and other account information. | 4.7M |
![]() | Fanlore | Fanlore, a fan culture wiki operated by the Organization for Transformative Works, was compromised in August 2026, exposing 145k unique email addresses along with usernames and passwords stored as MD5 or PBKDF2 hashes. | 145.2K |
![]() | Baxter International | Baxter International, a healthcare and medical products company, was compromised in August 2026, exposing 489k unique email addresses along with names, geographic locations, physical addresses, and nationalities from more than 7.1M Salesforce records. | 489.0K |
![]() | Manchester Airports Group | Manchester Airports Group (MAG), an airport operator, was compromised in August 2026, with data later published by the FulcrumSec group exposing email addresses and phone numbers relating to 8.4M customers along with vehicle registrations, parking history, Fast Track purchases, and lounge bookings. | 8.4M |
![]() | Sharecare | Sharecare, a digital health company, was compromised in August 2026, exposing 326k unique email addresses along with names, phone numbers, titles, geographic locations, physical addresses, and internal corporate data from more than 3.4M Salesforce records. | 326.4K |
![]() | Lumenis | Lumenis, a medical device company, was compromised in August 2026, exposing 384k unique email addresses along with names, physical addresses, phone numbers, geographic locations, dates of birth, and internal corporate data from more than 1.1M records. | 384.2K |
![]() | Carhartt | Carhartt, a clothing retailer, was allegedly breached by the ShinyHunters group in August 2026, with data later published online exposing 24.9M unique email addresses along with names, phone numbers, and physical addresses. | 24.9M |
![]() | Questel | Questel, an intellectual property and innovation management company, was compromised in August 2026, exposing 1.7M unique email addresses along with physical addresses, dates of birth, phone numbers, and internal corporate data from more than 21M Salesforce records. | 1.7M |
![]() | Oz Hair and Beauty | Oz Hair and Beauty, an online beauty retailer, was breached in August 2026, exposing 2M unique email addresses along with names, phone numbers, and geographic location data. | 2.0M |
![]() | Brinks Home | Brinks Home, a home security company, was targeted by the ShinyHunters group in July 2026, with data later published online exposing 877k unique email addresses along with names, phone numbers, physical addresses, purchase information, and partial payment card data relating to leads, customers, and staff. | 877.1K |














