You already know the ritual. A big breach hits the news, your CEO forwards the article with "are we exposed to this?", and you spend an hour confirming you're not before getting back to actual work. The recent-breaches list is the most-read content in security, and almost nobody does anything with it.
That's the gap this page tries to close. Below you'll find the biggest data breaches on record, the latest confirmed incidents of 2026, and a plain-English breakdown of why they happened. But the useful part isn't the list. It's the pattern underneath it, because the pattern is what tells you whether your organization would survive the same attack, and the pattern almost always ends at a device someone forgot to watch.
We track confirmed incidents only: official breach notifications, regulator filings, and reputable reporting. For each, the questions that matter to an IT or security team are the same three. What was exposed, how did they get in, and what would have contained it faster.
Recent data breaches keep getting more expensive, too. IBM's 2025 Cost of a Data Breach Report put the average U.S. breach at an all-time-high $10.22 million, up 9% in a single year, even as the global average fell. The U.S. has led the world on breach cost for 15 years running.
What counts as a recent data breach?
A data breach is confirmed when sensitive information is accessed, stolen, or exposed: customer records, employee files, payment details, or intellectual property. That differs from a cyberattack that only disrupts operations. A ransomware event that also exfiltrates files is both; a DDoS that just knocks a site offline is an incident, not a breach.
For an event to make this list, one of these has to be true
- Personal or corporate data was confirmed exposed.
- A company or regulator issued a formal breach notification.
- Credible reporting tied the event to stolen or leaked data.
We verify each entry against at least two sources: regulator filings, company disclosures, and independent investigations. If something is still under investigation, we say so. That keeps the difference between a real breach and dark-web bravado clear, which matters more than it sounds, because plenty of "mega-breach" headlines turn out to be recycled data. For the underlying concepts, our guide to what data security actually covers is the companion read.
The biggest data breaches, and the latest
The biggest data breach in history is still the Yahoo breach, which exposed all 3 billion user accounts across 2013 and 2014. The largest recent one is the 2024 National Public Data leak, which put roughly 2.9 billion records, including Social Security numbers, into circulation, some of it stored in plain text. Neither was a clever zero-day. Both came down to data that was over-collected and under-protected.
That's the through-line for the landmark breaches worth knowing:
- Yahoo (2013-2014), 3 billion accounts. The largest confirmed breach ever. Names, emails, and hashed passwords for every account Yahoo had.
- National Public Data (2024), ~2.9 billion records. A background-check data broker most victims had never heard of, exposing SSNs and addresses.
- Snowflake-linked campaign (2024), dozens of firms. Attackers used stolen customer credentials with no MFA to loot cloud data warehouses, hitting Ticketmaster (560M records), Santander, AT&T, and more.
- The "16 billion credentials" story (2025). Widely reported as the biggest leak ever. It wasn't a breach at all. It was a compilation of previously stolen infostealer logs, repackaged. Aggregated old data is not a new incident, and knowing the difference is part of the job.
If you want the ranked, exhaustive version, UpGuard and Fortinet maintain long historical lists. What they don't do is tell you what to change, which is the rest of this page.
The latest breaches (2026)
Fresh incidents follow the same script as the historical ones. A quick roundup of confirmed 2026 disclosures:
Fresh incidents follow the same script as the historical ones. A quick roundup of confirmed 2026 disclosures:
- Coca-Cola / fairlife. A ransomware attack on Coca-Cola's fairlife dairy subsidiary halted U.S. production, and the Anubis group claimed it stole around 1TB of data. Coca-Cola disclosed it in an SEC filing and later confirmed data theft.
- Bank of Baroda (India). Roughly 1TB reportedly exposed by the TripleX group, including up to 300,000 customers' Aadhaar numbers and account records. The bank confirmed the root cause: one compromised employee email account, reached through a weak password.
- UK Police (PNLD) and the Department for Education. One campaign by a group calling itself ExfilSquad. Around 135,000 records from the Police National Legal Database surfaced on the dark web (traced to a Microsoft Power Platform misconfiguration), alongside roughly 607,000 DfE contact records.
- Healthcare stayed the top target. Providers and health-tech vendors continued to file the largest volume of notifications, and healthcare again carried the highest average breach cost of any sector.
The specifics change monthly. The causes don't.
Data breach snapshot table
A scannable version of the incidents above, plus the landmark breaches for context. Sorted newest first.
The pattern behind the headlines
Strip the logos off the news and almost every recent breach reduces to one of four causes. That's the useful part, because a cause maps to a control, and a control has a realistic containment window.
The most common cause is credential compromise. A phished login, a reused password, or an infostealer that scraped a session token. Bank of Baroda's 2026 breach started with exactly this, one employee email reached through a weak password, and the 284-million-email TXTBASE stealer dataset shows how many valid logins are harvested daily. Stolen credentials don't trip alarms, so attackers linger for weeks. The control is credential monitoring plus MFA, with dark-web exposure monitoring as the early-warning layer.
Third-party and supply-chain exposure is the second. Allianz Life's breach began at a CRM vendor, Hertz's at a file-transfer provider. Your perimeter can be airtight while a partner's back door is open. The control is vendor inventory and least-privilege access.
Unpatched systems and misconfigurations are the third. The UK police PNLD leak traced back to a misconfigured Microsoft Power Platform setup; in cloud environments, one exposed bucket or stale token can expose millions of records. The control is knowing what you run and its state, which is an inventory problem before it's a patching one.
Ransomware is the fourth, now evolved from encrypt-and-extort to steal-then-extort, as the fairlife and McLaren Health Care incidents both showed. Segmented backups decide whether you recover in hours or negotiate for days.
Four causes, four control families. For the deeper anatomy of each, our breakdown of what actually causes data breaches goes further. The point here: the pattern behind the headline is boringly consistent, and it almost always terminates at an endpoint.
Quick win: Take your last real incident or near-miss and sort it into one of these four buckets. Whichever bucket it lands in is the control family you're weakest on. Start there.
What to do after a breach
Once a breach is confirmed, the clock starts, and it's a compliance clock and a trust clock at the same time. Notification timelines are non-negotiable: GDPR gives you 72 hours to notify authorities, HIPAA gives 60 days for affected individuals, and most U.S. state laws require disclosure "without unreasonable delay." Our breach response guide walks the full sequence.
Containment comes first, notification second, but they run almost in parallel. In practice the order that limits damage looks like this:
- Contain. Isolate affected systems, revoke exposed credentials, and lock or wipe compromised devices before more data walks out.
- Assess. Confirm what was exposed and for whom. You can't notify accurately if you don't know the scope.
- Notify. Tell regulators and affected people what happened, when, what you're doing, and what they should do.
- Fix the class, not the instance. If credentials were the way in, the follow-up is MFA everywhere and credential monitoring, not just resetting the one account.
Quick win: Write down, today, who has authority to trigger a remote lock or wipe at 2 a.m. without waiting for a meeting. If that person and that process aren't defined before an incident, your containment window is however long it takes to schedule a call.
The endpoint controls that would have contained these
Here's what the big breach roundups leave out, and it's the same omission in every one of them: they tell you what happened and stop. The two highest-authority lists on this exact topic, from Fortinet and UpGuard, both stop at description with little remediation guidance and no realistic containment windows. For an IT team, that's the only part that matters. You can't un-breach Yahoo. You can decide whether the same attack pattern gets contained on your fleet in minutes or in weeks.
Map the four causes to what actually stops them on the endpoint:
- Lost or stolen device with company data on it. This is the breach vector nobody puts on a slide, and it's the single most common scenario IT teams actually describe to us: a device was stolen or never returned, and all the company data is on it. Not a sophisticated hack. The control is always-on device visibility plus one-click remote lock and wipe, and the metric that matters is time-to-wipe. One MSP testing Intune measured a remote wipe taking 34 minutes just to start. That's 34 minutes of exposure a purpose-built response tool closes in a fraction of the time.
- Credential compromise. MFA, credential-reuse monitoring, and dark-web alerts so a leaked login is a same-day event, not a same-quarter one. Pair it with layered detection.
- Offboarding gaps. As one MSP put it, "even after disabling a user's account, employees can still delete data stored locally due to cached credentials." Lock or wipe on exit, don't just disable the account.
- Unpatched and unmanaged devices. You can't secure what you can't see. A live hardware and software inventory tells you which machines are missing patches, missing encryption, or missing entirely.
This is where endpoint management tools earn their place. Prey exists for exactly this layer: always-on location and visibility across Windows, macOS, Linux, Android, iOS and Chromebook, remote lock and full remote wipe, encryption status, and hardware and software inventory, all from one dashboard. It won't stop a determined nation-state APT. It will make sure the far more common story, the laptop that walked out the door, is contained in minutes instead of becoming next quarter's notification. For the broader control set, our data security controls and prevention guides go wider.
Quick win: Pick one lost-or-stolen scenario and time it. From "device reported missing" to "data confirmed wiped," how long is your process right now? If you can't answer in a number, that's the gap.
Reading the news vs. reducing your risk
Reading the breach list is easy. It's the security equivalent of doomscrolling: informative, faintly alarming, and completely passive. The teams that actually reduce risk do one extra thing. They take each headline, find which of the four patterns it belongs to, and ask whether that pattern would be contained on their own fleet, and how fast.
That's the difference between reading the news and reducing your risk. Visibility over your devices, a control that can act on them remotely, and the evidence to prove both worked. The next breach in the list is already being written. Whether your organization is in it depends less on the attacker's sophistication than on how quickly you can see and lock the endpoint where it lands.
Frequently asked questions
What are the most recent data breaches?
As of 2026, confirmed incidents include the Coca-Cola/fairlife ransomware attack (production halted, data stolen), Bank of Baroda in India (~1TB exposed via a compromised employee email), and a UK public-sector campaign hitting the police PNLD (~135,000 records) and the Department for Education (~607,000 records). Healthcare continues to file the highest volume of notifications of any sector.
What is the biggest data breach ever?
The biggest data breach in history is the Yahoo breach, which exposed all 3 billion user accounts between 2013 and 2014. The largest recent one is the 2024 National Public Data leak of roughly 2.9 billion records, including Social Security numbers. The widely reported "16 billion credentials" of 2025 was a compilation of old stolen data, not a single new breach.
How are data breaches different from cyberattacks?
A cyberattack is any malicious action against systems, including disruption, fraud, or ransomware. A data breach is the specific outcome where sensitive data is confirmed accessed, stolen, or leaked. Every breach involves an attack, but not every attack results in a breach.
What are the main causes of the latest data breaches?
Four causes account for the vast majority: stolen or phished credentials, third-party and supply-chain compromise, unpatched systems or misconfigurations, and ransomware with data exfiltration. These stayed consistent across 2025 and 2026 incidents.
How can organizations prevent future breaches?
Enforce MFA, monitor for leaked credentials, keep a live device inventory with patch and encryption status, apply least-privilege access to vendors, segment networks, and test backups. Most importantly, shorten your containment window so a compromised device is locked in minutes. See our prevention guide for the full set.
Where can I check if my data was exposed in a recent breach?
Individuals can use services like Have I Been Pwned or follow official breach notifications. If you want to know whether your organization's credentials are circulating, check whether your accounts have been compromised and monitor the dark web for credential dumps tied to your domain.
Most breaches end at a device someone lost track of. Prey gives IT teams always-on visibility and one-click remote lock and wipe across the whole fleet, so a lost laptop is a contained event, not a breach notification. See how it works with a demo.




