Our Repository
Real-time insights into global data breaches. Explore patterns, risks, and trends to stay informed.
768
Total Breaches
11.54B
Exposed Records
5.13B
Unique Emails
836.0M
Exposed Passwords
Key Statistics
As of , the XposedOrNot data breach repository indexes 768 data breaches totalling 11,542,386,487 exposed records, including 5,134,275,604 unique email addresses and 835,955,029 exposed passwords.
The most affected industry is Entertainment with 220 breaches, followed by Information Technology (128) and Retail (107). Just 14 breaches account for 51% of all exposed records. The largest single breach, 1.4BillionRecords, exposed 1,114,303,554 records.
Key Insights
Live DataTop Contributors
14
breaches account for 51% of all records
Verified Breaches
734
95.6% of all breaches verified
Searchable
716
breaches available for lookup
Industries Affected
20
distinct sectors impacted
Yearly Breach Trend
| Year | Breaches |
|---|---|
| 2007 | 1 |
| 2008 | 2 |
| 2009 | 2 |
| 2010 | 3 |
| 2011 | 15 |
| 2012 | 14 |
| 2013 | 27 |
| 2014 | 41 |
| 2015 | 57 |
| 2016 | 77 |
| 2017 | 36 |
| 2018 | 53 |
| 2019 | 70 |
| 2020 | 78 |
| 2021 | 59 |
| 2022 | 51 |
| 2023 | 32 |
| 2024 | 53 |
| 2025 | 35 |
| 2026 | 62 |
Password Security Risk
| Risk level | Breaches |
|---|---|
| Plaintext | 84 |
| Easy to crack | 210 |
| Hard to crack | 155 |
| Unknown | 319 |
Most Exposed Data Types
| Data type | Share of breaches |
|---|---|
| Email Addresses | 100% |
| Passwords | 67% |
| Names | 51% |
| Usernames | 51% |
| IP Addresses | 36% |
| Phone Numbers | 34% |
| Physical Addresses | 27% |
| Dates of Birth | 25% |
Breach Size Distribution
Mega (100M+)
24
62.7% of records
Large (10M-100M)
104
27.9% of records
Medium (1M-10M)
274
8.4% of records
Small (100K-1M)
276
1.1% of records
Tiny (<100K)
90
0.04% of records
Identity Theft Risk Combinations
Full Identity Exposure
Name + DOB + Address + Phone combined
54
Breaches
1.08B
Records
Email + Government ID
High-risk for account takeover and fraud
24
Breaches
166.9M
Records
Email + Financial Data
Credit cards, SSN, account info exposed
8
Breaches
40.9M
Records
Breaches by Industry
Top 10 Largest Breaches
| Logo | Breach | Description | Records |
|---|---|---|---|
![]() | 1.4BillionRecords | 4iQ, a cybersecurity company, uncovered a massive credential collection in 2017 containing more than 1.4B unique username and password combinations along with email addresses and IP addresses. The dataset was widely circulated on dark web marketplaces and represented data aggregated from multiple prior breaches rather than a single incident. | 1.11B |
![]() | Collection-1 | Collection #1 is the name of a collection of email addresses and passwords that appeared on the dark web around January 2019. The database contains over 773 million unique email addresses, resulting in more than 2.7 billion email/password sets. | 790.8M |
![]() | Verifications | Verifications.io, a comprehensive email verification service, suffered a severe data breach in 2019 that compromised a vast array of personal user data. The exposed data included email addresses, phone numbers, dates of birth, and other personal details, which presented a considerable privacy and security risk to the affected users. | 762.6M |
![]() | ExploitIN | Exploit.IN was a hacking forum and marketplace that was hacked in 2016. The hacker gained access to the site's database, which contained over 590 million user accounts with email addresses, usernames, IP addresses, and hashed passwords. The database was subsequently made available for free download on a popular hacking forum. | 592.9M |
![]() | AntiPublicCombo | The Anti Public Combo List, an aggregate collection consisting of data from various breaches, was made public on 2016.This compilation predominantly contained email addresses and passwords from multiple sources, thereby amplifying the potential risks to affected individuals. | 457.4M |
![]() | AlienStealerLogs | ALIEN TXTBASE, a stealer log collection, was exposed in February 2025 when 23 billion rows of logs were obtained from a Telegram channel, revealing 299M unique email addresses along with the websites they were entered into and the passwords used. | 299.6M |
![]() | Alleged-SOCRadar | SOCRadar faced allegations from a threat actor, identified as USDoD, claiming a leak of over 330 million email addresses. However, SOCRadar's investigation revealed no breach of its internal systems. The actor had legitimately acquired access to SOCRadar's platform and utilized its capabilities to gather publicly available email addresses from Telegram channels. SOCRadar confirmed that no customer data or sensitive internal information was compromised. | 283.0M |
![]() | Wattpad | Wattpad, a self-publishing platform that claims to be “the world’s most-loved social storytelling platform,” suffered a data breach exposing all of its users. The leaked database included more than 270 million records with more than 268 million unique email address and password combinations. Exposed data includes email address, date of birth, gender if provided, IP address upon sign up, if signed up before 2017, display name, account name, and salted and cryptographically hashed passwords. | 268.1M |
![]() | Deezer | Deezer, a music streaming service, suffered a data breach that was made public in November 2022 but originally occurred in 2019. The breach exposed the personal details of 240 million users, including first and last names, dates of birth, email addresses, gender, location data, join date, user ID, session IP addresses, and language. | 244.0M |
![]() | NetEase | NetEase, a Chinese internet technology company, suffered a data breach in 2015, where personal information of around 200 million users was exposed, including email addresses, usernames, and hashed passwords. | 232.9M |
Recent Breaches
| Logo | Breach | Description | Records |
|---|---|---|---|
![]() | Autocentrum | Autocentrum.pl, a popular automotive website, suffered a data breach on 2018. The compromised data included passwords and email addresses of Autocentrum.pl users | 164.6K |
![]() | Paytm | Paytm, an Indian mobile payments and financial services provider, experienced a data breach around August 2020. This incident affected approximately 3.3 million customers, exposing their email addresses, full names, physical addresses, phone numbers, and income levels. | 3.4M |
![]() | Fluke | Fluke, an electronic test and measurement equipment manufacturer, was allegedly breached by the ShinyHunters group in June 2026, with data later published online exposing more than 800k unique email addresses along with names, phone numbers, physical addresses, and support case information. | 862.5K |
![]() | ACTMobile | ActMobile, the company behind Dash VPN and FreeVPN, was compromised in October 2021, exposing 10M unique email addresses along with IP addresses and password hashes. The data was later shared on a hacking forum. | 10.1M |
![]() | GlendaleCommunityCollege | Glendale Community College, a public community college, was allegedly breached by the ShinyHunters group in June 2026, with data later published online exposing almost 1.4M unique email addresses along with names, addresses, phone numbers, Social Security numbers, and student enrolment information. | 1.4M |
![]() | Turknet | TurkNet, a major Turkish internet service provider, was breached in March 2025, exposing over 2.8M customer records including dates of birth, email addresses, static IP addresses, names, national ID numbers, phone numbers, physical addresses, and a small number of plaintext passwords and usernames. | 5.3M |
![]() | Mercer | Mercer Advisors, a financial advisory firm, was allegedly breached by the ShinyHunters group in February 2026, exposing 321k unique email addresses along with names, phone numbers, physical addresses, and dates of birth. | 320.7K |
![]() | Maxance | Maxance, a French wholesale insurance broker, was breached in December 2024 with the data later leaked, exposing over 348k client records including 268k unique email addresses, names, genders, IBANs, physical addresses, phone numbers, login details, and vehicle information. | 268.8K |
![]() | IllinoisCentralCollege | Illinois Central College, a community college, was allegedly breached by the ShinyHunters group in June 2026, exposing 220k unique email addresses along with names, usernames, phone numbers, and dates of birth. | 220.2K |
![]() | Sysco | Sysco, a food distribution company, was targeted by ShinyHunters in June 2026, with data later published online exposing 2.7M unique email addresses along with names, phone numbers, physical addresses, internal job titles, and other corporate contact information belonging to staff and customers. | 2.7M |














