Original research

Two decades of data breaches

We analyzed 874 known data breaches from 2007 to 2026 — roughly 12.7 billion exposed accounts, more than one for every person alive. Email shows up in 99% of them, but the most dangerous payload is the password: 67% of breaches leak one — and that’s what turns a single leak into a chain of account takeovers.

ByNikita Silianov· Founder & CEO ·LinkedIn
67%
of breaches leak a password
99%
expose an email address
12.7B
accounts exposed across 874 breaches

Key findings

  • Passwords are the real danger. 67% of breaches leak a password — and because people reuse them, one leak gets tried against all your other accounts.
  • Your email is almost always in there. 99% of breaches expose an email address, the key that ties your leaked data together across incidents.
  • Breaches are data-rich. The typical breach exposes about 5.2 different types of personal data — not just a login, but names, phones (38%), addresses and dates of birth.
  • Exposure comes in waves. Across 20072026, billions of accounts leaked in the biggest years — and leaked data is resold for years afterward, so old breaches still hurt.

Accounts exposed, by year

Total accounts exposed in the known breaches dated to each year.

2012 · 16 breaches455M
2013 · 28 breaches523M
2014 · 45 breaches143M
2015 · 62 breaches140M
2016 · 84 breaches397M
2017 · 45 breaches337M
2018 · 66 breaches1.1B
2019 · 75 breaches2.7B
2020 · 89 breaches965M
2021 · 64 breaches692M
2022 · 52 breaches148M
2023 · 39 breaches118M
2024 · 72 breaches1.3B
2025 · 51 breaches2.8B
2026 · 66 breaches242M

What actually leaks

Share of the 874 breaches whose exposed records include each type of data.

Email addresses99%
Passwords67%
Names55%
Usernames47%
IP addresses38%
Phone numbers38%
Physical addresses30%
Dates of birth27%
Genders18%
Geographic locations14%
Purchases8%
Website activity8%

The 10 biggest breaches in the dataset

Ranked by accounts exposed — a single incident can leak hundreds of millions of records.

#BreachYearAccounts exposedData types
1Synthient Credential Stuffing Threat Data20252 billion2
2Verifications.io2019763 million10
3Data Enrichment Exposure From PDL Customer2019622 million7
4Facebook2019509 million8
5Combolists Posted to Telegram2024361 million3
6MySpace2008359 million3
7ALIEN TXTBASE Stealer Logs2025284 million2
8Not SOCRadar2024282 million1
9Wattpad2020269 million11
10Deezer2019229 million8

Breach, stealer log, or malware?

Not every exposure is a company being hacked. Of the 874 incidents, 863 are classic data breaches (an attacker steals a company’s user database). A growing share are stealer logs — data quietly harvested from people’s own infected devices by info-stealer malware, then compiled and sold in bulk — and the rest are other malware-harvested sets. Stealer logs are especially dangerous because they capture live passwords and session data straight from the victim’s browser, bypassing even a strong, unique password.

Two decades, two halves

Breach activity accelerated sharply in the second decade — more incidents and far more accounts.

PeriodBreachesAccounts exposed
2007–20162552.1 billion
2017–202661911 billion

Why the password is the story

It’s tempting to read breach news as a count of incidents, but the data tells a sharper story. Email addresses leak in nearly every breach (99%) — that’s the constant that lets criminals match your records across dozens of separate dumps into one profile. The password, present in 67% of breaches, is the payload: because most people reuse passwords, a single leaked credential is immediately replayed against your email, bank and shopping accounts. That’s credential stuffing, and it’s why one old breach you’ve forgotten can still drain a current account. Leaked data also doesn’t expire — it’s copied, sold and re-posted for years, so the 12.7 billion accounts in this dataset keep circulating long after the headlines fade. The defense is unglamorous but effective: a unique password per account, two-factor authentication, and ongoing monitoring so you know the moment your details resurface.

What to do if your data is in a breach

  1. Change the password on the breached account — and everywhere you reused it. Reuse is what turns one leak into many.
  2. Turn on two-factor authentication (an authenticator app or passkey beats SMS) so a stolen password alone can’t get in.
  3. Use a password manager to give every account a unique, strong password you don’t have to remember.
  4. Watch for breach-themed phishing. Scammers reference real breaches to look legitimate — never act on an unsolicited “reset” link; go to the site directly.
  5. Monitor for re-exposure. Leaked data is resold for years, so a one-time fix isn’t enough. Check your email and keep watching.

Key terms

Data breach. An incident where personal data is exposed or stolen — usually when attackers break into a company that holds it.
Credential stuffing. Attackers take username/password pairs leaked in one breach and automatically try them on other sites, exploiting password reuse.
Stealer log. Data harvested directly from an infected device by info-stealer malware — often including live passwords and active browser sessions.
Dark web. Parts of the internet not indexed by search engines, where leaked data is frequently traded, sold and re-posted.

Methodology

This analysis covers 874 known, verified data breaches catalogued in public breach databases, dated 20072026(snapshot current as of July 2026). “Prevalence” is the share of breaches whose exposed-data classes include a given category; account totals are the breach owners’ reported figures and are approximate. We excluded entries flagged as sensitive, fabricated, retired or spam. Browse the underlying breaches in our data breach directory.

Sources & further reading

Use this data

Free to cite under Creative Commons BY 4.0 with a link back. Copy the snippet to embed a headline stat:

<p>According to PersProtect's analysis of 874 data breaches, 67% leak passwords. <a href="https://persprotect.com/research/two-decades-of-data-breaches">Read the study</a>.</p>

Journalists: email support@persprotect.com for the full breakdown.

Cite this report

Free to share and cite under a Creative Commons BY 4.0 license, with attribution and a link back. Suggested citation:

PersProtect. (2026). Two Decades of Data Breaches. Retrieved from https://persprotect.com/research/two-decades-of-data-breaches

Journalists & researchers: email support@persprotect.com for the underlying data or an interview.

Is your password in one of these breaches?

Check your email against known breach and dark-web databases for free — in seconds, no account needed. Then we help you lock down what’s exposed and watch for new leaks.

See also: data breach directory · data-broker opt-out · more research

Common questions

About this study

What is the most commonly leaked data in a breach?

Across 874 known breaches, email addresses appear in 99% — but the most dangerous item is the password: 67% of breaches leak one. Names (55%) and phone numbers (38%) are also common.

How many accounts have been exposed in data breaches?

The 874 known breaches in our dataset span 2007–2026 and total roughly 12.7 billion exposed accounts — more than one for every person on Earth. The typical breach exposes about 5.2 different types of personal data.

Why are leaked passwords so dangerous?

Because people reuse them. A password leaked from one breach is immediately tried against your other accounts (credential stuffing), so a single leak can cascade into email, banking and shopping takeovers. That’s why reused passwords turn one breach into many.

What is credential stuffing?

Credential stuffing is when attackers take username and password pairs leaked in one breach and automatically try them on other sites — banking, email, shopping. It works because so many people reuse the same password, so one leak can unlock many accounts.

How long does leaked data stay dangerous?

Indefinitely. Breached data is copied, sold and re-posted across forums and dark-web markets for years, so an old breach you have forgotten can still be used against you. That is why ongoing monitoring matters more than a one-time cleanup.

Should I change my password after a breach?

Yes — change it on the breached account and anywhere you reused it, and turn on two-factor authentication. Using a password manager to give every account a unique password is the single most effective defense against credential stuffing.

Can I cite or reuse this data?

Yes — under a Creative Commons BY 4.0 license, with a link back. Email support@persprotect.com for the underlying breakdown.