Original research

Two decades of data breaches

We analyzed 885 known data breaches from 2007 to 2026 — roughly 12.7 billion exposed accounts, more than one for every person alive. Email shows up in 99% of them, but the most dangerous payload is the password: 66% of breaches leak one — and that’s what turns a single leak into a chain of account takeovers.

ByNikita Lushpanov· Chief Product Officer ·LinkedIn
66%
of breaches leak a password
99%
expose an email address
12.7B
accounts exposed across 885 breaches

Key findings

  • Passwords are the real danger. 66% of breaches leak a password — and because people reuse them, one leak gets tried against all your other accounts.
  • Your email is almost always in there. 99% of breaches expose an email address, the key that ties your leaked data together across incidents.
  • Breaches are data-rich. The typical breach exposes about 5.2 different types of personal data — not just a login, but names, phones (38%), addresses and dates of birth.
  • Exposure comes in waves. Across 20072026, billions of accounts leaked in the biggest years — and leaked data is resold for years afterward, so old breaches still hurt.
  • 2026 has already passed 2025 on count, and the payload has changed. 76 breaches are dated to 2026 against 52 for all of 2025, but a password shows up in only 16% of them (31% a year earlier), while home addresses (63% vs 38%) and phone numbers (70% vs 48%) are in far more.

2026 so far: more breaches, less that you can reset

On 14 August 2026, CNBC and Quartz both reported that breach notifications sent out this year had already overtaken the whole of 2025, with attacks involving AI named as part of the rise. Those are US notification counts. Our dataset measures something different — breach records that reached the public breach databases, worldwide — and it moves the same way.

20252026 to date
Breaches dated to the year5276
Accounts exposed2.9 billion262 million
Leaked a password31%16%
Leaked a home address38%63%
Leaked a phone number48%70%
Leaked a government ID number4%11%
Types of data per breach4.65.7

More incidents, smaller sets, richer records. The 2026 breaches carry 5.7 types of personal data each against 4.6 a year earlier, and the extra fields are the ones tied to you rather than to a login: where you live, what your number is, and in 11% of cases a government ID number. That is the signature of records lifted out of a company’s customer, order or HR systems rather than out of a login table, which is how most of this year’s extortion cases have been described by the companies themselves. It changes what a response looks like. A password you can change in a minute; an address, a phone number and a date of birth stay valid for years, and the only thing that reduces that exposure is getting the same details off the sites that republish them.

Two caveats worth stating. 2026 is still running and breach records surface months after the event, so both columns will keep growing and the gap will widen further. And the AI attribution above is the reporting’s, not ours: how an intruder got in is not recorded in these records, so nothing in this table confirms or denies it.

Accounts exposed, by year

Total accounts exposed in the known breaches dated to each year.

2012 · 16 breaches455M
2013 · 28 breaches523M
2014 · 45 breaches143M
2015 · 62 breaches140M
2016 · 84 breaches397M
2017 · 45 breaches337M
2018 · 66 breaches1.1B
2019 · 75 breaches2.7B
2020 · 89 breaches965M
2021 · 64 breaches692M
2022 · 52 breaches148M
2023 · 39 breaches118M
2024 · 72 breaches1.3B
2025 · 52 breaches2.9B
2026 · 76 breaches262M

What actually leaks

Share of the 885 breaches whose exposed records include each type of data.

Email addresses99%
Passwords66%
Names56%
Usernames47%
Phone numbers38%
IP addresses38%
Physical addresses30%
Dates of birth27%
Genders18%
Geographic locations14%
Purchases8%
Website activity7%

The 10 biggest breaches in the dataset

Ranked by accounts exposed — a single incident can leak hundreds of millions of records.

#BreachYearAccounts exposedData types
1Synthient Credential Stuffing Threat Data20252 billion2
2Verifications.io2019763 million10
3Data Enrichment Exposure From PDL Customer2019622 million7
4Facebook2019509 million8
5Combolists Posted to Telegram2024361 million3
6MySpace2008359 million3
7ALIEN TXTBASE Stealer Logs2025284 million2
8Not SOCRadar2024282 million1
9Wattpad2020269 million11
10Deezer2019229 million8

Breach, stealer log, or malware?

Not every exposure is a company being hacked. Of the 885 incidents, 874 are classic data breaches (an attacker steals a company’s user database). A growing share are stealer logs — data quietly harvested from people’s own infected devices by info-stealer malware, then compiled and sold in bulk — and the rest are other malware-harvested sets. Stealer logs are especially dangerous because they capture live passwords and session data straight from the victim’s browser, bypassing even a strong, unique password.

Two decades, two halves

Breach activity accelerated sharply in the second decade — more incidents and far more accounts.

PeriodBreachesAccounts exposed
2007–20162552.1 billion
2017–202663011 billion

Why the password is the story

It’s tempting to read breach news as a count of incidents, but the data tells a sharper story. Email addresses leak in nearly every breach (99%) — that’s the constant that lets criminals match your records across dozens of separate dumps into one profile. The password, present in 66% of breaches, is the payload: because most people reuse passwords, a single leaked credential is immediately replayed against your email, bank and shopping accounts. That’s credential stuffing, and it’s why one old breach you’ve forgotten can still drain a current account. Leaked data also doesn’t expire — it’s copied, sold and re-posted for years, so the 12.7 billion accounts in this dataset keep circulating long after the headlines fade. The defense is unglamorous but effective: a unique password per account, two-factor authentication, and ongoing monitoring so you know the moment your details resurface.

What to do if your data is in a breach

  1. Change the password on the breached account — and everywhere you reused it. Reuse is what turns one leak into many.
  2. Turn on two-factor authentication (an authenticator app or passkey beats SMS) so a stolen password alone can’t get in.
  3. Use a password manager to give every account a unique, strong password you don’t have to remember.
  4. Watch for breach-themed phishing. Scammers reference real breaches to look legitimate — never act on an unsolicited “reset” link; go to the site directly.
  5. Monitor for re-exposure. Leaked data is resold for years, so a one-time fix isn’t enough. Check your email and keep watching.

Key terms

Data breach. An incident where personal data is exposed or stolen — usually when attackers break into a company that holds it.
Credential stuffing. Attackers take username/password pairs leaked in one breach and automatically try them on other sites, exploiting password reuse.
Stealer log. Data harvested directly from an infected device by info-stealer malware — often including live passwords and active browser sessions.
Dark web. Parts of the internet not indexed by search engines, where leaked data is frequently traded, sold and re-posted.

Methodology

This analysis covers 885 known, verified data breaches catalogued in public breach databases, dated 20072026(snapshot current as of August 2026). “Prevalence” is the share of breaches whose exposed-data classes include a given category; account totals are the breach owners’ reported figures and are approximate. We excluded entries flagged as sensitive, fabricated, retired or spam. Browse the underlying breaches in our data breach directory.

Sources & further reading

Use this data

Free to cite under Creative Commons BY 4.0 with a link back. Copy the snippet to embed a headline stat:

<p>According to PersProtect's analysis of 885 data breaches, 66% leak passwords. <a href="https://persprotect.com/research/two-decades-of-data-breaches">Read the study</a>.</p>

Journalists: email support@persprotect.com for the full breakdown.

Cite this report

Free to share and cite under a Creative Commons BY 4.0 license, with attribution and a link back. Suggested citation:

PersProtect. (2026). Two Decades of Data Breaches. Retrieved from https://persprotect.com/research/two-decades-of-data-breaches

Journalists & researchers: email support@persprotect.com for the underlying data or an interview.

Is your password in one of these breaches?

Check your email against known breach and dark-web databases for free — in seconds, no account needed. Then we help you lock down what’s exposed and watch for new leaks.

See also: data breach directory · data-broker opt-out · more research

Common questions

About this study

What is the most commonly leaked data in a breach?

Across 885 known breaches, email addresses appear in 99% — but the most dangerous item is the password: 66% of breaches leak one. Names (56%) and phone numbers (38%) are also common.

How many accounts have been exposed in data breaches?

The 885 known breaches in our dataset span 2007–2026 and total roughly 12.7 billion exposed accounts — more than one for every person on Earth. The typical breach exposes about 5.2 different types of personal data.

Why are leaked passwords so dangerous?

Because people reuse them. A password leaked from one breach is immediately tried against your other accounts (credential stuffing), so a single leak can cascade into email, banking and shopping takeovers. That’s why reused passwords turn one breach into many.

What is credential stuffing?

Credential stuffing is when attackers take username and password pairs leaked in one breach and automatically try them on other sites — banking, email, shopping. It works because so many people reuse the same password, so one leak can unlock many accounts.

How long does leaked data stay dangerous?

Indefinitely. Breached data is copied, sold and re-posted across forums and dark-web markets for years, so an old breach you have forgotten can still be used against you. That is why ongoing monitoring matters more than a one-time cleanup.

Should I change my password after a breach?

Yes — change it on the breached account and anywhere you reused it, and turn on two-factor authentication. Using a password manager to give every account a unique password is the single most effective defense against credential stuffing.

Can I cite or reuse this data?

Yes — under a Creative Commons BY 4.0 license, with a link back. Email support@persprotect.com for the underlying breakdown.