The largest confirmed data breach of all time is Yahoo's 2013 breach, which exposed all 3 billion of its user accounts, according to Verizon's October 2017 disclosure. Yahoo first reported it in December 2016 as affecting 1 billion accounts, then Verizon revised the total to every account after acquiring Yahoo's core business.

That single number dwarfs every other confirmed breach by accounts affected, but a clean ranking is harder than it looks. Some of the biggest figures in circulation are scrapes of public data rather than hostile intrusions, and a few of the biggest of all are compilations that re-package prior breaches into one giant file. The ranking below separates those categories so the count means what it says.

What is the biggest data breach of all time?

Yahoo's 2013 breach is the largest confirmed data breach by accounts affected, at 3 billion accounts. Yahoo disclosed the incident in December 2016, initially estimating 1 billion accounts, then Verizon, which acquired Yahoo's core business, announced in October 2017 that all 3 billion accounts had been affected.

The stolen data included names, email addresses, telephone numbers, dates of birth, and hashed passwords. A separate Yahoo breach from 2014, disclosed in September 2016, affected at least 500 million accounts and is counted as its own incident rather than folded into the 3 billion figure. The two are distinct events with different attributions, which is why serious rankings list them separately rather than summing them.

Largest single-incident breaches by records affected (millions) Yahoo 20133,000MNat. Public Data2,900MAadhaar1,100MAlibaba1,100MLinkedIn700MTicketmaster560MSina Weibo538MFacebook533M

Figure 1: Ranked by claimed records, with contested figures included. Sources: Verizon disclosure (2017), National Public Data statement (2024), The Tribune / UIDAI dispute (2018).

The takeaway: no other confirmed single breach comes within a billion accounts of Yahoo 2013.

What are the 10 biggest data breaches ever?

Ranked by claimed accounts or records affected, the top single-incident breaches run from Yahoo's 3 billion down to Marriott's corrected 383 million. Several entries carry caveats, marked in the table, because the raw number is contested, self-reported, or describes a scrape rather than a hack.

RankBreach (year)Records affectedNote
1Yahoo (2013)3 billion accountsConfirmed, revised up in 2017
2National Public Data (2024)2.9 billion rowsSelf-reported rows, not unique people
3Aadhaar / UIDAI (2018)1.1 billion recordsDenied by UIDAI
4Alibaba / Taobao (2019)1.1 billion data pointsScrape by a rogue contractor
5LinkedIn (2021)700 million recordsScrape of public profiles
6Ticketmaster (2024)560 million recordsAttacker-claimed figure
7Sina Weibo (2020)538 million recordsCompany-confirmed
8Facebook (2019 or 2021)533 million recordsScrape, not a hack
9Yahoo (2014)500 million accountsSeparate incident
10Marriott / Starwood (2018)383 million recordsRevised down from 500 million
Largest confirmed or reported incident by year (records, millions) 01,0002,0003,0004,000M20132014201820192020202120242,900M

Figure 2: The single largest incident reported in each year, showing how mega-breaches recur. Sources: Verizon (2017), The Tribune (2018), National Public Data statement (2024).

First American Financial exposed roughly 885 million documents in 2019, which would rank high by raw count, but that was a misconfigured public website rather than a breach, so it sits in its own category. The long tail below the top 10 includes Adobe's 153 million credentials (2013), Equifax's 147 million consumers (2017), and a Twitter/X scrape of more than 200 million records surfaced in 2023, alongside dozens of smaller incidents that push a full "top 40" list well past the 100 million mark at its lower end. Interested readers can dig deeper into the aggregate picture in our data breach statistics roundup.

The takeaway: only one confirmed breach clears the billion-account line without a major caveat attached.

What is the difference between a breach and a data scrape?

A breach is unauthorized access into a company's internal systems; a scrape harvests data that was already publicly visible. The distinction matters because roughly half the biggest "breaches" by headline number were scrapes, where no private data left a protected server. LinkedIn's 700 million and Facebook's 533 million records both fall in this category.

LinkedIn stated in June 2021 that its 700 million-record incident was "not a data breach and no private LinkedIn member data was exposed," describing it as a scrape of public profile information plus data pulled from other sources. Facebook likewise attributed its 533 million-record 2021 leak to scraping through a contact-import feature, not an intrusion. The data is still real and still dangerous for phishing and identity fraud, but calling it a hack overstates what happened to the company's defenses.

Records by category among the largest incidents 2,533M4,098M885MScrapes (LinkedIn, Facebook, Twitter, Alibaba)2,533MConfirmed hacks (Yahoo, Ticketmaster, Weibo)4,098MMisconfiguration exposure (First American)885M

Figure 3: How the largest incidents split by root cause, in millions of records. Sources: LinkedIn statement (2021), Facebook / BleepingComputer (2021), Krebs on Security (2019).

The takeaway: a big number alone does not tell you whether a company was actually breached.

What about the "Mother of All Breaches"?

The Mother of All Breaches, or MOAB, reported by Cybernews in January 2024, is a compilation of roughly 26 billion records, not a single new hack. Security researcher Bob Dyachenko and the Cybernews team found a 12-terabyte database re-indexing thousands of previously disclosed breaches into one searchable trove.

Because MOAB folds in already-counted breaches, including subsets of Adobe's 153 million records, LinkedIn's 251 million, and Twitter's 281 million, ranking it alongside single incidents would double-count data that already appears elsewhere on the list. The same caution applies to RockYou2024, a July 2024 compilation of nearly 10 billion unique passwords aggregated from roughly 4,000 historical databases. RockYou2024 counts passwords, not accounts, so it is not comparable to the account-based figures at all. Treat both as compilations that measure the cumulative fallout of past breaches, not fresh intrusions.

Figure 4: Selected mega-incidents plotted chronologically. Sources: Verizon (2017), Cybernews (2024), Krebs on Security (2019).

The takeaway: a 26 billion figure sounds like the biggest breach ever, but it is a re-index of old ones.

Which industries suffer the biggest breaches?

Technology and social platforms dominate the very top of the list because they hold the largest single user bases, so a single breach can expose billions of accounts at once. Yahoo, LinkedIn, Facebook, Sina Weibo, and Alibaba are all in this bracket, and together they account for the majority of the multi-hundred-million-record entries in the top 10.

Beyond big tech, the pattern spreads across data brokers, hospitality, and financial services. National Public Data, a background-check data broker, self-reported 2.9 billion rows in 2024. Marriott's hospitality breach hit 383 million records after revision, and First American exposed 885 million real-estate documents through a misconfigured site. Equifax's 2017 breach affected only 147 million consumers by count, yet it produced one of the heaviest regulatory responses in breach history because of the sensitivity of the data, including 145.5 million Social Security numbers. Any organization holding personal data of that sensitivity should generate a compliant privacy policy that discloses what it collects, how it secures it, and how users are notified if something goes wrong.

Figure 5: How a mega-breach typically unfolds from access to disclosure. Source: composite of Krebs on Security and Cybernews breach reporting, 2019 to 2024.

The takeaway: the biggest breaches cluster where the biggest datasets live, which is tech, data brokers, and finance.

The Bottom Line

The record holder is settled: Yahoo's 2013 breach exposed 3 billion accounts, and nothing confirmed comes close. The messier truth is that many of the other giant numbers deserve an asterisk. National Public Data's 2.9 billion was a self-reported row count, not a headcount of real people. Aadhaar's 1.1 billion was disputed by the agency that held the data. LinkedIn, Facebook, and Alibaba were scrapes of public information rather than intrusions, and the 26 billion Mother of All Breaches was a compilation of leaks already counted elsewhere. Reading a breach ranking well means reading the caveats, not just the headline. For any business, the practical lesson is the same one the largest cases teach: the data you hold is a liability as much as an asset, and being clear with users about what you collect and how you protect it is the baseline. Our companion piece on the cost of a data breach covers what those incidents cost the organizations that suffer them.

Frequently Asked Questions

What is the biggest data breach of all time? Yahoo's 2013 breach exposed all 3 billion of its user accounts, the largest confirmed single-incident data breach by accounts affected. Yahoo first disclosed it in December 2016 as affecting 1 billion accounts, then Verizon revised the figure upward to all 3 billion accounts in October 2017 after acquiring the company.

What is the difference between a data breach and a data scrape? A breach is unauthorized access to a company's internal systems; a scrape collects data that was already publicly accessible. LinkedIn's 2021 incident involving 700 million records was a scrape of public profile data, and LinkedIn stated publicly that no private member data was exposed and it was not a breach.

Was the Mother of All Breaches a single hack? No. The Mother of All Breaches (MOAB), reported in January 2024, is a compilation of roughly 26 billion records re-indexed from thousands of earlier, already-disclosed breaches, including subsets of Adobe, LinkedIn, and Twitter data. It is an aggregation, not one new hostile intrusion.

How many people were affected by the Equifax breach? About 147 million consumers, per the US Federal Trade Commission, which announced a settlement of up to 700 million US dollars in July 2019. The breach exposed 145.5 million Social Security numbers, making it one of the most consequential breaches despite ranking below the largest ones by raw record count.

Where the Numbers Come From

  1. NPR : Every Yahoo Account That Existed in Mid-2013 Was Likely Hacked (2017). Reports Verizon/Oath's October 3, 2017 disclosure that all 3 billion accounts were affected by the 2013 breach.
  2. Troy Hunt : Inside the 3 Billion People National Public Data Breach (2024). Independent analysis finding the 2.9 billion figure is a row count, with far fewer unique individuals.
  3. Computer Weekly : LinkedIn Denies Exposure of 700 Million User Records Is a Data Breach (2021). LinkedIn's own statement that the 700 million-record incident was a scrape, not a breach.
  4. Cybernews : Mother of All Breaches Reveals 26 Billion Records (2024). Documents that MOAB is a compilation of previously disclosed breaches, roughly 26 billion records across 12 terabytes.
  5. Marriott / PR Newswire : Update on Starwood Database Security Incident (2019). Marriott's January 4, 2019 revision of the figure from 500 million down to roughly 383 million records.
  6. US Federal Trade Commission : Equifax to Pay Up to 700 Million in Settlement (2019). Confirms 147 million consumers affected and 145.5 million Social Security numbers exposed.
  7. BleepingComputer : Facebook Attributes 533 Million Users' Data Leak to Scraping (2021). Facebook's attribution of the 533 million-record leak to scraping, not hacking.
  8. Krebs on Security : First American Financial Corp Leaked Hundreds of Millions of Records (2019). Original reporting on the roughly 885 million documents exposed via a misconfigured website.

Note: All figures verified as of July 2026. Several entries are explicitly contested and should be read with their caveats: the Aadhaar 1.1 billion figure was denied by UIDAI, National Public Data's 2.9 billion is a self-reported row count rather than a headcount of unique people, and the Mother of All Breaches (26 billion) and RockYou2024 (nearly 10 billion) are compilations of prior breaches, not single new hacks. Figures are refreshed at least twice a year.