More than 17.7 billion accounts have appeared in a data breach, according to Have I Been Pwned's live breach-notification tracker, checked in July 2026, a total that now exceeds the world's population of roughly 8.2 billion people. That is an account count, not a headcount of unique individuals, since most people who have used more than a handful of online services over the years show up on the list more than once.
Named annual studies fill in the individual-level picture that a running tally cannot. The Identity Theft Resource Center puts a number on how many Americans get an actual notification letter each year, Verizon counts how many breaches get confirmed worldwide, and specific incidents like Yahoo's 2013 breach and Equifax's 2017 breach show what "affected" means at the scale of a single event. Below is what each of those sources measured, side by side, with every figure traced to a named source and a publication date. For the broader picture of breach costs, causes, and detection times behind these numbers, see our data breach statistics roundup.
How many accounts have been exposed in data breaches overall?
Have I Been Pwned, the breach-notification service built by security researcher Troy Hunt, tracked 17,763,864,959 pwned accounts across 1,020 pwned websites when checked in July 2026. Divide that by the world's population of roughly 8.2 billion, per the United Nations' population estimates, and the math works out to more than two breached accounts for every person alive, though that comparison only illustrates scale rather than measuring unique individuals.
The gap between "accounts" and "people" matters. HIBP's total adds together every breach it has loaded, so an email address used to sign up for a retailer, a forum, and a streaming service that were each later breached counts three times toward the 17.7 billion figure. HIBP itself does not publish an estimate of unique individuals behind that total, and no public tracker currently does, which is exactly why the named annual studies below matter for anyone trying to answer "how many people," rather than "how many accounts."
How do the major breach trackers differ in what they count?
Four credible sources currently publish different pieces of the "how many people were breached" question, and none of them measure the same thing.
| Source | What it counts | Latest figure | Coverage |
|---|---|---|---|
| Have I Been Pwned | Cumulative breached accounts loaded into its database | 17,763,864,959 accounts | 1,020 breached websites, live and continuously updated (checked July 2026) |
| Identity Theft Resource Center | US consumers sent an official breach notice in one year | 278,827,933 people (2025) | United States only, annual report |
| Verizon Data Breach Investigations Report | Confirmed data breach events worldwide | 12,195 breaches (2025) | 139 countries, contributor dataset |
| IBM Cost of a Data Breach Report | Organizations studied to model per-breach cost | 600 organizations (2025 edition) | 17 industries, 16 countries and regions |
Have I Been Pwned answers "how many accounts exist on breach lists." The ITRC answers "how many people got a notice this year." Verizon answers "how many breach events happened." None of the four numbers converts cleanly into any of the others, and a single person can appear in all four data sets at once: as several rows in HIBP, as one notified individual in the ITRC's count, connected to one of Verizon's confirmed incidents, at an organization IBM may have studied for cost.
How many Americans get a data breach notification each year?
The Identity Theft Resource Center recorded 278,827,933 victim notices in the United States in 2025, according to its Annual Data Breach Report published in January 2026. That is down 79 percent from 1,367,117,021 notices in 2024, even though the number of underlying data compromises actually rose 5 percent, to a record 3,322, over the same period. The ITRC attributes the drop in people notified to the absence of billion-record mega-breaches in 2025, not to fewer incidents.
Figure 1: More US breach events in 2025, but far fewer people notified per event, because 2025 lacked mega-breaches. Source: Identity Theft Resource Center, Annual Data Breach Report 2026 (covering 2025 and 2024).
More people were notified than breach events would suggest, and the imbalance shows up by industry too. The ITRC's 2025 sector breakdown counted 739 compromises in financial services, 534 in healthcare, 478 in professional services, 299 in manufacturing, and 188 in education, with the remaining 1,084 spread across other tracked sectors.
Figure 2: Financial services logged the most tracked compromises of any single named sector in 2025, though the combined "other" category is larger still. Source: Identity Theft Resource Center, Annual Data Breach Report 2026.
What is the biggest data breach by number of people affected?
The largest confirmed breach by people affected is Yahoo's 2013 breach, which exposed all 3 billion of its user accounts, according to Verizon's October 2017 disclosure made after it acquired Yahoo's core business. Yahoo first reported the incident in December 2016 as affecting 1 billion accounts, and Verizon revised the total upward to every account two years later.
National Public Data, a background-check data broker, self-reported roughly 2.9 billion rows exposed in a 2024 breach, but independent analysis by security researcher Troy Hunt found the true number of unique individuals affected is far lower than the row count, since the leaked file contained large numbers of duplicate and incomplete records. Equifax's 2017 breach, by contrast, is a cleanly confirmed figure: 147 million consumers, including 145.5 million Social Security numbers, per the US Federal Trade Commission's July 2019 settlement announcement.
Figure 3: Yahoo remains the largest confirmed breach by individuals affected. The LinkedIn and Facebook incidents were scrapes of public data, and National Public Data's total is a self-reported row count rather than a confirmed headcount. Sources: Verizon (2017), Troy Hunt independent analysis (2024), LinkedIn and Meta public statements (2021), US FTC (2019).
Two of the entries above carry an asterisk worth explaining. LinkedIn stated in June 2021 that its 700 million-record incident was "not a data breach," describing it as a scrape of already-public profile data rather than unauthorized system access. Meta made a similar statement about its 533 million-record 2021 incident, attributing it to scraping through a contact-import feature. The exposed data was still real and still useful to a scammer, but neither company's own defenses were breached in the way Yahoo's or Equifax's were.
How have the biggest breaches changed over time?
Figure 4: The biggest single-incident breaches cluster in 2013 and 2021, while annual US victim-notice totals swing sharply year to year depending on whether a mega-breach lands. Source: Verizon, US FTC, LinkedIn and Meta public statements, Identity Theft Resource Center Annual Data Breach Report 2026.
How do people react after being notified of a breach?
A companion Identity Theft Resource Center survey of 1,040 US consumers found that 88% reported a negative personal consequence after receiving a breach notification, and 60% described feeling immediate anxiety on learning their data had been exposed. That reaction is compounded by a transparency problem: 70% of 2025 breach notices lacked any specific information about how the breach happened, up from 65% in 2024 and 45% in 2023, meaning fewer disclosures tell affected people or investigators what actually went wrong.
Figure 5: Nearly nine in ten surveyed consumers reported harm after a breach notice, even as the notices themselves grew less informative. Source: Identity Theft Resource Center consumer survey, 1,040 US respondents, Annual Data Breach Report 2026.
How can you find out if your own data has been breached?
Two paths exist, and they answer slightly different questions. A company that suffers a breach is legally required to notify affected individuals once a state-law threshold for the number of people or type of data involved is met, so a mailed letter or an email from a company you recognize is one signal. The other path is proactive: searching an email address at Have I Been Pwned checks it against the full 17.7 billion-account database directly, without waiting for a company to send anything.
Figure 6: Legal notification and proactive lookup are two separate ways the same breach eventually reaches an individual. Source: US state breach-notification law summaries, Have I Been Pwned methodology.
If your organization collects personal data from users, the same notification obligation applies to you, and the fastest way to see the gap is to check whether your own privacy policy still describes your current breach-notification process. You can generate an updated privacy policy that spells out how you handle a breach, what data you collect, and how affected users are notified, in less time than most organizations spend just detecting an incident in the first place.
The Bottom Line
Slice the question any way you like, and the honest answer to "how many people have had their data breached" still depends on which named source you cite. Have I Been Pwned's 17.7 billion accounts is the largest number and the easiest to misread as a headcount, when it is really a count of exposed logins accumulated across more than a thousand breached sites. The Identity Theft Resource Center's 278.8 million US victim notices in 2025 is the more defensible answer to "how many people got told this year," and Yahoo's 3 billion accounts remains the largest confirmed single event. None of the three numbers is wrong. They are answers to three different questions that a headline rarely bothers to separate, and the practical response is the same regardless of which figure you lead with: the organizations behind these numbers overwhelmingly failed at the basics, an unpatched system, a phishing click, a stolen credential, not an exotic attack, which is exactly the gap a current, accurate privacy policy and a clear breach-notification commitment are meant to close.
Frequently Asked Questions
How many people have had their data breached? Have I Been Pwned's live tracker lists more than 17.7 billion breached accounts as of July 2026, more than double the world's population of roughly 8.2 billion. That figure counts accounts, not unique individuals, since most people who have used many online services appear in more than one breach on the list.
How many Americans get a data breach notification each year? The Identity Theft Resource Center recorded 278,827,933 US victim notices in 2025, down 79 percent from 1,367,117,021 in 2024 because 2025 lacked the handful of billion-record mega-breaches that inflated the prior year's total.
What is the biggest data breach by number of people affected? Yahoo's 2013 breach affected all 3 billion of its user accounts, the largest confirmed breach by individuals affected, according to Verizon's October 2017 disclosure after it acquired Yahoo's core business.
How can you find out if your own data was breached? Search your email address at Have I Been Pwned, which cross-references more than 17.7 billion breached accounts, or watch for an official notification letter or email, which US companies must send once a state notification threshold is met.
Where the Numbers Come From
- Have I Been Pwned. Live breach-notification database, 17,763,864,959 pwned accounts across 1,020 pwned websites, checked July 2026.
- Identity Theft Resource Center. (2026). "2025 Annual Data Breach Report." 3,322 US data compromises, 278,827,933 victim notices, sector breakdown, consumer survey of 1,040 respondents, published January 2026.
- Verizon. (2025). "2025 Data Breach Investigations Report." 22,052 security incidents analyzed, 12,195 confirmed breaches, contributors across 139 countries.
- IBM. (2025). "Cost of a Data Breach Report 2025." 600 organizations studied across 17 industries and 16 countries and regions, breaches investigated March 2024 to February 2025.
- US Federal Trade Commission. (2019). "Equifax to Pay 575 Million as Part of Settlement." Confirms 147 million consumers affected and 145.5 million Social Security numbers exposed.
- Troy Hunt. (2024). "Inside the 3 Billion People National Public Data Breach." Independent analysis finding the self-reported 2.9 billion row count overstates unique individuals affected.
Note: All figures verified as of July 2026. The Have I Been Pwned total is a live, continuously updated count and will read higher the next time this post is refreshed. Victim-notice and breach-count totals are refreshed at least twice a year alongside the ITRC and Verizon report cycles.