Roughly 278.8 million people had their personal records exposed in publicly disclosed U.S. data breaches during 2025, according to the Identity Theft Resource Center's 2025 Annual Data Breach Report, published 29 January 2026 and covering the full calendar year. That figure is a sharp drop from 2024's 1.37 billion, even though 2025 set an all-time record for the number of separate breach events tracked: 3,322, the third consecutive year above 3,000.
The gap between "fewer records" and "more breaches" is the real story of 2025, and it is why a single headline number can mislead a reader who only catches the drop or only catches the record. Below is what actually happened by quarter, by sector, and by incident, along with why some reports circulating this year claim totals in the billions rather than the low hundreds of millions.
How many records were exposed in data breaches in 2025?
ITRC's tally puts the 2025 figure at 278,827,933 victim notices, the lowest annual total since 2014 and a steep fall from 2024's 1,367,117,021. The two years sit at opposite ends of the same five-year run: 2025 had more separate breach events than any year on record, but none of them came close to the scale of 2024's largest incidents.
A single mega breach can swing the annual total by hundreds of millions of records almost by itself, which is exactly what happened in reverse between these two years. Read on for the mechanics of that swing, then the industries and quarters driving 2025's record event count.
Why did exposed records fall while breach events hit a record high?
2024's total was inflated by a small number of breaches that each exposed hundreds of millions of records. 2025 had no incident of that scale. Its largest single breach, PowerSchool, exposed 71.9 million records, meaning even the year's biggest event was a fraction of what a single mega breach contributed to 2024's count.
That pattern holds across the five-year run ITRC tracks. Compromise counts climbed almost every year even as victim totals swung independently, because the two metrics measure different things: one counts breach events, the other counts the people caught in them.
Figure 1: Compromise events by year, a 79% jump over the five-year span. Source: Identity Theft Resource Center Annual Data Breach Reports, 2021 through 2025 editions.
Compromise counts and victim counts are reported separately for a reason: a company can suffer one compromise that triggers thousands of individual notices, or thousands of small compromises that together notify far fewer people than a single mega breach. For a full breakdown of how the two metrics diverge across the entire 2018 to 2026 span, see Data Breach Statistics 2026: Key Facts and Global Figures.
What was the biggest data breach of 2025?
PowerSchool's breach, which exposed 71.9 million records, was 2025's largest single incident, per ITRC's ranking. AT&T followed at 44 million, then Aflac at 22.7 million, Prosper Funding at 17.6 million, and Conduent Business Services at 14.7 million in Texas alone.
Figure 2: The five largest single data breaches of 2025 by records exposed. Source: Identity Theft Resource Center 2025 Annual Data Breach Report.
| Company | Sector | Records exposed |
|---|---|---|
| PowerSchool | Education technology | 71.9 million |
| AT&T | Telecommunications | 44 million |
| Aflac | Insurance | 22.7 million |
| Prosper Funding | Consumer finance | 17.6 million |
| Conduent Business Services | Government services (Texas) | 14.7 million |
None of these five incidents comes close to 2024's largest breaches, which is the main reason the annual victim total fell so far even as the event count climbed. A single company's breach can still outweigh hundreds of smaller compromises combined, so the "biggest breach of the year" figure and the "total records exposed" figure tell two related but distinct stories.
Which industries had the most data breaches in 2025?
Financial services recorded the most breach events of any sector in 2025, with 739 compromises, ahead of healthcare at 534 and professional services at 478, per ITRC's sector classification.
Figure 3: Reported breach events by sector, 2025. Source: Identity Theft Resource Center 2025 Annual Data Breach Report.
Manufacturing (299 compromises) and education (188 compromises) rounded out the top five. ITRC also flagged professional services as the fastest-growing sector over five years, with compromise counts up 162% since 2021, a rate that outpaces every other industry the report tracks. None of these sector counts map directly to records exposed: a healthcare breach involving a single hospital system's patient records can expose far more individuals than dozens of small financial-services incidents combined.
How many data breaches happened per day in 2025?
3,322 compromises across 365 days works out to just over nine data-compromise events every day of 2025 on average, though the real pace varied by quarter: 824 in Q1, 913 in Q2, 835 in Q3, and roughly 750 in Q4 by subtraction from the full-year total.
Figure 4: Quarterly compromise events in 2025. Q4 is calculated as the full-year ITRC total minus the published Q1 through Q3 figures, which ITRC itself revises as late notices arrive. Source: Identity Theft Resource Center quarterly and annual reports, 2025.
Q2 was the busiest three-month stretch of the year, and Q3 alone produced 23,053,451 victim notices from 749 confirmed breaches, the clearest single-quarter snapshot ITRC has published of how records-exposed and compromise-count move independently within a single year. A companion piece looks at the day-by-day pace across the full 2018 to 2026 run rather than just 2025: How Many Data Breaches Happen Per Day?
Why do some reports put 2025's total in the billions?
Two widely cited figures put 2025's records-exposed total far above ITRC's 278.8 million, and both need a label most articles quoting them skip.
| Source | Figure | What it actually covers |
|---|---|---|
| ITRC 2025 Annual Data Breach Report | 278.8 million | U.S. victim notices tied to breaches that occurred in 2025 |
| Flashpoint Global Threat Intelligence Report | 16.8 billion | Global exposed records, but the underlying breach data is from 2024, not 2025 |
| Cybernews infostealer compilation | 16 billion | A June 2025 compilation of older, previously leaked credentials, not new 2025 breaches |
Info
Flashpoint's report carries a "2025" title but its 6,670 breaches and 16.8 billion exposed records describe calendar-year 2024 activity, not 2025. Cybernews' 16 billion figure was explicitly described by its own researchers as a compilation of credentials stolen by infostealer malware across earlier years, discovered and published in June 2025, not a new breach that happened that year. Treat both as global, differently scoped figures rather than a direct comparison to ITRC's U.S.-focused annual count.
Once the labels are corrected, the discrepancy mostly disappears: ITRC counts confirmed 2025 breach notifications in the United States, Flashpoint's billions describe a prior year of global activity, and Cybernews' billions describe a discovery event, not a breach event. A journalist citing "billions of records exposed in 2025" without checking which of these three definitions applies is very likely repeating a mislabeled figure.
What's driving the record number of breach events?
Two structural shifts explain most of 2025's record 3,322 compromises: a growing share of breaches now trace back to third-party vendors, and a shrinking share of breach notices explain how the breach happened at all.
Figure 5: Share of 2025's 3,322 breach notices that named a root cause, versus those that did not. Source: Identity Theft Resource Center 2025 Annual Data Breach Report.
Supply-chain-linked breach notices nearly doubled from 660 in 2024 to 1,251 in 2025, and third-party vendor relationships were tied to roughly 30% of all 2025 breach notices, per ITRC. Meanwhile, root-cause transparency kept eroding: 70% of 2025's notices, 2,324 of 3,322, gave no attack method at all, up from 65% in 2024 and just 45% in 2023. A regulator or reporter trying to count "how many 2025 breaches involved ransomware" or "how many involved a vendor" is working with a shrinking pool of notices that actually say so.
Do all data breaches require notifying affected individuals?
Not automatically. Whether a breach triggers a legal notification duty depends on what kind of data was exposed and whether it was encrypted, and the answer varies by U.S. state.
Figure 6: A simplified U.S. state breach-notification decision path. Actual thresholds and deadlines vary by state statute. Source: ITRC 2025 Annual Data Breach Report methodology notes on state notification triggers.
Every one of 2025's 3,322 compromises eventually required someone to decide, state by state, whether a notification duty applied, and most state breach laws assume the organization already had a privacy policy on file describing what personal data it collects and how it is protected. If that policy predates 2025's shift toward supply-chain risk and shrinking root-cause disclosure, it is worth reviewing: you can generate an updated privacy policy that reflects current data-handling and incident-response practices in minutes.
The Bottom Line
2025 delivered a genuinely two-sided data-breach story: the fewest records exposed since 2014, at 278.8 million, alongside the most breach events ever recorded, at 3,322. Neither number tells the full story alone, and reports citing "billions of records exposed in 2025" are almost always describing a different year or a different kind of event, not a bigger version of the same ITRC count. For any organization deciding whether last year's incident response and disclosure language still hold up, the more useful signal than the headline total is the trend underneath it: more breaches tied to vendors, and fewer notices that explain what actually happened.
Frequently Asked Questions
How many records were exposed in data breaches in 2025? About 278.8 million individual records, or victim notices, were exposed in publicly disclosed U.S. data breaches during 2025, according to the Identity Theft Resource Center's 2025 Annual Data Breach Report, published 29 January 2026. That total is down 79% from 2024's 1.37 billion, even though the number of separate breach events hit an all-time high of 3,322.
Why did exposed records fall while the number of breaches hit a record high? Because 2024's total was inflated by a handful of mega breaches affecting hundreds of millions of people each, while 2025's largest single incident, the PowerSchool breach, exposed 71.9 million records. Spread that mega-breach effect across 3,322 separate events in 2025 and the per-event average drops sharply even as the event count keeps climbing.
What was the biggest data breach of 2025? The PowerSchool breach, which exposed 71.9 million records, was the largest single data breach of 2025 by ITRC's count, ahead of AT&T at 44 million and Aflac at 22.7 million records.
Why do some reports put the 2025 total in the billions instead of millions? Because they count a different thing. Flashpoint's Global Threat Intelligence Report cites 16.8 billion exposed records, but that figure covers 2024 breach activity despite the report carrying a 2025 title. Cybernews' 16 billion credential figure from June 2025 is an aggregated compilation of older infostealer-malware logs, not new breaches that occurred in 2025.
Where the Numbers Come From
- Identity Theft Resource Center. (2026). "2025 Annual Data Breach Report." 3,322 data compromises, 278,827,933 victim notices, published 29 January 2026.
- Identity Theft Resource Center. "Data Breach 2025 Q1 Trends." 824 compromises and just over 91.3 million victim notices in Q1 2025.
- HIPAA Journal. (2025). "ITRC: 23 Million Individuals Affected by Data Breaches in Q3, 2025." Cites ITRC's Q2 (913 compromises) and Q3 (835 compromises, 23,053,451 victim notices) figures and root-cause breakdown.
- NetSec News. (2026). "ITRC Reports Record Number of U.S. Data Breaches in 2025." 2025 vs. 2024 sector breakdown and the five largest 2025 breaches by records exposed.
- Bluefin. (2026). "2025 Data Breach Report: Understanding New Attack Tactics." Corroborates ITRC's exact 2025 and 2024 totals and the five-year, 79% compromise-count trend.
- Flashpoint. "2025 Global Threat Intelligence Report." 6,670 publicly reported breaches and 16.8 billion exposed records worldwide, covering 2024 breach activity, 63% of incidents in the US.
- Cybernews. (2025). "Billions of Credentials Exposed in Infostealer Data Leak." 16 billion compiled credentials discovered June 20, 2025, from previously leaked infostealer-malware logs, not a new single breach.
Note: All figures verified as of July 2026. ITRC revises quarterly and annual totals as late breach notices arrive, so figures for the most recent quarter of any year should be treated as provisional. This post is refreshed at least twice a year to track new ITRC editions and any restated totals.