At least 37 individually disclosed data breaches have each exposed 100 million or more records since 2008, according to PrivacyTerms' count cross-referencing UpGuard's ranked list of history's biggest data breaches and Wikipedia's List of data breaches, both checked in July 2026. That count excludes disputed leak compilations that aggregate previously stolen data rather than representing one new intrusion.
Mega breaches, the small subset of incidents large enough to expose nine or ten figures of records in a single event, drive most of the public conversation about data breaches even though they are a small fraction of total incidents each year. This post counts them directly: how many there have been, which ones are largest, how the pace has changed since 2008, and what these incidents have in common.
How many data breaches have exposed 100 million or more records?
PrivacyTerms counted 37 separate incidents where a named organization disclosed a single breach affecting 100 million or more records, spanning Heartland Payment Systems' 2008 breach through the National Public Data breach reported in 2024. The count treats repeat incidents at the same company, such as Yahoo's 2013 and 2014 breaches or LinkedIn's 2012 and 2021 incidents, as separate entries because each stemmed from a distinct intrusion or exposure event.
The count deliberately excludes two categories that inflate other public rankings: aggregated leak compilations such as the 2024 "Mother of All Breaches," which security researchers have shown mostly repackages previously stolen credentials rather than representing one new intrusion, and incidents still under active investigation at publication time with no confirmed scope. Both would push a headline number higher without meeting the same disclosure bar as the 37 counted here.
Figure 1: The eight largest single-population mega breaches by records exposed, excluding CAM4's duplicate-heavy 10.88 billion row count. Source: UpGuard biggest data breaches ranking, Wikipedia List of data breaches, checked July 2026.
What is the biggest data breach of all time?
The answer depends on whether duplicate rows count. By raw record count, the 2020 CAM4 exposure tops the ranking at 10.88 billion records, discovered on an unsecured Elasticsearch server belonging to the adult live-streaming platform. Security researchers who examined the exposed database, including Comparitech's team credited with the discovery, noted that the count reflects log entries rather than unique individuals, since the same user's activity generated many repeated rows.
Among breaches treated as affecting one bounded, countable population, Yahoo's 2013 breach is the largest, at 3 billion accounts, which was every Yahoo account that existed at the time. Yahoo first disclosed a 2014 breach affecting 500 million accounts in September 2016, then revised its estimate for a separate, earlier 2013 intrusion to all 3 billion accounts in October 2017 during Verizon's acquisition of Yahoo's operating business. The two disclosures are usually counted as separate incidents because they involved different intrusion windows.
| Breach | Year disclosed | Records affected | Primary cause |
|---|---|---|---|
| CAM4 | 2020 | 10.88 billion (rows, not unique users) | Unsecured Elasticsearch server |
| Yahoo (2013 breach) | 2016 to 2017 | 3 billion accounts | State-sponsored hacking |
| National Public Data | 2024 | Approximately 2.9 billion | Hacked; leaked admin credentials |
| Real Estate Wealth Network | 2023 | 1.5 billion | Unsecured 1.16 TB database |
| Aadhaar (UIDAI, India) | 2018 | 1.1 billion | Poor access controls |
| Alibaba | 2022 | 1.1 billion | Scraped from cloud servers |
| First American Financial | 2019 | 885 million | Website misconfiguration |
Table 1: The seven largest mega breaches by disclosed record count. National Public Data's 2.9 billion figure includes duplicate and derived records; the FTC's related 2025 settlement cites roughly 170 million people with Social Security numbers affected. Source: UpGuard, Wikipedia List of data breaches, Federal Trade Commission.
Which years have had the most mega breaches?
Mega breach disclosures are not evenly spread across the last 17 years. They cluster heavily around 2017 to 2019, a period that includes Equifax, Marriott, Capital One, First American, Facebook's scraped-data disclosure, and Verifications.io, then fall off sharply before climbing again after 2023.
Figure 2: Nine milestone incidents spanning the full 2008 to 2024 mega-breach timeline. Source: UpGuard, Wikipedia List of data breaches, company and regulator disclosures.
Counting all 37 mega breaches in three-year windows by the year each intrusion occurred, rather than the year it was disclosed, shows the 2017 to 2019 window alone accounts for 15 of the 37, roughly 4 in 10 of every mega breach on record.
Figure 3: Count of the 37 tracked mega breaches, grouped by the three-year window in which the underlying intrusion occurred (not the disclosure date). Source: PrivacyTerms count of UpGuard and Wikipedia List of data breaches entries.
The 2020 to 2022 dip does not mean breaches stopped. It more likely reflects a lag between smaller intrusions occurring during those years and their eventual disclosure, since several of the incidents counted in the 2023 to 2025 window, including Real Estate Wealth Network and National Public Data, trace back to data collection and storage practices that began earlier. If you handle customer records at any scale, a current privacy policy that accurately discloses what you collect, how long you retain it, and how a breach would be reported is one of the few controls that costs nothing to maintain and directly addresses what regulators check first after an incident.
What causes mega breaches?
Hacking is the leading disclosed cause across the 37 mega breaches PrivacyTerms tracked, accounting for roughly 6 in 10 incidents, but misconfigured or exposed databases, found without any active intrusion, account for more than a quarter on their own.
Figure 4: Primary cause classification for the 37 tracked mega breaches, based on PrivacyTerms' review of each incident's public disclosure. Source: UpGuard, Wikipedia List of data breaches, company breach notifications.
Misconfigured databases, cloud storage buckets left open without a password, and exposed internal tools account for a disproportionate share of the largest individual breaches. First American Financial's 885 million records, Verifications.io's 763 million records, and Real Estate Wealth Network's 1.5 billion records were all found sitting on the open internet rather than stolen through an active attack, which means each was preventable with a basic access-control review rather than a sophisticated defense against an attacker.
How is a breach classified as a mega breach in the first place?
There is no single legal or regulatory definition of "mega breach." Trackers, researchers, and regulators each draw the line differently, so this post's methodology is stated explicitly rather than assumed.
Figure 5: The inclusion test PrivacyTerms applied to reach the 37-breach count in this post. Source: PrivacyTerms methodology, built from UpGuard and Wikipedia List of data breaches entries.
IBM's own Cost of a Data Breach Report uses a narrower band for its mega-breach cost analysis: 50 to 60 million records, less than half this post's 100-million-record threshold. That means the average mega-breach cost IBM publishes describes a considerably smaller incident than most breaches in the ranking above, and the true average cost for a 100-million-plus breach is likely higher, though IBM has not published a figure specific to that tier.
How much does a mega breach cost?
A mega breach of 50 to 60 million records cost an average of $375 million in 2024, according to IBM's Cost of a Data Breach Report, an increase of $43 million from the 2023 average. IBM's figure covers detection, notification, post-breach response, and lost business, and applies specifically to its own 50-to-60-million-record definition rather than the 100-million-plus threshold used throughout this post.
| Breach size band | 2024 average cost | Source |
|---|---|---|
| Overall average (all sizes) | $4.88 million | IBM Cost of a Data Breach Report 2024 |
| Mega breach (50 to 60 million records) | $375 million | IBM Cost of a Data Breach Report 2024 |
Table 2: IBM's own two published cost bands. No published figure exists specifically for the 100 million-plus tier this post tracks, so treat $375 million as a conservative floor for breaches nearly double that size. Source: IBM Cost of a Data Breach Report 2024.
Regulatory penalties add to that figure without being included in it. Equifax's 148 million-record breach alone resulted in a $575 million settlement with the FTC, the CFPB, and all 50 states, separate from IBM's own cost modeling, and Capital One's 106 million-record breach carried an $80 million penalty from the Office of the Comptroller of the Currency on top of remediation costs.
The Bottom Line
At least 37 data breaches have each exposed 100 million or more records since 2008, and the pace has not been steady: nearly 4 in 10 of them landed in the single 2017 to 2019 window, followed by a lull, then a fresh cluster starting in 2023 led by National Public Data's roughly 2.9 billion-record breach. Hacking remains the leading disclosed cause, but more than a quarter of these incidents involved no attacker at all, just a misconfigured database or exposed cloud bucket sitting open on the public internet. That distinction matters for any organization handling customer data: the largest, most expensive breaches on record were frequently avoidable with basic access controls rather than advanced threat defense, and a clear, current privacy policy that accurately states what data you collect, how it is secured, and how a breach would be disclosed is one of the cheapest controls available against both the operational and regulatory fallout documented above.
Frequently Asked Questions
How many data breaches have exposed 100 million or more records? At least 37 individually disclosed data breaches have each exposed 100 million or more records since Heartland Payment Systems in 2008, per PrivacyTerms' count of the UpGuard and Wikipedia breach trackers as of July 2026. Fifteen of those 37 were disclosed in just the 2017 to 2019 window.
What is the biggest data breach of all time? By raw row count, the 2020 CAM4 exposure tops most rankings at 10.88 billion records, though security researchers caution that figure counts duplicate log entries rather than unique individuals. Among breaches widely treated as one confirmed incident affecting a bounded population, Yahoo's 2013 breach, disclosed in 2016 and 2017, affected all 3 billion Yahoo accounts that existed at the time.
What counts as a mega breach? There is no single legal definition. IBM's Cost of a Data Breach Report uses a narrower 50 to 60 million record threshold for its own mega-breach cost analysis, while trackers like UpGuard and Wikipedia's List of data breaches rank any single disclosed incident by total records affected, with no fixed cutoff. This post uses 100 million or more records in one disclosed incident, a round threshold that isolates the roughly three dozen breaches large enough to routinely make national news.
How much does a mega breach cost? A mega breach of 50 to 60 million records cost an average of $375 million in 2024, a $43 million increase from 2023, according to IBM's Cost of a Data Breach Report. That average is for a breach roughly half the size of this post's 100-million-record threshold, so breaches in this post's ranking likely cost more on average, though IBM has not published a cost figure specific to the 100 million-plus tier.
Where the Numbers Come From
- UpGuard. "The Biggest Data Breaches in US History." Ranked list of major breaches with record counts and disclosure dates, accessed July 2026.
- Wikipedia. "List of Data Breaches." Compiled, sourced table of breach incidents by organization, year, and records affected, accessed July 2026.
- IBM. "Cost of a Data Breach Report 2024." Mega-breach cost figure of $375 million average for 50 to 60 million records, up $43 million from 2023.
- Federal Trade Commission. "Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach." Press release, July 2019.
- Office of the Comptroller of the Currency. "OCC Assesses Civil Money Penalty Against Capital One." $80 million penalty related to the 2019 data breach, August 2020.
- Comparitech. "CAM4 Data Breach: 10.88 Billion Records Exposed." Discovery and analysis of the unsecured Elasticsearch server, 2020.
Note: All figures verified as of July 2026. The 37-breach count is PrivacyTerms' own tally cross-referencing the UpGuard and Wikipedia trackers against a stated inclusion methodology, not a single published figure from either source, and is refreshed at least twice a year as new mega breaches are disclosed and confirmed.