Recomputed on every load

What a Data Breach Exposes, and How Long It Stays Hidden

By Nick Forshteyn · CISO AI
Figures as at 26 September 2026, from a file read 26 September 2026

A data breach used to mean a hacked website handing over its login table. It now means a company handing over its customer records, and the two expose entirely different things about you. Measured across 1,038 breaches holding 17.8 billion accounts, the change is not subtle: passwords appeared in 86% of the earliest entries on the list and 32% of the latest, while names, phone numbers and home addresses have taken their place.

Every figure on this page is computed from Have I Been Pwned, Troy Hunt's public record of breached accounts, used under its Creative Commons Attribution licence. It is the most complete public list there is, and it is still not a census: it holds the breaches one person has obtained and chosen to load. Read the trends below as what surfaces, not as everything that happens. Every breach counted here is named in the full list.

32% was 86% in 2013 to 2017 of the most recent breaches exposed passwords. You can change a password. That is what makes this the good news on the page.
21 days was 178 days across 2015 to 2025 is how long the typical breach now takes to surface, about 8 times faster than every year before it.

What actually leaks

The comparison below is the 200 oldest breaches on the list against the 200 most recent: November 2013 to March 2017 on one side, December 2024 to September 2026 on the other. Equal slices, so a quiet year cannot make one half look unlike the other for want of records.

November 2013 to March 2017 December 2024 to September 2026
  • Email addresses 98% 100%
  • Names 28% 71%
  • Phone numbers 15% 54%
  • Physical addresses 16% 45%
  • Passwords 86% 32%
  • Usernames 71% 28%
  • Dates of birth 29% 28%
  • IP addresses 51% 19%
  • Genders 16% 18%
  • Geographic locations 10% 18%

Share of breaches in each window that exposed this kind of data. A breach usually exposes several, so the columns do not add to 100%.

What has risen is everything that identifies a person rather than logs them in: names (28% to 71%), phone numbers (15% to 54%), physical addresses (16% to 45%), geographic locations (10% to 18%). What has fallen is the material of a stolen database: passwords (86% to 32%), usernames (71% to 28%), IP addresses (51% to 19%).

This is a change in who is being robbed and how. A decade ago the typical entry here was a forum or a games site whose user table was dumped, and the prize was credentials to try elsewhere. The recent entries are extortion campaigns against companies, where the prize is the customer database itself. That matters because of what you can do afterwards. A password is revocable and most of this audience has already moved to a manager and second factors. A date of birth, a home address and a phone number are not revocable, and they are exactly what someone needs to pass a call-centre identity check in your name.

How long a breach stays hidden

Every record carries two dates: when the breach happened and when it was added to the list. The gap between them is how long the exposure ran before anyone affected could find out. Across the whole corpus the typical gap is 133 days. In 2026 it is 21 days. The chart below is not a clean downward line, and the worst years are recent ones, so the fall is a change in the last two years rather than a decade of steady improvement.

125 250 375 500 2015: 43 days typical, from 33 breaches 15 2016: 273 days typical, from 111 breaches 16 2017: 336 days typical, from 81 breaches 17 2018: 81 days typical, from 76 breaches 18 2019: 181 days typical, from 84 breaches 19 2020: 122 days typical, from 77 breaches 20 2021: 154 days typical, from 75 breaches 21 2022: 293 days typical, from 70 breaches 22 2023: 434 days typical, from 97 breaches 23 2024: 48 days typical, from 106 breaches 24 2025: 113 days typical, from 91 breaches 25 2026: 21 days typical, from 103 breaches 26

Median days between the breach and its appearance on the list, by the year it appeared. Years with fewer than 10 entries are not drawn. Hover a column for the year's figure.

The fall is real but it is not victims disclosing faster. It is who publishes. When a criminal group steals a customer database and posts it to force payment, the data is public within weeks of the theft by design. The long lags in the older bars are the opposite case: a database traded quietly for years before a collector obtained it. Faster surfacing is better for the people in the file, and it is not a sign that anyone is handling this better.

The largest on the list

Ranked by accounts. The password column is the point: the biggest breaches are mostly old, and the old ones are the ones with credentials in them.

BreachOccurredAccountsPasswords
Synthient Credential Stuffing Threat Data April 2025 2.0B Yes
Collection #1 January 2019 772.9M Yes
Verifications.io February 2019 763.1M No
Onliner Spambot August 2017 711.5M Yes
Data Enrichment Exposure From PDL Customer October 2019 622.2M No
Exploit.In October 2016 593.4M Yes
Facebook August 2019 509.5M No
Anti Public Combo List December 2016 458.0M Yes

Australian organisations on the list

13 breaches on the list are of an Australian organisation: those on an Australian domain, plus 4 mores we have identified by name because their domain does not say so. Canva is the largest of them by a wide margin, and no automatic rule would have found it. This is still a floor rather than a count, and it misses every global breach that held Australian customers, which is most of them.

BreachOccurredAccountsWhat was exposed
Oz Hair and Beauty August 2026 2.0M Email addresses, Geographic locations, Names, Phone numbers
Finsure October 2024 296K Email addresses, Names, Phone numbers, Physical addresses
digiDirect September 2024 304K Dates of birth, Email addresses, Names, Phone numbers
Ticketek May 2024 17.6M Dates of birth, Email addresses, Genders, Names
Tangerine February 2024 243K Dates of birth, Email addresses, Names, Passwords
Dymocks June 2023 836K Dates of birth, Email addresses, Genders, Names
Amart Furniture May 2022 109K Email addresses, Names, Passwords, Phone numbers
CTARS May 2021 12K Dates of birth, Email addresses, Genders, Names
Oxfam January 2021 1.8M Bank account numbers, Dates of birth, Email addresses, Genders
Appen June 2020 5.9M Email addresses, Employers, IP addresses, Names
Canva May 2019 137.3M Email addresses, Geographic locations, Names, Passwords
Sephora January 2017 780K Dates of birth, Email addresses, Ethnicities, Genders

The most recent additions

The 12 most recently loaded, newest first, with the gap between the breach and its appearance here. All 1,038 are in the full list, searchable by company, domain or the kind of data exposed, and filterable to Australian organisations alone.

BreachOccurredTook to surfaceAccounts
LimeLeads August 2019 7.1 years 17.8M
Burger King Russia August 2024 2.1 years 3.2M
Chess.com (2026) August 2026 41 days 4.7M
McKesson August 2026 20 days 6.4M
Manchester Airports Group August 2026 6 days 8.8M
Questel August 2026 31 days 1.2M
Carhartt August 2026 12 days 12.9M
NIUS July 2025 406 days 6K
Golf Canada May 2026 100 days 569K
Oz Hair and Beauty August 2026 4 days 2.0M
Fanlore August 2026 13 days 145K
RingCentral July 2026 17 days 1.6M

What this page can and cannot say

  • This is not a census of breaches. It is what one collector has obtained, verified and chosen to load. Breaches that were never traded, never noticed or never handed over are absent, and nothing here can measure them.
  • Both trends partly measure the collector. If the list has become quicker at loading recent extortion dumps, the falling gap reflects that as well as the world. The direction is consistent across ten years and too large to be only that, but it is not purely a fact about attackers.
  • A breach date is often a month, not a day. Where the exact date is unknown the list records the first of the month, so an individual gap can be out by weeks. Medians across hundreds of records absorb that; a single row may not.
  • Account counts are unique email addresses, not people and not records. One person with three addresses counts three times, and the same person appears across many breaches.
  • 42 breaches are flagged unverified, meaning the data could not be confirmed as genuinely from the named organisation. They are counted here, because excluding them would be a judgement this page is not in a position to make.

Method

The source is the public breach list published by Have I Been Pwned under a Creative Commons Attribution 4.0 licence. Our news worker caches it and this page reads that cache and computes every figure above at request time, so the numbers and the sentences describing them can never disagree. A record whose dates will not parse is dropped rather than guessed. The "what leaks" comparison uses equal slices from each end of the list rather than calendar windows. The gap-to-surface chart draws a year only once it holds 10 entries. Descriptions of each breach are the source's own writing and are not reproduced here; every row links to the breach's own page. The page is cached for fifteen minutes.

Comments

No comments yet.

To comment, confirm your email once. We send a sign-in link; no password to remember.

Your name appears with your comment; your email never does. By continuing you accept our terms and privacy policy.

Written analysis by Nick Forshteyn. Breach data from Have I Been Pwned, used under CC BY 4.0. The automated briefings are published separately.