What a Data Breach Exposes, and How Long It Stays Hidden
A data breach used to mean a hacked website handing over its login table. It now means a company handing over its customer records, and the two expose entirely different things about you. Measured across 1,038 breaches holding 17.8 billion accounts, the change is not subtle: passwords appeared in 86% of the earliest entries on the list and 32% of the latest, while names, phone numbers and home addresses have taken their place.
Every figure on this page is computed from Have I Been Pwned, Troy Hunt's public record of breached accounts, used under its Creative Commons Attribution licence. It is the most complete public list there is, and it is still not a census: it holds the breaches one person has obtained and chosen to load. Read the trends below as what surfaces, not as everything that happens. Every breach counted here is named in the full list.
What actually leaks
The comparison below is the 200 oldest breaches on the list against the 200 most recent: November 2013 to March 2017 on one side, December 2024 to September 2026 on the other. Equal slices, so a quiet year cannot make one half look unlike the other for want of records.
Share of breaches in each window that exposed this kind of data. A breach usually exposes several, so the columns do not add to 100%.
What has risen is everything that identifies a person rather than logs them in: names (28% to 71%), phone numbers (15% to 54%), physical addresses (16% to 45%), geographic locations (10% to 18%). What has fallen is the material of a stolen database: passwords (86% to 32%), usernames (71% to 28%), IP addresses (51% to 19%).
This is a change in who is being robbed and how. A decade ago the typical entry here was a forum or a games site whose user table was dumped, and the prize was credentials to try elsewhere. The recent entries are extortion campaigns against companies, where the prize is the customer database itself. That matters because of what you can do afterwards. A password is revocable and most of this audience has already moved to a manager and second factors. A date of birth, a home address and a phone number are not revocable, and they are exactly what someone needs to pass a call-centre identity check in your name.
How long a breach stays hidden
Every record carries two dates: when the breach happened and when it was added to the list. The gap between them is how long the exposure ran before anyone affected could find out. Across the whole corpus the typical gap is 133 days. In 2026 it is 21 days. The chart below is not a clean downward line, and the worst years are recent ones, so the fall is a change in the last two years rather than a decade of steady improvement.
Median days between the breach and its appearance on the list, by the year it appeared. Years with fewer than 10 entries are not drawn. Hover a column for the year's figure.
The fall is real but it is not victims disclosing faster. It is who publishes. When a criminal group steals a customer database and posts it to force payment, the data is public within weeks of the theft by design. The long lags in the older bars are the opposite case: a database traded quietly for years before a collector obtained it. Faster surfacing is better for the people in the file, and it is not a sign that anyone is handling this better.
The largest on the list
Ranked by accounts. The password column is the point: the biggest breaches are mostly old, and the old ones are the ones with credentials in them.
| Breach | Occurred | Accounts | Passwords |
|---|---|---|---|
| Synthient Credential Stuffing Threat Data | April 2025 | 2.0B | Yes |
| Collection #1 | January 2019 | 772.9M | Yes |
| Verifications.io | February 2019 | 763.1M | No |
| Onliner Spambot | August 2017 | 711.5M | Yes |
| Data Enrichment Exposure From PDL Customer | October 2019 | 622.2M | No |
| Exploit.In | October 2016 | 593.4M | Yes |
| August 2019 | 509.5M | No | |
| Anti Public Combo List | December 2016 | 458.0M | Yes |
Australian organisations on the list
13 breaches on the list are of an Australian organisation: those on an Australian domain, plus 4 mores we have identified by name because their domain does not say so. Canva is the largest of them by a wide margin, and no automatic rule would have found it. This is still a floor rather than a count, and it misses every global breach that held Australian customers, which is most of them.
| Breach | Occurred | Accounts | What was exposed |
|---|---|---|---|
| Oz Hair and Beauty | August 2026 | 2.0M | Email addresses, Geographic locations, Names, Phone numbers |
| Finsure | October 2024 | 296K | Email addresses, Names, Phone numbers, Physical addresses |
| digiDirect | September 2024 | 304K | Dates of birth, Email addresses, Names, Phone numbers |
| Ticketek | May 2024 | 17.6M | Dates of birth, Email addresses, Genders, Names |
| Tangerine | February 2024 | 243K | Dates of birth, Email addresses, Names, Passwords |
| Dymocks | June 2023 | 836K | Dates of birth, Email addresses, Genders, Names |
| Amart Furniture | May 2022 | 109K | Email addresses, Names, Passwords, Phone numbers |
| CTARS | May 2021 | 12K | Dates of birth, Email addresses, Genders, Names |
| Oxfam | January 2021 | 1.8M | Bank account numbers, Dates of birth, Email addresses, Genders |
| Appen | June 2020 | 5.9M | Email addresses, Employers, IP addresses, Names |
| Canva | May 2019 | 137.3M | Email addresses, Geographic locations, Names, Passwords |
| Sephora | January 2017 | 780K | Dates of birth, Email addresses, Ethnicities, Genders |
The most recent additions
The 12 most recently loaded, newest first, with the gap between the breach and its appearance here. All 1,038 are in the full list, searchable by company, domain or the kind of data exposed, and filterable to Australian organisations alone.
| Breach | Occurred | Took to surface | Accounts |
|---|---|---|---|
| LimeLeads | August 2019 | 7.1 years | 17.8M |
| Burger King Russia | August 2024 | 2.1 years | 3.2M |
| Chess.com (2026) | August 2026 | 41 days | 4.7M |
| McKesson | August 2026 | 20 days | 6.4M |
| Manchester Airports Group | August 2026 | 6 days | 8.8M |
| Questel | August 2026 | 31 days | 1.2M |
| Carhartt | August 2026 | 12 days | 12.9M |
| NIUS | July 2025 | 406 days | 6K |
| Golf Canada | May 2026 | 100 days | 569K |
| Oz Hair and Beauty | August 2026 | 4 days | 2.0M |
| Fanlore | August 2026 | 13 days | 145K |
| RingCentral | July 2026 | 17 days | 1.6M |
What this page can and cannot say
- This is not a census of breaches. It is what one collector has obtained, verified and chosen to load. Breaches that were never traded, never noticed or never handed over are absent, and nothing here can measure them.
- Both trends partly measure the collector. If the list has become quicker at loading recent extortion dumps, the falling gap reflects that as well as the world. The direction is consistent across ten years and too large to be only that, but it is not purely a fact about attackers.
- A breach date is often a month, not a day. Where the exact date is unknown the list records the first of the month, so an individual gap can be out by weeks. Medians across hundreds of records absorb that; a single row may not.
- Account counts are unique email addresses, not people and not records. One person with three addresses counts three times, and the same person appears across many breaches.
- 42 breaches are flagged unverified, meaning the data could not be confirmed as genuinely from the named organisation. They are counted here, because excluding them would be a judgement this page is not in a position to make.
Method
The source is the public breach list published by Have I Been Pwned under a Creative Commons Attribution 4.0 licence. Our news worker caches it and this page reads that cache and computes every figure above at request time, so the numbers and the sentences describing them can never disagree. A record whose dates will not parse is dropped rather than guessed. The "what leaks" comparison uses equal slices from each end of the list rather than calendar windows. The gap-to-surface chart draws a year only once it holds 10 entries. Descriptions of each breach are the source's own writing and are not reproduced here; every row links to the breach's own page. The page is cached for fifteen minutes.
Written analysis by Nick Forshteyn. Breach data from Have I Been Pwned, used under CC BY 4.0. The automated briefings are published separately.
Comments
No comments yet.