Every public data breach, newest first
8,377 so far, +19 this week. 6,928 confirmed by an official notice, a filing or the organization, across 7,809 organizations. Scanned daily.
Breaches disclosed per month
Latest disclosed
All breachesLargest in the last 12 months
By sizeQuestions
What counts as a breach here?
Any publicly disclosed security breach or data exposure: hacks and intrusions, ransomware with data theft, leaked or exposed databases, supply-chain compromises, vendor breaches, AI and model-related data incidents, insider incidents and credential stuffing that an organization disclosed.
Where does the data come from?
Official breach notices filed with state attorneys general (California, Washington, Delaware, Oregon), the HHS Office for Civil Rights breach portal, SEC 8-K Item 1.05 filings, the Have I Been Pwned breach list, regulator decisions, the organizations own statements and reputable security news. Every breach links to its sources.
What does confirmed mean?
A breach is confirmed when an official notice, a regulator, an SEC filing or the organization itself confirms it. Breaches known only from news reports or leak data are marked unverified until then. Settled means a settlement or fine has concluded.
Are the record counts exact?
They are the figures the organization or a regulator reported, and they often change: a later, larger count replaces the earlier one and the history keeps both. Counts from Have I Been Pwned are accounts found in the leaked data, labelled as such. State portals report only their own residents, so those are shown on the breach page, not as the total.
How often is it updated?
A scan runs every day at 05:10 UTC over the notice portals, HHS, SEC EDGAR, Have I Been Pwned and security news. Every Wednesday a deeper pass re-reads every portal in full, links breach lawsuits from lawsuits.fru.dev, looks for new sources and saves weekly counts. Nothing is overwritten: changes are kept on the Changes page.