# Breaches: every publicly known security breach we can find > Breaches tracks publicly disclosed security breaches and data exposures (hacks, ransomware with data theft, exposed databases, supply-chain and vendor breaches, AI and model data incidents, credential stuffing), most recent first, each with its official notice and sources. It grows every day. By fru.dev. So far: 25,701 breaches (24,281 confirmed by an official notice, a filing, a regulator or the organization), 0 disclosed in the last 7 days, 23,465 organizations. A daily scan (05:10 UTC) reads state attorney general notice portals (California, Washington, Delaware, Oregon), the HHS OCR breach portal, SEC 8-K Item 1.05 filings, the Have I Been Pwned breach list and security news; a weekly pass (Wednesdays 13:10 UTC) re-reads every portal in full, links breach lawsuits from lawsuits.fru.dev, probes for new sources and saves weekly counts. History is append-only (/changes). Last rebuilt: 2026-09-25 15:21:23 UTC. ## About this data Breaches from public sources only: state attorney general notices (California, Washington, Delaware, Oregon), the HHS breach portal, SEC 8-K filings, Have I Been Pwned and security news, scanned every day with a deeper pass every Wednesday. A breach counts as confirmed once an official notice, a filing or the organization itself confirms it; news leads stay marked unverified until then. The list grows as new breaches are disclosed. Record counts are as reported by the organization or regulator. Not legal advice. Logos via logo.dev; trademarks belong to their owners. Anonymous usage stats via Google Analytics. ## Pages - [Latest breaches](https://breaches.fru.dev/): the newest disclosures first - [All breaches, with filters](https://breaches.fru.dev/breaches): sector, attack type, data exposed, year - [Organizations](https://breaches.fru.dev/companies) - [By sector](https://breaches.fru.dev/sectors), [by attack type](https://breaches.fru.dev/types), [by year](https://breaches.fru.dev/years) - [Changes (append-only history)](https://breaches.fru.dev/changes) - [Method and coverage by year and source](https://breaches.fru.dev/method) ## Sectors - [Healthcare](https://breaches.fru.dev/sectors/health): 8,070 breaches - [Other](https://breaches.fru.dev/sectors/other): 7,900 breaches - [Finance](https://breaches.fru.dev/sectors/finance): 2,036 breaches - [Tech](https://breaches.fru.dev/sectors/tech): 1,642 breaches - [Education](https://breaches.fru.dev/sectors/education): 1,338 breaches - [Insurance](https://breaches.fru.dev/sectors/insurance): 1,337 breaches - [Government](https://breaches.fru.dev/sectors/government): 659 breaches - [Retail](https://breaches.fru.dev/sectors/retail): 594 breaches - [Nonprofit](https://breaches.fru.dev/sectors/nonprofit): 500 breaches - [Manufacturing](https://breaches.fru.dev/sectors/manufacturing): 349 breaches - [Legal and services](https://breaches.fru.dev/sectors/legal): 279 breaches - [Transport](https://breaches.fru.dev/sectors/transport): 202 breaches - [Hospitality](https://breaches.fru.dev/sectors/hospitality): 195 breaches - [Energy](https://breaches.fru.dev/sectors/energy): 175 breaches - [Media](https://breaches.fru.dev/sectors/media): 149 breaches - [Telecom](https://breaches.fru.dev/sectors/telecom): 128 breaches - [AI](https://breaches.fru.dev/sectors/ai): 65 breaches - [Gaming](https://breaches.fru.dev/sectors/gaming): 44 breaches - [Data brokers](https://breaches.fru.dev/sectors/data): 20 breaches - [Crypto](https://breaches.fru.dev/sectors/crypto): 19 breaches ## Attack types - [Not stated](https://breaches.fru.dev/types/unknown): 15,652 breaches - [Hacking](https://breaches.fru.dev/types/hacking): 5,691 breaches - [Insider](https://breaches.fru.dev/types/insider): 1,553 breaches - [Lost or stolen device](https://breaches.fru.dev/types/lost-device): 1,439 breaches - [Ransomware](https://breaches.fru.dev/types/ransomware): 684 breaches - [Phishing](https://breaches.fru.dev/types/phishing): 167 breaches - [Vendor breach](https://breaches.fru.dev/types/third-party): 148 breaches - [Exposed data](https://breaches.fru.dev/types/misconfiguration): 126 breaches - [Supply chain](https://breaches.fru.dev/types/supply-chain): 123 breaches - [Extortion](https://breaches.fru.dev/types/extortion): 53 breaches - [Credential stuffing](https://breaches.fru.dev/types/credential-stuffing): 28 breaches - [Scraping](https://breaches.fru.dev/types/scraping): 25 breaches - [AI or model](https://breaches.fru.dev/types/ai-model): 12 breaches ## Largest confirmed breaches - [Facebook, 2021-04-03](https://breaches.fru.dev/breaches/facebook-2021-04): 533,000,000 affected - [Marriott International, 2018-11-30](https://breaches.fru.dev/breaches/marriott-international-2018-11): 500,000,000 affected - [Myspace, 2016-05-31](https://breaches.fru.dev/breaches/myspace-2016-06): 359,420,698 affected - [Deezer, 2023-01-02](https://breaches.fru.dev/breaches/deezer-2023-01): 229,037,936 affected - [Change Healthcare, 2024-02-22](https://breaches.fru.dev/breaches/change-healthcare-2024-08): 192,700,000 affected - [Delaware Community School, 2024-12-28](https://breaches.fru.dev/breaches/delaware-community-school-2024-12): 190,000,000 affected - [Zynga, 2019-08-31](https://breaches.fru.dev/breaches/zynga-2019-09): 172,869,660 affected - [LinkedIn, 2016-05-21](https://breaches.fru.dev/breaches/linkedin-2016-06): 164,611,595 affected - [MyFitnessPal, 2018-03-29](https://breaches.fru.dev/breaches/myfitnesspal-2019-02): 150,000,000 affected - [Equifax, 2017-09-07](https://breaches.fru.dev/breaches/equifax-2017-09): 147,000,000 affected - [LinkedIn, 2021-04-08](https://breaches.fru.dev/breaches/linkedin-2021-10): 125,698,496 affected - [AT&T, 2024-03-19](https://breaches.fru.dev/breaches/at-and-t-2024-04): 110,000,000 affected - [Capital One, 2019-02-01](https://breaches.fru.dev/breaches/capital-one-2021-03): 106,000,000 affected - [MyHeritage, 2018-06-15](https://breaches.fru.dev/breaches/myheritage-2018-06): 91,991,358 affected - [Facebook, 2018-03-17](https://breaches.fru.dev/breaches/facebook-2018-03): 87,000,000 affected - [JPMorgan Chase, 2013-12-05](https://breaches.fru.dev/breaches/jpmorgan-chase-2014-10): 83,000,000 affected - [Anthem, 2015-02-04](https://breaches.fru.dev/breaches/anthem-2015-02): 78,800,000 affected - [Sony PlayStation Network, 2011-04-20](https://breaches.fru.dev/breaches/sony-playstation-network-2011-04): 77,000,000 affected - [AT&T, 2023-07-13](https://breaches.fru.dev/breaches/at-and-t-2024-03): 73,000,000 affected - [Neopets, 2022-08-29](https://breaches.fru.dev/breaches/neopets-2022-08): 69,000,000 affected - [Dropbox, 2012-07-31](https://breaches.fru.dev/breaches/dropbox-2016-08): 68,648,009 affected - [Conduent Business Services, 2025-10-08](https://breaches.fru.dev/breaches/conduent-business-services-2026-04): 62,486,662 affected - [CONDUENT, 2025-01-21](https://breaches.fru.dev/breaches/conduent-2025-04): 62,224,658 affected - [Uber, 2017-11-21](https://breaches.fru.dev/breaches/uber-2017-11): 57,000,000 affected - [Hot Topic, 2023-07-28](https://breaches.fru.dev/breaches/hot-topic-2024-03): 56,904,909 affected ## Data - [Everything as plain text](https://breaches.fru.dev/llms-full.txt) - [Sitemap](https://breaches.fru.dev/sitemap.xml) - [JSON: breaches](https://breaches.fru.dev/api/breaches) - [JSON: organizations (registry feed)](https://breaches.fru.dev/api/companies) - [JSON: counts and coverage](https://breaches.fru.dev/api/stats) ## Related fru.dev sites - [Lawsuits](https://lawsuits.fru.dev): breach class actions and regulator decisions - [Incidents](https://incidents.fru.dev): outages and incidents of the same companies - [Companies](https://companies.fru.dev): the shared company registry ## API - [For AI agents](https://breaches.fru.dev/agents): how to use this data in an agent (system prompt line, tool definition, code) - [OpenAPI 3.1 spec](https://breaches.fru.dev/openapi.json): the public read endpoints below, ready to load as tools - [GET /api/breaches](https://breaches.fru.dev/api/breaches?sector=tech&limit=3): Breaches, most recently disclosed first, with filters; returns breaches with id, organization (slug, name, domain), title, disclosed date, records and their basis, attack type, sector, data types, status (disclosed, confirmed, settled), verified, campaign, the sources that back it, and the page URL - [GET /api/breaches/{id}](https://breaches.fru.dev/api/breaches/change-healthcare-2024-08): One breach with every source, the official notices it was matched to, and its change history; returns the breach with summary, occurred, discovered and disclosed dates, records, data types, attack, lawsuit or fine, sources (url, type, title), notices (portal, date, people affected in that state) and history (field, old, new, when, source) - [GET /api/companies](https://breaches.fru.dev/api/companies?since=2026-09-01&limit=2): Organizations with a known breach, with their breaches as dated items (the companies.fru.dev registry feed); returns companies with slug (companies.fru.dev slug rule), name, domain, in_registry, sector, the page here, breach count, records, first seen, and items (each breach with type, date, title, url, source, verified). By default only organizations with a known web domain; all=1 for every organization - [GET /api/stats](https://breaches.fru.dev/api/stats): Counts by sector, attack type, data type and year, plus the coverage grid by year and source; returns growth (total, verified, disclosed in the last 7 and 30 days, organizations), sectors, attacks, data types and years with breach and record counts, and coverage per year per source - [GET /api/sources](https://breaches.fru.dev/api/sources): The growing list of sources the scan reads, with when each last answered and what it yielded; returns sources with id, name, kind (portal, regulator, filing, api, rss, trust, sibling, registry), URL, scope, status, found by, first seen, last ok, yield and breaches added - [GET /api/changes](https://breaches.fru.dev/api/changes?since=2026-09-01&limit=3): The append-only history: breaches added, record counts that rose, statuses and sources that changed; returns changes with time, item type, item, field, old and new value, source URL and who made it (seed, daily, weekly, backfill, admin) - [GET /api/search](https://breaches.fru.dev/api/search?q=ticketmaster&limit=3): Search organizations, breaches and pages; returns up to 20 ranked results with title, link and one line Free to read. Cite "Breaches (breaches.fru.dev)" with a link. Responses are cached at the edge; keep to about 60 requests a minute. Rows with verified=false come from news leads or leak data (Have I Been Pwned) and are not yet confirmed by an official notice, a filing, a regulator or the organization. Record counts are as reported; records_basis says by whom (organization, hhs, hibp = accounts in the leaked data, press).