Skip to content

Method and coverage

25,697 breaches so far from 70 sources (39 found by the scan itself), 24,281 of them confirmed. Where each one comes from, how a breach is confirmed, and what is still missing.

Coverage by year and source

Breaches per disclosure year, and how many each source backs. One breach can be backed by several. Darker is more.

YearTotalCalifornia AGWashington AGDelaware DOJOregon DOJTexas AGIndiana AGVermont AGMaine AGHHS OCRHHS archiveSEC 8-KSEC 8-K 8.01SEC filingUK ICOHave I Been PwnedResearchSecurity news
20262,067345141221154337065110353137181102992232
20252,979456194562321831,570665033242514602842830
20242,5424722116114641,2546990576342410051001410
20232,4665362569122211,1505960267920014921230
20222,1313781665715101,22316200662000266470
20212,2504391884217601,392500665000069180
20202,1133712074511611,09913651612000077150
20191,596230572898072604610469000075160
20181,4972476311102074703870340000071170
20171,45227281110105940455033200006580
20161,35522252073058403670312000097220
20159621831603038302670251000033200
2014859158050032902130277000027200
2013568133080041222025100004140
20123041050100002019800003120
201121310000100019000002230
201019710000000018400001130
2009380000000001700000210
200819000000010000000180
200728000001000000200270
200628000000000000000280
200532000000000000000320
2004100000000000000010

Companies in the fru.dev registry

All 1,154 companies in companies.fru.dev are enrolled here. 204 have a known breach so far. 80 of 1,154 (7%) have been checked for their own security, trust or news page, 39 with one found; the weekly pass checks 40 more each Wednesday.

How a breach gets here

Every day at 05:10 UTC the scan reads the state attorney general notice portals (California, Washington, Delaware, Oregon, Texas, Vermont, Indiana), the HHS Office for Civil Rights breach portal, SEC 8-K filings under Item 1.05 and cybersecurity incidents under Item 8.01 (each filing read to check it describes an incident the company had), the Have I Been Pwned breach list and security news feeds. Every Wednesday at 13:10 UTC a deeper pass re-reads every portal in full, the HHS archive of resolved cases since 2009, the Maine notice archive (2010 to 2020) and UK ICO enforcement, links breach lawsuits from lawsuits.fru.dev, reads the companies.fru.dev registry, probes registry companies for their own security and trust pages, and saves weekly counts.

Notices about the same organization within a few months are merged into one breach, and each notice stays attached as evidence. A breach is confirmed when an official notice, a regulator, an SEC filing or the organization itself confirms it. News leads that no official source confirms yet are shown as Unverified.

People affected is the figure the organization or a regulator reported. When a later notice raises it, the new figure replaces the old one and the history keeps both. Have I Been Pwned counts are accounts found in the leaked data and are labelled as such. State portals count only their own residents, so they appear on the breach page, not as the total.

The major breaches before the official portals existed, and the big waves (MOVEit, Snowflake customers, Salesforce data theft), were researched by hand from the organizations' notices, regulators and reputable reporting, each with its sources.

Known gaps

  • Massachusetts and New Hampshire answer scripted requests with 403 (robots.txt included), so their notices are not read. They are probed once a week and read as soon as they answer.
  • Maine took its live breach database offline in 2026 after hoax reports; only its archive (August 2010 to September 2020) is read. Texas lists reports from April 2025 on; Vermont lists them from 2022.
  • Outside the US, the UK ICO is read for its fines, reprimands and notices about security failings (2022 on). Australia's OAIC publishes notifiable breaches only as twice-yearly statistics, and EU authorities publish decisions as news, not a per-breach list, so other countries rest on regulators' decisions, Have I Been Pwned and news. Canada, Japan, India and most of Asia and Latin America have no public per-breach list.
  • 2004 to 2011: no public notice portals existed yet. Those rows are confirmed only against a primary source (an HHS or Maine notice, the company's own SEC filing, a regulator or the organization's statement); 423 of 556 are, the rest are marked Unverified.

Sources

SourceBreaches added
Hand researchMajor breaches and waves researched from notices, regulators and reporting857
Indiana Attorney GeneralYear-to-date breach reports (PDF, 2014 on) with Indiana and total affected8,697
California Attorney GeneralEvery notice sent to more than 500 Californians, since 20124,549
Vermont Attorney GeneralReports since April 2026 (table with Vermonters affected and data types) and notices 2022 to April 20261,682
Maine Attorney GeneralArchived notices, August 2010 to September 2020 (spreadsheets); the live database is offline since the 2026 hoax reports1,485
Washington Attorney GeneralNotices affecting 500 or more Washingtonians, with cause and industry712
Oregon Department of JusticeNotices affecting more than 250 Oregonians, with dates of breach and discovery498
Texas Attorney GeneralReports affecting 250 or more Texans, with total affected and data types315
Delaware Department of JusticeNotices with total people affected, data exposed and the letter172
Massachusetts Office of Consumer AffairsYearly breach report spreadsheets; mass.gov answers scripted requests (robots.txt included) with 403 (blocks scripted access: skipped)
New Hampshire DOJNotice letters (PDF per notice); doj.nh.gov answers scripted requests (robots.txt included) with 403 (blocks scripted access: skipped)
HHS Office for Civil Rights, archiveResolved health data breach cases since October 2009, with the portal description of each5,101
HHS Office for Civil RightsHealth data breaches affecting 500 or more people, open cases (24 months)617
UK ICO enforcementUK fines, reprimands and enforcement notices for security failings (UK GDPR Articles 5(1)(f) and 32), 2022 on25
Australian OAIC notifiable data breachesTwice-yearly statistics on notified breaches; no per-breach list is published (aggregate statistics only)
EDPB and EU data protection authoritiesEU fines and decisions tied to breaches (news items, no per-breach list) (listed, not parsed yet)
SEC EDGAR, 8-K Item 1.05Material cybersecurity incidents reported by US public companies since December 202349
SEC EDGAR, 8-K Item 8.01Cybersecurity incidents US public companies disclosed under Item 8.01 (other events), read from each filing, since December 202316
SEC EDGAR full-text search, older filingsPrimary-source check for 2004 to 2011 breaches of public companies: the 8-K, 10-K or 10-Q in which the company described the incident (scripts/verify-historic.ts)
Have I Been PwnedBreaches whose data was loaded and verified by HIBP, with account counts926
CISA Known Exploited VulnerabilitiesExploited vulnerabilities, context for supply-chain waves (not breaches by themselves)
SecurityWeekSecurity news2
BleepingComputerSecurity news1
DataBreaches.netBreach reporting1
TechCrunch SecuritySecurity news1
CISA advisoriesGovernment advisories; campaign context
KrebsOnSecuritySecurity reporting
The RecordSecurity news
Incidents (incidents.fru.dev)Outages and incidents of the same companies
Lawsuits (lawsuits.fru.dev)Breach class actions and regulator decisions
Companies (companies.fru.dev)The shared company registry: slugs, domains, categories
1Password security pageThe company's own security, trust or news page
50skills security pageThe company's own security, trust or news page
7-Eleven security pageThe company's own security, trust or news page
AI Squared security pageThe company's own security, trust or news page
AI21 Labs security pageThe company's own security, trust or news page
AMD newsroom pageThe company's own security, trust or news page
AT&T security pageThe company's own security, trust or news page
AWS security pageThe company's own security, trust or news page
Accenture security pageThe company's own security, trust or news page
Adobe security pageThe company's own security, trust or news page
Airbnb security pageThe company's own security, trust or news page
Airbus security pageThe company's own security, trust or news page
Airtable security pageThe company's own security, trust or news page
Alation security pageThe company's own security, trust or news page
Alibaba security pageThe company's own security, trust or news page
Alteryx security pageThe company's own security, trust or news page
Amazon security pageThe company's own security, trust or news page
Amgen newsroom pageThe company's own security, trust or news page
Amplitude security pageThe company's own security, trust or news page
Aon security pageThe company's own security, trust or news page
AppFolio security pageThe company's own security, trust or news page
AppLovin security pageThe company's own security, trust or news page
Appen newsroom pageThe company's own security, trust or news page
Appian trust pageThe company's own security, trust or news page
Apple security pageThe company's own security, trust or news page
Ariba security pageThe company's own security, trust or news page
Arista Networks security pageThe company's own security, trust or news page
Arm security pageThe company's own security, trust or news page
Asana security pageThe company's own security, trust or news page
Aspen Technology security pageThe company's own security, trust or news page
Astera Labs newsroom pageThe company's own security, trust or news page
Astronomer security pageThe company's own security, trust or news page
Atira security pageThe company's own security, trust or news page
Atlassian security pageThe company's own security, trust or news page
Augment Code security pageThe company's own security, trust or news page
Barings security pageThe company's own security, trust or news page
Baseten trust pageThe company's own security, trust or news page
Baz security pageThe company's own security, trust or news page
BigBear.ai newsroom pageThe company's own security, trust or news page

Last run: daily, ok, 2026-09-25 15:13:31 UTC. Found 3, added 3, updated 0; probed 11 sources, added 0.

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.