Cybersecurity: The 10 Worst Data Breaches from 2015 to Today
Data

Cybersecurity: The 10 Worst Data Breaches from 2015 to Today

A detailed analysis of the 10 most devastating data breaches from 2015 to today, in chronological order: from Adobe to Equifax, discover what happened, how, and the consequences for millions of users.

16 min read
The 10 Worst Data Breaches in Digital History | Cyber Catastrophes

The 10 Worst Data Breaches in Digital History: Lessons from Cyber Catastrophes

A complete analysis of the 10 worst data breaches from 2015 to today: Yahoo, Adobe, Anthem, Equifax and other digital catastrophes that compromised billions of personal records. Discover the recurring patterns and their devastating consequences.

Introduction: A Decade of Digital Disasters

From 2015 to today, the digital world has witnessed an unprecedented escalation of data breaches that have compromised billions of pieces of personal information. In the first half of 2018 alone, around 4.5 billion records were exposed, while in January 2024 a breach dubbed the "mother of all breaches" was discovered, containing over 26 billion records from Twitter, Adobe, Canva, LinkedIn and Dropbox. These are not mere technical incidents, but digital catastrophes that have exposed the sensitive data of hundreds of millions of people, caused billions of dollars in economic damage and deeply undermined trust in digital platforms.

An analysis of the worst breaches of this period, presented in chronological order, reveals recurring patterns that show how negligence in cybersecurity, unpatched vulnerabilities and inadequate data protection protocols can turn into global disasters. Understanding what happened, how it happened and what the consequences were is not just an academic exercise, but a fundamental lesson for any organization that handles personal data.

First Breach: Yahoo 2013-2014 - The All-Time Record

The Yahoo data breach is one of the worst and most notorious known cases of cyber attack and currently holds the record for the largest number of people affected. The first attack occurred in 2013, and many others continued over the following three years. A team of Russian hackers targeted Yahoo's database using backdoors, stolen backups and access cookies to steal records from all user accounts.

The scale of the disaster emerged progressively. Yahoo initially reported the theft of data from about one billion accounts, a staggering figure in itself. However, after Verizon acquired Yahoo in 2017, the full truth emerged: the final number of compromised records amounted to approximately 3 billion affected accounts. This essentially means that every single Yahoo account in existence at the time of the attack was compromised.

The stolen data included personally identifiable information such as names, email addresses, phone numbers, dates of birth, hashed passwords and, in some cases, security questions and answers. The severity of the situation was compounded by Yahoo's slow response. The company was not only late to react, but failed to disclose a 2014 incident to users, resulting in a $35 million fine and, in total, 41 class action lawsuits.

The consequences for Yahoo were devastating both reputationally and financially. When Verizon finally acquired the company, the purchase price was significantly reduced precisely because of the data breaches. The Yahoo affair shows how years of security negligence can culminate in a catastrophe that wipes out billions of dollars of corporate value and destroys trust built over decades.

Second Breach: Adobe October 2013 - 153 Million Accounts and Source Code

In early October 2013, Adobe reported that hackers had stolen nearly three million encrypted customer credit card records and login data for an undetermined number of user accounts. Days later, Adobe raised that estimate to include IDs and encrypted passwords for 38 million "active users". Security blogger Brian Krebs then reported that a file posted just days earlier "appears to include more than 150 million username and password pairs with hashes taken from Adobe".

What initially seemed a relatively contained breach turned out to be one of the largest data compromises in history. The attackers stole not only customer information but also the source code of Adobe products such as Photoshop, ColdFusion and Acrobat. This posed a threat to both Adobe and its customers, since access to the source code could reveal vulnerabilities that attackers could then exploit.

The situation was aggravated by the discovery that Adobe had used weak security practices to protect user passwords. Many passwords were encrypted using the 3DES algorithm in ECB mode, which is considered insecure for this purpose because identical passwords produce identical ciphertext. This allowed security researchers to decrypt millions of passwords by analyzing patterns in the stolen database.

Further investigations revealed that the database contained plain-text password hints, which in many cases made it trivial to guess the actual password even without decrypting it. Krebs published analyses showing the most common password hints, revealing that millions of users relied on incredibly weak and predictable passwords.

Adobe faced multiple class action lawsuits and in 2015 agreed to a settlement that included paying $1.1 million in legal fees and an undisclosed amount to users to resolve claims of violating California's Consumer Records Act. The breach significantly damaged Adobe's reputation and led to scrutiny of the security of the company's cloud services.

Third Breach: Anthem 2015 - 80 Million Health Records

In 2015, Anthem Inc., one of the largest American health insurers, suffered a breach that compromised the personal information of approximately 80 million people. The stolen data included names, dates of birth, Social Security numbers, email addresses, employment information, member identification numbers and income information. Although Anthem stated that medical information and credit card data were not compromised, the stolen data was more than enough for large-scale identity fraud.

The attackers gained access through a targeted phishing attack that compromised an employee's credentials. Once inside the network, they used those credentials to move laterally through Anthem's systems, eventually gaining access to the databases containing member information. Security experts attributed the attack to a Chinese state-sponsored group, interested not so much in financial fraud as in gathering intelligence on American citizens.

Anthem took weeks to discover the breach after it had begun, and by the time it was discovered, the damage was already done. The company faced hundreds of lawsuits and eventually agreed to a $115 million settlement, one of the largest health data breach settlements in history. The incident also led to regulatory sanctions, including a fine from the Department of Health and Human Services' Office for Civil Rights for HIPAA violations.

The Anthem breach highlighted the particular vulnerability of the healthcare sector. Healthcare organizations handle some of the most sensitive data possible, yet often have cybersecurity investments that are inadequate compared to the criticality of the information they hold. Medical records are especially valuable on the black market because, unlike credit card numbers that can be cancelled, medical data remains valid indefinitely and can be used for a wider range of fraud.

Fourth Breach: FriendFinder Networks 2016 - 412 Million Adult Site Accounts

The popular adult entertainment company FriendFinder Networks suffered a massive data breach in 2016 when six of its main databases were hacked, including its best-known subsidiaries, AdultFriendFinder and Penthouse. Over 20 years of data were stolen, amounting to roughly 412 million accounts, including 15 million deleted accounts that had never been removed from the databases.

What sets this breach apart is the extremely compromising nature of the information stolen. The data included not only the usual personally identifiable information, but also intimate details about users' sexual preferences, orientations, fantasies and behaviors. For an adult dating platform, this kind of information represents perhaps the most sensitive content possible, with enormous potential for blackmail, extortion and reputational damage.

According to LeakedSource, FriendFinder Networks had protected passwords with the unsalted SHA-1 hashing algorithm and stored user data in plain text files. This is an incredibly weak security practice for any platform, but it is particularly irresponsible for a service that handles such sensitive information. The use of SHA-1, an algorithm considered obsolete and vulnerable, and the absence of salting made it relatively easy for attackers to decrypt the passwords.

In addition, a white-hat security researcher known as Revolver revealed a Local File Inclusion vulnerability through photos shared on social media. This was a huge security problem for the adult entertainment company because it had been hacked just a year earlier, in May 2015, compromising 3.5 million users. The fact that they had not learned the lesson from the first breach and implemented adequate security measures demonstrates systematic negligence.

The consequences for the users involved were particularly severe. Unlike breaches involving mainstream services, where the embarrassment may be limited, the exposure of information from adult dating sites can have devastating repercussions on personal relationships, professional careers and social reputation. Cases of blackmail and extortion that emerged after the breach confirmed the worst fears of the users involved.

Fifth Breach: Equifax 2017 - 147 Million Americans and the Worst Negligence

Between May and July 2017, the American credit agency Equifax was breached. The private records of 147.9 million Americans, along with 15.2 million British citizens and about 19,000 Canadian citizens, were compromised in the breach, making it one of the largest identity theft-related cybercrimes.

The information accessed in the breach included first and last names, Social Security numbers, dates of birth, addresses and, in some cases, driver's license numbers for approximately 143 million Americans. For a credit agency holding sensitive financial information on most of the American adult population, this breach represents perhaps the worst possible catastrophe.

Extraordinary Negligence: When the Fundamentals Are Ignored

The sequence of events reveals almost unbelievable negligence. In March 2017 a critical security patch for Apache Struts, a web application framework, was released after a critical security vulnerability was identified. The Equifax data breach began on May 12, 2017, when Equifax had still not updated its credit dispute website with the latest version of Apache Struts.

The situation worsened due to a series of systemic security failures. The attackers extracted data from the network in encrypted form without being detected for months because Equifax had crucially failed to renew an encryption certificate on one of its internal security tools. The certificate had expired almost ten months earlier, which meant that encrypted traffic was not being inspected. The expired certificate was not discovered and renewed until July 29, 2017, when Equifax administrators almost immediately began noticing all the suspicious activity that had previously been obscured.

Equifax discovered the breach in late July but did not disclose it to the public until September 2017. In the meantime, several Equifax executives sold company shares, leading to suspicions of insider trading. This breach was also made possible by the use of default credentials with username and password "admin" and by the lack of two-factor authentication on accounts with elevated access.

The consequences were devastating. Equifax faced 41 class action lawsuits and accepted a $1.38 billion settlement to resolve customer claims. CEO Richard Smith, CSO Susan Mauldin and CIO David Webb resigned in the aftermath of the breach. In February 2020, the United States government indicted members of the Chinese People's Liberation Army for hacking Equifax and stealing sensitive data.

Sixth Breach: Facebook and Cambridge Analytica 2018 - 87 Million Profiles and the Manipulation of Democracy

The data was collected through an app called "This Is Your Digital Life", developed by data scientist Aleksandr Kogan and his company Global Science Research in 2013. The app consisted of a series of questions to build psychological profiles of users, and collected the personal data of users' Facebook friends via Facebook's Open Graph platform. The app harvested the data of up to 87 million Facebook profiles. Cambridge Analytica used the data to provide analytical assistance to the 2016 presidential campaigns of Ted Cruz and Donald Trump.

What makes this breach particularly insidious is not so much its size as the way the data was used. By inappropriately harvesting data from approximately 87 million Facebook profiles, the data analytics firm Cambridge Analytica created psychographically tailored advertisements allegedly aimed at influencing voting preferences in the 2016 American presidential election.

The mechanism was as clever as it was troubling. About 270,000 users were paid to take a psychological personality test through the app. However, the app collected not only the data of those taking the test, but also that of all their Facebook friends, exploiting a feature of the Facebook API called Open Graph. This allowed Kogan to collect data from tens of millions of people who had never given any consent and were unaware that their data was being collected.

While some within Facebook saw this data collection as acceptable for academic purposes, Kogan subsequently passed the collected data on to Cambridge Analytica, which allegedly proceeded to use the data for distinctly non-academic activities. This would have been outside the scope of activity approved by Facebook and certainly outside the scope of consent given by the people using Kogan's app.

When Facebook discovered in 2015 that Kogan had passed on this data, it removed API access for Kogan's app and required Kogan and Cambridge Analytica to certify that they had destroyed the collected data. All parties provided this certification, but it was evident that copies of the information continued to persist and remain in use. The New York Times viewed samples of Cambridge Analytica's data as late as March 2018.

On March 26, 2018, just over a week after the story was first published, Facebook shares plunged by about 24%, equivalent to $134 billion. CEO Mark Zuckerberg publicly apologized and was called to testify before the United States Congress. In July 2019, Facebook agreed to pay $100 million to settle with the U.S. Securities and Exchange Commission for "misleading investors about the risks it faced from the misuse of user data".

The Cambridge Analytica scandal was not just a data breach; it marked a turning point in the public understanding of how personal data can be used for psychological manipulation and interference in democratic processes. The implications go far beyond Facebook, raising fundamental questions about privacy, informed consent and the power of digital platforms to influence society.

Seventh Breach: Marriott International 2018 - 500 Million Guests Compromised

This incident highlighted the lack of data security within the hospitality industry. When Marriott acquired Starwood in 2016, it failed to upgrade the old reservation system, leaving it highly vulnerable to malware and data breaches. Many cybersecurity experts believe the Chinese government initiated this attack to obtain valuable information. In 2019, Marriott was fined nearly $24 million by the UK Information Commissioner's Office for failing to meet cybersecurity standards.

The attack on Marriott's systems had begun long before its discovery. Hackers had had access to the Starwood reservation system databases since 2014, remaining undetected for four years. During this period, they extracted data on approximately 500 million guests, including names, postal addresses, phone numbers, email addresses, passport numbers, Starwood Preferred Guest account details, arrival and departure dates and, in some cases, even encrypted credit card numbers.

The Marriott breach exemplifies a common problem in corporate mergers: inadequate IT system integration. When Marriott acquired Starwood, it also inherited the acquired company's outdated technology infrastructure and already compromised systems. Inadequate technical due diligence and the failure to prioritize cybersecurity during post-acquisition integration turned what could have been a business success into a cybersecurity disaster.

Experts attribute the attack to groups linked to the Chinese government, interested not so much in financial data as in information on the movements and travel habits of political figures, business executives and government officials. This kind of intelligence can be used for espionage operations, to identify behavioral patterns or to build detailed profiles of specific targets. The Marriott breach demonstrates that hotel data is not just commercial information, but a potential geopolitical intelligence asset.

Eighth Breach: First American Financial Corp 2019 - 885 Million Records Exposed

In 2019, First American Financial Corp, one of the largest title insurance companies in the United States, left 885 million sensitive records exposed online. The documents included bank statements, Social Security numbers, real estate transaction information, driver's license images and mortgage documents going back more than a decade.

The most disconcerting feature of this breach was its technical simplicity. It was not a sophisticated attack by expert hackers or advanced malware. The documents were simply accessible to anyone with a web browser, with no authentication required. By changing a simple number in a URL, anyone could access hundreds of millions of sensitive documents. This vulnerability, known as Insecure Direct Object Reference, is one of the most basic and easily avoidable in web security.

A journalist at KrebsOnSecurity discovered the vulnerability and contacted First American, which eventually shut down public access to the documents. However, it is unclear how long the data had been exposed or how many people had actually accessed this information before the shutdown. The company faced numerous lawsuits and regulatory investigations, including a fine from the New York Department of Financial Services.

This breach highlights a systemic problem: organizations that handle extremely sensitive data often fail to implement even the most basic security measures. In the real estate and financial sector, where documents contain enough information to commit full identity theft, the absence of proper access controls is inexcusable. The First American case shows that you do not have to be the victim of sophisticated hackers to suffer a catastrophic breach: sometimes incompetence is enough.

Ninth Breach: Capital One 2019 - 100 Million Customers and the Insider Threat

In 2019, Capital One announced that a hacker had gained unauthorized access to the personal information of approximately 100 million individuals in the United States and 6 million in Canada. The compromised data included Social Security numbers, bank account numbers, names, addresses, ZIP codes, phone numbers, email addresses, dates of birth and self-reported income information.

What made this breach particularly interesting was the identity of the attacker and the method used. Paige Thompson, a former Amazon Web Services employee, was arrested and charged with carrying out the attack. Thompson had exploited a misconfiguration in a web application firewall at Capital One to access data stored on Amazon Web Services cloud servers.

The attack highlighted two critical vulnerabilities in the era of cloud computing. First, even the most secure cloud configurations can be compromised if not implemented correctly. Capital One had migrated many of its systems to AWS, but had left configuration vulnerabilities that could be exploited by someone with sufficient technical knowledge of cloud infrastructure. Second, the risk of insider threats: people with specialized knowledge of systems from within, or from previous employment at service providers.

Thompson not only accessed the data but also posted information about the breach on social media and in online forums, boasting about her actions. This behavior ultimately led to her identification and arrest by the FBI. She was charged with computer fraud and abuse, facing up to 25 years in prison if convicted.

Capital One faced intense criticism for failing to implement adequate security measures to protect customer data in the cloud. The Federal Reserve fined the bank $80 million for deficient risk management practices, and Capital One agreed to a $190 million class action settlement with affected customers. The Office of the Comptroller of the Currency also fined Capital One $80 million, citing deficient cybersecurity practices.

Tenth Breach: Chinese Surveillance Network 2019 - 4 Billion Records Exposed

The largest data leak ever recorded exposed 4 billion records, including WeChat data, banking details and Alipay profile information of hundreds of millions of users, mainly from China. The 631GB database, which also included phone numbers, home addresses and behavioral profiles, was left completely open on the internet, protected by no password or any other form of authentication control.

Bob Dyachenko, a cybersecurity researcher, and the website Cybernews stumbled upon the billions of exposed records during a research project. The database, meticulously collected and maintained, offered complete behavioral, economic and social profiles of the vast majority of the Chinese population. What sets this breach apart is that it was not a traditional hacking attack, but a nonexistent security configuration that left extremely sensitive data completely exposed to anyone who knew where to look.

The database contained information that went well beyond simple personal records. The behavioral profiles included purchasing patterns, physical movements tracked through smartphones, social networks, consumption habits and even social trustworthiness ratings. This kind of information, in the wrong hands, can be used for sophisticated fraud, blackmail, industrial-scale identity theft and social manipulation.

The breach raised disturbing questions about privacy in an era of pervasive digital surveillance. When billions of people see every aspect of their digital lives exposed, the very concept of personal privacy becomes an abstraction. The Chinese Surveillance Network case perhaps represents the culmination of an era in which mass data collection has far outstripped organizations' ability to protect it adequately.

Conclusion: Recurring Patterns and Lessons Not to Be Forgotten

The analysis of these ten catastrophic breaches reveals alarming patterns that repeat across different organizations, sectors and geographies. The first and most obvious is that size and resources do not guarantee security. Yahoo, Facebook, Equifax and Marriott were all massive organizations with substantial budgets, yet they suffered some of the worst breaches in history. Cybersecurity is not a function of an organization's size but of its culture, priorities and implementation.

The second recurring pattern is the crucial role of human error and negligence. In case after case, breaches were made possible not by revolutionary attack technologies but by basic failures: security patches left unapplied, expired certificates left unrenewed, default configurations left unchanged, databases left unprotected. Equifax failed to apply a critical patch, First American left documents publicly accessible, FriendFinder used obsolete hashing algorithms. These are not exotic technical vulnerabilities but fundamental negligence.

The third common theme is the inadequate and delayed response to breaches. Yahoo waited years before fully disclosing the extent of the compromise. Equifax discovered the breach in July but did not announce it until September, while executives sold shares. Marriott did not discover for four years that Starwood's systems were compromised. These delays not only allow attackers to keep stealing data, but hugely amplify the reputational damage when the truth emerges.

A fourth pattern is the systematic underestimation of the value and sensitivity of the data being handled. Organizations that hold Social Security numbers, medical information, financial details and intimate behavioral data often fail to implement levels of security proportionate to the criticality of this information. The idea that "we are not an interesting target" or "our data is not that valuable" has proved consistently wrong.

Looking at these ten catastrophic breaches from 2015 to today, it is hard to escape an uncomfortable conclusion: despite growing awareness of the problem, the situation is not improving significantly. Breaches continue, growing larger and more frequent. In 2025, the global average cost of a data breach is $4.44 million, while healthcare data breaches remain the most expensive, with an average cost of $7.42 million. The question is not whether more mega-breaches will occur, but when.

For organizations: Security must be built in by design, not added as an afterthought. Patches must be applied immediately, not months later. Systems must be monitored continuously, not checked sporadically. Employees must be trained constantly. Default configurations must be changed. Multi-factor authentication must be mandatory. Sensitive databases must be encrypted and segmented. And when breaches inevitably occur, they must be disclosed promptly and managed transparently.

For consumers, the reality is that their data has probably already been compromised in at least one of these breaches. Using unique passwords for every service, enabling two-factor authentication wherever possible, regularly monitoring credit reports and staying vigilant against phishing attempts are no longer optional but necessities of digital survival. The question is not whether more mega-breaches will occur, but when. And until cybersecurity becomes a genuine strategic priority rather than a compliance checkbox, we will keep seeing the names of familiar organizations added to this sadly long list of avoidable digital catastrophes.

Share this article