Thanks to IT Governance. It has compiled Cyber Attacks and Data Breaches list by month and year since 2014, might be earlier.
Here are leaked records numbers since 2014:
- 2020 – 20.1 billion data records leaked.
- 2019 – 12.3 billion data records reported lost or stolen.
- 2018 – 2.3 billion records leaked.
- 2017 – about 1.51 billion records leaked
- 2016 – 3.1 billion records leaked
- 2015 – over 480 million leaked records
- 2014 – about 248.36 million records leaked
Following information are collected from https://www.itgovernance.co.uk/blog.
2021
2020
2020 cyber security statistics
- List of data breaches and cyber attacks in December 2020 – 148 million records breached
- List of data breaches and cyber attacks in November 2020 – 587 million records breached
- List of data breaches and cyber attacks in October 2020 – 18.4 million records breached
- List of data breaches and cyber attacks in September 2020 – 267 million records breached
- List of data breaches and cyber attacks in August 2020 – 36.6 million records breached
- List of data breaches and cyber attacks in July 2020 – 77 million records breached
- List of data breaches and cyber attacks in June 2020 – 7 billion records breached
- List of data breaches and cyber attacks in May 2020 – 8.8 billion records breached
- List of data breaches and cyber attacks in April 2020: 216 million records breached
- List of data breaches and cyber attacks in March 2020 – 832 million records breached
- List of data breaches and cyber attacks in February 2020 – 623 million records breached
- List of data breaches and cyber attacks in January 2020 – 1.5 billion records breached
2019
- List of data breaches and cyber attacks in December 2019 – 627 million records breached
- List of data breaches and cyber attacks in November 2019 – 1.34 billion records breached
- List of data breaches and cyber attacks in October 2019 – 421 million records breached
- List of data breaches and cyber attacks in September 2019 – 531 million records leaked
- List of data breaches and cyber attacks in August 2019 – 114.6 million records leaked
- List of data breaches and cyber attacks in July 2019 – 2.3 billion records leaked
- List of data breaches and cyber attacks in June 2019 – 39.7 million records leaked
- List of data breaches and cyber attacks in May 2019 – 1.39 billion records leaked
- List of data breaches and cyber attacks in April 2019 – 1.33 billion records leaked
- List of data breaches and cyber attack in March 2019 – 2.1 billion records leaked
- List of data breaches and cyber attacks in February 2019 – 873,919,635 records leaked
- List of data breaches and cyber attacks in January 2019 – 1,170,983,728 records leaked
- Total 12.3 billion data records reported lost or stolen.
- There were 956 reported data breaches in 2019.
- It was increased 425% on last year.
- There were 2.3 billion breaches in 2018, compared to just 826 million in 2017
- There were 557 reported data breaches in 2018, increased 183% compared to 2017.
- GDPR year.
- List of data breaches and cyber attacks in November 2018 – 251,286,753 records leaked
- List of data breaches and cyber attacks in October 2018 – 44,701,278 records leaked
- List of data breaches and cyber attacks in September 2018 – 925,633,824 records leaked
- List of data breaches and cyber attacks August 2018 – 215,000,000 records leaked
- List of data breaches and cyber attacks in July 2018 – 139,731,894 million records leaked
- List of data breaches and cyber attacks in June 2018 – 145,942,680 records leaked
- List of data breaches and cyber attacks in May 2018 – 17,273,571 records leaked
- List of data breaches and cyber attacks in April 2018 – 72,611,721 records leaked
- List of data breaches and cyber attacks in March 2018 – 20,836,531 records leaked
- List of data breaches and cyber attacks in February 2018 – 2,234,633 records leaked
- List of data breaches and cyber attacks in January 2018 – 7,073,069 records leaked
- Jan 3, Spectre and Meltdown vulnerabilities (CVE-2017-5715, CVE-2017-5753, CVE-2017-5754)
- Jan 29, Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability
- Mach 20, Facebook’s privacy scandal – The Guardian revealed that the personal data of 50 million Facebook profiles was illegally harvested by Cambridge Analytica.
- June 27, Exactis – Data warehouse / consumer marketing data – 340 million PII records accessible via unprotected, online-accessible database
- Jul 29, Adidas – Shoes, clothing and sports equipment – PII for millions of customers (emails, login IDs, hashed passwords) – Technical details not released, potentially vulnerability on online-accessible server.
- Tickemaster UK – Online tickets – PII compromised, 40,000 users had their payment system compromised and money stolen – Breached through vulnerability in 3rd party chat software used on public website
- Typeform – Online surveys for large companies – PII for 20,000 users affected – Backup of database downloaded by exploiting vulnerability
- Under Armour – Sports clothing – Email, login IDs and hashed passwords for 150 million MyFitnessPal app users compromised, no details released
- Delta/Sears/K-Mart – Transportation, retail – PII for hundreds of thousands of customers breached – Vulnerability in chat software provided by 3rd party [24]7.ai provider
- Timehop – Developer / Phone Apps – 21 million PII records compromised due to weak privileged account authentication
- Macy’s / Bloomingdale – Retail – Stolen user credentials were used to login and access additional PII (names, addresses, credit card information)
- debate2018.mx – Mexican presidential election debate content – DDoS crashed the site during a presidential debate. Attacking host originated mostly from Russia and China, 185,000 accounts requesting registration within 15 minutes.
- CarePartners – Home medical care – Detailed medical records stolen for 273,000 patients. Details not disclosed, attackers claim they exploited vulnerability of Internet-accessible server and weak passwords. Hundreds of Gb exfiltrated.
- LabCorp – Clinical medical diagnostics – Large clinical laboratories, holding medical records for millions of patients. Anomalous network activity detected on July 14. Potentially hacked, extent of breach unknown.
- Reddit breached employees accounts (exploited vulnerabilities in SMS authenticators). Cloud-based, 2005-2007 user data files exposed.
- Cryptocurrency investment platform Atlas Quantum breached, 261,000 exposed. Details not disclosed but most likely public website was compromised through vulnerabilities
- T-Mobile breached, PII for 2 million customers potentially accessed by malicious actors. No technical details provided.
- Babysitting app Sitter exposed PII of 93,000 customers through a publicly accessible MongoDB file
- Darden Restaurants suffered a POS system data breach – 567,000 payment cards compromised.
- Phishing attack on Augusta University Health leads to breach exposing PII on 400,000 persons.
- 50.5 million Sungy Mobile customers exposed through publicly accessible data
- 14 million customer records exposed in GovPayNow leak (last four digits of payment cards, names, phone numbers and addresses). Details not disclosed but most likely public website was compromised through unpatched vulnerabilities
- US State Department email breach leaks employee PII. Potentially due to weak authentication.
- Blue Cross and Blue Shield of Rhode Island and Independence Blue Cross report breached, health information for approx. 1500 patients compromised. Breached occurred due to human error in services provided by third party (supply chain). Independence Blue Cross data breach which affected nearly 17,000 people after an employee uploaded member information to an unprotected public website.
- Tech Bureau Corp Japanese cryptocurrency exchange hack led to $60 million being stolen during a 2 hour attack against their server. No details provided, potentially through weakness in custom code.
- Colorado Timberline (printing firm) out of business following multiple ransomware attacks.
2017
Infographic: List of data breaches in 2017
- List of data breaches and cyber attacks in December 2017 – 33.8 million records leaked
- List of data breaches and cyber attacks in November 2017 – 59 million records leaked
- List of data breaches and cyber attacks in October 2017 – 55 million records leaked
- List of data breaches and cyber attacks in September – 174 million records leaked
- List of data breaches and cyber attacks in August 2017 – 715.6 million records leaked
- List of data breaches and cyber attacks in July 2017 – 143 million records leaked
- List of data breaches and cyber attacks in June 2017 – 199 million records leaked
- List of data breaches and cyber attacks in May 2017 – 61 million records leaked
- List of data breaches and cyber attacks in April 2017 – 10 million records leaked
- List of data breaches and cyber attacks in March 2017 – 74,000,000 records compromised
- List of data breaches and cyber attacks in February 2017 – about 35 million records leaked (My estimation)
- List of data breaches and cyber attacks in January 2017 – 7,073,069 records leaked
- Feb 17, CloudBleed – Google vulnerability researcher Tavis Ormandy discovered a bug in the internet infrastructure company Cloudflare‘s platform caused random leakage of potentially sensitive customer data.
- March 7, Wikileaks CIA Vault 7 – WikiLeaks published a data trove containing 8,761 documents allegedly stolen from the CIA that contained extensive documentation of alleged spying operations and hacking tools.
- April, Shadow Brokers (A hacking group, stole NSA data) / EternalBlue (Released by Shadow Brokers, which alleged NSA tool)
- May 12 , WannaCry – Ransomware :WannaCry searches for and encrypts 176 different file
types and appends .WCRY to the end of the file name. It asks users to pay a US$300 ransom in
bitcoins. The ransom note indicates that the payment amount will be doubled after three days. If payment is not made after seven days it claims the encrypted files will be deleted.
- June, Petya / NotPetya / Nyetya / Goldeneya – Ransomware , which is more advanced than WannaCry. Hit Ukraninian infrastructure hard.It spreads rapidly across an organization once a computer is infected using the EternalBlue vulnerability in Microsoft Windows
- Sep 7, Apache Struts : Equifax data breach was confirmed to be a vulnerability in Apache Struts. The security flaw (CVE-2017-5638), which was patched last March, allowed attackers to gain unauthorized access to data via remote code execution.
- Oct 3, 3 billion Yahoo user accounts were hacked by 2013 security breach, which make yahoo tops the list of largest ever data breaches
- Oct 16, Krack : Key Reinstallation Attack (KRACK) is a proof of concept that exploits vulnerabilities in the Wi-Fi Protected Access 2 (WPA2) protocol.
- Nov 28, Major macOS High Sierra Bug Allows Full Admin Access Without Password
Here is another good review for 2017 security threats from youtube video 2017 Security Threats | Year in Review | WEBINAR. I have watched it and made some notes in the following points:
- Q1. The Botnet Menace , Zeus and Conflicker, Mirai (IoT) and Pushdo (SpamBots)
- Q2. WannaCry, Locky, H-Worm (Houdini Worm)
- Q3. SMB, Petya (Ransomware)
- Q4. AAEH New Hope, Apache Struts Remote Code Execution, Necurs Botnets, H-Worm
2016
- List of data breaches and cyber attacks in 2016 – 3.1 billion records leaked (includes Dec 2016)
- List of data breaches and cyber attacks in November 2016 – 456,403,757 records exposed
- List of data breaches and cyber attacks in October 2016 – 142,160,000 records leaked
- List of data breaches and cyber attacks in September 2016
- List of data breaches and cyber attacks in August 2016
- List of data breaches and cyber attacks in July
- List of data breaches and cyber attacks in June 2016 (289,150,000+ records leaked)
- List of data breaches and cyber attacks in May 2016
- List of data breaches and cyber attacks in April 2016 – 166,687,282 records stolen
- List of data breaches and cyber attacks in March 2016
- List of data breaches and cyber attacks in February 2016
- List of data breaches and cyber attacks in January – 57,740,000 records stolen
- February, Israel breached the US Department of Justice’s database.
- March, Cyber criminals stole $81 million from Bangladesh’s central bank through a series of transfers from its account at the Federal Reserve Bank of New York.
- June, ‘Peace’ came to prominence after data on millions of LinkedIn, Tumblr and Myspace users was made available online.
- September, Krebs site hit with DDoS attack measuring in at between 620 and 655 Gbps.
- September, Yahoo suffers from massive data breach
- October, Dyn DDoS Attack
- November, AdultFriendFinder.com gets attacked once more
- December, Hackers Stole a Billion Yahoo Accounts on a 2013 hit.
2015
List of data breaches and cyber attacks in 2015 – over 480 million leaked records
- January, A critical vulnerability has been found in glibc, the GNU C library, that affects all Linux systems dating back to 2000. CVE-2015-0235, has already been nicknamed GHOST because of its relation to the _gethostbyname function.
- March, All Major browsers hacked
- April, Obsolete NPAPI extension blocked in Chrome
- June, hard-coded default SSH keys were found in Cisco’s security appliances
- July, Vulnerabilities discovered in the Stagefright media playback engine that is native to Android devices could be the mobile world’s equivalent to Heartbleed.
- October, SHA-1 Collision
2014
List of cyber attacks and data breaches in 2014 – about 248.36 million records leaked (My Estimation)
- April, OpenSSL heartbleed vulnerability
- September, ShellShock
- December, Misfortune Cookie – 12 MILLION HOME ROUTERS VULNERABLE TO TAKEOVER
Other Sourcess
- World’s Biggest data breaches and hacks.
- Gemalto’s
breachlevelindex.com website collects disclosed breaches from public sources and allows organizations to do their own risk assessment based on a few simple inputs that will calculate their own risk scores, overall breach severity level, and summarize actions IT can take to reduce the risk score.
References:
- 2016年网络安全大事记
- 2017年网络安全行业大事记(最全完整版)
- 2017 Security Threats | Year in Review | WEBINAR
- The Biggest Cybersecurity Disasters of 2017 So Far
- 2017’s Notable Vulnerabilities and Exploits
- The unconventional list of top security events in 2015
- The 10 biggest security incidents of 2016
- Wikipedia: List of data breaches
- The most infamous data breaches
Great info!
I think that most issues with privacy can be solved with virtual number, that you can use from various provider.
Would love to see topic, like, privacy options in 2021.