Crime

This Corporate Data Breach Lasted 3 Years and Exposed 3 Billion Accounts

Dark, hacker and computer with malware screen for cybersecurity, virus or ransomware for erp system. Monitor, spy and hacking website for government espionage, surveillance and internet scam at night
PeopleImages.com - Yuri A / Shutterstock.com

While every business hopes to protect and secure its data networks, sometimes, the worst-case scenario occurs, and a data breach takes place. Over the computer age, computer breaches have ranged in size and expense, ranging from just a few hundred leaks to tens of millions, if not hundreds of millions, of users affected. 

Key Points

  • The largest corporate data breaches are a huge red flag for the future.

  • These hacks or breaches resulted in the data of billions of users being exposed online.

  • Some companies took more significant action than others to enhance website security.

  • Retiring early is possible, and may be easier than you think. Click here now to see if you’re ahead, or behind. (Sponsor)

As awful as these data breaches are for those impacted, they’re also a public relations nightmare for companies that must focus on rebuilding customer trust. With the world moving toward everything digital, the likelihood of more breaches has unfortunately increased, not decreased, which makes the largest corporate data breaches in history a giant warning for the future. 

10. MySpace

Internet Market Considers MIcrosoft Bid for Yahoo
2008 Getty Images / Chris Jackson Collection via Getty Images
  • Date of breach: June 2013
  • Number of customers impacted: 360 million accounts
  • Type of breach: Unauthorized access
  • What was stolen: Usernames, email addresses, dates of birth

More Than Just Tom’s Data

New Myspace Launch Event
2013 Getty Images / Getty Images Entertainment via Getty Images

Having pivoted to a music-friendly site long ago, MySpace’s data breach was still among US history’s most significant and most concerning. Over 360 million user accounts were compromised and posted for sale on the dark web in 2016. The company confirmed that the stolen data was from before 2013, so it had already taken steps to update its security measures and notified all affected users to change their passwords. MySpace was not fined, and little legal action was taken. 

9. Friend Finder Networks

hacker with laptop on black background
KonstantinChristian / Shutterstock.com
  • Date of breach: November 2016
  • Number of customers impacted: 412 million
  • Type of breach: Unauthorized access
  • What was stolen: 20 years worth of data 

The Adult Website Breach

gorodenkoff / iStock via Getty Images

Often going under the radar because of the nature of the business, Friend Finder Networks suffered one of the worst corporate data breaches in history. Over 412 million customers, including usernames, email addresses, membership details, and user activity, were affected. The company implemented stronger security measures and notified users to change their passwords. Ironically, the company was not fined, and its websites still report around 50 million monthly users. 

8. Marriott International

Marriott hotel
JHVEPhoto / iStock Editorial via Getty Images
  • Date of breach: September 2018
  • Number of customers impacted: 500 million customers
  • Type of breach: Database breach (guest reservation database) 
  • What was stolen: Names, mailing addresses, phone numbers, passport numbers, Starwood Preferred Guest account information, credit card numbers

Worst Hotel Breach

volkan.basar / iStock Unreleased via Getty Images

Following an attack on its systems in September 2018, Marriott International (Starwood) indicated that they had been alerted that a database had received unauthorized access as far back as 2014. In 2018, the company decrypted the information and acknowledged it was a guest reservation database that had been affected. As a result, the company had to pay a $52 million fine through the FTC to 49 states and fines across the UK while promising to enhance security measures. 

7. Facebook

panida wijitpanya / iStock Editorial via Getty Images
  • Date of breach: April 2010
  • Number of customers impacted: 533 million
  • Type of breach: Unauthorized access, data scraping
  • What was stolen: Facebook IDs, locations, profile details

Mega Meta Leak

Derick Hudson / iStock Editorial via Getty Images

This April 2019 breach accessed the data of more than 533 million Facebook customers and revealed information on over 530 million Facebook users. This data included phone numbers, Facebook IDs, and account names, all posted online for free in April 2021. Facebook was widely criticized for not publicizing the breach earlier, but little action was taken. Meta has committed to stronger security practices since the breach first became public. 

6. Sina Weibo

jonrussell / Flickr
  • Date of breach: March 2020
  • Number of customers impacted: 538 million accounts
  • Type of breach: Database hack
  • What was stolen: Personal details including names, gender, location, phone numbers

Biggest Chinese Data Breach

Business person identifies vulnerabilities cyber security to prevent hacks. Learn how to safeguard systems against hackers with effective security measures and hack-proof strategies FaaS
Owlie Productions / Shutterstock.com

China’s largest social media network, Sina Weibo, exposed data from more than 538 million users, with almost 90% of its users’ posts exposed online. China’s Ministry of Industry and Information Technology ordered Weibo to enhance its security measures, and the company indicated it strengthened security measures and was working with the appropriate Chinese authorities. 

5. LinkedIn

Justin Sullivan / Getty Images News via Getty Images
  • Date of breach: April 2021
  • Number of customers impacted: 700 million users
  • Type of breach: Data scraping
  • What was stolen: Names, phone numbers, geolocation records, details around linked social media accounts

“God User” Attack 

GM Stock Films / Getty Images

Known by the hacker handle “God User,” the April 2021 data breach was among the largest in corporate America, specifically for social media companies. Initially claiming to have data of around 500 million users, God User later claimed to expose more than 700 million users when the data was posted to the dark web in June 2021. LinkedIn was hit with a $335 million fine by the European Union for the breach. Still, only $1.25 million was paid to victims in the U.S., or $50 per user, while enhancing security measures was a commitment LinkedIn had to make good on. 

4. First American Financial Corporation 

First American Corporation
Coolcaesar / Wikimedia Commons
  • Date of breach: May 2019
  • Number of customers impacted: 885 million records
  • Type of breach: Unauthorized access
  • What was stolen: Bank account details, bank statements, mortgage payments, Social Security numbers

Giant Real Estate Mess

criminal and burglary concept - thief in mask searching info about real estate in internet
Di Studio / Shutterstock.com

Taking place in May 2019, First American Financial Corporation, a well-known real estate title insurance company, suffered a significant data leak. This resulted from poor website design and security measures. Still, it didn’t involve hacking but did allow access to bank account information, including statements, mortgage documents, Social Security numbers, and driver’s licenses. The company was fined $1 million for violating cybersecurity laws, ignoring potential red flags, and individual lawsuits. 

3. Alibaba 

maybefalse / iStock Unreleased via Getty Images
  • Date of breach: November 2019
  • Number of customers impacted: 1.1 billion
  • Type of breach: Data scraping
  • What was stolen: Usernames, phone numbers, general customer data

Biggest Chinese Breach

David Ramos / Getty Images

Impacting the lives of over 1.1 billion users over 8 months, Alibaba suffered a significant data breach affecting its Chinese shopping website Taobao. A developer and his manager working for an affiliate marketer were found to have scraped customer data, including usernames and phone numbers, on behalf of his employer. The individual and his manager were sentenced to three years in prison, with no other apparent penalties or fines. 

2. Real Estate Wealth Network

Warning alert icon with a hacked document system.Hands typing on a keyboard with a red cybersecurity threat alert, surrounded by digital files and documents.
pixadot.studio / Shutterstock.com
  • Date of breach: December 2023
  • Number of customers impacted: 1.5 billion records leaked
  • Type of breach: Database leak
  • What was stolen: Property history, names, addresses, mortgage information, tax IDS

Concerning Social Engineering Leak

Business person identifies vulnerabilities cyber security to prevent hacks. Learn how to safeguard systems against hackers with effective security measures and hack-proof strategies FaaS
Owlie Productions / Shutterstock.com

One of the most significant corporate data leaks in US history, the New York-based online real estate platform Real Estate Wealth Network, had more than 1.5 billion records leaked. Over 1.16 TB of data contained information about celebrities like Floyd Mayweather, Nancy Pelosi, and Britney Spears. Hackers could easily conduct social engineering attacks with this data, but legal action remains unclear as of January 2025. 

1. Yahoo

4x6 / iStock Unreleased via Getty Images
  • Date of breach: August 2013 – December 2016
  • Number of customers impacted: 3 billion accounts
  • Type of breach: Unauthorized access
  • What was stolen: User information like names, email, addresses, phone numbers

The Largest Breach Ever

Justin Sullivan / Getty Images

Yahoo has the honor of being the target of the most significant corporate data breach in history. In 2016, the company disclosed that more than 3 billion user accounts were compromised due to Russian hacking. Using a backdoor, the hackers stole all types of customer information. A lawsuit determined that Yahoo failed to notify its users of the hack, which led to 41 class action lawsuits and a 35 million dollar fine. It also caused the company’s valuation to drop when sold to Verizon.

It’s Your Money, Your Future—Own It (sponsor)

Retirement can be daunting, but it doesn’t need to be.

Imagine having an expert in your corner to help you with your financial goals. Someone to help you determine if you’re ahead, behind, or right on track. With SmartAsset, that’s not just a dream—it’s reality. This free tool connects you with pre-screened financial advisors who work in your best interests. It’s quick, it’s easy, so take the leap today and start planning smarter!

Don’t waste another minute; get started right here and help your retirement dreams become a retirement reality.

Thank you for reading! Have some feedback for us?
Contact the 24/7 Wall St. editorial team.

AI Portfolio

Discover Our Top AI Stocks

Our expert who first called NVIDIA in 2009 is predicting 2025 will see a historic AI breakthrough.

You can follow him investing $500,000 of his own money on our top AI stocks for free.