RepublicCyberIntel

The biggest data breaches in history — and what their autopsies teach you

20 September 2026

Cracked database leaking records

Breach headlines blur together. But autopsies of the biggest ones reveal the same few failure modes — and the same few things you can do about them.

Yahoo (2013–14, disclosed 2016–17): 3 billion accounts

The largest breach ever: every single Yahoo account, compromised via forged cookies, undisclosed for years. The lesson is about dwell time — attackers sat inside for years. For you: assume old accounts from dead services are breached. Check yours with our breach self-check and close what you don't use.

Equifax (2017): ~147 million Americans

A credit bureau holding data on people who never chose to be its customers failed to patch a known Apache Struts vulnerability for months. Attackers walked in through a disclosed, patched-elsewhere hole. Settlements ran past half a billion dollars. The lesson: your data is only as safe as the least careful company holding it — minimise who holds it, freeze credit where possible.

Marriott/Starwood (2018): ~500 million guests

Intruders lived in the Starwood reservation database since 2014. Passport numbers, travel histories — a foreign-intelligence goldmine wearing a hotel uniform. The lesson: breaches are discovered years late, so compromise must be assumed, not awaited — unique passwords per site contain the blast radius.

Facebook–Cambridge Analytica (2018): ~87 million profiles

Not a hack but a harvest: a quiz app collected users and their friends under loose platform rules, and the data went to political profiling. The lesson: permissions are the product — audit which apps can read your accounts, and check what your handle exposes with our handle self-check.

Collection #1 (2019): 773 million emails

Researcher Troy Hunt's aggregation of credential-stuffing "combo lists" proved the real economy: breached passwords get replayed automatically against banks, email, and UPI-linked accounts. The lesson: password reuse is the actual vulnerability — a manager plus 2FA defeats the entire stuffing industry.

The three defences behind all five autopsies

  1. Unique password per site (a manager makes this free).
  2. App-based 2FA on email, banking, and UPI-linked accounts.
  3. A quarterly breach re-check — free, here.