The biggest data breaches in history — and what their autopsies teach you
20 September 2026
Breach headlines blur together. But autopsies of the biggest ones reveal the same few failure modes — and the same few things you can do about them.
Yahoo (2013–14, disclosed 2016–17): 3 billion accounts
The largest breach ever: every single Yahoo account, compromised via forged cookies, undisclosed for years. The lesson is about dwell time — attackers sat inside for years. For you: assume old accounts from dead services are breached. Check yours with our breach self-check and close what you don't use.
Equifax (2017): ~147 million Americans
A credit bureau holding data on people who never chose to be its customers failed to patch a known Apache Struts vulnerability for months. Attackers walked in through a disclosed, patched-elsewhere hole. Settlements ran past half a billion dollars. The lesson: your data is only as safe as the least careful company holding it — minimise who holds it, freeze credit where possible.
Marriott/Starwood (2018): ~500 million guests
Intruders lived in the Starwood reservation database since 2014. Passport numbers, travel histories — a foreign-intelligence goldmine wearing a hotel uniform. The lesson: breaches are discovered years late, so compromise must be assumed, not awaited — unique passwords per site contain the blast radius.
Facebook–Cambridge Analytica (2018): ~87 million profiles
Not a hack but a harvest: a quiz app collected users and their friends under loose platform rules, and the data went to political profiling. The lesson: permissions are the product — audit which apps can read your accounts, and check what your handle exposes with our handle self-check.
Collection #1 (2019): 773 million emails
Researcher Troy Hunt's aggregation of credential-stuffing "combo lists" proved the real economy: breached passwords get replayed automatically against banks, email, and UPI-linked accounts. The lesson: password reuse is the actual vulnerability — a manager plus 2FA defeats the entire stuffing industry.
The three defences behind all five autopsies
- Unique password per site (a manager makes this free).
- App-based 2FA on email, banking, and UPI-linked accounts.
- A quarterly breach re-check — free, here.