Most data breach statistics you read are distorted by a handful of enormous incidents. We analysed all 1,020 breaches in our catalogue: the typical one exposed 993,097 records, and half are smaller than a million. But two in three exposed passwords, and that is the part that actually affects you.
If you have just found out your email turned up in a breach, headline numbers are not much help. “Two billion records exposed” tells you nothing about your situation. What follows is what the data actually says, and what it means for your accounts.
Every figure below describes our catalogue of 1,020 tracked breaches. These describe a specific set of recorded incidents — not every breach that has ever happened.
How big is a typical data breach?
Smaller than the headlines suggest.
- Median breach: 993,097 records — half of all tracked breaches are smaller than this
- Smallest: 126 records
- Largest: 1,957,476,021 records
We quote the median rather than the average deliberately. A few enormous entries pull the average up to more than seventeen times the median, so the “average breach” describes almost none of the breaches in the file. When you see a very large average breach size quoted anywhere, this distortion is usually why.
Broken into size bands:
| Breach size | Number of breaches |
|---|---|
| Under 1 million records | 513 |
| 1–10 million | 330 |
| 10–100 million | 140 |
| Over 100 million | 37 |
Half the catalogue sits under a million records. Only 37 breaches out of 1,020 are the mega-breaches that make the news.
What data actually gets exposed in a breach?
This is the part that matters for you, and it is remarkably consistent.
- Almost every breach exposed email addresses (99.3%)
- Two in three exposed passwords (66.0%)
- Nearly two in three exposed passwords and the matching email together (65.6%)
- Nine in ten exposed at least one sensitive data type (91.0%)
- About one in twenty-two exposed data enabling direct financial fraud (4.5%)
Those last two numbers are the ones that matter, so here is exactly what each counts.
“Sensitive data type” means any of these eight: passwords, credit card numbers, bank account numbers, Social Security numbers, government issued IDs, phone numbers, physical addresses, or dates of birth.
“Direct financial fraud” is the much narrower group: credit card numbers, bank account numbers, Social Security numbers and government issued IDs only. It deliberately excludes partial card data and passport numbers.
So almost every breach exposes something sensitive, but very few expose the things that let someone take money directly.
Across our catalogue, breaches exposing direct financial data are the rare exception. For most people the realistic risk is account takeover, not bank fraud — someone taking your email address and password and trying that combination on your other accounts, which works whenever you have reused that password elsewhere.
That is why 65.6% is the important figure. It is not simply that a password leaked. It is that the password leaked next to the email address it belongs to, which hands an attacker a ready-made login attempt.
What should you actually do about it?
The statistics point to a short list, in order.
- Change the password that leaked, and change it anywhere you reused it. Given that nearly two in three breaches expose email-and-password pairs, reuse is the single thing that turns a breach into a cascade. Use the password reuse checklist.
- Turn on two-factor authentication, starting with your email account. A stolen password is far less useful without the second step.
- Use a password manager so every account has a different password. This is what stops one breach cascading into others.
- Do not panic about your bank. Only about one breach in twenty-two involves direct financial data. Monitor your statements, but the likely problem is account access, not fraud.
For the full step-by-step version, see what to do after a data breach. If you are still unclear on the basics, what is a data breach explains it in plain English.
Not sure whether you are affected? Check if your email was exposed → — free, no signup, and we do not store what you search.
Why are the biggest entries in our catalogue not really breaches?
Here is something the raw numbers hide.
The ten largest entries account for 40.2% of all exposed records. The top fifty account for 72.6%. A handful of entries dominate every total.
But look at what those largest entries actually are: most of the top twenty are not single-company breaches at all. They are compiled credential lists, stealer-log collections and scraped datasets that bundle together information already stolen in earlier, separate incidents.
This has a practical consequence. You cannot add up breach records to get a number of people. The same email address can appear in an original breach, then again in two or three compilations built from it. Any total that treats records as people counts some individuals many times over.
It also explains a common and confusing experience — finding your email in a breach you have never heard of, belonging to a service you never signed up for. You may not have been in that breach at all. Your details may have been swept into a compiled list from somewhere else entirely.
Do small breaches matter?
By volume, barely. The smallest 510 breaches — half the entire catalogue — account for just 0.9% of all exposed records.
By personal risk, they matter enormously, and the volume figure is misleading here.
A small breach that exposed your password is a genuine problem for you. A huge breach that exposed only email addresses is mostly a spam problem. When assessing your own exposure the question is never “how many people were affected” — it is “what was exposed, and did I reuse that password anywhere?”
Can you trust data breach statistics that show a trend?
Be careful with them, including ours.
We checked whether our catalogue shows breaches becoming more or less frequent over time, and we are not publishing an answer. The direction changes depending on which years you include — it can point either way and still be defensible. That is not a real-world finding, it is a reflection of when incidents happened to be discovered and recorded.
We would rather publish five numbers we can stand behind than a trend line that looks authoritative and is not. You can check the full breakdown yourself in our tracked breach database, which lists every incident and what was exposed.
What are the key data breach statistics to remember?
- The median breach exposed 993,097 records — smaller than headlines suggest
- Two in three exposed passwords; nearly two in three exposed passwords with the matching email
- Nine in ten exposed something sensitive, but only about one in twenty-two exposed direct financial data
- Ten entries hold 40.2% of all records, and most of those are compiled lists rather than single breaches
- Records are not people — compilations count the same person repeatedly
The practical takeaway is unchanged by any of it: find out whether your password was involved, change it everywhere you used it, and turn on two-factor authentication.
Can I cite or reuse these data breach statistics?
Yes — these figures are free to cite, quote, and reference in your own articles, reports, and research, provided you credit EmailLeaked with a link back to this page. We would rather the numbers be used correctly and attributed than misquoted, so everything you need to reference them is below.
Plain citation:
EmailLeaked (2026). Data Breach Statistics: What 1,020 Real Breaches Look Like. https://emailleaked.com/blog/data-breach-statistics/
Embed a live stat card on your own site. Copy this snippet — it displays a headline figure and links back to the full analysis:
<a href="https://emailleaked.com/blog/data-breach-statistics/"
style="display:block;max-width:340px;padding:16px 18px;border:1px solid #e2e2e2;border-radius:10px;font-family:system-ui,-apple-system,sans-serif;text-decoration:none;color:#111827;">
<strong style="font-size:26px;">66%</strong>
<span style="display:block;font-size:14px;margin-top:2px;">of tracked data breaches exposed passwords</span>
<span style="display:block;font-size:12px;color:#6b7280;margin-top:8px;">Source: EmailLeaked — analysis of 1,020 breaches</span>
</a>
Headline figures, ready to quote (analysis of 1,020 tracked breaches, as of 2026):
- Median breach size: 993,097 records
- Breaches exposing passwords: 66.0%
- Breaches exposing passwords next to the matching email: 65.6%
- Breaches exposing at least one sensitive data type: 91.0%
- Breaches exposing direct financial data: 4.5%
- Share of all records held by the ten largest entries: 40.2%
If you are writing about a specific incident and need detail, our tracked breach database lists every breach and what was exposed in each.
Figures calculated from our catalogue of 1,020 tracked breaches, last updated July 2026. Each figure was computed independently twice and cross-checked; figures that did not reconcile are not published.