Data Breach Statistics: What 1,020 Real Breaches Look Like — EmailLeaked
Explainers

Data Breach Statistics: What 1,020 Real Breaches Look Like

Data breach statistics from 1,020 tracked breaches: how big the typical breach really is, what gets exposed most often, and what it all means for you.

On this page

Most data breach statistics you read are distorted by a handful of enormous incidents. We analysed all 1,020 breaches in our catalogue: the typical one exposed 993,097 records, and half are smaller than a million. But two in three exposed passwords, and that is the part that actually affects you.

If you have just found out your email turned up in a breach, headline numbers are not much help. “Two billion records exposed” tells you nothing about your situation. What follows is what the data actually says, and what it means for your accounts.

Every figure below describes our catalogue of 1,020 tracked breaches. These describe a specific set of recorded incidents — not every breach that has ever happened.

How big is a typical data breach?

Smaller than the headlines suggest.

  • Median breach: 993,097 records — half of all tracked breaches are smaller than this
  • Smallest: 126 records
  • Largest: 1,957,476,021 records

We quote the median rather than the average deliberately. A few enormous entries pull the average up to more than seventeen times the median, so the “average breach” describes almost none of the breaches in the file. When you see a very large average breach size quoted anywhere, this distortion is usually why.

Broken into size bands:

Breach sizeNumber of breaches
Under 1 million records513
1–10 million330
10–100 million140
Over 100 million37

Half the catalogue sits under a million records. Only 37 breaches out of 1,020 are the mega-breaches that make the news.

What data actually gets exposed in a breach?

This is the part that matters for you, and it is remarkably consistent.

  • Almost every breach exposed email addresses (99.3%)
  • Two in three exposed passwords (66.0%)
  • Nearly two in three exposed passwords and the matching email together (65.6%)
  • Nine in ten exposed at least one sensitive data type (91.0%)
  • About one in twenty-two exposed data enabling direct financial fraud (4.5%)

Those last two numbers are the ones that matter, so here is exactly what each counts.

“Sensitive data type” means any of these eight: passwords, credit card numbers, bank account numbers, Social Security numbers, government issued IDs, phone numbers, physical addresses, or dates of birth.

“Direct financial fraud” is the much narrower group: credit card numbers, bank account numbers, Social Security numbers and government issued IDs only. It deliberately excludes partial card data and passport numbers.

So almost every breach exposes something sensitive, but very few expose the things that let someone take money directly.

Across our catalogue, breaches exposing direct financial data are the rare exception. For most people the realistic risk is account takeover, not bank fraud — someone taking your email address and password and trying that combination on your other accounts, which works whenever you have reused that password elsewhere.

That is why 65.6% is the important figure. It is not simply that a password leaked. It is that the password leaked next to the email address it belongs to, which hands an attacker a ready-made login attempt.

What should you actually do about it?

The statistics point to a short list, in order.

  1. Change the password that leaked, and change it anywhere you reused it. Given that nearly two in three breaches expose email-and-password pairs, reuse is the single thing that turns a breach into a cascade. Use the password reuse checklist.
  2. Turn on two-factor authentication, starting with your email account. A stolen password is far less useful without the second step.
  3. Use a password manager so every account has a different password. This is what stops one breach cascading into others.
  4. Do not panic about your bank. Only about one breach in twenty-two involves direct financial data. Monitor your statements, but the likely problem is account access, not fraud.

For the full step-by-step version, see what to do after a data breach. If you are still unclear on the basics, what is a data breach explains it in plain English.

Not sure whether you are affected? Check if your email was exposed → — free, no signup, and we do not store what you search.

Why are the biggest entries in our catalogue not really breaches?

Here is something the raw numbers hide.

The ten largest entries account for 40.2% of all exposed records. The top fifty account for 72.6%. A handful of entries dominate every total.

But look at what those largest entries actually are: most of the top twenty are not single-company breaches at all. They are compiled credential lists, stealer-log collections and scraped datasets that bundle together information already stolen in earlier, separate incidents.

This has a practical consequence. You cannot add up breach records to get a number of people. The same email address can appear in an original breach, then again in two or three compilations built from it. Any total that treats records as people counts some individuals many times over.

It also explains a common and confusing experience — finding your email in a breach you have never heard of, belonging to a service you never signed up for. You may not have been in that breach at all. Your details may have been swept into a compiled list from somewhere else entirely.

Do small breaches matter?

By volume, barely. The smallest 510 breaches — half the entire catalogue — account for just 0.9% of all exposed records.

By personal risk, they matter enormously, and the volume figure is misleading here.

A small breach that exposed your password is a genuine problem for you. A huge breach that exposed only email addresses is mostly a spam problem. When assessing your own exposure the question is never “how many people were affected” — it is “what was exposed, and did I reuse that password anywhere?”

Can you trust data breach statistics that show a trend?

Be careful with them, including ours.

We checked whether our catalogue shows breaches becoming more or less frequent over time, and we are not publishing an answer. The direction changes depending on which years you include — it can point either way and still be defensible. That is not a real-world finding, it is a reflection of when incidents happened to be discovered and recorded.

We would rather publish five numbers we can stand behind than a trend line that looks authoritative and is not. You can check the full breakdown yourself in our tracked breach database, which lists every incident and what was exposed.

What are the key data breach statistics to remember?

  • The median breach exposed 993,097 records — smaller than headlines suggest
  • Two in three exposed passwords; nearly two in three exposed passwords with the matching email
  • Nine in ten exposed something sensitive, but only about one in twenty-two exposed direct financial data
  • Ten entries hold 40.2% of all records, and most of those are compiled lists rather than single breaches
  • Records are not people — compilations count the same person repeatedly

The practical takeaway is unchanged by any of it: find out whether your password was involved, change it everywhere you used it, and turn on two-factor authentication.

Can I cite or reuse these data breach statistics?

Yes — these figures are free to cite, quote, and reference in your own articles, reports, and research, provided you credit EmailLeaked with a link back to this page. We would rather the numbers be used correctly and attributed than misquoted, so everything you need to reference them is below.

Plain citation:

EmailLeaked (2026). Data Breach Statistics: What 1,020 Real Breaches Look Like. https://emailleaked.com/blog/data-breach-statistics/

Embed a live stat card on your own site. Copy this snippet — it displays a headline figure and links back to the full analysis:

<a href="https://emailleaked.com/blog/data-breach-statistics/"
   style="display:block;max-width:340px;padding:16px 18px;border:1px solid #e2e2e2;border-radius:10px;font-family:system-ui,-apple-system,sans-serif;text-decoration:none;color:#111827;">
  <strong style="font-size:26px;">66%</strong>
  <span style="display:block;font-size:14px;margin-top:2px;">of tracked data breaches exposed passwords</span>
  <span style="display:block;font-size:12px;color:#6b7280;margin-top:8px;">Source: EmailLeaked — analysis of 1,020 breaches</span>
</a>

Headline figures, ready to quote (analysis of 1,020 tracked breaches, as of 2026):

  • Median breach size: 993,097 records
  • Breaches exposing passwords: 66.0%
  • Breaches exposing passwords next to the matching email: 65.6%
  • Breaches exposing at least one sensitive data type: 91.0%
  • Breaches exposing direct financial data: 4.5%
  • Share of all records held by the ten largest entries: 40.2%

If you are writing about a specific incident and need detail, our tracked breach database lists every breach and what was exposed in each.

Figures calculated from our catalogue of 1,020 tracked breaches, last updated July 2026. Each figure was computed independently twice and cross-checked; figures that did not reconcile are not published.

Frequently asked questions

How many data breaches are there?
Our catalogue currently tracks 1,020 separate data breaches. That is not every breach that has ever happened — it is the ones that have been publicly identified and confirmed. Many breaches are never discovered, and others are never disclosed, so the real number is higher than any catalogue can show.
How big is the average data breach?
The median breach in our catalogue exposed 993,097 records — just under a million. We use the median rather than the average because a handful of enormous entries pull the average up to more than seventeen times the median, which describes almost none of the breaches in the file. Half of all tracked breaches are smaller than a million records.
Do most data breaches include passwords?
In our catalogue, yes — two in three. Exactly 66.0% of the breaches we track exposed passwords, and 65.6% exposed passwords alongside the matching email address. That pairing is what makes breaches dangerous, because the two pieces together are what attackers use to try logging into your other accounts.
Will a data breach expose my credit card or bank details?
Rarely. In our catalogue only 4.5% of breaches exposed data enabling direct financial fraud, counting credit card numbers, bank account numbers, Social Security numbers and government issued IDs. That count deliberately excludes partial card data and passport numbers. The far more common outcome is your email address and password being exposed, which is a login problem rather than a banking problem.
What is the biggest data breach in the catalogue?
The largest single entry holds 1,957,476,021 records. But most of the very biggest entries are not company breaches at all — they are compiled credential lists that bundle together data already stolen in earlier, separate breaches. That distinction matters, because the same person can appear in several of them.
Should I worry if my email appears in a small breach?
The size of the breach matters far less than what was exposed. A small breach that leaked your password is more dangerous to you than a huge breach that leaked only email addresses. Look at what data was exposed, not how many people were affected, then change any password that was involved.
Are data breaches getting worse over time?
We deliberately do not publish a trend from our catalogue. The number of breaches recorded in any given year depends heavily on when incidents were discovered, disclosed and added to breach records, so a rise or fall in the data reflects record-keeping as much as reality. Anyone presenting a confident trend line from breach records alone is overstating what the data can support.

Founder and editor of EmailLeaked. A software and web developer, he built the site's breach checker and its no-storage privacy model, and writes its plain-English guides for people who need a straight answer about a leak — not a data dump. LinkedIn

Our editorial standards →
Breach education

Read the data breach guide

Learn how breaches happen, how stolen data is used, and how to check your exposure.

Open the hub

Get monthly breach alerts — free

One email per month. Biggest breaches, what was exposed, what to do. No spam.

No spam · Unsubscribe anytime · Your email is never shared

Find out where you stand.

Check which breaches include your email — free, instant, never stored.

Check my email — free
No signup · Under 2 seconds · Never stored