Search catalogued breaches by company or domain. Each record shows when it happened, how many accounts it covered, and exactly what was exposed.
What this directory is, and what it is not
It searches catalogued breach records: incidents where a dataset has been identified, attributed to an organisation and counted. Each entry shows the breach date, the number of accounts the source publishes, and the exact categories of data the record lists.
An organisation missing from this directory has not been cleared of anything. Many incidents are disclosed only in a state Attorney General filing or on the federal healthcare breach portal and never appear in a catalogued corpus. Entries marked Unverified are ones the source has not been able to confirm against the organisation named.
Sources
- Breach catalogue: Have I Been Pwned, used under a Creative Commons Attribution 4.0 licence. Account totals and data categories are that source’s figures, not ours. Cached on our server for up to 12 hours so your browser never downloads the full dataset.
- Healthcare incidents affecting 500 or more people: HHS Office for Civil Rights breach portal.
- State-level disclosures: California Attorney General breach list.
Data Breach Radar is not affiliated with the operators of the services above.