2026 Cybersecurity Report: $20.9 Billion Lost to Data Breaches, 1 Million Affected
Cybercrime losses topped $20.9 billion in 2025, but the real total is likely three times higher due to unreported incidents.

Who was breached, what was exposed, and what to do about it.
Hashed in your browser - only five characters of the hash are ever sent.
1,000+ catalogued breaches: the date, the account count, and exactly what was exposed.
Tick what was leaked and get the steps in order, each linked to the rule behind it.
All three bureaus, plus the four registries a credit freeze does not cover.
Tips to protect your data and privacy
Browse →484 guidesBreaking news on recent data breaches
Browse →287 guidesAll the latest and largest data breaches
Browse →229 guidesIdentity theft prevention and news
Browse →203 guidesData breaches at technology companies
Browse →139 guidesData breaches affecting retail and e-commerce companies
Browse →Cybercrime losses topped $20.9 billion in 2025, but the real total is likely three times higher due to unreported incidents.
Oracle PeopleSoft systems have been confirmed compromised in multiple breaches, with 3.1 terabytes of stolen data now circulating on dark web marketplaces.
LastPass customers’ encrypted vaults were exposed through a compromised vendor, revealing the risks of centralizing millions of passwords in a single system.
Ransom extortion through file-locking malware has hit major manufacturers, exposing the inadequacy of traditional backup and recovery strategies.
South Korean golf simulator company Golfzon faced a record regulatory fine after hackers accessed 2.21 million customer records through stolen VPN credentials.
KDDI Corporation, one of Japan’s largest telecommunications providers, disclosed a significant data breach on June 28, 2026, revealing that up to 14.22 million customer accounts may have been compromised. The breach, which also affected five partner internet service providers that rely on KDDI’s email infrastructure, exposed customer email addresses and passwords stored within the company’s … Read more
AhnLab V3 achieves 99%+ detection rates in Virus Bulletin testing, but “perfect detection” claims require scrutiny and verification.
Hidden attacks operate across both public and private networks, requiring integrated monitoring and correlation to detect what single-environment tools consistently miss.
Qihoo 360’s claim about its bug-finding superiority over Mythos demands scrutiny on methodology, vulnerability types, and applicability to your specific risks.
The compromise illustrates how security breaches at third-party vendors can cascade across entire customer networks, leaving even security-conscious firms…

Breach coverage goes wrong in two directions: inflating an exposure into a certainty, or burying it. We publish the disclosed numbers, name the source, and mark clearly where an investigation is still open and the count may change.

Most people find out from a letter weeks after the fact. These are the steps that still work at that point, in the order they should be done, with what each one does and does not protect.
Primary sources: the breached organization's own notification letter, filings in state Attorney General breach databases, the U.S. Department of Health and Human Services breach portal for healthcare incidents, SEC filings, court records and regulator announcements. Where we cite a figure, that figure comes from one of those documents.
Not necessarily, and the difference matters. Most notices state that an unauthorized party accessed or acquired data. That is a different finding from evidence that the data has been used for fraud. We report which one a given notice supports, and we do not fill the gap with speculation.
No. Only the organization that holds your records can confirm that, and it is required to notify you. What we can do is tell you what was disclosed, who the claims administrator or notification contact is, and what steps are worth taking while you wait.
No. Data Breach Radar is independent reporting. Nothing on this site creates a professional relationship or substitutes for advice from a lawyer, a security professional or your bank. Always verify details against the notice you received.
The site is free to read and carries advertising. Some pages may contain affiliate links, which are disclosed on our Affiliate Disclosure page. Advertisers and affiliate partners have no input into what we cover or what we say about it, and we do not accept payment to include, exclude or soften a breach report.
Email contact@databreachradar.com with the URL and what is inaccurate. Corrections to a published report are made on the page itself. Our approach to sourcing and corrections is set out in the Editorial Policy.