Let’s recap the Top 10 data breaches from 2024:
National Public Data: A U.S. background-check / data-broker exposure that dumped about 2.9 billion records (hundreds of millions of unique people, including a vast trove of Social Security numbers) with major public reporting in August.[1]
Ticketmaster (Live Nation): A U.S. ticketing giant whose Snowflake cloud environment was compromised, with threat actors claiming roughly 560 million customer records in May.[2]
Change Healthcare (UnitedHealth): A U.S. healthcare clearinghouse ransomware attack in February that ultimately tied to personal and medical data on roughly 190 million people and paralyzed claims nationwide.
DemandScience: A U.S. B2B demand-generation / data-aggregator breach whose leaked business-contact dataset covered about 122 million unique emails, confirmed in reporting through November.
AT&T: A U.S. telecom incident in July in which nearly all ~110 million wireless customers’ call and text metadata were stolen from a third-party Snowflake environment.
MC2 Data: A U.S. background-check-related firm whose unsecured database exposed on the order of 100 million consumer records around August–September.
Dell: A U.S. PC maker whose partner portal API abuse led to claims that about 49 million customer purchase records were scraped in May.
France Travail: France’s public employment agency suffered a breach in March affecting up to about 43 million job seekers and related individuals.
Internet Archive (Wayback Machine): The U.S. nonprofit’s authentication database was compromised in October, exposing about 31 million user records including email addresses and hashed passwords.
loanDepot: A U.S. mortgage lender hit by ransomware in January that confirmed personal data—including Social Security numbers—for roughly 17 million customers was stolen.
DataBreaches.com would like to highlight that several of the largest 2024 incidents—especially the Snowflake-linked thefts and major ransomware cases—stemmed from stolen credentials and social-engineering-adjacent access, not exotic zero-days alone. It’s crucial for organizations to use a trustworthy digital identity that can’t easily be Phished. Their domain name choice has never been more critical. Having the most authoritative version of your brand/product name in the exact match .Com along with training your staff on how to recognize these attacks can be far more effective than blindly investing millions in cybersecurity infrastructure.
Footnotes
[1] The widely cited ~2.9 billion figure for National Public Data refers to records/rows in the exposed datasets, not unique people. Unique-person estimates are far lower (on the order of hundreds of millions), with substantial duplication, deceased individuals, and inaccurate data in the dumps.
[2] The ~560 million Ticketmaster figure is primarily a threat-actor claim. Live Nation confirmed a Snowflake-related breach affecting Ticketmaster customer data but did not publicly match that headcount in early coverage.
[3] A viral “Advance Auto Parts / 380 million” figure circulating in some 2024 roundups was not used here. The company confirmed personal information for about 2.3 million individuals in its notices—orders of magnitude below the unverified total.