Top 10 Data Breaches of 2025

Let’s recap the Top 10 data breaches from 2025:

Infostealer credential mega-leak: Researchers in June uncovered roughly 16 billion login credentials across dozens of exposed datasets—largely malware stealer logs and recycled older breaches, not a single company’s fresh customer database.[1]

Conduent Business Services: A U.S. healthcare/government business associate whose late-2024–early-2025 network intrusion compromised protected health information for more than 62 million people, with major disclosures and notifications through 2025.

PowerSchool: The K-12 education SaaS provider disclosed in January that attackers used stolen support-portal credentials to pull student and teacher data at massive scale—on the order of 60–70+ million people across U.S. and Canadian districts (attacker and notice tallies; company has not published a full public census).

Aflac: The U.S. insurer contained a June cyberattack within hours and later said personal information associated with about 22.65 million individuals was involved.

Prosper: The U.S. peer-to-peer lending marketplace disclosed a September breach in which attackers obtained applicant/customer data including Social Security numbers; Have I Been Pwned reported about 17.6 million unique emails affected.

Episource: A U.S. UnitedHealth/Optum healthcare coding subsidiary hit by ransomware in early 2025, with OCR-linked impact rising to about 6.7 million individuals.

700Credit: A U.S. auto-dealership credit-check technology provider breach reported in October affecting about 5.8 million dealership customers.

Yale New Haven Health System: Connecticut’s largest health system reported a March network breach affecting about 5.56 million individuals’ personal data (electronic medical records not accessed).

Qantas: The Australian airline confirmed a mid-year Salesforce-instance customer-data theft tied to a wider third-party CRM campaign, with on the order of 5 million customer records later reported leaked.[2]

TransUnion: The U.S. credit bureau was among major victims of the 2025 Salesforce-linked data-theft wave, with about 4.4 million people affected via a compromised CRM instance rather than its core credit databases.[2]

DataBreaches.com would like to highlight that many of the year’s most damaging incidents—Aflac’s social-engineering-style intrusion, PowerSchool’s stolen support credentials, and the Salesforce/vishing and OAuth-integration campaign hitting airlines, insurers, and credit firms—show how attackers bypass “more firewalls” by impersonating trust. Credential mega-dumps then fuel follow-on phishing and account takeover at global scale. It’s crucial for organizations to use a trustworthy digital identity that can’t easily be Phished. Their domain name choice has never been more critical. Having the most authoritative version of your brand/product name in the exact match .Com along with training your staff on how to recognize these attacks can be far more effective than blindly investing millions in cybersecurity infrastructure.

Footnotes

[1] The ~16 billion credentials figure is an aggregation of exposed datasets (largely infostealer malware logs and recycled older breaches), not a single corporate customer-database breach. Some security outlets dispute framing this as the “largest breach ever.”

[2] Some reporting cited an unverified ~1.5 billion aggregate across the broader 2025 Salesforce / third-party CRM theft campaign. That campaign-wide total was not used as a headcount here; Qantas and TransUnion are listed as named victims with their own reported impact figures instead.