Military-connected families are always welcome

DATA BREACH EDUCATION

Your information was exposed. What happens next should be informed—not panicked.

A breach can create risk without proving that identity theft occurred. Learn which major incidents exposed credit-relevant data, how to verify your own exposure, and how to begin a documented recovery journey.

WHAT THIS LIST COVERS

A verified starting point—not a claim that one page contains every breach ever reported.

Breaches are reported continuously across countries, states, industries, and legal systems. There is no single complete worldwide consumer list. This page highlights major publicly documented incidents with clear identity, account, health, or financial relevance through July 2026.

For the changing record, use the official repositories below and the notice sent to you. Inclusion does not mean every customer was affected or that every listed data type applied to every person.

MAJOR INCIDENT TIMELINE

Search by organization, year, sector, or type of data.

The source link on every entry leads to a government, regulator, court, or organization disclosure. Always compare these summaries with your own official breach notice.

2025Education

PowerSchool

A cybersecurity incident involving student and educator information prompted notifications across school communities.

Information involved: Varied by school and person; potentially contact, demographic, medical, and Social Security information.
Official source ↗
2024Healthcare

Change Healthcare

A ransomware attack disrupted health-payment services and affected a very large volume of patient information.

Information involved: Potentially health, insurance, billing, contact, and identification information; details vary by person.
Official source ↗
2024Telecommunications

AT&T

AT&T disclosed separate incidents involving customer account data and call/text interaction records.

Information involved: In one incident, account fields including passcodes; in another, call and text metadata—not message content.
Official source ↗
2024Data broker

National Public Data

A data-broker incident led to public notices and renewed warnings about identity theft and credit freezes.

Information involved: Names, addresses, dates of birth, and Social Security numbers were reported for some people.
Official source ↗
2024Entertainment

Ticketmaster / Snowflake environment

Ticketmaster notified customers after unauthorized activity in a third-party cloud database environment.

Information involved: Potentially contact and payment-card information, depending on the customer record.
Official source ↗
2023Software / multi-sector

MOVEit Transfer campaign

A vulnerability in MOVEit file-transfer software was used against many unrelated organizations, so notices came from individual affected entities.

Information involved: Varied widely by organization and file, including identity, payroll, health, and financial information.
Official source ↗
2023Genetic testing

23andMe

Attackers used credential stuffing to access some accounts and information connected through DNA Relatives features.

Information involved: Profile, ancestry, relationship, and other account information; scope varied by user.
Official source ↗
2023Telecommunications

T-Mobile

T-Mobile reported that an API was used without authorization to obtain data for about 37 million current postpaid and prepaid accounts.

Information involved: Names, billing addresses, email, phone, dates of birth, account numbers, and plan details—not payment cards or Social Security numbers in this event.
Official source ↗
2022Password management

LastPass

An incident involving a third-party cloud environment exposed customer vault backups, increasing long-term phishing and password-cracking risk.

Information involved: Account metadata and encrypted vault data; some website fields were unencrypted.
Official source ↗
2021Telecommunications

T-Mobile

A breach affected tens of millions of current, former, and prospective customers.

Information involved: Depending on the person: names, dates of birth, Social Security and driver-license information, and account data.
Official source ↗
2020Technology / government

SolarWinds Orion compromise

A software supply-chain compromise affected public- and private-sector networks; it was primarily an enterprise security event rather than a consumer credit-file breach.

Information involved: Network and organizational information varied by victim.
Official source ↗
2019Financial services

Capital One

Capital One disclosed unauthorized access to credit-card application and customer data in the United States and Canada.

Information involved: Application data; about 140,000 U.S. Social Security numbers and 80,000 linked bank-account numbers were affected.
Official source ↗
2018Hospitality

Marriott / Starwood

Unauthorized access to the Starwood guest reservation database began years before discovery and affected hundreds of millions of records.

Information involved: Names, addresses, passport numbers, travel details, and some payment-card information.
Official source ↗
2017Credit reporting

Equifax

The breach exposed highly sensitive identity information for approximately 147 million people and led to a federal settlement.

Information involved: Names, Social Security numbers, dates of birth, addresses, and some driver-license and payment-card information.
Official source ↗
2016Transportation technology

Uber

Uber failed to timely disclose a breach involving rider and driver data and later entered an FTC settlement.

Information involved: Names, email addresses, phone numbers, and driver-license numbers for some drivers.
Official source ↗
2015Federal government

U.S. Office of Personnel Management

Two related incidents affected federal personnel records and background-investigation files.

Information involved: Social Security numbers, fingerprints, background-investigation and personnel information.
Official source ↗
2015Healthcare

Anthem

A cyberattack affected the personal information of nearly 79 million people and led to a record HIPAA settlement at the time.

Information involved: Names, Social Security numbers, medical identification numbers, addresses, employment and income information.
Official source ↗
2014Retail

Home Depot

Malware on payment systems affected cards used at U.S. and Canadian stores and customer email addresses.

Information involved: Payment-card data and email addresses.
Official source ↗
2013–2014Technology

Yahoo

Yahoo later stated that all three billion accounts existing at the time were affected by its 2013 breach; a separate 2014 breach also occurred.

Information involved: Names, email addresses, phone numbers, dates of birth, hashed passwords, and security questions/answers.
Official source ↗
2013Retail

Target

Attackers obtained payment-card data and customer contact information during the holiday shopping season.

Information involved: Payment-card data and, for some customers, names, addresses, phone numbers, and email addresses.
Official source ↗

THE RECOVERY JOURNEY

Turn a frightening notice into an organized response.

Use the steps that match the information exposed and what you actually observe. A credit freeze helps with new-account fraud, but it does not stop every kind of misuse, including tax, medical, employment, or existing-account fraud.

01

Read the actual notice

Confirm which organization sent it, the incident date, exactly what data was involved, and any response deadline. Reach the company through a known official channel—not a link in an unexpected message.

02

Secure the accounts

Change affected passwords, replace reused passwords, enable multi-factor authentication, and contact the card issuer or bank if payment credentials were involved.

03

Freeze all three credit files

A free security freeze can make it harder for someone to open new credit in your name. Place it separately with Equifax, Experian, and TransUnion.

04

Review your reports

Use AnnualCreditReport.com, examine every account and inquiry, and save copies. A breach alone does not mean every unfamiliar item is fraud.

05

Report identity theft

If your information was actually misused, build a personalized recovery plan and Identity Theft Report at IdentityTheft.gov. Consider an initial or extended fraud alert when appropriate.

06

Dispute with evidence

Identify the exact fraudulent or inaccurate field, send supporting records, keep delivery proof, and track every response. Do not dispute accurate information simply because it is negative.

WHY THE BOOK + WEBSITE

Recovery takes more than a breach headline.

The website gives you current official links, free learning resources, and practical tools. The Choice Credit Education Dispute Manual 2026 gives you a structured place to understand reports, organize evidence, document identity-theft issues, select the right dispute path, and track follow-up without relying on deletion promises.

  • Learn the difference between exposure, fraud, and a reporting error.
  • Prepare before contacting a bureau, furnisher, collector, or agency.
  • Build a repeatable paper trail for the months ahead.

Educational information only—not legal, financial, cybersecurity, lending, or credit-repair advice. A breach does not prove misuse, and no deletion, score change, loan approval, or recovery outcome is guaranteed.