Sandra Koutsopoulos
Senior Member
- Joined
- Jul 13, 2005
- Professional Status
- Certified Residential Appraiser
- State
- California
So I asked AI for the major security breaches of personal information during the past year, and it's a doozey! Everybody who thinks their password-protected info is safe are/will be victims. The techies are more clever than most of us. No matter what the GSEs say about the info being secure, it absolutely is NOT!
Between June 11, 2025, and June 11, 2026, over 3,300 data compromises occurred in the U.S.. Driven by infostealer malware, compromised credentials, and third-party vendor exposures, several high-profile nationwide data breaches exposed hundreds of millions of personal records. [1, 2, 3]
Major nationwide incidents during this period include:
Between June 11, 2025, and June 11, 2026, over 3,300 data compromises occurred in the U.S.. Driven by infostealer malware, compromised credentials, and third-party vendor exposures, several high-profile nationwide data breaches exposed hundreds of millions of personal records. [1, 2, 3]
Major nationwide incidents during this period include:
- Mass Credential Dump: In June 2025, over 16 billion stolen passwords and user logins from Google, Apple, and Facebook were leaked from malware-infected devices. [1]
- National Public Data: This background check service experienced a breach exposing the Social Security numbers, names, and addresses of up to 170 million people in the U.S. [1]
- Identity Theft Resource Center (ITRC) Data: The ITRC recorded a historic 3,322 breaches affecting nearly 279 million individuals nationwide, with a notable spike in attacks on third-party cloud integrations. [1, 2, 3, 4]
- ADT: In April 2026, an extortion group breached ADT's cloud environment, exposing personal information for 5.5 million customers. [1]
- McGraw-Hill: An April 2026 third-party Salesforce environment compromise exposed 13.5 million student and educator records. [1]
- Amtrak: April 2026 saw the exposure of 2.1 million Amtrak records after a third-party vendor breach. [1]
- Navia Benefit Solutions: An exposed API in December 2025 resulted in the theft of 2.7 million records, including SSNs and health plan information. [1, 2]
- Aflac: In June 2025, an attack on internal systems exposed customer and agent details, including Social Security numbers. [1, 2]
- Match Group: Early in 2026, hackers accessed the internal documentation and user records of platforms like Tinder, Hinge, and OkCupid, potentially exposing 10 million records. [1]
- TransUnion: In July 2025, a breach of TransUnion systems exposed the names, dates of birth, and SSNs of 4.4 million customers. [1, 2]
