Incident posture
Timeline
Summary
A massive data breach exposed over 26 billion records from multiple platforms including Twitter, Adobe, Canva, LinkedIn, and Dropbox, with no organization claiming responsibility. Earlier large-scale incidents had exposed billions of records, including collections of hundreds of millions of email addresses and millions of passwords posted for sale. The breaches typically involve the theft or compromise of at least thirty thousand records, and hacking remains the most frequently used method.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
This incident is documented in a non-exhaustive list of data breaches that compiles reports from press releases, government news, and mainstream articles. The list includes breaches involving the theft or compromise of 30,000 or more records. Although many smaller breaches occur continually, they are not captured in this compilation. Breaches of large organizations where the exact number of records is unknown are also listed. The list records the various methods used in breaches, noting that hacking is the most common. The compilation relies on multiple sources to provide a broad overview of significant data loss events.
In January 2024, a data breach was uncovered and dubbed the "mother of all breaches." The breach exposed over 26 billion records in a single database. Among the exposed records were some belonging to Twitter, as well as data from Adobe, Canva, LinkedIn, and Dropbox. No organization immediately claimed responsibility for the breach. The incident is included in the list of data breaches that tracks events with 30,000 or more compromised records. With over 26 billion records, the breach far exceeds the 30,000-record threshold used for inclusion in the list.
Sources
Sources available to members: 1 source.