Chronology of Data Breaches
Security Breaches 2005 - Present

Posted Date: April 20, 2005
Updated Date: December 31, 2013

Is this your first visit to our Chronology of Data Breaches?

  • Read our FAQ about what we define as a breached record, how we calculate the "total" records breached, our data sources, state breach notice laws, studies and other resources

  • Learn how to use our Chronology and take advantage of its sophisticated search and sort features

  • Get our RSS Feed to see when we add new breaches to the list

What would you like to do?

Chronology of Data Breaches

Custom Sort
Select your desired results. Then click "Go!"

Click or unclick the boxes then select go.


Select features, then click GO.



Help Guide

Can't find the sort feature you're looking for? Click here to download a CSV file of the data breach list as it exisits today.
Breach Total
931,529,111 RECORDS BREACHED
(Please see explanation about this total.)
from 4,467 DATA BREACHES made public since 2005

Save or Print PDF of Entire Breach List including introduction.Save or Print a PDF of Entire Breach List (including introductory FAQ)

Filter breach list before saving or printing PDF. Conduct a search of the Chronology using its sorting features, and Save or Print a PDF of your search results (Select filters)

If you do not have access to PDF, you can print the Chronology in landscape view.

Date Made Publicsort icon Name Entity Type
October 25, 2006 Swedish Medical Center, Ballard Campus
Seattle, Washington
MED INSD

Up to 1,100 patients

(800) 840-6452

An employee stole the names, birthdates, and Social Security numbers from patients who were hospitalized or had day-surgeries from June 22 to Sept 21. She used 3 patients' information to open multiple credit accounts.

 
Information Source:
Dataloss DB
records from this breach used in our total: 1,100

October 25, 2006 Tuscarawas County and Warren County
Tuscarawas County, Ohio
GOV DISC

Unknown

Additional location: Warren County, OH

The Social Security numbers of some Tuscarawas and Warren County voters were available on the LexisNexis Internet database service. Local boards of elections may be the source of the information. 

UPDATE (11/1/06): LexisNexis says it has now removed the SSNs.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

October 25, 2006 Department of Homeland Security
Portland, Oregon
GOV PORT

900

A computer storage device that may have held the personal information of current and former employees was lost or stolen. The device had names, Social Security numbers, addresses and telephone numbers. The device was discovered missing on October 16 at the Transportation Security Administration's command center at Portland International Airport.

 
Information Source:
Dataloss DB
records from this breach used in our total: 900

October 24, 2006 Jacobs Neurological Institute
Buffalo, New York
MED PORT

Unknown

The laptop of a research doctor was stolen from her locked office at the Institute. It included records of patients and her research data.

 
Information Source:
Media
records from this breach used in our total: 0

October 24, 2006 Bethpage Federal Credit Union
Bethpage, New York
BSF PHYS

106

A courier's envelope was delivered to the Credit Union ripped and missing the twenty reports it was supposed to contain.  Some of the reports contained confidential information such as name, address, telephone number, credit card number, and financial institution checking account number.

 
Information Source:
Dataloss DB
records from this breach used in our total: 106

October 23, 2006 Sisters of St. Francis Health Services via Advanced Receivables Strategy (ARS), a Perot Systems Company
Indianapolis, Indiana
MED PORT

266,200

(866) 714-7606

On July 28, 2006, a contractor working for Advanced Receivables Strategy, a medical billing records company, misplaced CDs containing the names and SSNs of 266,200 patients, employees, physicians, and board members of St. Francis hospitals in Indiana and Illinois. About 260,000 patients and about 6,200 employees, board members and physicians were affected for a total of 266,200.  Also affected were records of Greater Lafayette Health Services. The disks were inadvertently left in a laptop case that was returned to a store. The purchaser returned the disks. The records were not encrypted even though St. Francis and ARS policies require encryption.

 
Information Source:
Dataloss DB
records from this breach used in our total: 266,200

October 23, 2006 Chicago Voter Database
Chicago, Illinois
GOV DISC

1.35 million Chicago residents

An official from the not-for-profit Illinois Ballot Integrity Project says his organization hacked into Chicago's voter database, compromising the names, SSNs and dates of birth of 1.35 million residents. The Chicago Election Board is reportedly looking into removing SSNs from the database. Election officials have patched the flaw that allowed the intrusion.

 
Information Source:
Dataloss DB
records from this breach used in our total: 1,350,000

October 23, 2006 Mount Sinai Medical Center
New York, New York
MED PORT

311

A flash drive that contained visitor names, Social Security numbers, children's names, children's dates of birth and dates of visit was lost or stolen during an emergency evacuation. A researcher working with data from New York Children's Environmental Study conducted in Community Medicine reported that the flash drive she left in her computer was missing after she returned sometime around October 5. 

 
Information Source:
Dataloss DB
records from this breach used in our total: 311

October 20, 2006 Manhattan Veterans Affairs Medical Center, New York Harbor Health Care System
New York, New York
MED PORT

1,600

On Sept. 6, an unencrypted laptop computer containing veterans' names, Social Security numbers, and medical diagnosis, was stolen from the Hospital. Veterans who receive pulmonary care were affected.

 
Information Source:
Dataloss DB
records from this breach used in our total: 1,600

October 20, 2006 BlueCross BlueShield of Western New York, HealthNow New York Inc., Administrative Services of Kansas
Buffalo, New York
BSF PORT

96

The theft occurred in a Kansas hospital. Potential HealthNow New York Inc. members were affected.

The laptop of an employee of HealthNow's outside claims vendor Administrative Services of Kansas was stolen during the lunch break of a presentation.  The laptop had potential member names and Social Security numbers.  The theft occurred sometime around June 19 and notification letters were sent on October 16.

 
Information Source:
Dataloss DB
records from this breach used in our total: 96

October 19, 2006 Allina Hospitals and Clinics
Minneapolis, Minnesota
MED PORT

Individuals in 17,000 households

A laptop stolen from a nurse's car on October 8 contains the names and SSNs of individuals in approximately 17,000 households participating in the Allina Hospitals and Clinics obstetric home-care program since June 2005.

 
Information Source:
Dataloss DB
records from this breach used in our total: 17,000

October 19, 2006 University of Minnesota
Minneapolis-St.Paul, Minnesota
EDU PORT

200 students (not included in total)

In June, a University of Minnesota art department laptop computer stolen from a faculty member while traveling in Spain holds personally identifiable information of 200 students.

 
Information Source:
Media
records from this breach used in our total: 200

October 17, 2006 City of Visalia, Recreation Division
Visalia, California
GOV PHYS

200 current and former employees

Personally identifiable information of approximately 200 current and former Visalia Recreation Department employees was exposed when copies of city documents were found scattered on a city street.

 
Information Source:
Dataloss DB
records from this breach used in our total: 200

October 16, 2006 Germanton Elementary School
Germanton, North Carolina
EDU STAT

Unknown

A computer stolen from Germanton Elementary school holds students' SSNs. The data on the computer are encrypted.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

October 16, 2006 VISA, FirstBank (1st Bank)
Lakewood, Colorado
BSF UNKN

Unknown

FirstBank sent a letter to an unknown number of customers informing them their FirstTeller Visa Check Card numbers were compromised when someone accessed “a merchant card processor's transaction database.” The FirstBank letter said customers would receive new cards by October 27.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

October 16, 2006 Dr, Charles Kay of Orchard Family Practice
Englewood, Colorado
MED PHYS

"Hundreds"

Sheriff's deputies evicting Dr. Charles Kay put files from his office in a nearby parking lot. In a news report, Dr. Kay said he had removed the patient files but not the business files.

 
Information Source:
Media
records from this breach used in our total: 100

October 16, 2006 Twin Tier Mortgage
Elmira, New York
BSF STAT

34

An office burglary occurred sometime between October 13 and October 15. A computer with the information of some, but not all clients was stolen. partial list of client information was stolen. Social Security numbers of applicants, names, addresses, phone numbers, dates of birth, income, assets and other mortgage related financial information may have been exposed. At least 34 New York residents were affected, but the total number of affected clients nationwide was not revealed.

 
Information Source:
Dataloss DB
records from this breach used in our total: 34

October 15, 2006 Poulsbo Department of Licensing
Poulsbo, Washington
GOV PORT

2,200

An unspecified “storage device” containing personally identifiable data of approximately 2,200 North Kitsap (WA) residents has been lost from the Poulsbo Department of Licensing. The data include names, addresses, photographs and driver's license numbers of individuals who conducted transactions at the Poulsbo branch in late September.

 
Information Source:
Media
records from this breach used in our total: 2,200

October 14, 2006 T-Mobile USA Inc.
Bellvue, Washington
BSO PORT

43,000 current and former employees

A laptop computer holding personally identifiable information of approximately 43,000 current and former T-Mobile employees disappeared from a T-Mobile employee's checked luggage. T-Mobile has reportedly sent letters to all those affected. The data are believed to include names, addresses, SSNs, dates of birth and compensation information.

 
Information Source:
Dataloss DB
records from this breach used in our total: 43,000

October 14, 2006 CBA Information Solutions, Washington Savings Bank
Bowle, Maryland
BSF UNKN

Unknown

An unauthorized user gained access to the log in information of Washington Savings Bank. The unauthorized user could have accessed customer and non-customer names, Social Security numbers, addresses and credit histories. The breach occurred between September 15 and September 21. At least 20 New York residents were affected, but the nationwide total was not reported.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

October 13, 2006 Ohio Ethics Commission
Columbus, Ohio
GOV PHYS

Unknown

Papers belonging to the Ohio Ethics Commission were found floating on the wind in an alley. The documents are related to state employees' finances and contained SSNs and financial statements. They were supposed to be in the possession of the state archives.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

October 12, 2006 U.S. Census Bureau
Washington, District Of Columbia
GOV PORT

Unknown

Additional location: Travis Co., TX

This spring, residents of Travis County, TX helped the Census Bureau test new equipment. When the test period ended, 15 devices were unaccounted for. The Census Bureau and the Commerce Department issued a press release saying the devices held names, addresses and birthdates, but not income or SSNs.

 
Information Source:
Media
records from this breach used in our total: 0

October 12, 2006 Congressional Budget Office
Washington, District Of Columbia
GOV HACK

Unknown

Hackers broke into the Congressional Budget Office's mailing list and sent a phishing e-mail that appeared to come from the CBO.

 
Information Source:
Media
records from this breach used in our total: 0

October 12, 2006 University of Texas, Arlington
Arlington, Texas
EDU STAT

2,500 students

http://www.uta.edu/oit/iso/Datatheft.php

Two computers stolen from a University of Texas faculty member's home hold the names, SSNs, grades, e-mail addresses and other information belonging to approximately 2,500 students enrolled in computer science and engineering classes between fall 2000 and fall 2006. The theft occurred on September 29 and was reported on October 2.

 
Information Source:
Dataloss DB
records from this breach used in our total: 2,500

October 12, 2006 Sears Holding Corporation
Winter Park, Florida
BSF PORT

Unknown

A laptop was stolen from the office on September 28. Certain customers had their information on an access database file that was on the laptop. Names, telephone numbers, addresses, account number, account types and account expiration dates were exposed.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

October 11, 2006 Republican National Committee (RNC)
Washington, District Of Columbia
NGO DISC

76 RNC donors

http://www.nysun.com/national/gop-donors-personal-data-disclosed-in-rnc-privacy/41341/

The Republican National Committee (RNC) inadvertently emailed a list of donors' names, SSNs and races to a New York Sun reporter.

 
Information Source:
Dataloss DB
records from this breach used in our total: 76

October 11, 2006 DirecTV, Deloitte and Touche LLC
El Segundo, California
BSR PORT

55

A laptop containing the names and Social Security numbers of some current and former DirecTV employees was stolen during a home burglary of a Deloitte and Touche LLP employee. The theft occurred sometime in August. Deloitte and Touche performs audits of The DirecTV Group's pension plans.

 
Information Source:
Dataloss DB
records from this breach used in our total: 55

October 10, 2006 Florida Labor Department
Tallahassee, Florida
GOV DISC

4,624

The names and SSNs of 4,624 Floridians were accessible on the Internet for approximately 18 days in September. The data were not accessible through websites, but an individual came across the information when Googling his own name. The agency has asked Google to remove the pages from its cache, and has notified all affected individuals by mail.  Individuals who had registered with Florida 's Agency for Workforce Innovation were affected.

 
Information Source:
Dataloss DB
records from this breach used in our total: 4,624

October 9, 2006 Troy Athens High School
Troy, Michigan
EDU PORT

4,400

For questions or comments, call (248) 823-4035

A hard drive stolen from Troy Athens High School in August contained transcripts, test scores, addresses and SSNs of students from the graduating classes of 1994 to 2004. The school district and the superintendent have notified all affected alumni by regular mail.

 
Information Source:
Dataloss DB
records from this breach used in our total: 4,400

October 9, 2006 Atlantis Plastic Inc.
Atlanta, Georgia
BSR PORT

720

A laptop was stolen from Atlantis' accounting firm on October 5.  The laptop contained personal information for 720 participants in the Atlantis 401(k) plan.  Names, Social Security numbers, dates of birth, addresses and 401(k) account balance information may have been exposed.

 
Information Source:
Dataloss DB
records from this breach used in our total: 720

October 6, 2006 Cleveland Air Route Traffic Control Center
Oberlin, Ohio
GOV STAT

400

A computer hard drive missing from the Cleveland Air Route Traffic Control Center in Oberlin (OH) contains the names and SSNs of at least 400 air traffic controllers.

 
Information Source:
Dataloss DB
records from this breach used in our total: 400

October 6, 2006 Camp Pendleton Marine Corps base via Lincoln B.P. Management
Camp Pendleton, California
GOV PORT

2,400

A laptop missing from Lincoln B.P. Management Inc. holds personally identifiable data about 2,400 Camp Pendleton residents.

 
Information Source:
Dataloss DB
records from this breach used in our total: 2,400

October 6, 2006 StarCite Inc.
Philadelphia, Pennsylvania
BSO PORT

Unknown

A laptop containing personal information of employees was stolen from a hotel room on September 13. The information included name, Social Security number, date of birth, address, date of hire, occupation, salary, supplemental insurance information, and identified the type and tier of medical and/or dental coverage.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

October 5, 2006 San Juan Capistrano Unified School District (CA)
San Juan Capistrano, California
EDU STAT

Unknown

Five computers stolen from the HQ of San Juan Capistrano Unified School District likely contain the names, SSNs and dates of birth of district employees enrolled in an insurance program.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

October 5, 2006 Homecoming Financial Network Inc.
Minneapolis, Minnesota
BSF DISC

988

On September 9, a web-based tool for mortgage brokers was released that allowed brokers to view all loan applications submitted by all other brokers. The information included names, Social Security numbers and addresses.  The flaw was discovered and fixed the next day.

 
Information Source:
Dataloss DB
records from this breach used in our total: 988

October 4, 2006 Orange County Controller
Orlando, Florida
GOV DISC

Unknown

A Florida woman discovered her marriage license was visible on the Orange County (FL) controller's Web site with no information blacked out, not even SSNs. She discovered the breach because someone had applied for a loan in her name. The Orange County Comptroller is reportedly paying a vendor $500,000 to black out all SSNs by January 2008.

 
Information Source:
Media
records from this breach used in our total: 0

October 3, 2006 Cumberland County
Carlisle, Pennsylvania
GOV DISC

1,200 employees of the county

Cumberland County (PA) officials removed salary board meeting minutes from their Web site because they contained the SSNs of 1,200 county employees. The information was included in minutes from meetings prior to 2000. The county no longer uses SSNs as unique identifiers for employees. Employees will be informed of the data breach in a note included with their paychecks.

 
Information Source:
Dataloss DB
records from this breach used in our total: 1,200

October 3, 2006 Willamette Educational Service District (ESD)
Salem, Oregon
EDU STAT

4,500 Oregon high school students [not included in total because not thought to contain sensitive info. such as SSNs]

Seven computers stolen from a Willamette Educational Service District office were believed to contain personal information of 4,500 Oregon high school students. Backup tapes indicate the computers hold information about the students' school clubs but do not contain sensitive information.

 
Information Source:
Media
records from this breach used in our total: 0

October 3, 2006 Picatinny Arsenal
Rockaway, New Jersey
GOV UNKN

Unknown

 If you have tips, call (973) 989-0652

28 computers are missing from the Picatinny Arsenal, a Department of Defense Weapons Research Center. The computers were reported lost or stolen over the last two years. None of the computers was encrypted. Officials state the computers did not contain classified information.

 
Information Source:
Media
records from this breach used in our total: 0

October 3, 2006 Western Financial Services Inc.
Englewood, Colorado
BSF PORT

43

A laptop lost during shipping contained names, Social Security numbers, driver's license numbers and addresses.  The laptop was first discovered missing on or sometime before August 31. At least 43 New York residents were affected, but the number of affected customers nationwide was not reported.  Affected individuals were notified on October 4.

 
Information Source:
Dataloss DB
records from this breach used in our total: 43

October 2, 2006 Port of Seattle, Seattle-Tacoma Airport (Sea-Tac)
Seattle, Washington
GOV PORT

6,939 current and former Seattle-Tacoma International Airport employees

http://www.portseattle.org, (888) 902-PORT

Six CDs missing from the ID Badging office at Seattle-Tacoma International Airport hold the personal information of 6,939 airport workers. The data include names, addresses, birth dates, SSNs and driver's license numbers, telephone numbers, employer information, and height/weight. The data on the disks were scanned from paper applications for airport badges. The port learned of the missing disks on September 18 and sent letters to the affected employees on Oct. 2.

 
Information Source:
Dataloss DB
records from this breach used in our total: 6,939

October 2, 2006 Citigroup
Chicago, Illinois
BSF PORT

11

An employee from a Pennsylvania branch reported a missing laptop after a flight. It is believed that the laptop may have been stolen from the employee's luggage after the bags were checked-in for a flight from Chicago to Philadelphia sometime around August 26. At least 11 New York residents and an unknown number of clients nationwide may have had their names, Social Security numbers, addresses and other information exposed.

 
Information Source:
Dataloss DB
records from this breach used in our total: 11

September 29, 2006 University of Iowa Department of Psychology
Iowa City, Iowa
EDU HACK

14,500

A computer containing SSNs of 14,500 psychology department research study subjects was the object of an automated attack designed to store pirated video files for subsequent distribution.

 
Information Source:
Dataloss DB
records from this breach used in our total: 14,500

September 29, 2006 Kentucky Personnel Cabinet via Bluegrass Mailing
Frankfort, Kentucky
GOV DISC

146,000

State employees received letters from the Kentucky Personnel Cabinet with their SSNs visible through the envelope windows.

 
Information Source:
Dataloss DB
records from this breach used in our total: 146,000

September 29, 2006 Nationwide Agribusiness, Farmland Mutual Insurance Company
Columbus, Ohio
BSF PORT

306

A laptop computer was stolen from the home of an employee on or around May 23.  This laptop contained claimants' names, Social Security numbers and addresses.  Nationwide Agribusiness learned of the theft in early September and began the process of developing a privacy and security awareness package for all employees.

 
Information Source:
Dataloss DB
records from this breach used in our total: 306

September 28, 2006 North Carolina Department of Motor Vehicles
Louisville, North Carolina
GOV STAT

16,000

(888) 495-5568

A computer was stolen from a NC Dept. of Motor Vehicles office, reported Sept. 10. It contains names, addresses, driver's license numbers, SSNs, and in some cases immigration visa information of 16,000 people who have been issued licenses in the past 18 months. Most are residents of Franklin County.

 
Information Source:
Dataloss DB
records from this breach used in our total: 16,000

September 28, 2006 Illinois Department of Transportation (IDOT)
Springfield, Illinois
GOV PHYS

40

Documents found by state auditors in recycling bins in a hallway contained IDOT employee names and SSNs.

 
Information Source:
Media
records from this breach used in our total: 40

September 28, 2006 Stevens Hospital Emergency Room via dishonest employee of billing company Med Data
Edmonds, Washington
MED INSD

30

A manager for the hospital's billing company, Med Data, stole patients' credit card numbers. She gave them to her brother who bought $30,000 worth of clothes and gift cards over the Internet. The woman is scheduled for sentencing in Nov. and her brother's trial is expected Jan. 2007.

 
Information Source:
Dataloss DB
records from this breach used in our total: 30

September 28, 2006 New York State Banking Department
New York, New York
BSF DISC

19,640

During the routine process of indexing the search engine of the Department's website, data files from the 2005 Volume of Operations Reports were inadvertently made accessible to members of the public between July 27 and August 29. Personal information included the Social Security numbers of all independent contractors employed by both licensed mortgage bankers and registered mortgage brokers. Social Security numbers of all felons employed by those registrants who also opted to electronically failed their 2005 VOO reports were also available through the Department's website search engine.

 
Information Source:
Dataloss DB
records from this breach used in our total: 19,640

September 27, 2006 New York Life Insurance Company
Boston, Massachusetts
BSF STAT

Unknown

A life insurance agent reported that two desktops were stolen from his office.  Customer names, Social Security numbers, addresses, dates of birth and policy numbers may have been exposed. An unspecified number of customers nationwide were affected.

 
Information Source:
Dataloss DB
records from this breach used in our total: 0

Breach Total
931,529,111 RECORDS BREACHED
(Please see explanation about this total.)
from 4,467 DATA BREACHES made public since 2005
Showing 3951-4000 of 4467 results


X

Sign In!

Loading