Some of history’s most damaging cyber incidents began with surprisingly ordinary weaknesses: an unpatched server, a stolen password, an exposed software interface, or a convincing message sent to the right employee. Others used sophisticated supply-chain attacks to compromise thousands of organizations at once. The consequences have included stolen financial and medical records, disrupted fuel supplies, grounded business operations, and billions of dollars in losses. From early payment-card breaches to ransomware attacks affecting nearly 200 million people, these incidents reveal how cybercrime evolved into a threat capable of reaching nearly every part of modern life.
Facebook and Cambridge Analytica

©Rawpixel.com/Shutterstock.com
The Cambridge Analytica scandal was not a conventional hack. Beginning in 2014, researcher Aleksandr Kogan used a Facebook personality-quiz app to collect information from participating users and tens of millions of their Facebook friends. Cambridge Analytica later used data derived from the app for voter profiling and political targeting. Most of the affected people had never installed the app or knowingly agreed to let the consulting firm use their information.
The arrangement became a global controversy after it was exposed in 2018. The Federal Trade Commission found that Cambridge Analytica used deceptive tactics to collect personal information. Facebook separately paid a record $5 billion penalty to settle allegations that it violated a 2012 privacy order. That penalty covered broader privacy failures and should not be described solely as a fine for the Cambridge Analytica incident.
Target Data Breach
Between November 27 and December 15, 2013, attackers installed malware on Target’s point-of-sale systems and captured payment information as customers used their cards. Target initially reported that approximately 40 million credit and debit card accounts might have been affected. Its continuing investigation found that names, addresses, phone numbers, or email addresses belonging to as many as 70 million people had also been taken, although the two groups likely overlapped.
The attackers reportedly entered Target’s network using credentials stolen from a third-party vendor before moving into systems connected to store checkout equipment. The breach became an influential cybersecurity case because warnings were generated during the attack but did not prevent the theft. Target’s own January 2014 update confirmed the scale of the exposed customer information.
Twitter API Data Scraping

©Golden Dayz/Shutterstock.com
A Twitter programming error introduced in 2021 allowed someone to submit an email address or phone number and learn which Twitter account was associated with it. Twitter fixed the vulnerability in January 2022 but later confirmed that an attacker had exploited it before the repair. Information connected to approximately 5.4 million accounts was subsequently offered for sale online.
Later reports claimed that files containing data associated with 200 million or even 400 million accounts had appeared online. Twitter’s investigation found that the 5.4-million-account file was connected to the known vulnerability, but it said it could not establish that the much larger collections came from a new exploitation of its systems. No passwords or direct messages were found in the examined datasets. Even so, linking private contact information to pseudonymous accounts created serious phishing, harassment, and identification risks.
Yahoo Data Breaches
Yahoo experienced two enormous breaches that were not publicly disclosed until years later. The company announced in 2016 that attackers had stolen information connected to at least 500 million accounts in late 2014. A separate August 2013 breach was eventually determined to have affected every Yahoo account that existed at the time, totaling approximately three billion accounts.
The stolen information included names, email addresses, telephone numbers, dates of birth, hashed passwords, and, in some cases, security questions and answers. The breaches also became a landmark corporate-disclosure case. The Securities and Exchange Commission said Yahoo failed to tell investors about the 2014 breach for nearly two years. The company formerly known as Yahoo later agreed to a $35 million SEC penalty, while Verizon reduced its acquisition price by $350 million.
Heartland Payment Systems

©Bits And Splits/Shutterstock.com
Heartland Payment Systems disclosed its breach in January 2009 after discovering malicious software inside its payment-processing environment. Prosecutors said Albert Gonzalez and his accomplices used SQL injection attacks to penetrate corporate networks and then installed malware capable of collecting card data as transactions moved through the compromised systems.
The broader criminal operation stole information associated with more than 130 million credit and debit cards from Heartland and other targets, making it the largest payment-card breach prosecuted in the United States at that time. Gonzalez pleaded guilty in December 2009 and was later sentenced to 20 years in federal prison. The Justice Department’s case demonstrated how a single intrusion into a major payment processor could expose customers across thousands of businesses.
Equifax Data Breach
Equifax announced in September 2017 that attackers had accessed personal information belonging to approximately 147 million people. The stolen data included names, birth dates, addresses, Social Security numbers, and, in some cases, driver’s license and payment-card information. Unlike a stolen password, much of this information cannot simply be changed, leaving victims exposed to identity-theft risks for years.
The attackers exploited a known vulnerability in Apache Struts that had already received a security patch. They remained inside Equifax’s environment from May through July 2017 before the intrusion was detected. Equifax later reached a global settlement with the FTC, the Consumer Financial Protection Bureau, and state authorities requiring it to pay at least $575 million and potentially as much as $700 million. The original claim that the incident cost taxpayers $1.5 billion is not supported by the FTC’s settlement record.
WannaCry Ransomware Attack
On May 12, 2017, WannaCry began spreading automatically between vulnerable Windows computers. The ransomware encrypted files and demanded Bitcoin payments, but its ability to move from one computer to another turned a conventional extortion attempt into a worldwide emergency. Microsoft had released a security update addressing the underlying weakness two months earlier, but many organizations had not installed it.
The United Kingdom’s National Cyber Security Centre reported that WannaCry affected roughly 300,000 computers across 150 countries. Forty-eight National Health Service trusts were disrupted, forcing hospitals to cancel appointments, divert ambulances, and temporarily return to paper-based procedures. Authorities in the United States and United Kingdom later attributed the attack to hackers associated with North Korea. WannaCry became one of history’s clearest demonstrations of how quickly ransomware can spread when large numbers of systems share the same unpatched vulnerability.
NotPetya

©Pungu x/Shutterstock.com
Just weeks after WannaCry, another destructive program began spreading from Ukraine on June 27, 2017. NotPetya displayed a ransom demand, but researchers concluded that it was designed primarily to destroy data rather than generate recoverable ransom payments. The malware initially spread through a compromised update to Ukrainian accounting software before using stolen credentials and Windows vulnerabilities to move across corporate networks.
The attack disrupted shipping companies, manufacturers, hospitals, government agencies, and other organizations around the world, producing billions of dollars in estimated losses. In 2020, the Justice Department charged six officers of Russia’s military intelligence agency in connection with NotPetya and other destructive cyber operations. Unlike many criminal ransomware attacks, NotPetya demonstrated how malicious software could be used as a weapon of geopolitical disruption while spilling far beyond its initial target.
Marriott and Starwood Data Breaches
Attackers gained access to Starwood’s guest reservation network in approximately July 2014 and remained undetected until September 2018, two years after Marriott acquired the hotel company. The prolonged intrusion exposed information from approximately 339 million guest records worldwide. The compromised data included names, reservation details, loyalty numbers, payment information, and millions of unencrypted passport numbers.
That was not the companies’ only security incident. The FTC said three Marriott and Starwood breaches between 2014 and 2020 affected more than 344 million customers worldwide. In 2024, Marriott agreed to a $52 million multistate penalty and new security requirements. The Starwood intrusion remains notable not only for its size, but also for the length of time attackers operated inside a reservation system containing unusually detailed travel and identity information.
SolarWinds Supply-Chain Attack
The SolarWinds attack showed how compromising one trusted software provider could open doors into thousands of other organizations. Beginning in early 2020, attackers secretly inserted malicious code into updates for SolarWinds’ Orion network-management software. Customers installed the updates believing they came from a trusted vendor, unknowingly creating a backdoor into their own systems.
SolarWinds estimated that nearly 18,000 customers received a compromised update, although the attackers selected a much smaller group for additional intrusion and espionage. Victims included federal agencies and major private companies. The campaign remained undiscovered until December 2020 and was later attributed by the U.S. government to Russia’s Foreign Intelligence Service. According to the Government Accountability Office, the incident required an extensive federal and private-sector response and exposed the risks created by trusted software supply chains.
Colonial Pipeline Ransomware Attack
On May 7, 2021, the DarkSide ransomware group gained access to Colonial Pipeline’s business network. The company shut down portions of its infrastructure while investigating, interrupting the delivery of gasoline, diesel, and jet fuel across the eastern United States. The disruption contributed to panic buying, fuel shortages, and temporary price increases, demonstrating how an attack on business computers could produce immediate consequences in the physical world.
Colonial paid the attackers approximately 75 Bitcoin, valued at about $4.4 million at the time. The Justice Department later recovered 63.7 Bitcoin, then worth approximately $2.3 million, by tracing the payment through the cryptocurrency ledger. The incident helped move ransomware from an information-technology concern to a national-security priority because it showed that cybercriminals could disrupt critical infrastructure without directly attacking its industrial control equipment.
MOVEit Transfer Attacks

©Summit Art Creations/Shutterstock.com
In May 2023, attackers began exploiting a previously unknown SQL injection vulnerability in MOVEit Transfer, software used by organizations to exchange sensitive files. The vulnerability allowed unauthorized access to customer environments before a patch was available. Progress Software discovered the flaw after receiving reports of suspicious activity and released security fixes on May 31.
The Clop cybercrime group used the vulnerability to steal information from companies, government agencies, universities, pension systems, and service providers. Because many organizations shared files with outside vendors, the effects spread far beyond companies that operated MOVEit themselves. CISA and the FBI later described the exploitation as affecting thousands of organizations. The campaign became a defining supply-chain incident because a single weakness in widely used file-transfer software exposed data belonging to tens of millions of people across otherwise unrelated institutions.
23andMe Genetic Data Breach
In 2023, attackers used credentials recycled from other breaches to enter thousands of 23andMe accounts. Once inside, they accessed information that users had chosen to share through features connecting them with genetic relatives. That allowed the attackers to collect profile and ancestry information extending well beyond the accounts they had directly compromised.
The incident ultimately affected approximately 6.9 million customers worldwide. Depending on a user’s settings, exposed information could include names, birth years, ancestry details, predicted relationships, and portions of genetic profiles. Some of the stolen information was later advertised for sale online. A 2026 multistate settlement addressed allegations that 23andMe failed to use adequate safeguards. The breach was particularly alarming because genetic information, unlike a password or card number, cannot be replaced after it is exposed.
Change Healthcare Cyberattack
A ransomware attack struck Change Healthcare on February 21, 2024, forcing the company to disconnect systems used to process medical claims, prescriptions, and payments. Because Change Healthcare serves as a major link between insurers, pharmacies, hospitals, and medical practices, the outage disrupted health care operations across the United States. Some providers struggled to submit claims or receive payments for weeks.
The scale of the privacy breach became clearer over time. In July 2025, Change Healthcare told the Department of Health and Human Services that approximately 192.7 million people had been affected, making it the largest health care data breach reported in the United States. The compromised information varied by person but could include medical, insurance, billing, contact, and identification data. UnitedHealth Group reported $2.2 billion in direct response costs during 2024, illustrating how one cyberattack against a central service provider could disrupt an entire industry.
Conduent Data Breach
Attackers maintained unauthorized access to Conduent systems between October 21, 2024, and January 13, 2025. Conduent provides technology and administrative services for governments, insurers, transportation systems, and health programs, giving the breach an unusually broad reach. The company initially disclosed a service disruption, but later notifications showed that sensitive information had been stolen.
By February 2026, government breach records indicated that more than 25 million people had been affected across the United States. According to the Wisconsin Department of Agriculture, Trade and Consumer Protection, the exposed data included names, addresses, birth dates, Social Security numbers, health-insurance details, and medical information. The final total may change as notifications continue. Conduent’s role behind numerous public and private services made the incident another example of how compromising a largely invisible contractor can affect millions of people at once.
Carnival Data Breach

One of the newest major incidents occurred in April 2026, when an attacker used social engineering to deceive a Carnival employee and gain access through the worker’s account. Carnival identified the unauthorized activity on April 14. The exposed information potentially included names, contact details, dates of birth, payment information, passport or driver’s license data, and health information collected through Carnival’s cruise brands.
The breach was estimated to have affected more than six million people worldwide. Carnival reported that 800,060 Texas residents were involved, according to a June 2026 announcement from the Texas attorney general. The investigation remained underway as of August 2026, so the final number and full range of compromised information could change. The incident also reflected the growing importance of defending against social engineering, since attackers may bypass sophisticated technology by manipulating someone with legitimate access.
What These Cyberattacks Have in Common
No single failure explains every incident on this list. Some attackers exploited software vulnerabilities, while others relied on stolen passwords, poorly protected programming interfaces, malicious updates, or social engineering. The largest incidents often became catastrophic because one compromised company processed information or provided services for thousands of other organizations.
The history of these attacks also shows that prevention is only part of cybersecurity. Organizations must detect suspicious behavior quickly, limit how far an intruder can move, maintain recoverable backups, and disclose breaches promptly. Individuals cannot prevent a company from being attacked, but unique passwords, multifactor authentication, credit freezes, and careful monitoring can reduce the damage caused when personal information inevitably appears in another breach.
