Not every data breach makes headlines. What turns an ordinary security incident into a high-profile breach everyone remembers is a mix of two factors: scale (how many people were affected) and sensitivity (how damaging the exposed information is). A breach of ten million email addresses might barely register. A breach of 9,500 police officers’ identities, in the wrong political context, can put lives at risk.
This article works through both sides of that equation. It covers the largest global breaches on record by sheer numbers, then turns to a set of UK and Irish cases that rarely receive the same international attention, despite being among the most consequential breaches in either country’s history. Along the way, it looks at what actually causes these incidents, what they cost, what happens to the organisations afterwards, and what any business can do to reduce its own risk.
Table of Contents
High-Profile Breaches at a Glance
| Organisation | Year | Location | People/Records Affected | Primary Cause | Regulatory Outcome |
|---|---|---|---|---|---|
| Yahoo | 2013 | Global | 3 billion accounts | Cyber-attack | No GDPR-era fine (pre-dates regulation) |
| National Public Data | 2024 | US/UK/Canada | 2.9 billion records | Database compromise | Company filed for bankruptcy |
| Aadhaar | 2018 | India | 1.1 billion residents | System vulnerability | No public fine confirmed |
| Marriott | 2018 | Global | Up to 500 million guests | Cyber-attack (Starwood systems) | Multi-jurisdiction fines |
| Equifax | 2017 | US-led, global impact | 147 million consumers | Unpatched vulnerability | Multi-jurisdiction fines and settlements |
| Police Service of Northern Ireland | 2023 | Northern Ireland | 9,483 officers and staff | Human error (FOI disclosure) | £750,000 ICO fine |
| Capita | 2023 | UK | 6.6 million individuals | Ransomware attack | £14 million ICO fine |
| HSE Ireland | 2021 | Ireland | ~100,000 people, national IT outage | Ransomware attack | No ICO/DPC fine confirmed; recovery costs continue to rise |
| British Airways | 2018 | UK, global customers | ~400,000 customers and staff | Inadequate security controls | £20 million ICO fine |
| TalkTalk | 2015 | UK | 157,000 customers | SQL injection attack | £400,000 ICO fine |
The Biggest Global Data Breaches Ever Recorded
Scale alone doesn’t tell the whole story, but it’s still the easiest way to understand how far attackers have been able to reach. These five high-profile breaches remain the largest confirmed incidents by number of accounts or records exposed, and each one changed how its industry thinks about data security.
Yahoo (2013)
Yahoo’s high-profile breach remains the largest confirmed data breach in history by the number of accounts affected. Attackers compromised all three billion Yahoo accounts in existence at the time, taking names, email addresses, and passwords. The company didn’t disclose the full scale of the incident until 2016, three years after it happened, which became almost as significant a story as the breach itself: a stark example of how delayed disclosure can compound the damage to user trust.
National Public Data (2024)
The newest entry on this list is also nearly as large as Yahoo’s. National Public Data, a Florida-based background-check broker most people had never heard of, held a database of roughly 2.9 billion records covering people across the US, UK, and Canada, much of it collected without those individuals’ knowledge or consent. A hacker calling themselves USDoD began selling the data in April 2024, and a broader leak followed that summer. The company later filed for bankruptcy. This high-profile breach is a useful case for showing how a business that most consumers never interact with directly can still hold and lose data on hundreds of millions of them.
Aadhaar (2018)
India’s Aadhaar system, the national biometric identity database covering over a billion residents, was reported to have exposed the personal records of roughly 1.1 billion people through a vulnerability in a third-party utility connected to the system. Given that Aadhaar numbers are tied to banking, mobile phone registration, and government benefits, this high-profile breach raised serious questions about the risks of centralising identity infrastructure at that scale.
Marriott (2018)
Marriott disclosed in 2018 that its Starwood guest reservation database had been compromised, with unauthorised access dating back to 2014, meaning the intrusion had gone undetected for roughly four years. Up to 500 million guest records were affected, including passport numbers and, for some guests, payment card details. The long dwell time (the gap between initial compromise and discovery) is one of the most-cited lessons from this high-profile breach: acquisitions inherit whatever security debt sits inside the systems they absorb.
Equifax (2017)
Equifax’s breach exposed personal data, including Social Security numbers and dates of birth, for 147 million consumers after attackers exploited a known, unpatched vulnerability in a web application framework. This high-profile breach led to a combined US settlement exceeding $700 million and remains one of the clearest examples of how a single missed patch can cascade into a breach affecting nearly half the US population.
High-Profile Breaches in the UK and Ireland
Global lists like the one above are almost always dominated by American companies, since the US has more, and larger, consumer data brokers and tech platforms. That leaves a gap: some of the most damaging and instructive high-profile breaches of the last decade happened in the UK and Ireland, and rarely get the depth of coverage they deserve.
The PSNI Data Leak (2023)
Scale isn’t the only measure of harm. A leak affecting fewer than 10,000 people can still be one of the most serious breaches on record if the data is sensitive enough, as the PSNI case shows.
In August 2023, the Police Service of Northern Ireland responded to a routine Freedom of Information request with an Excel spreadsheet. A worksheet that was meant to have been deleted, containing the surnames, initials, ranks, roles, and service numbers of all 9,483 PSNI officers and staff, had been hidden rather than removed, and nobody caught it during quality assurance. The file sat publicly accessible on the WhatDoTheyKnow website for around two hours and twenty minutes before it was taken down.
Given the security context in Northern Ireland, where many officers actively conceal their profession from friends and family, an independent review described this high-profile breach as the most significant data breach in the history of UK policing. PSNI worked on the assumption that the file had reached dissident republican groups. Officers reported installing home security systems, changing their routines, and in some cases relocating.
The Information Commissioner’s Office fined PSNI £750,000 in October 2024. That figure was already reduced from a starting point of £5.6 million under the ICO’s public-sector approach, which limits fines on public bodies so penalties don’t divert money from public services. Had PSNI been a private company, the ICO indicated the fine could have reached £17.5 million. Separately, thousands of officers have pursued civil claims that could be worth significantly more than the regulatory fine itself.
The Capita Cyber-Attack (2023)
Capita, one of the UK’s largest outsourcing firms, handles pension administration, NHS services, and local council contracts. In March 2023, an employee unintentionally downloaded a malicious file, and although a security alert was raised within ten minutes, the affected device wasn’t quarantined for 58 hours. In that window, the attacker deployed further tools and escalated access using a privileged service account with domain administrator rights that had already been flagged as a risk in earlier penetration tests but never remediated. That kind of unchecked privilege escalation is a recurring theme in large-scale, high-profile breaches, and is worth understanding on its own terms if you’re responsible for access controls.
The attack, attributed to the Black Basta ransomware group, ultimately exposed data on approximately 6.6 million individuals across 325 organisations, including special category data such as health and criminal record information. The Universities Superannuation Scheme alone had to notify around 470,000 pension members. Capita’s own costs from this high-profile breach exceeded £25 million, and in October 2025, the ICO fined Capita plc and its pensions subsidiary a combined £14 million for failing to secure the data adequately. A High Court group action brought on behalf of more than 8,000 claimants was cleared to proceed in February 2026.
The HSE Ireland Ransomware Attack (2021)
On 14 May 2021, Ireland’s Health Service Executive was hit by Conti ransomware that forced the shutdown of every IT system across the national health service, the most significant cyber-attack against a health system anywhere at that point. The attackers had actually gained their initial foothold roughly two months earlier, in March 2021, and went undetected despite several warning signs along the way.
HSE refused to pay the ransom and instead rebuilt its systems from the ground up, a process that took around four months before most services were substantially restored. Confidential medical information for hundreds of patients, along with internal corporate documents, was published online by the attackers. Recovery costs were still climbing years later, reported at tens of millions of euros in the first year alone, and continued to rise as HSE modernised the outdated infrastructure that had made the attack possible in the first place.
British Airways and TalkTalk: Two Regulatory Landmarks
Two earlier UK cases are worth understanding together because they show how the ICO’s approach to fining has evolved. In 2018, attackers diverted traffic from the British Airways website to a fraudulent page for over two months before the airline noticed, exposing payment and personal details for around 400,000 customers and staff. The ICO originally signalled a fine of £183.39 million, but after BA’s representations and consideration of the pandemic’s impact on the airline industry, the final penalty was reduced to £20 million, still the largest the ICO had issued at the time.
TalkTalk’s 2015 high-profile breach looks small by comparison (around 157,000 customers, with sort codes and bank details exposed for roughly 15,600 of them), but it set an earlier precedent. Attackers exploited a known SQL injection vulnerability that TalkTalk had failed to patch despite having more than three years’ warning. The ICO’s £400,000 fine was a record at the time, and the company’s own estimated costs from the incident, including lost customers, ran to around £77 million.
What Actually Causes a High-Profile Breach
Every case above traces back to one of two broad root causes, and the distinction matters because the fix for each is completely different.
Cyber-Attacks and Ransomware
Capita and HSE Ireland were both hit by ransomware gangs that gained access through a single compromised device or account, then moved laterally through the network before encrypting or exfiltrating data. This is the category most people picture when they think of a high-profile breach, and it’s also the category with the clearest defensive playbook: patching, endpoint monitoring, and reliable offline backups. Our guide to ransomware protection covers the practical controls that reduce exposure to this type of attack.
Human Error and Accidental Disclosure
PSNI’s breach wasn’t caused by a hacker at all; it was caused by a hidden spreadsheet tab that nobody checked before publishing a document. British Airways’ failure was arguably closer to this category, too: not a sophisticated attack, but over two months of inadequate monitoring that let a known intrusion type go unnoticed. Human error and process failure are consistently among the most common causes of reportable, high-profile breaches, and they’re also the hardest to fully eliminate, because they depend on people following procedures correctly every single time rather than technology blocking an attacker outright.
The Real Cost of a High-Profile Breach

According to IBM’s 2025 Cost of a Data Breach Report, the global average cost of a breach fell to $4.44 million, down 9% from the previous year, largely thanks to faster detection driven by AI-assisted security tools. The average time to identify and contain a breach dropped to 241 days, a nine-year low. In the United States specifically, though, average costs rose to a record $10.22 million, driven by heavier regulatory fines and higher litigation exposure. Healthcare remains the most expensive sector to experience a high-profile breach, averaging $7.42 million, which aligns with how disruptive and costly the HSE Ireland case turned out to be.
Regulatory fines tell a similar story on a UK scale. British Airways’ £20 million, Capita’s £14 million, PSNI’s £750,000, and TalkTalk’s £400,000 span more than three orders of magnitude, but in every case, the fine was only one part of the total bill. Capita’s own remediation costs alone were nearly double its eventual fine. TalkTalk’s total costs, including customer losses, were around 190 times its fine.
What Happens After a High-Profile Breach
After a high-profile breach, the fine is rarely the end of the story. Litigation frequently runs for years afterwards: Capita’s High Court group action, brought on behalf of more than 8,000 claimants, was still working through the courts in 2026, three years after the original attack. PSNI faced thousands of individual civil claims from affected officers, with potential damages reportedly far exceeding the regulatory fine itself.
Stolen data doesn’t disappear once an organisation recovers its systems, either. It’s common for breached records to circulate on the dark web long after the headlines fade, which is why checking your own exposure through a tool like Have I Been Pwned is worth doing periodically rather than just after a high-profile breach you already know about. Our guide to dark web risks explains how to monitor for this and what to do if your information turns up.
Reputational damage is harder to quantify but often longer-lasting. TalkTalk lost more than 100,000 customers in the aftermath of its high-profile breach. Organisations that respond transparently, as TalkTalk did by proactively notifying customers early, tend to recover trust faster than those that delay disclosure, as Yahoo’s three-year gap between breach and disclosure demonstrated the opposite.
How to Reduce Your Organisation’s Risk

A handful of practical steps show up repeatedly across the cases in this article:
- Enforce least-privilege access. Capita’s high-profile breach escalated as far as it did because a single service account had unrestricted domain administrator rights that had already been flagged, and never fixed, in earlier penetration tests. Understanding how privilege escalation works is the first step to closing that kind of gap before an attacker finds it.
- Quality-check anything before it’s disclosed publicly. PSNI’s breach came from a single, unchecked worksheet. A simple second-person review step before any FOI or data-sharing response goes out would have prevented it entirely.
- Patch known vulnerabilities promptly. TalkTalk and Equifax were both breached through vulnerabilities that had been publicly known for months or years beforehand.
- Know your reporting obligations. Under UK GDPR, most personal data breaches must be reported to the ICO within 72 hours of discovery. Our cybersecurity law guide sets out exactly what triggers that requirement and what happens if you miss it.
- Detect faster. IBM’s research is unambiguous on this point: organisations that detect and contain a high-profile breach quickly consistently pay less in fines, remediation, and lost business than those that take months to notice.
Frequently Asked Questions
What is considered a “high-profile” data breach?
There’s no fixed threshold. A breach becomes high-profile through some combination of the number of people affected, the sensitivity of the data involved, and the level of public or regulatory attention it draws. The PSNI leak affected fewer than 10,000 people but is treated as one of the most serious breaches in UK history because of what the data revealed and who it put at risk.
What was the largest data breach in history?
Yahoo’s 2013 breach, affecting all three billion of its accounts, remains the largest confirmed breach by account count. The 2024 National Public Data breach came close behind it at around 2.9 billion records.
What was the largest data breach in UK history?
By scale, Capita’s 2023 breach affected the most individuals through UK organisations (6.6 million people across 325 organisations). Given their historical significance and regulatory precedent, TalkTalk’s 2015 breach and British Airways’ 2018 breach remain the two most commonly cited landmark UK cases.
How do I know if my data was involved in a high-profile breach?
Check a service like Have I Been Pwned using your email address, and keep an eye on direct notifications from any organisation you have an account or relationship with. Companies are legally required to notify affected individuals when a breach poses a high risk to their rights and freedoms.
What are the main causes of high-profile breaches today?
IBM’s 2025 research found that just over half of breaches (51%) result from malicious cyber-attacks, with human error (26%) and IT failure (23%) accounting for the rest. Phishing was the single most common initial attack vector.
Can an organisation be fined more than once for the same breach?
It’s possible when more than one legal entity is responsible for the data. In the Capita case, the ICO issued separate, combined fines against Capita plc and its pensions subsidiary, Capita Pension Solutions Limited, because each held distinct legal responsibilities for the data involved.