Honest, In-Depth & Transparent VPN Reviews from Real Users

Honest, In-Depth & Transparent VPN Reviews

We may earn a commission from links. Learn more

Largest Data Breach in US History

13-step review process Fact-checked

Last updated: July 20, 2026

Largest Data Breach in US History

 

Key Takeaways

  • Yahoo (2013/2016): 3 billion accounts exposed – largest US breach on record
  • National Public Data (2024): 2.9 billion records, ~1.3 billion people, including Social Security numbers
  • Yahoo was hacked directly; NPD’s data was exposed via an unsecured, misconfigured database
  • NPD collapsed under lawsuits after the breach

The Story Behind the Numbers

In 2016, Yahoo admitted that hackers had broken into its systems years earlier. At first, the company said 1 billion accounts were affected. A year later, that number changed. The real figure was 3 billion – every single Yahoo account that existed at the time.

Names, birth dates, phone numbers, and security questions were all exposed. No financial data was taken, but the scale was staggering: roughly 3 billion accounts, more than the population of North and South America combined.

For years, Yahoo held the record without a serious challenger. Then, in 2024, a little-known data broker called National Public Data (NPD) was hacked. The breach exposed close to 2.9 billion records, covering about 1.3 billion people – many of them Americans, with Social Security numbers included. NPD later collapsed under the weight of lawsuits.

Why This Data is Important

These aren’t just headlines. They’re a preview of what happens to your personal information once it leaves your hands. Yahoo’s breach happened to a company you may have used directly. NPD’s breach happened to a company most people had never heard of – a data broker that collected and sold information without ever asking permission.

That’s the uncomfortable part: your data can be exposed even if you never signed up for anything, simply because some company decided to buy or collect it. And the causes varied – Yahoo was actively hacked, while NPD’s records sat in an unsecured database anyone could find. Either way, once details like a Social Security number are out, they don’t expire. The risk lasts a lifetime, not just a news cycle.

Looking Ahead: Future Outlook

Data brokers like NPD operate with far less oversight than banks or hospitals, and there are thousands of them. As more get breached, “largest ever” records will likely keep falling. That’s a good reason to understand what a VPN can and can’t protect you from – it won’t stop a database from being hacked, but it limits what else gets exposed about you. Browse our VPN reviews and guides to compare your options.

Source & Methodology

Figures are drawn from IBM’s coverage of the National Public Data breach, which compares the 2024 NPD incident directly against the 2013-2016 Yahoo breach using company disclosures and court filings. Numbers reflect accounts or records exposed, as reported by the companies involved and confirmed through public disclosures, not estimates or projections.