← All resources

The Largest Data Breaches of the 21st Century (and What They Teach SMBs)

July 16, 2026 · Greg Brainerd

The largest corporate data breaches of the 21st century and the lessons for Houston and DFW small businesses

Data breaches happen just about every hour of every day. Most of them never make the news, because most of them hit small businesses, and they quietly turn the lives of those owners and their employees upside down. The breaches that do grab headlines involve giant brands we all know, with millions of dollars in theft and damages attached.

I want to walk through some of those famous breaches, because the case studies are instructive. When you look at how these big companies got breached, what data was lost, and how their management teams handled the fallout, you start to see the same handful of mistakes over and over. And those mistakes are exactly the ones a small business can learn to avoid.

This post is adapted from Chapter 3 of my book, Protecting Your Business Against Hackers. If you’d like the whole thing, you can download the full book here.

Seven Breaches Worth Studying

Home Depot (2014)

Hackers got into Home Depot’s network using a vendor’s stolen login credentials, then installed their own malware on the stores’ self-checkout registers. That malware evaded even the latest antivirus software, and the breach went undetected for several months.

The damage: credit and debit card information from 56 million cards across the US and Canada, plus 53 million email addresses. The stolen data included customer names, card numbers, expiration dates and the verification codes off the back of the cards. The initial breach cost Home Depot $62 million, and they later agreed to pay $19.5 million to settle a class-action lawsuit, including a $13 million fund to compensate customers. They also handed out $50 gift cards, offered free credit monitoring, and were forced to adopt new data security measures.

The lesson: your vendors’ credentials are your attack surface. And “the latest antivirus” alone won’t catch a determined attacker who’s already inside.

Adobe (2013)

Adobe was hacked in 2013, exposing customer IDs, encrypted passwords and credit card records. What made it worse was how badly Adobe underestimated the scope. They first said about 2.9 million users were affected. Weeks later, they had to admit the real number was 38 million accounts, more than ten times their first estimate. A file with millions of usernames and hashed passwords ended up on a hacking forum. Adobe reset passwords, notified customers, and was fined $1 million in a multistate lawsuit.

The lesson: if you don’t know exactly what you have and where it lives, you can’t accurately scope a breach, and a lowball estimate erodes trust fast.

eBay (2014)

The world’s online marketplace was hacked in 2014. At first eBay didn’t think customer accounts were affected, so they kept the breach private. After forensic investigators dug in, they realized hackers had accessed the personal data of all 145 million of their customers, one of the largest corporate cyberattacks on record. The attackers used the credentials of just three corporate employees to reach the entire user database, exposing email addresses and encrypted passwords. eBay took heat not just for the breach but for being slow to investigate and slow to notify customers.

The lesson: a handful of compromised employee logins can unlock everything. Identity is the perimeter now.

Heartland Payment Systems (2008)

Heartland is a credit card processor: handling card payments, payroll and loyalty cards is the whole business. In 2008 they suffered one of the largest data breaches in US history, losing information from 100 million credit and debit cards. The attackers used SQL injection to break in, and Heartland wasn’t their only victim: the same gang hit 7-Eleven and Hannaford Brothers. Heartland paid American Express $3.6 million to settle, agreed to fines with Visa and MasterCard, and set aside $12.6 million for charges related to the hack. Banks sued to recover the cost of reissuing cards.

The lesson: when you hold other people’s sensitive data, a breach ripples out to every bank and partner downstream. Basic application security (like guarding against SQL injection) is non-negotiable.

Yahoo (2013)

Having one billion customer accounts hacked is historically bad. Finding out years later that it was actually three billion, every single Yahoo user, is even worse. In 2013, attackers stole names, passwords and email addresses (financial information was spared). A 2017 forensic investigation revealed the true scope: all accounts. Yahoo emailed everyone affected, forced password changes and invalidated unencrypted security questions. The stolen data turned up for sale on the dark web. And a separate attack a year later hit roughly 500 million more customers; the DOJ later indicted two Russian spies and two hackers for it.

The lesson: breaches can stay hidden for years, and the full damage often isn’t clear until long after the fact. Detection matters as much as prevention.

Capital One (2019)

How much damage can a single hacker do? About $150 million. In 2019, one cybercriminal, a former software engineer, broke into Capital One’s servers by exploiting a misconfigured web application firewall and accessed more than 100 million customer accounts and credit card applications. The haul included 140,000 Social Security numbers, a million Canadian Social Insurance numbers, and 80,000 bank accounts, plus names, addresses, credit scores and balances. Capital One may only have found out because the attacker bragged about it on GitHub, social media and Slack, even explaining exactly how she did it. Expected costs: $100–150 million.

The lesson: a single misconfiguration is all it takes. Configuration review isn’t busywork; it’s frontline defense.

MyFitnessPal and Uber: Two Ways to Respond

The last two are a study in contrast. When Under Armour’s MyFitnessPal app was hacked in 2018, about 150 million users were affected, but the company did two things right. They had separated their users’ data, so the intrusion only exposed usernames, emails and passwords, not credit cards, locations or birthdays. And they moved fast: breach occurred in late February, discovered late March, public less than a week later.

Uber is the cautionary tale. In late 2016, attackers stole emails, names and phone numbers from 50 million riders and 7 million drivers, plus 600,000 driver’s license numbers. Then the hackers demanded a $100,000 ransom to stay quiet, and Uber paid it, hiding the breach from riders and drivers for over a year. The settlement, one of the largest data-privacy penalties in history, came to $148 million, in part because Uber failed to give timely notice and, per Texas, engaged in deceptive trade practices.

The lesson: segment your data so a breach is contained, and disclose quickly. How you respond can cost, or save, more than the breach itself.

What Small Businesses Should Actually Take From This

It’s easy to read a list like this and feel relieved you’re not Yahoo. But look past the eye-watering numbers and you’ll notice every one of these breaches came down to fundamentals a business of any size can get wrong: a vendor’s stolen credentials, a few compromised employee logins, a misconfigured firewall, an unpatched injection flaw, data that wasn’t segmented, a slow or dishonest response.

Those aren’t enterprise problems. They’re the same gaps I see in businesses with 10 to 200 employees around Houston every week, just without the headlines or the legal team. Big brands get magnified and made into examples; their fines are massive and their customer fallout is often irreparable. A small business doesn’t get that kind of coverage, but it also doesn’t have the cash reserves to absorb the hit.

The good news is that the defenses are the same too: strong identity controls, configuration review, network monitoring, data segmentation, and a clear plan for when, not if, something goes wrong. (For a look at how those layers fit together, see our cybersecurity services page.)

Frequently Asked Questions

What was the largest data breach of the 21st century?

By sheer number of accounts, Yahoo’s 2013 breach is the largest on this list. It ultimately affected all three billion Yahoo user accounts, a figure that wasn’t confirmed until a forensic investigation in 2017. A separate 2014 attack hit roughly another 500 million customers.

How did hackers get into these big companies?

The methods are surprisingly ordinary. Home Depot’s attackers used a vendor’s stolen login. eBay’s used the credentials of three employees. Heartland fell to a SQL injection attack. Capital One was breached through a misconfigured web application firewall. In other words, the entry points were everyday weaknesses, not exotic, movie-style hacking.

My business is small, so why should these enterprise breaches matter to me?

Because the root causes are size-agnostic. Stolen vendor credentials, compromised employee logins, misconfigurations and unsegmented data are exactly the gaps small businesses have too, and small businesses are actually cybercriminals’ number-one target, just without the news coverage. The companies above could absorb nine-figure losses. Most small businesses can’t.

What’s the biggest takeaway from how these companies responded?

Speed and honesty. MyFitnessPal contained the damage by segmenting user data and went public in under a week. Uber hid its breach for over a year and paid hackers to stay quiet, which helped drive a $148 million settlement. A fast, transparent response can cost far less than a cover-up.

Find Your Gaps Before Someone Else Does

You don’t need a corporate budget or an in-house security team to defend against the mistakes that took down these giants. You just need the right fundamentals in place, predictably and consistently. That’s the gap we exist to fill, as your IT team, for one flat monthly fee with no surprises.

Get a Free Cybersecurity Risk Assessment

If you’re ready to find out exactly where your gaps are, book a free discovery call, request a cybersecurity risk assessment, or call us in Houston at 281-367-8253.

Ready for IT that just works?

Book a no-pressure discovery call. We'll review your setup and show you exactly where you stand.