The Top 5 Data Breaches Of 2024 And What You Need To Know About Them
The five largest data breaches of 2024 so far are National Public Data (2.7 billion records claimed), Ticketmaster (560 million customers), Change Healthcare (145 million people), AT&T (73 million accounts), and Dell (49 million records). Between them, they exposed Social Security numbers, payment details, medical records, and account credentials on a scale that touches nearly every American household, and nearly every business.
The instinct is to read these as big-company stories. They aren’t. Every one of these breaches started with a weakness that exists in small businesses too: a stolen credential, an unpatched system, a third-party portal nobody was watching. The difference is that a Fortune 500 company can absorb the lawsuits and the cleanup. A 20-person firm in Houston usually cannot.
What Were the Biggest Data Breaches of 2024?
Here are the five incidents that defined the year, and the specific lesson each one carries for a smaller organization.
1. National Public Data: 2.7 Billion Records
A hacking group claimed to have pulled 2.7 billion personal records from a background-check and data-brokering company, including Social Security numbers and addresses. Portions surfaced on the dark web. Researchers questioned the raw count, since the countries involved only hold about half a billion people combined, but the practical takeaway stands: a very large share of American Social Security numbers should now be treated as exposed.
The lesson: you were probably swept into this one whether or not you ever heard of the company. Freezing your credit with the three bureaus is free, takes minutes, and can be lifted whenever you apply for a loan or card.
2. Ticketmaster: 560 Million Customers
Attackers spent April and May inside Ticketmaster’s environment and walked out with names, emails, phone numbers, and payment details for more than 560 million customers. Victims reported unauthorized charges and identity theft afterward, and the breach piled onto parent company Live Nation’s existing legal troubles with the US Department of Justice.
The lesson: attackers who get in quietly can stay for weeks. Detection matters as much as prevention, which is why continuous monitoring is a core piece of any real cybersecurity program.
3. Change Healthcare: 145 Million People
The February ransomware attack on Change Healthcare exposed personal information for more than 145 million people, including Social Security numbers and medical records, making it one of the largest healthcare breaches on record. Pharmacies and providers across the country, including plenty here in Texas, felt the operational fallout for months as claims processing stalled.
The lesson: ransomware doesn’t just steal data, it stops the business. Tested backups and a recovery plan are what turn a ransomware event from an existential threat into a bad week. If you can’t say when your backups were last test-restored, that’s the gap.
4. AT&T: 73 Million Accounts
In March, data tied to roughly 73 million current and former AT&T customers surfaced on the dark web, including Social Security numbers, account details, and passcodes. Some of the data traced back to 2019, and the incident followed a separate 2023 breach affecting 9 million users. Class action lawsuits followed.
The lesson: stolen data has a long shelf life. Credentials taken years ago get recycled into attacks today, which is why unique passwords and multifactor authentication on every account are non-negotiable.
5. Dell: 49 Million Records
In May, an attacker going by Menelik used brute force against a Dell reseller’s client portal and extracted 49 million records with customer names, email addresses, and account details. Dell issued a public apology and now faces regulatory scrutiny.
The lesson: your vendors’ security is your security. A partner portal with weak rate limiting was all it took. Small businesses in Houston and Dallas-Fort Worth run on vendor portals too, from payroll to supply ordering, and each one is part of your attack surface.
What Should You Do Personally?
Two actions cover most of the risk. First, freeze your credit at Equifax, Experian, and TransUnion, and watch your bank statements. Second, check haveibeenpwned.com to see which breaches already include your email address, then change any password you reused across those accounts.
Why Small Businesses Should Pay Attention
Cybercriminals increasingly target small and midsize businesses precisely because they hold valuable data without enterprise-grade defenses. A single breach can mean days of downtime, lost customer trust, and cleanup costs that run into the tens of thousands. The headlines feature the giants, but the volume of attacks lands on companies your size.
The good news is that the fixes are known and affordable: multifactor authentication, patched systems, monitored endpoints, tested backups, and employees trained to spot phishing. The hard part is knowing which gaps you actually have, which is exactly what a cyber security risk assessment is for.
If 2024’s breach headlines have you wondering where your own weak spots are, let’s find them before someone else does.