Ask anyone which industry gets breached most and you will hear the same guesses: banks, hospitals, maybe government.
We get to test those guesses against data, and the data disagrees. Twice.
First, a quick word on where these numbers come from, if this is your first time here. XposedOrNot is a free, open-source breach notification service: you give it your email, it tells you which public breaches your accounts appeared in, and it can keep watching for you. Behind it sits a catalog of 777 verified public data breaches, each one indexed with what leaked, when, and from what kind of company. All of it is queryable through an open API, no key needed. Every number below comes from that catalog, pulled live this morning, and the exact script sits at the end of this post so you can pull it yourself. Receipts included, same deal as our breach-lag analysis.
So what does the catalog say? Count breaches, and Entertainment leads with 220 of 777. Count exposed records instead, and the crown moves to Information Technology, at 4.65 billion. The answer flips depending on how you count, and by the end you will see why the flip itself is the lesson.
The short version
- Most breaches: Entertainment. 220 of the 777 in our catalog. Banks sit fifth, healthcare twelfth.
- Most records: Information Technology, at 4.65 billion. Fewer incidents, vastly bigger ones: 35.8 million records per breach.
- The industries everyone guesses first are nowhere near the top, because attackers at scale go where harvesting is easy, not where records are valuable.
Before we dig in, one definition, because it matters here. A record is one exposed account entry in one breach, not one person; the same email address shows up in many breaches. Records, not people. We keep that distinction everywhere.
Count #1: By number of breaches
Run the tally by incidents (live, 24 August 2026) and here is your top five:
| Rank | Industry | Breaches |
|---|---|---|
| 1 | Entertainment | 220 |
| 2 | Information Technology | 130 |
| 3 | Retail | 108 |
| 4 | Miscellaneous | 78 |
| 5 | Finance | 49 |

Entertainment is not even close to losing this one. Gaming sites, media platforms, forums, streaming services: that one bucket holds nearly as many breaches as the next two industries combined. Meanwhile the sector everyone guards hardest, finance, sits fifth with fewer than a quarter of Entertainment’s count. And healthcare, everyone’s other guess? Not even in the top ten (12th of 20 industries, with 12 breaches).
Why does it look like this? Attack surface and economics. There are vastly more gaming forums and media sites than banks, they hold exactly the assets credential attackers want (email + password pairs, the stuff dumps and combolists are made of), and their security budgets look nothing like a bank’s. Attackers, like everyone else, do more of what is cheap. And the category is not abstract: Zynga, the games company behind Words With Friends, sits in our catalog at 172 million records from 2019.
Maybe you are already pushing back: fine, lots of small forum breaches, but the serious data still lives somewhere else, right? Good instinct. Let’s count again.
Count #2: By records exposed
Same catalog, same day, ranked by total records instead of incidents:
| Rank | Industry | Records exposed |
|---|---|---|
| 1 | Information Technology | 4.65 billion |
| 2 | Entertainment | 3.24 billion |
| 3 | Miscellaneous | 949 million |
| 4 | Retail | 813 million |
| 5 | Education | 584 million |
Finance drops to eighth, at 146 million. Healthcare: 184 million.

There is your flip. IT companies suffer fewer breaches than Entertainment but catastrophically bigger ones, because IT platforms aggregate. One breached platform holding user data for thousands of downstream services outweighs a hundred breached forums. (Three of the five biggest entries in the catalog, led by the 790-million-record Collection-1 compilation, carry the IT label. Aggregators and the compilations built from them both pile up in that bucket.) The cleanest single example is Verifications.io, an email-verification service most people had never heard of: one breach, 762 million records, in 2019.
Which raises an obvious question. If IT has fewer breaches but more records, how big is a typical IT incident, exactly?
Count #3: By records per breach
Divide one ranking by the other and you get blast radius, the average incident size in each industry:
| Industry | Records per breach | Breaches |
|---|---|---|
| Information Technology | 35.8 million | 130 |
| Entertainment | 14.7 million | 220 |
| Finance | 2.9 million | 49 |

This is the aggregation argument as a single number. An IT incident averages well over double an Entertainment one, and almost twelve times a Finance one. A fairness note before anyone quotes the chart’s top bar: Music technically leads at 39.1 million per breach, but that is 11 breaches with Deezer’s 244 million records doing most of the lifting. Small samples, loud averages.
Averages, though, deserve suspicion. Ours included.
The typical breach is nowhere near these numbers
Here is the honest correction. The median breach in our catalog is 1.13 million records; the mean is 14.9 million. And by median size, IT (1.26 million) and Entertainment (1.28 million) are practically the same breach.
Which means the entire flip at the top of this post is a tail phenomenon. A handful of giant platforms and compilations drive the records ranking; the everyday breach looks similar no matter the industry. That does not weaken the story (the tail is where the aggregate damage lives), but it is the difference between quoting this post accurately and quoting it wrong.
So what survives two flips and a median reality-check? One thing did not move in any of the three counts, and it is the thing worth remembering.
The one lesson both counts teach
Notice what neither list has at the top: the industries with the most valuable individual records. Bank data is worth more per record than forum data; banks still are not where the volume is.
Because attackers at scale do not target value. They target availability. Automated credential attacks harvest wherever harvesting is easy, then let password reuse transport the value: the forum password becomes the bank password because someone used it in both places.
Which is why the “we’re not a target, we’re not a bank” instinct fails twice over. Run anything with logins and you are in the most-breached category there is; being uninteresting is not a defense, because the tooling does not check how interesting you are. And as an individual, your “unimportant” accounts are the likely leak source and your important ones are the destination: the gaming password from 2019 is the one that matters, if it is also your email password.
If you run one of those “uninteresting” sites
Say you run a modest forum, a game community, an indie shop. The tables above put you in the single most-breached category we track, and no, you cannot buy a bank’s security team. The good news: three moves cover a surprising amount of the gap, and none of them costs money.
- Assume your users’ passwords are already leaked somewhere else. Because statistically, they are. Rate-limit login attempts and offer two-factor; you are defending against replayed credentials more than against clever exploits.
- Store passwords like it is 2026: a slow, salted hash (bcrypt, scrypt, argon2). Of the catalog entries where we actually know how passwords were stored, roughly two in three did not bother.
- Put your own domain on free breach monitoring. When your users’ emails surface in someone else’s dump, you hear about it early enough to force resets before the credential-stuffing wave arrives, instead of reading about yourself on a forum.
That last one is ten minutes of setup. From our data, early warning is the cheapest defense there is.
Find your industry
We have been talking top-fives; you probably want your own row. Here is the whole board, all 20 industries, same live pull, floor-rounded for readability (the script below prints exact figures; labels are the catalog’s own):
| # | Industry | Breaches | Records | Records per breach |
|---|---|---|---|---|
| 1 | Information Technology | 130 | 4.65B | 35.8M |
| 2 | Entertainment | 220 | 3.24B | 14.7M |
| 3 | Miscellaneous | 78 | 949M | 12.1M |
| 4 | Retail | 108 | 813M | 7.5M |
| 5 | Education | 33 | 584M | 17.7M |
| 6 | Music | 11 | 430M | 39.1M |
| 7 | Health Care | 12 | 184M | 15.3M |
| 8 | Finance | 49 | 146M | 2.9M |
| 9 | Telecommunication | 18 | 139M | 7.7M |
| 10 | Transport | 19 | 115M | 6.0M |
| 11 | News Media | 17 | 80.8M | 4.7M |
| 12 | Electronics | 18 | 63.1M | 3.5M |
| 13 | Hospitality | 9 | 39.9M | 4.4M |
| 14 | Food | 16 | 39.8M | 2.4M |
| 15 | Non-Profit/Charities | 6 | 37.5M | 6.2M |
| 16 | Sports | 11 | 27.0M | 2.4M |
| 17 | Energy | 8 | 17.0M | 2.1M |
| 18 | Government | 7 | 9.7M | 1.3M |
| 19 | Manufacturing | 4 | 4.1M | 1.0M |
| 20 | Environment | 3 | 3.6M | 1.2M |
Whatever row you sit in, checking your own exposure takes ten seconds at xposedornot.com. Free, no signup.
Now the fine print, which with breach data is never optional.
The caveats (every number has them)
- Industry labels are ours, assigned per breach; another catalog’s taxonomy would shuffle the mid-table. The top-of-table gaps are too large for labeling to explain away.
- “Miscellaneous” is big (78 breaches, 949M records), partly compilations and hard-to-classify entries; a stricter taxonomy would redistribute some of it.
- The big compilations carry industry labels too, and they distort whichever bucket they land in. Two are mislabeled right now, and we know it: the 1.11-billion-record “1.4BillionRecords” compilation sits under Entertainment, and a 457M-record combolist sits under Education (78% of Education’s entire total). Both are on our cleanup list. We re-ran the ranking with both moved to Miscellaneous to see what changes: IT keeps first place by records, Entertainment slides to third behind Miscellaneous, and Education falls out of the top five entirely. The flip story survives the cleanup; the mid-table does not. Run the script below and you will find these yourself, which is exactly why it is below.
- Small industries have loud averages. Music (11 breaches), Government (7), Environment (3): one entry can own the whole bucket. Read the per-breach column with the breach count next to it.
- Our catalog is public breaches, not all breaches. Sectors that disclose less (or get covered less) are undercounted; that plausibly includes healthcare and government.
FAQ
Which industry has the most data breaches?
Entertainment, by incident count: 220 of the 777 breaches in the XposedOrNot catalog as of August 2026, ahead of Information Technology (130) and Retail (108). By total records exposed, Information Technology leads with 4.65 billion.
Is healthcare breached less than everyone thinks?
In public data, yes: 12 incidents and 184 million records in our catalog, 12th of 20 industries by breach count. Two caveats travel with that: healthcare disclosure runs through different channels, and our catalog only sees public breaches. Less visible is not the same thing as safe.
Why does finance rank so low?
49 breaches and 146 million records: fifth by count, eighth by records. Banks are heavily regulated, well funded, and hard targets, so volume attackers harvest easier industries instead. Your banking password still leaks anyway when it is reused on a softer site, which is the actual lesson of this post.
Reproduce it
curl -s "https://api.xposedornot.com/v1/breaches" > breaches.json
python3 - <<'EOF'
import json, collections, statistics
d = json.load(open('breaches.json'))['exposedBreaches']
count = collections.Counter(x['industry'] for x in d)
records = collections.Counter()
for x in d:
records[x['industry']] += x['exposedRecords']
print("By count:", count.most_common(20))
print("By records:", [(k, f"{v:,}") for k, v in records.most_common(20)])
print("Per breach:", [(k, f"{v // count[k]:,}") for k, v in records.most_common(20)])
sizes = [x['exposedRecords'] for x in d]
print("Median:", f"{int(statistics.median(sizes)):,}", "| Mean:", f"{int(statistics.mean(sizes)):,}")
for k in ('Information Technology', 'Entertainment'):
print(k, "median:", f"{int(statistics.median([x['exposedRecords'] for x in d if x['industry'] == k])):,}")
EOF
Numbers as of 24 August 2026; the catalog grows weekly, so your output will drift upward from ours.
That is the whole story: one catalog, three ways of counting, one lesson that survives all three. Your own exposure does not care which industry it came from: xposedornot.com, ten seconds, free. And if the receipts-included format earns it, a star on GitHub helps others find the project. Honestly, it makes our day.
Appendix: Sources and references
- All figures: api.xposedornot.com/v1/breaches, script above, run 2026-08-24 (777 breaches)
- Named entries (all from the same catalog pull): Zynga 172,817,913 records (2019), Verifications.io (catalog ID: Verifications) 762,579,945 (2019), Deezer 244,007,616 (2019), Collection-1 790,803,860 (2019)
- The breach you heard about today happened 4+ years ago (median 1,591-day surfacing lag)
- H1 2026 Data Breach Report: 101 breaches, 1 billion records
- Data breach statistics 2026 (the running first-party stats page)
- Breach dump, combolist, stealer log: three leaks, three risks
- How to check if your email was in a data breach
- Monitor every domain you own for breaches, at zero cost
- A free breach-monitoring toolkit for sysadmins
—
Check out some of our posts for you.
- Domain Breach Check by API: Verify Once, Pull the Report Anytime
- Password Managers, From Someone Who Reads Breach Dumps
- 516 Breaches Leaked Passwords. 56% Stored Them Badly.
- August 2026 Breach Roundup: 33.8 Million Records, and One Group’s Fingerprints on Five of Them
- How to Set Up Breach Alerts for Your Whole Org, Free
- Your Email Is in Every Breach We Index. It’s the Master Key.





