Average Brit hit by five data breaches since 2004
While the number of breaches has fallen, the UK has been the worst-hit country in Northern Europe since 2004
Around seven British user accounts were breached every minute during the second quarter of 2025 – more than three million in total.
While data breaches dropped globally by 58% from the previous quarter, the number rose from 70 million to 94 million leaked accounts. The US was the most-affected country, with 42.5 million breached accounts, France, with 11.4 million, and India, with 1.7 million, followed by Germany and Israel.
The countries with the highest number of leaked accounts per 1,000 residents were France, at 172; Israel, at 130; the US, at 123; and Singapore, at 26.
"Whether sharing your name and address for food deliveries, or phone numbers when making a booking at a barber shop, there is no guarantee that businesses are keeping crucial information safe and secure," said Sarunas Sereika, product manager at Surfshark, which carried out the research.
"In the wrong hands, this data can be used to commit identity theft, via social media, for targeted scams or sold on the dark web – where they're traded for further illegal use."
In the UK, the number fell during the second quarter – down by 58% compared to the previous quarter. But, said the researchers, the numbers are still staggering. The UK ranks seventh globally, with 944,000 breached accounts.
Since 2004, said the firm, the UK has been the worst-hit country in Northern Europe, with 369.9 million compromised user accounts. A total of 79.4 million unique emails were breached, indicating that the average British person has been affected by data breaches around five times.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
And with 239.3 million passwords being leaked together with British accounts, nearly two-thirds of breached users were put in danger of account takeover that could lead to identity theft, extortion, or other cybercrimes.
The UK's biggest incident involved the leak of 32,272,135 billion unique British emails in an underground forum by a hacker known as Addka72424.
Meanwhile, 5,686,838 British emails were leaked after a Wattpad database containing 270 million records was offered for free on hacker forums, and 2,856,737 UK accounts were exposed when it was discovered that Gravatar could be abused for mass data collection of its profiles by web crawlers and bots.
Globally, there have been an astonishing 23 billion breached accounts since 2004. Around 7.7 billion of these have unique email addresses, meaning that a single email address has been breached around three times. For every 100 people, 94 unique email addresses and 281 accounts are breached.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
The trends that will shape workplace culture in 2026In-depth Tech leaders share their insights on how businesses can embrace change across hiring, training, and culture
-
Why the UK is primed to lead a global charge in ‘green AI’ innovationNews UKAI says there are major economic incentives and a big opportunity for the UK to lead the world in green AI development
-
LastPass hit with ICO fine after 2022 data breach exposed 1.6 million users – here’s how the incident unfoldedNews The impact of the LastPass breach was felt by customers as late as December 2024
-
OpenAI hailed for ‘swift move’ in terminating Mixpanel ties after data breach hits developersNews The Mixpanel breach prompted OpenAI to launch a review into its broader supplier ecosystem
-
Teens arrested over nursery chain Kido hacknews The ransom attack caused widespread shock when the hackers published children's personal data
-
Red Hat reveals unauthorized access to a GitLab instance where internal data was copiedNews Crimson Collective has claimed the attack, saying it has accessed more than 28,000 Red Hat repositories
-
Google warns executives are being targeted for extortion with leaked Oracle dataNews Extortion emails being sent to executives at large organisations appear to show evidence of a breach involving Oracle's E-Business Suite
-
Harrods rejects contact with hackers, after 430,000 customer records stolen from third-party providerNews The luxury department store has denied any link to a failed attack on its systems in May
-
Kido nursery hackers threaten to release more details – along with the personal data of 100 employeesNews The attack is the first to be claimed by the new threat group 'Radiant'
-
Air France and KLM confirm customer data stolen in third-party breachNews A spokesperson told ITPro the airlines are investigating "fraudulent access" to customer data following a third-party breach.
