A comprehensive yearly recap by VPN services provider Surfshark revealed that 300 million user accounts were breached globally in 2023, with the UK landing a spot in the top 10 most breached countries with 3.3 million breached accounts.
“As we look back on 2023, there’s a positive trend in data breaches – a 20% decrease in affected accounts compared to 2022. Despite this improvement, 300 million users worldwide still experienced breaches,” said Agneska Sablovskaja, lead researcher at Surfshark.
The data, collected from 29,000 publicly available databases, was aggregated by email address and analysed statistically by Surfshark researchers
The report highlights significant shifts in breach trends, with the US experiencing a drastic increase in breaches, jumping from third place in 2022 to first place in 2023 with almost 100 million breached online accounts.
Q2 2023 witnessed the highest number of data breaches, totalling 134 million, an 80% increase compared to the yearly average. In contrast, Q3 2023 saw the fewest breaches, totalling 31 million.
LinkedIn emerged as one of the most affected platforms, with nearly 11.5 million emails leaked due to the scraping of publicly available information. Russian platforms Chitai-gorod, Book24, Gloria Jeans, and SberSpasibo followed closely, collectively exposing around 20 million Russian email accounts.
The breach landscape varied significantly across regions, with Europe experiencing the highest number of breaches in 2023, followed by North America and Asia. Europe saw a decrease in breaches from 160 million in 2022 to 116.6 million in 2023, with Russia accounting for 67% of the breaches. North America experienced a staggering 193% increase in breaches compared to the previous year, totalling 101.7 million.
Recommended reading
- Which Data Breaches Had Everyone Talking This Year?
- Change Your Password Day: A Password-less Approach
- New Survey Reveals UK T&L Has “Significant” Data and AI Gap
In response to data breaches, Surfshark recommends immediate actions for affected users, including changing passwords, enabling two-factor authentication, and scanning devices for malware. Users are also advised to remain vigilant for potential scams and to contact their bank if credit card information was compromised.
“Even a single account data leak can lead to unauthorised access, risking the misuse of personal information, potential identity or financial theft. Using the same passwords across multiple accounts can compromise others, so it’s crucial to use unique and strong passwords for different online services,” continued Sablovskaja.





