Over the last decade, the collection of personal data has ramped up significantly, and our awareness of what is being given away is not always fully know.
General Data Protection Regulation (GDPR), which was announced in May 2018, aimed to strengthen data protection laws, keep businesses in check, and help keep threat actors from getting access to mishandled data.
The onus has been placed on businesses to keep the data they collect on us safe from harm; if they must collect and hold onto our information, then they should ensure it doesn’t fall into the wrong hands.
However, despite this tough stance, data protection authorities (DPAs) have issued fines totalling tens of millions of pounds for EU data breaches, as well as record fines from Britain’s Information Commissioner’s Office (ICO).
According to data from Atlas VPN, a record-breaking 5.9 billion accounts were affected by data breaches throughout 2021. The total count includes worldwide data breaches that took place from January 1st, 2021, to December 31st, 2021.
This article highlights some of the biggest data breaches that occurred last year, the impact they had across the tech landscape, and the importance of knowing more about how your data is handled.
Twitch – Unknown

Back in October, Twitch suffered a major data leak that included source code and sensitive information such as user pay-outs and the income of streamers.
An anonymous hacker claimed that 128GB of data was linked to a 4chan page hoping to ‘disrupt’ the online video streaming space and boosting ‘competition’ as the online streaming community is a “disgusting toxic cesspool”.
A Twitch spokesperson said that the company was working to fix the breach, adding: “We can confirm a breach has taken place. Our teams are working with urgency to understand the extent of this.”
Released documents revealed that some of the platform’s top streamers made millions of dollars from their content over the last two years.
Robinhood – 7 million

A threat actor supposedly gained access to US stock trading platform Robinhood’s systems after calling in to a Robinhood customer support employee and using social engineering to gain access to data.
Hackers stole the data of 7m app users, including 5m email addresses, the names of 2m people, dates of birth and postcodes of up to 300 people.
The company said that there didn’t appear to have been any financial loss for users at the time. The breach was quickly contained.
In a blog post, Robinhood said: “Late in the evening of November 3, we experienced a data security incident. An unauthorised third party obtained access to a limited amount of personal information for a portion of our customers.”
The company added: “After we contained the intrusion, the unauthorised party demanded an extortion payment. We promptly informed law enforcement and are continuing to investigate the incident with the help of Mandiant, a leading outside security firm.”
T-Mobile – 50 million

Telecoms giant T-Mobile suffered a major breach last year that released the personal information of 50m of its customers.
Hackers said they had started to sell the stolen information on the dark web. The data supposedly included phone numbers, names, physical addresses, and unique IMEI numbers.
According to Motherboard, the hacker claimed that they had obtained data of customers and that the data came from T-Mobile servers.
In a short statement to DIGIT, T-Mobile said: “We are aware of claims made in an underground forum and have been actively investigating their validity.”
That breach was not the first time that year that T-Mobile suffered a loss of private data.
In early December, the firm announced the possible breach of customer call records and potentially private information.
Android – 100+ million

In May, the personal data of more than 100m Android users was exposed due to misconfigurations of important cloud services.
Researchers from Check Point discovered anyone could access sensitive and personal information, including names, email addresses, dates of birth, chat messages, location, gender, passwords, photos, payment information, phone numbers and push notifications.
In addition, of the 23 analysed apps, around a dozen had more than 10m installations on Google Play. Most of them had the real-time database unprotected, exposing sensitive user information.
Socialarks – 214+ million

Safety Detectives researchers discovered a server belonging to social media management firm Socialarks that contained scrapped profiles of more than 214m social media users.
According to researchers, the exposed database had more than 408GB of data and more than 318m records. It also discovered 11.6m Instagram user profiles, 66m LinkedIn user profiles and 81.5m Facebook user profiles.
Around 55.3m Facebook profiles were supposedly deleted within a few hours after the server vulnerability was first discovered.
Exposed in the breach were names, countries of residence, workplaces, job roles, subscriber data and contact information as well as direct profile links.
Brazilian Database — 223 million

In January last year, Brazil suffered the largest personal data breach in its history.
The exposed databases, containing around 223m files, included names, unique tax identifiers, facial images, addresses, phone numbers, email, credit scores, salaries and more.
Additionally, the released information also contained the personal data of several deceased individuals as well as 104m vehicle records.
The data was offered for free on a dark net forum.
Facebook – 553 million

A massive data breach in April last year saw the valuable personal information from 533m Facebook users leaked online.
The leak included phone numbers, locations, birthdates, Facebook IDs, full names, and email addresses, according to Hudson Rock security researcher Alon Gal.
Hackers exploited a vulnerability that enabled them to see the phone number linked to every Facebook account.
The breach affected users from around 106 countries, including 11m in the UK. Amongst those affected was Facebook founder Mark Zuckerberg, whose phone number was leaked.
According to Gal: “A database of that size containing the private information such as phone numbers of a lot of Facebook’s users would certainly lead to bad actors taking advantage of the data to perform social-engineering attacks [or] hacking attempts.”
Given the sheer number of people affected, the data breach could be one of the largest ever recorded.
LinkedIn — 700 million

Data on around 700m LinkedIn users suddenly appeared for sale on a hacker forum in June last year, potentially affecting the 756m site users.
Online safety review site PrivacySharks said that a user of RaidForums made a post on June 22nd claiming to be in possession of the data. As proof, they provided a sample.
According to researchers the records included full names, genders, email addresses, phone numbers, and industry information.
The sample did not appear to contain financial information, such as banking or card details, or private messages, however. The data contained samples from 2020 and 2021.
LinkedIn issued a statement at the time stating that the data was not the result of an attack but a threat actor pulling data that was publicly available on a large scale.
Clubhouse and Facebook – 3.8 billion

A hacker announced they were selling a database containing information on a combined 3.8bn Clubhouse and Facebook users on a major hacker forum in September 2021.
The users previously had their phone numbers leaked and made available. However, the numbers alone were not considered valuable by cybercriminals and were eventually given away for free.
At the time, the database was being sold for $100,000 on a hacker forum. The information came with all entries from the two leaks, though smaller pieces are available for a discount.
COMB – 3.8 billion+

In February 2021 a compilation of previously breached user data was posted on an online hacking forum.
A .ZIP file, leaked onto RaidForums entitled “Compilation of Many Breaches (COMB) 3.8Billion (Public),” contained billions of usernames and passwords. It is believed to be the largest compilation of its kind in history.
Cybernews.com analysed the data and found that COMB contained more than 3.2bn unique pairs of email addresses and passwords, including approximately 200m Gmail addresses and 450m Yahoo! email addresses.
However, the data leak is not the result of a new breach, but a compilation of information collected from past data breaches involving a slew of major firms including Netflix, LinkedIn, Hotmail, and Bitcoin.
The COMB breach was so large that it potentially included the data of around 70% of internet users worldwide.
Data Protection Summit 2022 | Scotland’s Annual DP & Privacy Conference
The context of Data Privacy Day and the wider discussion around personal information will be areas of discussion at DIGIT’s 5th annual Data Protection Summit.
It will take place on 24th March at Dynamic Earth in Edinburgh, and streamed through our virtual conference platform.
The conference will contextualise the latest developments within the data protection field, with insight from frontline practitioners reflecting on key trends, challenges and best practice.
For more information, visit: https://www.dataprotection-summit.com/





