A breach notice says your data “may have been exposed” and lists a few field names. It does not say whether those fields matter, how the breach compares with a typical one, or how long the news took to reach you.
We pulled the full public Have I Been Pwned breach list, 1,036 entries, and classified each of the 1,009 genuine breaches by what leaked, how many records, when it happened, when it surfaced, and how passwords were stored. Email addresses leak in 99.3% of them, passwords in 65.7%, and an unchangeable identity number in 4.7%. The median breach took 135 days to surface.
Snapshot: September 15, 2026, from the Have I Been Pwned public breach API (CC BY 4.0). Method at the end.
Key Findings
- Email addresses appear in 99.3% of the 1,009 genuine breaches in the corpus; passwords appear in 65.7%, names in 53.5%, phone numbers in 36.4% and dates of birth in 27.5%.
- Only 32.1% of breaches (324 of 1,009) expose nothing beyond an email address and a password, plus non-identity extras such as usernames or IP addresses.
- The identity triad of name, date of birth and physical address leaks together in 11.8% of breaches (119), and an unchangeable identity number (government ID, passport, national ID, tax ID, driver’s licence or bank account) in 4.7% (47).
- Across all 1,009 breaches, the median gap between the breach date and its appearance in Have I Been Pwned is 135 days; 35% took more than a year and 16% more than three years.
- That lag has collapsed: breaches from 2011 took a median 1,926 days to surface, breaches from 2016 took 263, and breaches from 2026 have so far taken 14.
- The 1,009 genuine breaches hold 15.5 billion records, but the top 10 breaches account for 43.1% of them and the top 50 for 74.2%; the median breach has 918,529 records.
- Of the 663 breaches that exposed passwords, 36% describe MD5 hashing, 16% plain text storage and 19% bcrypt, all lower bounds because they rely on description text.
Key Takeaway
Most breaches leak an email address and a password, not an identity: fewer than one in twenty of the 1,009 breaches in this corpus exposed an unchangeable identity number, and the median breach now surfaces within weeks rather than years.
Email Addresses Leak in Almost Every Breach
Have I Been Pwned tags every breach with the data classes it contained. Table 1 counts those tags across the 1,009 genuine breaches; two classes tie for fifteenth place, so it runs to sixteen rows.
| Rank | Data class | Breaches | Share of 1,009 |
|---|---|---|---|
| 1 | Email addresses | 1,002 | 99.3% |
| 2 | Passwords | 663 | 65.7% |
| 3 | Names | 540 | 53.5% |
| 4 | Usernames | 483 | 47.9% |
| 5 | IP addresses | 380 | 37.7% |
| 6 | Phone numbers | 367 | 36.4% |
| 7 | Physical addresses | 293 | 29.0% |
| 8 | Dates of birth | 277 | 27.5% |
| 9 | Genders | 187 | 18.5% |
| 10 | Geographic locations | 145 | 14.4% |
| 11 | Purchases | 86 | 8.5% |
| 12 | Website activity | 76 | 7.5% |
| 13 | Social media profiles | 49 | 4.9% |
| 14 | Job titles | 45 | 4.5% |
| 15 | Private messages | 39 | 3.9% |
| 15 | Partial credit card data | 39 | 3.9% |
Email is close to universal, passwords appear in two thirds of breaches, names in half, and only eight classes appear in more than a quarter.
The 99.3% is partly a selection effect, since HIBP indexes by email and rarely loads a dataset without one. It is also why the email address matters most: it links one breach to the next, and it is where phishing and password resets land.
One Third of Breaches Are Only a Password Problem
We grouped breaches by what they let someone do. The simplest group is 324 breaches, 32.1% of the corpus, that contain email addresses and passwords and nothing identifying beyond that. This is a leaked password problem: change the password everywhere it was reused and the exposure is mostly closed.
Identity fields cluster. Email and password appear together in 659 breaches (65.3%), name and physical address in 282 (27.9%), name and date of birth in 206 (20.4%). The identity triad of name, date of birth and physical address, the three facts a call centre asks for before it will talk to you, appears in 119 breaches (11.8%). Add a phone number and the count is 108 (10.7%); add a password and it is 46 (4.6%). Someone holding the triad can impersonate you on the phone to a bank or telecom, so the fix is account-level: PINs, verbal passwords, transaction alerts.
The group people fear is small: 47 breaches (4.7%) exposed an unchangeable identity number. A password can be rotated and a card reissued, but a leaked SIN, passport number or driver’s licence stays valid for years, which is what justifies a fraud alert with the credit bureaus.
Unchangeable Identity Numbers Appear in 4.7% of Breaches
Table 2 breaks the 4.7% down by HIBP’s own labels. The classes overlap (a breach can carry both passport and government ID tags), so the rows do not sum to 47.
| Data class | Breaches | Share of 1,009 |
|---|---|---|
| Partial credit card data | 39 | 3.9% |
| Government issued IDs | 27 | 2.7% |
| Bank account numbers | 12 | 1.2% |
| Passport numbers | 11 | 1.1% |
| Credit cards (full) | 7 | 0.7% |
| Social security numbers | 7 | 0.7% |
Partial card data, usually the last four digits and the expiry, is more than five times as common as full card numbers.
Partial data is useful to a scammer mainly as a prop (“the card ending in 4412”) rather than as a way to spend your money. Full numbers appear in 0.7%; our guide to a leaked credit card covers what to do then.
See what your combination enables
The field sets from the largest breaches in this corpus, including Canadian Tire, Bell and Canada Goose, are preloaded in the free NotchUp data breach risk checker. Pick your breach, or tick what your notice listed, and see what that mix lets someone do.
The Median Breach Took 135 Days to Surface
The gap between HIBP’s breach date and added date is a usable proxy for how long stolen data circulated before the public could check for it. Across all 1,009 breaches the median lag is 135 days and the mean 486; the quartiles are 19 and 620 days. Only 44% were added within 90 days, 35% took more than a year and 16% more than three years.
Table 3, grouped by the year the breach happened, shows a steep trend.
| Breach year | Breaches | Median lag (days) | Added within 90 days |
|---|---|---|---|
| 2010 | 4 | 1,918 | 0% |
| 2011 | 18 | 1,926 | 0% |
| 2012 | 20 | 1,632 | 0% |
| 2013 | 31 | 1,159 | 10% |
| 2014 | 49 | 451 | 35% |
| 2015 | 73 | 300 | 26% |
| 2016 | 99 | 263 | 29% |
| 2017 | 51 | 218 | 41% |
| 2018 | 76 | 168 | 46% |
| 2019 | 80 | 168 | 39% |
| 2020 | 96 | 166 | 35% |
| 2021 | 78 | 162 | 40% |
| 2022 | 61 | 275 | 38% |
| 2023 | 44 | 40 | 64% |
| 2024 | 83 | 23 | 69% |
| 2025 | 58 | 34 | 74% |
| 2026 (to Sept 15) | 82 | 14 | 95% |
Breaches from 2011 took a median 1,926 days, over five years, to surface; breaches from 2016 took 263, from 2020 166, from 2023 40, and from 2026 so far 14, with 95% added within 90 days.
HIBP launched in late 2013, so older breaches were loaded retroactively; disclosure law and faster sharing of breach data with researchers probably account for the rest. The recent rows are censored: a 2025 breach that has not surfaced yet is not in the data, so the 2024 to 2026 medians count only the fast ones and will rise as slow breaches trickle in. Treat them as floors.
The slow tail is long. RuneScape Boards was breached in December 2011 and added to HIBP in March 2026, 14.2 years later. China Software Developer Network took 13.9 years and DivX SubTitles 12.5. The eight longest lags in the corpus all exceed a decade. If you get a notice about a service you barely remember, that is why; our guide to whether a breach email is real covers how to check it.
Most Records Sit in a Few Breaches
The 1,009 genuine breaches hold 15,511,357,434 records. That is records, not people: one person with accounts at three breached services is at least three records. The mean breach is 15.4 million records but the median is 918,529, and 151 breaches (15%) have fewer than 100,000. The top 10 breaches hold 43.1% of all records and the top 50, about 5% of the corpus, hold 74.2%.
By year of breach, 2019 is the peak at 3.54 billion records across 80 breaches, followed by 2025 at 2.25 billion across 58. So far 2026 has 82 breaches, well ahead of 2025’s 58, but only 238 million records: the year’s big one has not landed, or has not surfaced.
Headline record counts are a poor guide to personal risk. A 500 million record breach of email addresses and hashed passwords is a nuisance for each person in it; an 18,850 record breach of a school district is a different kind of problem for those families, and would never make national news.
Weak Hashing Is Mentioned Three Times as Often as bcrypt
We searched HIBP’s descriptions of the 663 password breaches for the common storage terms. MD5 is mentioned in 236 (36%), plain text in 108 (16%), bcrypt in 123 (19%), SHA-1 in 39 (6%) and the word unsalted in 49 (7%). Each is a lower bound, since a description that omits the method counts as none of the above.
Plain text, MD5 and SHA-1 (the last two fast enough to crack at scale) together outnumber bcrypt, the slow hash that resists cracking, by roughly three to one. The practical point is reuse. A password stored in MD5 in one breach and reused on your bank is effectively a plain text bank password. A unique password per site makes the storage method someone else’s problem.
Nine Canadian Entries Hold About 43 Million Records
Nine entries in the corpus are Canadian by our rule (a .ca domain, or a Canadian company on another domain). Table 4 lists them, largest first.
| Organisation | Breach date | Records | Notable fields |
|---|---|---|---|
| Canadian Tire | Oct 2, 2025 | 38,306,562 | Date of birth, name, address, phone, partial card, password |
| Bell (2017) | May 15, 2017 | 2,231,256 | Name, phone, job title, password, IP address |
| Shopper+ | Sept 14, 2020 | 878,290 | Date of birth, name, address, phone, gender |
| Canada Goose | Jul 4, 2025 | 581,877 | Name, address, phone, partial card, purchases, device info |
| Golf Canada | May 14, 2026 | 568,972 | Date of birth, name, gender, location, username |
| Canada Life | Apr 20, 2026 | 237,810 | Name, address, phone, job title, support tickets |
| Fair Vote Canada | Mar 2, 2024 | 134,336 | Name, address, phone, political donations |
| Bell (2014) | Feb 1, 2014 | 20,902 | Full credit cards, password, username |
| School District 42 (BC) | Jan 15, 2023 | 18,850 | Name, email |
Canadian Tire alone is 38.3 million of the roughly 43 million records across the nine.
It also pairs the identity triad with a password, a combination found in only 46 breaches in the whole corpus. Shopper+ and Golf Canada pair dates of birth with names, and the 2014 Bell breach is one of just seven in the corpus with full card numbers.
Nine out of 1,009 is under 1%. A Canadian’s exposure is far more likely to sit in one of the large global breaches than in a domestic one. Our running list of Canadian data breaches tracks the domestic ones as they surface.
Methodology
- Source: the Have I Been Pwned public breach list at https://haveibeenpwned.com/api/v3/breaches, retrieved September 15, 2026, licensed CC BY 4.0; 1,036 entries at snapshot time. We removed 3 entries flagged fabricated, 16 spam lists, 6 stealer logs and 2 retired; the remaining 1,009 are what we call genuine breaches. Of those, 969 are flagged verified and 91 sensitive (not publicly searchable by email).
- Record counts are HIBP’s PwnCount field, summed across breaches without deduplication. Data classes are HIBP’s own labels, unaltered; class counts are per breach, not weighted by records.
- “Only email and password” means email addresses and passwords with no identifying class (names, dates of birth, physical addresses, phone numbers, or any identity or financial class). Usernames, IP addresses and similar were permitted.
- “Unchangeable identity number” means any of: government issued IDs, passport numbers, social security numbers or national ID equivalents, tax identifiers, driver’s licences, bank account numbers.
- Disclosure lag is AddedDate minus BreachDate, in days. BreachDate is sometimes an estimate (several are set to January 1), which adds noise to individual lags but little to medians. Password storage figures are case-insensitive keyword counts over the Description field of the 663 password breaches.
- Canadian selection: a breach domain ending in .ca, or a Canadian company on another domain (Canada Goose, Canada Life). Some Canadian services will have been missed under this rule; the list is notable entries, not an exhaustive one.
Frequently Asked Questions
What data is most commonly leaked in a data breach?
Email addresses, by a wide margin. Across 1,009 genuine breaches in the Have I Been Pwned corpus as of September 15, 2026, email addresses appear in 99.3%, passwords in 65.7%, names in 53.5%, usernames in 47.9%, IP addresses in 37.7% and phone numbers in 36.4%. Physical addresses (29.0%) and dates of birth (27.5%) are the only other classes in more than a quarter of breaches.
How often do data breaches include government ID or SIN numbers?
Rarely: 47 of 1,009 breaches (4.7%) exposed any unchangeable identity number. Within that, 27 (2.7%) carried government issued IDs, 12 (1.2%) bank account numbers, 11 (1.1%) passport numbers and 7 (0.7%) social security or national ID numbers. The identity triad of name, date of birth and address, which enables impersonation without any ID number, is more common at 11.8%.
How long does it take for a data breach to be discovered?
Measured as the gap between the breach date and its appearance in Have I Been Pwned, the median across all 1,009 breaches is 135 days, and 35% took more than a year. The year matters: breaches from 2016 took a median 263 days to surface, from 2024 23 days, and from 2026 so far 14.
Which Canadian companies are in the Have I Been Pwned database?
Notable Canadian entries as of September 15, 2026 are Canadian Tire (38,306,562 records, October 2025), Bell (2,231,256 in 2017 and 20,902 in 2014), Shopper+ (878,290, September 2020), Canada Goose (581,877, July 2025), Golf Canada (568,972, May 2026), Canada Life (237,810, April 2026), Fair Vote Canada (134,336, March 2024) and School District 42 in BC (18,850, January 2023). Most Canadians’ exposure comes from the large global breaches rather than from these.
Does a large breach mean a higher personal risk?
Not by itself. Record counts measure how many people were affected, not how badly: the top 10 breaches hold 43.1% of the 15.5 billion records in the corpus. A small breach with your name, date of birth, address and an ID number is a bigger personal problem than a huge one with your email and a hashed password.
How to Cite
NotchUp Research, What Leaks in a Data Breach (September 2026), https://notchup.app/learn/what-leaks-in-a-data-breach/, based on Have I Been Pwned data, CC BY 4.0.
Related Reading
- Canadian data breaches: the running list
- Your password was leaked: what to do
- Your SIN was leaked: what to do
- Your credit card was leaked: what to do
- Is this data breach email real?
Knowing what usually leaks is not the same as knowing what leaked about you. You can check your own email address against these 1,009 breaches free, with no account, at NotchUp Shield, and be told when the next one lands.
Breach data from Have I Been Pwned, licensed CC BY 4.0.





