Top Data Breaches and Privacy Scandals of 2025 (So Far)

Martin Bastius
18.07.2025
999
min.

The first half of 2025 was marked by a significant rise in major data breaches. From 2025's genetic data leaks to massive social media data dumps — companies across a wide range of industries are struggling to keep personal data safe.

The reported incidents reveal a clear trend toward larger breaches involving increasingly sensitive categories of data. It is no longer just about usernames and passwords — genetic profiles, voice recordings, and biometric identifiers are being leaked. This data is not only extremely personal but also difficult or impossible to change once it has been compromised. Cybercriminals are primarily targeting systems with known but never-fixed vulnerabilities. These are often not sophisticated zero-day attacks but the exploitation of simple weaknesses and negligence: weak passwords, outdated software, or misconfigured cloud systems.

At the same time, regulators are getting stricter. Fines for GDPR violations are becoming ever more severe, and companies are under pressure to demonstrate genuine, continuous compliance.

Public awareness is rising as well. Users know their data rights better than ever, and even the smallest data breach in 2025 makes headlines immediately. Even minor leaks can result in a long-term loss of trust.

In the following article, you will find the most important data breaches of 2025 along with practical lessons companies can use to prevent similar incidents.

The Most Serious Data Breaches of 2025 at a Glance

1. 23andMe: Genetic Data Sold and Leaked

In 2023, DNA testing company 23andMe came under fire after hackers leaked and sold detailed genetic information along with identity data. The incident became public after excerpts of the stolen data were offered for sale on dark web forums. The data included names, contact details, genetic profiles, and ancestry information. According to reports, over seven million users were affected.

In March 2025 came the next negative headline, when 23andMe filed for bankruptcy. According to the company, the storage and management of personal data would not be affected by the insolvency. Nevertheless, 23andMe's privacy policy allows personal data to be shared with third parties — regardless of whether consent has been given.

Genetic data is considered particularly sensitive: it contains not only health information but also affects relatives who often never gave their consent. In the EU, such data falls under the "special categories of personal data" under the GDPR and may not be used by insurers or employers. Direct-to-consumer services like 23andMe, however, often operate in a legal gray area. Unlike medical providers, they are not subject to the same strict regulations. Particularly critical: one person's consent can compromise the privacy of their entire biological family.

23andMe's bankruptcy raises further questions about the storage, processing, and possible sale of this highly sensitive data — especially where strong legal safeguards are lacking.

2. Samsung: 270,000 Customer Records Leaked

In March 2025, Samsung fell victim to a data breach in which 270,000 customer records were stolen and published.

The leak included names, email addresses, phone numbers, order numbers, and product details (e.g., TV models) as well as customer complaints and Samsung's responses. The affected system belonged to Samsung Germany.

The attackers gained access using credentials that had been stolen back in 2021, after an employee of a Samsung partner was infected with malware. The malware harvested credentials from the affected person's device. Security firm Hudson Rock had alerted Samsung to the leaked credentials years earlier. Nevertheless, Samsung failed to rotate or secure the credentials. They remained active for years and ultimately enabled the successful attack in 2025.

Takeaway: Even very large companies often underestimate the danger posed by forgotten accounts and credentials. Size is no protection against negligence!

3. Amazon Echo: Removal of the Voice Data Opt-Out

On March 28, 2025, Amazon announced that it would remove the "Do not send voice recordings" setting for Echo devices that support on-device storage. From now on, all interactions with Alexa are recorded by default and sent to Amazon's servers. An opt-out option no longer exists. This change coincided with the launch of Alexa+, Amazon's new AI-powered assistant designed to enable context-aware conversations.

Amazon justifies this with Alexa+'s expanded capabilities, such as remembering past conversations, "smarter" answers, and more personalization. For users, however, this means they no longer have any control over whether their voice commands are uploaded to Amazon and analyzed. Consumer advocates and data protection organizations warn of new surveillance risks, especially since Alexa+ is meant to be even more deeply integrated into everyday life.

Critics see the removal of the opt-out option as an erosion of autonomy over one's own data. They are asking how long Amazon will store the voice data, what it will be used for in AI training, and whether it will be made available to third parties or advertising partners.

From a GDPR perspective, it is disputed whether this practice is lawful. 

The reason: if users cannot object to the data transfer while still using the product, consent is not "freely given, specific, informed, and unambiguous". That is the minimum for valid consent under the GDPR!

4. X (Twitter): 200 Million User Records Published

In March 2025, a hacker published a gigantic dataset containing 200 million X (formerly Twitter) accounts, including emails, handles, and IDs.

The root cause of the leak goes back to a vulnerability that had been reported to Twitter's bug bounty program as early as the beginning of 2022. It made it possible to match phone numbers or email addresses to Twitter accounts without verification. Although Twitter acknowledged the vulnerability and later had it fixed, it was already too late for a vast number of records: attackers had exploited the open flaw for mass data harvesting.

The result resurfaced in 2025 when a data researcher combined the old dataset with a newer network leak and published it as a single data dump.

Social networks in particular are in attackers' crosshairs because identity fraud, phishing, and social engineering are easy here and the data trove is enormous. The main lesson: if vulnerabilities are not closed immediately and consistently, data breaches affecting millions are inevitable!

Recommendation: Secure APIs just as well as websites or apps! Rate limiting, validation, authentication, and regular testing are a must. Bug bounty reports must always be taken seriously and addressed immediately.

5. Coinbase: Data Breach Through Bribed Support Staff

In May 2025, crypto exchange Coinbase disclosed a significant data incident. Attackers bribed outsourced support staff to gain access to internal systems and sensitive customer data. Around 510,000 customers were affected.

Stolen data included names, postal and email addresses, phone numbers, the last four digits of Social Security numbers, masked bank account numbers, bank IDs, ID documents (e.g., driver's licenses, passports), account balances, and transaction histories. Internal company documents were also exfiltrated.

The attackers demanded a $20 million ransom in exchange for not publishing the data. Coinbase refused to pay and instead offered a $20 million reward for information. The company estimates the total cost of the incident at $180 to $400 million for remediation and compensation.

Root cause: access via outsourced support roles carries massive risks. Vetting and monitoring third parties, especially when they have access to sensitive data, is essential.

6. Dior: Data Breach in China via a Third-Party Provider

In May 2025, Dior had to disclose a data breach involving Chinese customer data and issue an apology.

Affected were personal details such as names, contact information, and purchase histories of customers who had used Dior services in China. The incident was caused by an external service provider that disregarded the agreed data protection protocols — allowing the data to reach unauthorized third parties.

After the breach came to light, Dior immediately launched an internal investigation and tightened its security requirements for external partners.

Takeaway: All third-party data access should be strictly controlled and regularly audited.

7. TikTok: €530 Million Fine for Data Transfers to China

In May 2025, TikTok was hit by the Irish data protection authority with a record fine of €530 million for unlawfully transferring the personal data of around 1.1 million EU users — including many minors — to servers in China. The transferred data included names, contact information, behavioral data, and device identifiers.

The authorities particularly criticized the fact that between 2020 and 2022, TikTok failed to inform users that their data was being transferred to China. The transfer violated the GDPR's transparency requirements, and because China's surveillance laws allow far-reaching government access, storing data there was considered especially risky.

Key learning: Companies must clearly document and assess data transfers to third countries and communicate them openly and honestly.

8. Hertz: Data Breach via the Cleo File-Sharing Service

In early 2025, Hertz reported a data breach caused by a vulnerability at third-party provider Cleo, a file-sharing service.

From October to December 2024, information such as names, contact details, dates of birth, driver's license numbers, credit card details, and in individual cases Social Security numbers, passport information, and disability insurance details was siphoned off — over 100,000 customers worldwide were affected across the US, Canada, the EU, the UK, and Australia.

Once again it shows: careful vetting and control of the security standards of third-party tools is an obligation, not a nice-to-have!

9. Facebook: 1.2 Billion Records Allegedly Leaked

In May 2025, a hacker claimed to have scraped 1.2 billion Facebook accounts via an API. The leak allegedly contained user IDs, names, email addresses, usernames, phone numbers, locations, birthdays, and gender.

Security researchers at Cybernews verified several of the records but could not confirm that all 1.2 billion entries are actually new — Facebook considers them in part a recycled old leak.

Should the incident be confirmed, it would be one of the largest scraping incidents in Facebook's history.

10. 184 Million Records: Microsoft, Apple, Google & PayPal Affected

In May 2025, a security researcher discovered an exposed Elasticsearch database with over 184 million entries: from Microsoft, Apple, Google, Facebook, PayPal, and Netflix accounts to government and corporate data from at least 29 countries. The database was not protected by a password or encryption.

It also contained credentials for bank accounts, health platforms, and government websites — the risk of identity theft was immense. The data presumably originated from infostealer malware.

Warning: Credential collections like these are pure gold for cybercriminals and massively increase the risk of chain reactions in attacks on partner companies.

11. Meta: €200 Million Fine for Its "Consent or Pay" Model

In April 2025, the EU imposed a €200 million fine on Meta over its "consent or pay" model on Facebook and Instagram. Users had to either consent to broad processing of their data (including personalized advertising) or purchase a subscription that excludes tracking. The Commission found that this offered no "genuine" freedom of choice, which contradicts the GDPR.

Bottom line: voluntariness, transparency, and real choices are core principles of data protection — anyone who confronts users with a "consent or pay" choice risks fines and a loss of trust.

See also: EU Fines Apple and Meta Millions — A Signal to All Digital Companies

12. Apple: €500 Million Fine over App Store Restrictions

Also in April 2025, Apple was fined half a billion euros by the EU. The reason: developers had no way to point customers to cheaper alternatives outside the App Store — which stifled competition, limited user choice, and violated the Digital Markets Act (DMA).

Remember: dominant platforms are under special scrutiny and must create fair conditions. Walled gardens and a lack of transparency lead to enormous damage, both financial and reputational.

__wf_reserved_inherit
Timeline of the 2025 data breaches

The 5 Most Important Lessons for Companies from the 2025 Data Breaches

The first half of 2025 shows: the same well-known mistakes are being repeated everywhere. The key takeaways for companies — regardless of size or industry — are:

1. Third-party risk is underestimated:
Cases like Dior, Coinbase, Hertz, and Samsung all began with external partners. Never forget: every service provider expands your attack surface. Many companies fail to vet their partners or set standards that are too low.

Action: Conduct strict due diligence, secure data protection clauses in your contracts, and carry out regular security audits. Enforce least-privilege access rights. With heyData's Vendor Risk Management Tool, you can find GDPR-compliant vendors.

2. Long-known vulnerabilities stay open:
Outdated credentials at Samsung and a known API flaw at X show that many leaks trace back to age-old problems — usually because they are ignored.

Action: Implement consistent vulnerability management, document all reports, and fix them quickly. Rotate credentials regularly.

3. Data minimization remains theory:
The danger grows with the volume of sensitive data — from genetics to passport photos and account details. Those who store everything will eventually lose everything.

Action: Collect and store only what is strictly necessary for your service. Regularly review your data holdings, delete what is superfluous, and pseudonymize as much as possible.

4. Consent is missing or manipulated:
Amazon and TikTok deliberately bypass user rights — which causes not only legal damage but, above all, damage to trust.

Action: Stay true to the spirit of the GDPR: consent must be freely given, informed, specific, and unambiguous. Be open about changes and offer genuine choices.

5. The cost of mistakes is rising:
TikTok is paying €530 million, Coinbase expects up to $400 million in damages — data breaches threaten livelihoods, trust, and market share.

Action: Data protection is a top management issue, not a checkbox. Invest continuously in security, training, and compliance — not just when audits come around!

__wf_reserved_inherit
Common causes of data breaches (2025)

__wf_reserved_inherit
Distribution of compromised data types (2025)

Conclusion

The data breaches of 2025 reveal no new attack methods but reaffirm the old truths: security, third-party control, transparency, and immediate action are non-negotiable. Anyone still waiting risks everything — from fines to lasting reputational damage.

Does your company process personal data? Then now is the time to put all your processes, policies, and systems to the test.

Use the real-world examples from this article to systematically identify weaknesses and eliminate them. If you need help, heyData's All-in-One Compliance Solution offers intuitive tools plus legal expertise for data protection, cybersecurity, and AI compliance.

FAQ

What is a data breach?

A data breach (data leak) is the unauthorized retrieval, copying, disclosure, or theft of personal data — often through hacker attacks or misconduct by employees and service providers.

What were the biggest data leaks in 2025?

The most prominent incidents affected companies such as 23andMe (genetic data), Samsung, Coinbase, Facebook, TikTok, Meta, Apple, and Amazon.

What penalties do companies face for serious data protection violations?

Violations of the GDPR can be punished with fines in the millions (e.g., €530 million for TikTok, €500 million for Apple).

How can companies protect themselves against data breaches?

Key measures include: choosing secure service providers, regular IT security updates, data minimization, clearly defined access rights, and comprehensive employee awareness training.

What are the consequences for those affected?

Risks include identity theft, fraud, personal harm, and loss of control over one's own data. Trust in the company often suffers lasting damage.

What should you do in the event of a data leak?

Immediately inform the supervisory authority, notify affected individuals quickly and transparently, fix the cause, and prevent renewed risks.

Published
18.07.2025
Martin Bastius
Co-Founder & CLO

More articles

View all articles
Data Protection & GDPR
4/3/24

Secure Handling of Ex-Employee Emails Under GDPR

Secure Handling of Ex-Employee Emails Under GDPR
AI & Data Governance
7/11/25

Balancing Trust and Control: How to Make AI-Recorded Online Meetings GDPR-Compliant

Balancing Trust and Control: How to Make AI-Recorded Online Meetings GDPR-Compliant
AI & Data Governance
6/12/26

Whistleblower System for SMBs: What You Need to Know About Whistleblower Protection

Whistleblower System for SMBs: What You Need to Know About Whistleblower Protection
Discover all stories