The Most Expensive Data Breaches

A new study from Surfshark applies IBM's "Cost of a Data Breach" calculations to the largest data breaches in recent history in order to find the estimated cost of today's biggest data breaches.

What they found is that the Dark Web is currently the place to buy stolen data.

When hackers lifted 162 million personal records from Dubsmash in 2019, the databases soon showed up for sale for $1,976 in Bitcoin. The most likely buyers were phishers and spammers.

But like many thefts, the resale value is only small  in comparison to the costs incurred by the victims. A hacker just needs to know your email address and that you’re a customer of, say, a bank or financial services to begin impersonating your identity.

  • The biggest data breach of the past two years was the Advanced Info Service (AIS) hack, which may have cost $58m million to resolve.
  • America’s biggest data breach of the 2020s so far was at ‘big data’ analysis firm BlueKai, where two billion records were exposed at a potential cost of $13.94bn.
  • The Microsoft leak in December 2019 may have cost as much as $1,742,500,000 to rectify.

According to IBM, businesses face four substantial bills in the aftermath of a data hack:

  • Detection and escalation: Including investigations and crisis management.
  • Notification: Communicating with customers, regulators, and lawyers.
  • Lost business: Downtime, dropped stock prices, lost customers, and damaged reputation.
  • Post-breach response: Restoring and improving security, legal expenses, fines, and compensation.

Surfshark

You Might Also Read: 

Cybercrime’s Deadly Impact On Business:

 

« UK Warns Of Russian Cyber Attacks
Digital Advertising Fraud Will Cost $68 Billion »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Infosecurity Europe, 3-5 June 2025, ExCel London

Infosecurity Europe, 3-5 June 2025, ExCel London

This year, Infosecurity Europe marks 30 years of bringing the global cybersecurity community together to further our joint mission of Building a Safer Cyber World.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Cloud Security Alliance (CSA)

Cloud Security Alliance (CSA)

The CSA is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing

Cross Identity

Cross Identity

Cross Identity (formerly Ilantus Technologies) is a complete IAM solution that is deep, comprehensive, and can be implemented even by non-IT persons.

Exida

Exida

Exida is a leading product certification and knowledge company specializing in industrial automation system safety, security, and availability.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Digital Arts

Digital Arts

Digital Arts provides internet security software and appliance products for companies and individuals.

ICTSecurity Portal

ICTSecurity Portal

The ICTSecurity Portal is an interministerial initiative in cooperation with the Austrian economy and acts as a central internet portal for topics related to security in the digital world.

OCM Business Systems

OCM Business Systems

OCM are experts in the safe, secure and responsible disposal of IT & EPoS assets.

Onsist

Onsist

Onsist brand protection services provide proactive defense against fraudulent use of your brand online.

Finosec

Finosec

Finosec's mission is to change the way information security and cybersecurity are managed in banking.

SystemExperts

SystemExperts

SystemExperts is a premier provider of IT compliance and cyber security consulting services.

NARIS

NARIS

NARIS is the leading provider of an integrated Governance, Risk and Compliance platform called NARIS GRC.

HackEDU

HackEDU

HackEDU provides secure coding training to companies ranging from startups to the Fortune 500.

Defentry

Defentry

Defentry have created an Ecosystem that lets our users easily monitor, train and resolve their digital security issues.

CampusGuard

CampusGuard

CampusGuard focuses on the cybersecurity and compliance needs of campus-based organizations including higher education, healthcare, and state and local government.

Access Talent Today

Access Talent Today

Access Talent Today is an AI/ML and cyber security talent provider.

Kali Linux

Kali Linux

Kali Linux is an open-source, Debian-based Linux distribution geared towards various information security tasks, such as Penetration Testing.