Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityAccess ManagementIdentity ManagementCybersecurity News

A Look Back at the Most Prominent Data Breaches in 2019

By Craig Lurey
Coding data breach
December 27, 2019

While there is still time left in 2019, according to the recent Data Breach QuickView Report, there were 5,183 breaches reported just in the first nine months of 2019 exposing 7.9 billion records. Compared to Q3 2018, the total number of breaches was up 33.3% and the total number of records exposed more than doubled, up 112%. Per the report, hacking remains the top breach type for a number of incidents while Web has exposed the most records this year.

No two data breaches are exactly the same, but most occur due to a lack of a select group of missteps. These include: falling victim to phishing attacks, not installing software updates, general poor cybersecurity practices such as weak user name/password combinations, not training employees, falling victim to malware, and even inadvertently creating the breach by accidentally publishing or uploading records that ought to be kept secure.

The 2019 data breach numbers are daunting – and 2019 is possibly the worst year we had, in terms of data breaches. The sheer number of exposed records is astounding (up by 33% from last year). As a cautionary tale heading into 2020, here are some of the top publicly known data breaches from this year.

Facebook

Date: Two breaches in April and the third one in September - all disclosed by a third party. 

Type: Two breaches were bad security, the other was an accidental upload.

What happened: After spending 2018 answering for its Cambridge Analytica data scandal, the company seemingly has kept its head down over this year’s rolling series of data breaches.

The list begins with Facebook. Not because it suffered the largest exposure of records in any one breach, but because the social media giant allowed three disclosed data breaches in 2019. In April it was revealed Facebook harvested email contacts from 1.5 million users without their knowledge or consent when they opened their accounts. The privacy and security issue was discovered by a security researcher looking to a Facebook sign-up step that asked for users’ email passwords. It would then use those passwords to automatically harvest contacts from new users.

Before the privacy issue came to light, it was reported Facebook exposed the passwords of 540 million users by storing those records in a readable format internally. The plaintext passwords had been searchable by Facebook employees dating back to 2012 with the passwords viewable by up to 20,000 Facebook employees. In September another similar breach was uncovered with as many as 419 million user records found on an unprotected server.

First American Corp.

Date: May 2019 (disclosed by third-party)

Type: bad security

What happened: While Facebook’s data breaches were basically contained internally, real estate and title insurance company First American outdid Facebook in both volume and exposure. In May it was reported that 885 million sensitive customer financial records including social security numbers, driver’s license images, bank account numbers and statements, wire transaction receipts, and mortgage and tax documents dating back to 2013 were left available on the First American website for anyone to view.

Post-exposure of its lax cybersecurity practices, First American created a dedicated landing page for information about the breach and resulting investigation.

Capital One

Date: July 19, 2019

Type: hack

What happened: Data breaches around gaming companies and social media networks are concerning, but for consumers when breaches hit major banks, the news is chilling. In March a hacker gained access to the Capital One data because of a misconfigured web application firewall and as a result, the bank had 106 million customer accounts and credit applications stolen. The breach included 140,000 Social Security numbers, 1 million Canadian Social Insurance numbers and 80,000 bank account numbers along with customer names, addresses, credit scores, credit limits, account balances, and other data.

Capital One fixed the issue and began working with federal law enforcement leading to the capture of the hacker by the FBI. It’s believed the data was recovered and never used for fraud or shared by the hacker.

Zynga

Date: September 12, 2019 (disclosed)

Type: hack

What happened: In September Zynga fell victim to a hacker attack that got away with 218 million records of the players of popular mobile games Words with Friends and Draw Something. Data fields impacted in the breach included players’ names, email addresses, login IDs, hashed passwords, password reset tokens, phone numbers, Facebook IDs and Zynga account IDs.

When announcing the breach, Zynga said it was taking steps to protect users’ accounts from invalid logins and had plans to further notify players as the investigation proceeded.

Canava

Date: May 24, 2019

Type: hack

What happened: In May it was reported that Canava, an Australian online web-design service, had data about 139 million users hacked. The record fields stolen in the hack included real names, usernames, email addresses and city and country information. Dates of birth and street addresses weren’t part of the hack, and to Canava’s credit, it had salted and hashed email passwords protecting those records from the cybercriminal.

Since the incident, Canava notified users of the hack, worked closely with cybersecurity consultants and introduced internal data protection changes.

No two data breaches are exactly the same and there’s no magic bullet to avoid becoming victim to cybercriminals. Some breaches are the result of bad luck or a determined bad actor, others are due to cybersecurity negligence or falling victim to social engineering, and others – such as Facebook’s two announced breaches this year – are completely self-created and self-owned.

There are steps and best practices every company should take to mitigate the risk of suffering a data breach resulting in a financial loss as well as a public relations hit. The first step is to regularly educate employees on security practices and ways they can avoid social engineering attacks. Employ and enforce strong login credentials and multi-factor authentication across all employee devices, and finally conduct regular security audits as well as encrypt business data. These best practices used in concert will go a long way in thwarting cybercriminals.

KEYWORDS: cyber security cybercrime cybersecurity data breach

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Craig lurey
Craig Lurey is CTO and Co-Founder of Keeper Security, Inc.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Cargo ship sailing

You Can’t Secure a Ship Like a Laptop

Glasses in front of coding on screen

The Good Hackers Security Leaders Can’t Afford to Ignore

2026 Women in Security

Security’s 2026 Women in Security

Denise Platon. Image courtesy of Platon

Denise Platon — Women in Security 2026

Women in Security: Julia Stuyt

Julia Stuyt — Women in Security 2026

Kaseware sponsored webinar
Schneider Electric sponsored webinar

Events

August 19, 2026

From Investigative Question to Defensible Answer: AI in Digital Forensics and Incident Response

LIVE: August 19, 2026 at 2 PM EDT We'll examine where AI can deliver meaningful value, where incomplete context or black-box reasoning can introduce risk, and what governance, validation, and evidence-traceability controls organizations should establish.

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Outsourcing Data: Don't Take a Fairytale Approach

    40 Million Americans Affected by Health Data Breaches in 2019

    See More
  • cyber-security--data-freepik

    Data breaches in the first half of 2021 exposed 18.8 billion records

    See More
  • Healthcare Top Sector for Data Breaches in First Half 2015

    See More

Related Products

See More Products
  • Physical Security and Safety: A Field Guide for the Practitioner

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing