EFF presents: The Breachies 2025- The Worst, Weirdest, Most Impactful Data Breaches of the Year

I created a table from their page, but here is the source!

Award NameRecipientBreach DetailsDate
Say Something Without Saying AnythingMixpanelAnalytics SDK used by apps like Ring and PornHub; breached user data from many apps (exact scope unclear); OpenAI dropped them. effNovember 2025
We Still Told You SoDiscordAge verification data via Zendesk (third-party support): names, selfies, IDs, emails, addresses, phone numbers, IP addresses, billing info; 200M+ users affected. effSeptember 2025
Tea for TwoTea Dating Advice and TeaOnHerTea: 72K images (IDs/selfies), 1.1M private messages (phones, abortion/cheating discussions). TeaOnHer: emails, usernames, IDs/selfies publicly exposed. effJuly-August 2025
Just Stop Using Tracking TechBlue Shield of CaliforniaMisconfigured Google Analytics shared 4.7M health records (names, plans, providers, finances) for ~3 years, possibly for ads. effApril 2025 (disclosed)
Hacker’s Hall PassPowerSchool60M+ students/teachers’ data (SSNs, medical records, grades); weak support portal security; lawsuits filed. effDecember 2024
Worst. Customer. Service. Ever.TransUnion4.4M customers’ names, DOBs, SSNs via third-party support app. effAugust 2025
Annual Microsoft Screwed Up AgainMicrosoftSharePoint zero-day exploited by Chinese groups; 400+ orgs (incl. nuclear agency); thousands of vulnerable servers lingered. effJuly 2025
I Didn’t Even Know You Had My InformationGravy AnalyticsMillions’ location history (coords tied to ad IDs) from 1B phones/day via apps; sold to brokers/govt; revealed military/gay users in risky areas. effJanuary 2025
Keeping Up With My CybertruckTeslamate1,300+ self-hosted dashboards exposed Tesla locations, speeds, charging, trips. effAugust 2025
Disorder in the CourtsPACERFederal court system (CM/ECF) hacked; possible exposure of confidential informants; outdated/unsustainable tech. effAugust 2025
Only Stalkers AllowedCatwatchfulStalkerware data: 26K victims’ photos, messages, locations + customer emails/passwords. effJuly 2025
Why We’re Still Stuck on Unique PasswordsPlexEmails, usernames, hashed passwords (repeat from 2022 affecting 15M users). eff2025 (recent)
Uh, Yes, Actually, I Have Been PwnedTroy Hunt’s Mailing ListPhishing via Mailchimp stole blog mailing list credentials. eff2025
Silver GlobeFlat Earth Sun, Moon & ZodiacUser gender, names, emails, DOB, location (lat/long). effMarch 2025 (confirmed)

Discover more from Erkan's Field Diary

Subscribe to get the latest posts sent to your email.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.