The dataset
All 108 records, covering 2016–2026, are available as a single file. It is the same file the site is built from, so there is no separate export step and nothing can drift out of sync. Use it freely, with attribution to the Internet Freedom Foundation.
Fields
- slug
- Stable record identifier, also the URL of the record page.
- org
- Organisation or system that held the data.
- date
- ISO 8601 at the precision we can source: YYYY, YYYY-MM or YYYY-MM-DD. Null when never reported.
- affectedMn
- People affected, in millions, as reported. Null when no figure was reported.
- acknowledged
- One of yes, partial, no, denied, unknown.
- exposed
- List of the categories of data exposed.
- statement
- What the organisation said publicly, if anything.
- redressal
- What was offered to affected people, if anything.
- notes
- Context: how the breach happened, who claimed it, disputed figures.
- sources
- List of URLs to published reporting.
- legacyId
- Airtable record ID from the original tracker, kept so old links resolve.
Caveats worth reading
- 21 records have no reliable date. They sort last rather than being assigned a guess.
- Scale figures come from whoever reported them, often the attacker. Several are disputed by the organisation involved; the dispute is recorded in
statement. - Totals cannot be summed into "people affected in India". The same person appears in many breaches, and some records cover global services.
- Absence from this list is not evidence that an organisation was never breached. It usually means nobody reported it.