Evidenzqualität 4.38/5
Bewertungsergebnis nach acht Dimensionen gemäß der Qualitätsrubrik . Jede Dimension wird mit 1–5 bewertet.
- D1 Quellenverankerung
- 5/5
- D2 Quellenautorität
- 4/5
- D3 Arithmetik
- 4/5
- D4 Unsicherheit
- 4/5
- D5 Geltungsbereich
- 4/5
- D6 Prosa
- 5/5
- D7 Ehrlichkeit zur Wahrnehmung
- 4/5
- D8 Vollständigkeit der Einschränkungen
- 5/5
≈ Genauso wahrscheinlich wie
Wahrgenommen
Gallup befragt nicht speziell zu Datenlecks, aber sein nächstliegender Näherungswert – Identitätsdiebstahl – führt die jährliche Liste der Kriminalitätssorgen an. In der Erhebungswelle vom Oktober 2024 gaben 69 % der US-Erwachsenen an, sich häufig oder gelegentlich Sorgen zu machen, dass ihre Identität gestohlen wird – der höchste Wert der Umfrage. Da Identitätsdiebstahl überwiegend eine Folge von Datenlecks ist, ist der Wert von 69 % ein vernünftiger Näherungswert für die datenleckbezogene Angst. Eine Pew-Research-Umfrage von 2023 ergab separat, dass 79 % der US-Erwachsenen Bedenken darüber äußerten, wie Unternehmen ihre persönlichen Daten nutzen.
Grobe Schätzung: 69 % der US-Erwachsenen sorgen sich um Identitätsdiebstahl, den nächstliegenden Näherungswert (Gallup 2024)
Tatsächlich
~3.322 Datenkompromittierungen im Jahr 2025, ~279 Millionen Betroffenenbenachrichtigungen
US-Personen, deren Daten bei kompromittierten Organisationen gespeichert sind
Berechnung anzeigen
Der Annual Data Breach Report 2025 des ITRC verzeichnete 3.322 Datenkompromittierungen mit 278,8 Millionen Betroffenenbenachrichtigungen. 2024 lag die Zahl bei 1,35 Milliarden Betroffenenbenachrichtigungen über 3.158 Kompromittierungen (aufgebläht durch Mega-Datenlecks wie Change Healthcare mit über 190 Mio. Datensätzen). Unter Verwendung der konservativeren Zahl von 2025 wurden gegen eine US-Bevölkerung von ~335 Millionen rund 279 Millionen Betroffenenbenachrichtigungen ausgegeben, was impliziert, dass ~83 % der Bevölkerung in einem einzigen Jahr mindestens eine Datenleck-Benachrichtigung erhielten. Betroffenenbenachrichtigungen zählen jedoch Personen, die von mehreren Datenlecks betroffen sind, doppelt. Nach Bereinigung um Überschneidungen mit einer Capture-Recapture-Heuristik wird die jährliche Expositionsrate einzelner Personen auf 35–50 % geschätzt. Selbst bei der konservativen jährlichen Rate von 35 % ergibt die Aufaddierung über eine 59-jährige Erwachsenenlebenszeit 1 − (1 − 0,35)^59 ≈ praktisch 1,0. Bei einer moderateren jährlichen Wahrscheinlichkeit von 5 % einer erstmaligen Exposition (für jemanden, dessen Daten noch nie zuvor geleakt wurden – unter Berücksichtigung der Tatsache, dass die meisten Erwachsenen bereits exponiert sind), aufaddiert über 59 Jahre, ergibt sich 1 − (1 − 0,05)^59 ≈ 0,953. Die zentrale Schätzung von 95 % spiegelt die Beinahe-Gewissheit kumulativer Exposition wider, wobei das Unsicherheitsband die definitorische Ambiguität darüber anerkennt, was als Offenlegung »Ihrer« Daten zählt. Die Untergrenze wurde in der Überprüfung vom 2026-06-14 von 0,80 auf 0,90 angehoben: Die ITRC-Verbraucherumfrage 2025 (N=1.040) ergab, dass 80 % der Befragten in den letzten 12 Monaten mindestens eine Datenleck-Benachrichtigung erhielten und fast 40 % drei bis fünf – eine nahezu universelle Einjahres-Expositionsrate, die eine kumulative Lebenszeitwahrscheinlichkeit unter 90 % unplausibel macht. Der Punktschätzwert wird bewusst bei 0,95 gehalten statt nach oben revidiert, weil das ITRC eine gemeinnützige reputable_reference und keine staatliche Statistikbehörde ist und die schwer fassbare Unterscheidung zwischen Exposition und Schaden dagegen spricht, die Schlagzeile näher an 1,0 zu rücken.
Einschränkungen: »Datenleck-Exposition« ist ein definitorisch schwer fassbares Konzept. Ein Daten…
»Datenleck-Exposition« ist ein definitorisch schwer fassbares Konzept. Ein Datenleck, das Ihren Namen und Ihre E-Mail-Adresse preisgibt, unterscheidet sich kategorial von einem, das Ihre Sozialversicherungsnummer, medizinische Unterlagen oder Finanzdaten preisgibt – dennoch zählt das ITRC sie in seinen Kompromittierungsbilanzen identisch. Die Lebenszeitzahl von 95 % bedeutet, dass praktisch jeder Erwachsene mit einem digitalen Fußabdruck irgendwann einige Daten offengelegt bekommt; sie bedeutet nicht, dass 95 % der Erwachsenen finanziellen Schaden durch ein Datenleck erleiden. Die Umwandlungsrate von Exposition zu tatsächlichem Identitätsdiebstahl oder finanziellem Verlust ist viel niedriger – die FTC erhielt 2024 etwa 1,1 Millionen Beschwerden über Identitätsdiebstahl, ein winziger Bruchteil der von Datenlecks betroffenen Bevölkerung. Die Zahl ist in ihrer Normierung zudem US-zentriert, doch das Phänomen ist global; die Datenleckraten in der EU und im asiatisch-pazifischen Raum sind vergleichbar. Schließlich zählen »Betroffenenbenachrichtigungen« einzelne Personen zu hoch (eine Person erhält mehrere Benachrichtigungen) und untererfassen gleichzeitig die Exposition (viele Datenlecks bleiben unentdeckt oder ungemeldet, und 70 % der Benachrichtigungen von 2025 ließen Angaben zum Angriffsvektor gänzlich aus). Eine weitere Feinheit ist, dass das Schlagzeilen-*Volumen* der Exposition von einer Handvoll Mega-Datenlecks dominiert wird und nicht vom langen Ausläufer der Vorfälle. Das ITRC verzeichnete 2025 einen Rekord von 3.322 Kompromittierungen – 5 % mehr als 2024 –, doch die Betroffenenbenachrichtigungen fielen um 79 %, von 1,37 Milliarden im Jahr 2024 auf 279 Millionen im Jahr 2025, einfach weil 2025 kein Mega-Datenleck in der Größenordnung des Change-Healthcare-Vorfalls von 2024 aufwies. Diese Entkopplung bedeutet, dass Benachrichtigungszahlen ein schlechter Jahr-für-Jahr-Näherungswert für das individuelle Risiko sind: Die Zahl der Datenlecks stieg, während das gemeldete Expositionsvolumen einbrach. Die Wahrscheinlichkeit, dass *Sie* jedes Jahr von einer Exposition erfasst werden, ist nahezu universell und stabil (die ITRC-Umfrage beziffert sie auf 80 % in einem einzigen Jahr); die reine Gesamtzahl der Benachrichtigungen schwankt stark damit, ob einige katastrophale Datenlecks zufällig in jenes Kalenderjahr fielen.
Verwandte Risiken
Andere Risiken zu ähnlichen Themen — zum Erkunden verwandter Ängste.
Kreditkartenbetrug
Wie hoch ist die Wahrscheinlichkeit, Opfer von Kreditkartenbetrug zu werden?
Online-Betrug
Wie hoch ist die Wahrscheinlichkeit, durch einen Online-Betrug Geld zu verlieren?
Identitätsdiebstahl
Wie hoch ist die Wahrscheinlichkeit, Opfer eines Identitätsdiebstahls zu werden?
KI-Stimmenklon-Betrug
Wie hoch ist die Wahrscheinlichkeit, dass Sie in Ihrem Leben Ziel eines KI-Stimmenklon-Betrugs werden?
Kinder & explizite Inhalte
Wie hoch ist die Wahrscheinlichkeit, dass ein Kind vor dem 13. Lebensjahr online auf explizite oder gewalttätige Inhalte stößt?
Cybermobbing bei Teenagern
Wie hoch ist die Wahrscheinlichkeit, dass ein Teenager Opfer von Cybermobbing wird?
Intimes Deepfake
Wie hoch ist die Wahrscheinlichkeit, dass in Ihrem Leben ein KI-generiertes intimes Deepfake von Ihnen ohne Einwilligung erstellt oder geteilt wird?
Vergleichsrisiko wählen
The question is not whether your data has been exposed in a breach. The question is how many times. The Identity Theft Resource Center tracked a record 3,322 data compromises in the United States in 2025, generating roughly 279 million victim notices. In 2024, the figure was 1.37 billion notices — more than four per American — inflated by mega-breaches like the Change Healthcare incident that alone exposed over 190 million records. Healthcare data alone has been breached at a volume exceeding 2.6 times the US population since 2009. Compounding even a conservative annual first-exposure rate over a 59-year adult lifetime pushes the cumulative probability to roughly 95%, which is a polite way of saying near-certainty.
What makes data-breach risk unusual among Likelier entries is that it inverts the normal fear-vs-reality pattern. Most fears on this site are overestimated. Data-breach exposure is, if anything, underestimated — not because people think it is rare, but because they rarely compute the cumulative arithmetic. A 35-year-old American in 2026 has lived through the Equifax breach (147 million records), the Yahoo breach (3 billion accounts), the Change Healthcare breach, and thousands of smaller incidents. The probability that none of their personal data appeared in any of those events is negligible. The emotional disconnect is that “exposure” feels abstract until it converts into identity theft or financial loss, which happens to a much smaller fraction.
The important caveat is that “exposure” is not “harm.” The ITRC’s victim-notice count treats a leaked email address the same as a leaked Social Security number. Most breached records never result in measurable financial damage to the individual. The FTC received about 1.1 million identity-theft complaints in 2024 — less than 0.1% of the breach-notification volume. So while the probability of data exposure approaches 1, the probability of consequential harm from any given breach remains low. The risk is cumulative and combinatorial: each additional exposure adds another data point that can be cross-referenced against previous leaks, gradually assembling a more complete profile that is more useful to a motivated attacker.
Verwandte Fakten
Rund 95% kumulierte Wahrscheinlichkeit über ein Erwachsenenleben, dass Ihre persönlichen Daten bei einem Leck offengelegt werden. Allein 2025 gab es etwa 3.322 Datenkompromittierungen und rund 279 Millionen Benachrichtigungen an Betroffene.
Quellenregister
Jede Zahl unten ist das, was die jeweilige Quelle berichtet hat — mit dem wörtlichen Zitat, auf das wir uns stützen, und wie wir zu unserer Zahl gelangt sind. Klicke auf einen Link, um direkt zu prüfen.
-
[1] Identity Theft Resource Center — Identity Theft Resource Center 2025 Annual Data Breach Report
Identity Theft Resource Center 2025 Annual Data Breach Report- Statistik
3,322 data compromises in 2025 with 278,827,933 victim notices; 5% increase in compromises over 2024; record number of tracked compromises- Auszug
“"The ITRC tracked a record 3,322 data compromises in 2025, a 5% increase over 2024. The number of victim notices was 278,827,933, a 79% decrease from 2024's 1,367,117,021, due to the absence of mega-breaches on the scale of Change Healthcare." ”
- Quelldaten von
- 2026-01-29
- Abgerufen
- 2026-04-12 · archivierte Kopie
- Berechnung
- The 278.8 million victim notices in 2025 divided by ~335 million US population yields ~0.83 notices per person. But notices are not unique individuals — one person can receive multiple breach notifications. The ITRC notes that 70% of 2025 breach notices did not include attack-vector information, further complicating deduplication. The 2024 figure of 1.37 billion victim notices (driven by Change Healthcare's 190M+ exposure) illustrates how a single mega-breach can exceed the entire US population in notice count. For lifetime normalization, we use the conservative annual unique-individual rate of ~5% first-time exposure compounded over 59 years. Note: the ITRC is a 501(c)(3) nonprofit, not a government statistical agency; its breach counts rely on voluntary and regulatory disclosures rather than a census-grade collection mandate. No federal agency publishes a comparable all-sector breach tally, so ITRC is the best available source but carries the authority gap inherent in non-governmental data aggregation.
- Unabhängigkeit
- ITRC compiles breach data from state attorney general notifications, SEC filings, and federal regulatory disclosures. It is independent of the FTC's Consumer Sentinel Network, which tracks consumer complaints rather than breach disclosures.
-
[2] Identity Theft Resource Center (via PR Newswire) — ITRC 2025 Annual Data Breach Report consumer survey (N=1,040)
ITRC 2025 Annual Data Breach Report consumer survey (N=1,040)- Statistik
In an ITRC consumer survey of 1,040 US adults, 80% reported receiving at least one data breach notice in the past 12 months and nearly 40% received three to five separate notices in the past year- Auszug
“"As part of the 20th anniversary of the Data Breach Report, the ITRC asked 1,040 consumers if they had received a data breach notice in the past 12 months. The survey reveals that data breaches are a near-universal experience for consumers, with 80 percent of respondents having received a data breach notice in the last 12 months. Nearly 40 percent of people responding to the survey received three to five separate notices in the past year." ”
- Quelldaten von
- 2026-01-29
- Abgerufen
- 2026-06-14 · archivierte Kopie
- Berechnung
- This is the first direct, individual-level measurement of annual breach-notice incidence cited in this entry — prior figures were aggregate notice counts (which double-count individuals). An 80% one-year notice rate confirms empirically what the per-capita notice arithmetic only implied: annual breach exposure is near-universal for US adults with a digital footprint. Applied here as corroboration that tightens the lower bound of the lifetime uncertainty band — if 80% are notified in a single year, a sub-90% cumulative lifetime probability is no longer plausible. The point estimate is held at 0.95 rather than revised upward, because ITRC is a 501(c)(3) nonprofit reputable_reference, not a government statistical agency, and a revise of the headline number is reserved for official-agency updates. Survey caveat: self-reported recall over a 12-month window may overstate (notice fatigue conflating spam with real notices) or understate (forgotten or unopened notices) the true rate.
- Unabhängigkeit
- This is the consumer-survey component of the same ITRC 2025 report whose breach counts are cited above; it is a methodologically distinct instrument (a polled sample of individuals) rather than the aggregate breach-notice tally, so it corroborates rather than restates the count-based figure.
-
[3] Verizon Business — 2024 Data Breach Investigations Report (DBIR)
2024 Data Breach Investigations Report (DBIR)- Statistik
Verizon DBIR 2024 analyzed 30,458 security incidents and 10,626 confirmed breaches across 94 countries, confirming that the majority of breaches involve stolen credentials or human error rather than sophisticated attacks- Auszug
“"This year's dataset includes 30,458 real-world security incidents, of which 10,626 (about one-third) were confirmed data breaches. 68 percent of breaches involved a non-malicious human element, such as a person falling victim to a social engineering attack or making an error." ”
- Quelldaten von
- 2024-05-01
- Abgerufen
- 2026-04-16 · archivierte Kopie
- Berechnung
- Verizon DBIR does not publish a per-individual "exposure probability" — its unit of analysis is the incident/breach, not the person. Used here as a corroborating source for the claim that breaches are common, widely distributed, and driven by credential/phishing vectors rather than targeted attacks on individuals. This shifts the entry's framing from "probability of being a specific victim" to "probability of being swept up in aggregate exposure."
- Unabhängigkeit
- Verizon DBIR aggregates incident data from ~100 contributing organizations (forensic firms, CSIRTs, law enforcement including US Secret Service). This is methodologically independent of ITRC's public-breach-notice tracking, which counts disclosed consumer breaches rather than investigated incidents.
-
[4] Identity Theft Resource Center — ITRC 2024 Annual Data Breach Report
ITRC 2024 Annual Data Breach Report- Statistik
3,158 data compromises in 2024 with 1,728,519,397 victim notices; 1.7 billion individuals' data compromised- Auszug
“"The number of data breach notices issued in 2024 (1,728,519,397) increased 312 percent from 2023 (419,337,446)... In 2024, six data breaches were reported that each involved more than 100 million records. More than 1.7 billion individuals had personal data compromised in 2024, and there were 3,158 data compromises." ”
- Quelldaten von
- 2025-01-29
- Abgerufen
- 2026-04-12 · archivierte Kopie
- Berechnung
- The 2024 figure of 1.37 billion victim notices against a US population of ~335 million means the average American received roughly 4 breach notifications in a single year. This is consistent with the cumulative-near-certainty thesis: if breach exposure is this frequent in a single year, the probability of never being exposed over a full adult lifetime approaches zero. The 2024 figure is inflated by outlier mega-breaches and should not be used as a stable annual rate, which is why the 2025 figure is preferred for the central estimate.
- Unabhängigkeit
- The 2024 Annual Data Breach Report is the prior-year edition from the same ITRC methodology; included for the 72% year-over-year record count rather than as an independent estimate.
-
[5] HIPAA Journal — Healthcare Data Breach Statistics
Healthcare Data Breach Statistics- Statistik
7,357 healthcare data breaches affecting 935.5 million records between 2009 and 2025 — more than 2.6x the US population- Auszug
“"Between 2009 and 2025, 7,357 healthcare data breaches of 500 or more records have been reported to the HHS Office for Civil Rights, resulting in the exposure of more than 935,521,931 healthcare records — more than 2.6 times the population of the United States." ”
- Quelldaten von
- 2026-03-15
- Abgerufen
- 2026-04-12 · archivierte Kopie
- Berechnung
- Healthcare alone has exposed records equivalent to 2.6x the US population over 16 years. Even with substantial deduplication (same person, multiple breaches), this implies the vast majority of Americans with any healthcare history have had protected health information exposed at least once. Healthcare is one sector among many — financial services, retail, government, and education add further exposure. Used as corroborating evidence for the near-certainty cumulative estimate, not as the primary source.
- Unabhängigkeit
- HIPAA Journal tracks breaches reported to the HHS Office for Civil Rights under the HIPAA Breach Notification Rule. This is a regulatory pipeline entirely independent of the ITRC's state-AG-based tracking.
-
[6] Federal Trade Commission (FTC) — Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach
Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach- Statistik
The 2017 Equifax data breach exposed approximately 147 million US consumers' sensitive personal information, including Social Security numbers, names, addresses, and dates of birth- Auszug
“"In September of 2017, Equifax, a nationwide credit reporting company headquartered in Atlanta, Georgia, announced that a data breach at the company resulted in the exposure of approximately 147 million U.S. consumers' sensitive personal information, including names, addresses, social security numbers, and dates of birth." ”
- Quelldaten von
- 2019-07-22
- Abgerufen
- 2026-07-03 · archivierte Kopie
- Berechnung
- Cited in the body prose as a concrete, named illustration of the cumulative-exposure argument — a typical American adult has very likely had some personal data exposed in at least one major named breach. Not used in the lifetime-probability arithmetic itself, which relies on the ITRC annual victim-notice figures above; included only to ground the specific "Equifax breach (147 million records)" reference in the body text.
- Unabhängigkeit
- FTC/CFPB regulatory settlement documentation, independent of the ITRC's breach-notice tracking and of Verizon's DBIR incident dataset.
-
[7] Wikipedia — Yahoo data breaches
Yahoo data breaches- Statistik
Yahoo's 2013 breach, initially disclosed in December 2016 as affecting 1 billion accounts, was revised in October 2017 to confirm all 3 billion Yahoo accounts existing at the time were compromised- Auszug
“"Almost a year later, in October 2017 they revised that estimate and reported that all three billion Yahoo accounts had been compromised in the breach." ”
- Quelldaten von
- 2017-10-03
- Abgerufen
- 2026-07-03 · archivierte Kopie
- Berechnung
- Cited in the body prose alongside Equifax as a second concrete named mega-breach illustrating cumulative lifetime exposure. Not used in the lifetime-probability arithmetic. Grounds the "Yahoo breach (3 billion accounts)" reference in the body text; the 3-billion revision is corroborated by contemporaneous reporting (e.g. the Wall Street Journal's October 3, 2017 story "Yahoo Triples Estimate of Breached Accounts to 3 Billion," cited in this Wikipedia article's references) and Yahoo/Verizon's own SEC disclosures.
- Unabhängigkeit
- Tertiary compilation source; the underlying disclosure is Yahoo's own 2017 SEC filings and contemporaneous news reporting. Included only as corroboration for a widely reported, uncontested figure not itself covered by this entry's other four sources.
-
[8] Federal Trade Commission (FTC) — Consumer Sentinel Network Data Book 2024
Consumer Sentinel Network Data Book 2024See all 4 Likelier entries citing this source →
- Statistik
FTC Consumer Sentinel Network received 6.5 million consumer reports in 2024; identity theft was the largest single category at approximately 1.1 million reports, about 17% of all reports- Auszug
“"During 2024, Sentinel received 6.5 million consumer reports, which the FTC has sorted into 29 top categories. ... In 2024, there were more than 1.1 million reports of identity theft received through the FTC's IdentityTheft.gov website." ”
- Quelldaten von
- 2025-03-01
- Abgerufen
- 2026-07-03 · archivierte Kopie
- Berechnung
- Grounds the body prose's and caveats' "the FTC received about 1.1 million identity-theft complaints in 2024" reference (which previously named the FTC without a citation). Both figures are now quoted verbatim in the excerpt above: the 6.5-million-report total and the >1.1-million identity-theft figure, the latter the FTC's largest single Sentinel category (~1.1M / 6.5M ≈ 17% of all reports). Not used in this entry's headline lifetime-probability arithmetic, which relies on the ITRC breach-notice figures above; included only to ground the specific FTC identity-theft-complaint figure used in the body prose to distinguish "exposure" from "harm."
- Unabhängigkeit
- FTC Consumer Sentinel Network is a distinct federal consumer-complaint intake pipeline, independent of the ITRC's breach-notice tracking and Verizon's incident-investigation dataset used elsewhere in this entry.






