Kualitas bukti 4.38/5
Skor tinjauan delapan dimensi terhadap rubrik kualitas . Setiap dimensi dinilai 1–5.
- D1 Dasar sumber
- 5/5
- D2 Otoritas sumber
- 4/5
- D3 Aritmetika
- 4/5
- D4 Ketidakpastian
- 4/5
- D5 Cakupan
- 4/5
- D6 Prosa
- 5/5
- D7 Kejujuran persepsi
- 4/5
- D8 Kelengkapan peringatan
- 5/5
≈ Sama mungkinnya dengan
Dipersepsikan
Gallup tidak menyurvei pelanggaran data secara khusus, tetapi proksi terdekatnya — pencurian identitas — memuncaki daftar kekhawatiran kejahatan tahunan. Pada gelombang Oktober 2024, 69 % orang dewasa AS mengatakan mereka sering atau sesekali khawatir identitas mereka dicuri, angka tertinggi dalam survei. Karena pencurian identitas sebagian besar merupakan hilir dari pelanggaran data, angka 69 % adalah proksi yang wajar untuk kecemasan terkait pelanggaran. Survei Pew Research 2023 secara terpisah menemukan bahwa 79 % orang dewasa AS menyatakan kekhawatiran tentang bagaimana perusahaan menggunakan data pribadi mereka.
Perkiraan kasar: 69 % orang dewasa AS mengkhawatirkan pencurian identitas, proksi terdekat (Gallup 2024)
Aktual
~3.322 kompromi data pada 2025, ~279 juta pemberitahuan korban
Individu AS yang datanya dipegang oleh organisasi yang mengalami pelanggaran
Tampilkan perhitungan
Laporan Pelanggaran Data Tahunan 2025 ITRC mencatat 3.322 kompromi data dengan 278,8 juta pemberitahuan korban. Pada 2024, angkanya adalah 1,35 miliar pemberitahuan korban di 3.158 kompromi (meningkat oleh pelanggaran besar seperti Change Healthcare pada 190 juta+ catatan). Menggunakan angka 2025 yang lebih konservatif, sekitar 279 juta pemberitahuan korban diterbitkan terhadap populasi AS ~335 juta, menyiratkan ~83 % populasi menerima setidaknya satu pemberitahuan pelanggaran dalam satu tahun. Namun, pemberitahuan korban menghitung ganda individu yang terkena beberapa pelanggaran. Menyesuaikan tumpang tindih dengan heuristik capture-recapture, tingkat eksposur individu-unik tahunan diperkirakan pada 35–50 %. Bahkan pada tingkat tahunan konservatif 35 %, penggabungan selama masa dewasa 59 tahun memberikan 1 − (1 − 0,35)^59 ≈ efektif 1,0. Menggunakan probabilitas tahunan yang lebih moderat 5 % untuk eksposur pertama kali (bagi seseorang yang datanya belum pernah dilanggar sebelumnya — memperhitungkan fakta bahwa sebagian besar orang dewasa sudah terekspos) yang digabungkan selama 59 tahun memberikan 1 − (1 − 0,05)^59 ≈ 0,953. Estimasi sentral 95 % mencerminkan hampir kepastian eksposur kumulatif, dengan rentang ketidakpastian mengakui ambiguitas definisi seputar apa yang dihitung sebagai data «Anda» yang «terekspos». Batas bawah dinaikkan dari 0,80 menjadi 0,90 dalam tinjauan 2026-06-14: survei konsumen 2025 ITRC (N=1.040) menemukan bahwa 80 % responden menerima setidaknya satu pemberitahuan pelanggaran dalam 12 bulan terakhir dan hampir 40 % menerima tiga hingga lima — tingkat eksposur satu tahun yang hampir universal yang membuat probabilitas seumur hidup kumulatif sub-90 % tidak masuk akal. Estimasi titik sengaja dipertahankan pada 0,95 alih-alih direvisi ke atas, karena ITRC adalah reputable_reference nirlaba alih-alih lembaga statistik pemerintah dan perbedaan eksposur-vs-kerugian yang licin menyarankan untuk tidak mendorong angka utama lebih dekat ke 1,0.
Catatan: «Eksposur pelanggaran data» adalah konsep yang secara definisi licin. Pelanggara…
«Eksposur pelanggaran data» adalah konsep yang secara definisi licin. Pelanggaran yang membocorkan nama dan alamat email Anda secara kategoris berbeda dari yang membocorkan nomor Jaminan Sosial, catatan medis, atau kredensial finansial Anda — namun ITRC menghitungnya secara identik dalam penghitungan komprominya. Angka seumur hidup 95 % berarti hampir setiap orang dewasa dengan jejak digital akan memiliki sebagian data yang terekspos pada suatu titik; itu tidak berarti 95 % orang dewasa akan menderita kerugian finansial dari suatu pelanggaran. Tingkat konversi dari eksposur ke pencurian identitas atau kerugian finansial yang sebenarnya jauh lebih rendah — FTC menerima sekitar 1,1 juta keluhan pencurian identitas pada 2024, sebagian kecil dari populasi yang terekspos pelanggaran. Angka ini juga berpusat pada AS dalam normalisasinya tetapi fenomenanya global; tingkat pelanggaran di UE dan Asia-Pasifik sebanding. Terakhir, «pemberitahuan korban» menghitung berlebih individu unik (satu orang menerima beberapa pemberitahuan) dan sekaligus menghitung kurang eksposur (banyak pelanggaran tidak terdeteksi atau tidak dilaporkan, dan 70 % pemberitahuan 2025 menghilangkan detail vektor serangan sepenuhnya). Kerumitan lebih lanjut adalah bahwa *volume* eksposur utama didominasi oleh segelintir pelanggaran besar alih-alih ekor panjang insiden. ITRC mencatat rekor 3.322 kompromi pada 2025 — naik 5 % atas 2024 — namun pemberitahuan korban turun 79 %, dari 1,37 miliar pada 2024 menjadi 279 juta pada 2025, hanya karena 2025 tidak memiliki pelanggaran besar sebesar insiden Change Healthcare 2024. Pemisahan ini berarti jumlah pemberitahuan adalah proksi tahun-ke-tahun yang buruk untuk risiko individu: jumlah pelanggaran naik sementara volume eksposur yang dilaporkan runtuh. Probabilitas bahwa *Anda* terseret dalam eksposur setiap tahun hampir universal dan stabil (survei ITRC menempatkannya pada 80 % dalam satu tahun); total pemberitahuan mentah berayun liar tergantung apakah beberapa pelanggaran katastrofik kebetulan terjadi dalam tahun kalender itu.
Risiko terkait
Risiko lain dengan tema serupa — untuk menjelajahi ketakutan terkait.
Penipuan suara AI
Berapa kemungkinan Anda menjadi sasaran penipuan kloning suara AI seumur hidup?
Anak & konten eksplisit
Berapa kemungkinan seorang anak menemukan konten eksplisit atau kekerasan daring sebelum usia 13 tahun?
Deepfake intim
Berapa kemungkinan deepfake intim yang dihasilkan AI tentang Anda akan dibuat atau dibagikan tanpa persetujuan seumur hidup?
Pilih penantang
Pertanyaannya bukan apakah data Anda telah terekspos dalam pelanggaran. Pertanyaannya adalah berapa kali. Identity Theft Resource Center mencatat rekor 3.322 kompromi data di Amerika Serikat pada tahun 2025, menghasilkan sekitar 279 juta pemberitahuan korban. Pada tahun 2024, angkanya adalah 1,37 miliar pemberitahuan — lebih dari empat per orang Amerika — meningkat karena pelanggaran besar seperti insiden Change Healthcare yang sendiri mengekspos lebih dari 190 juta catatan. Data kesehatan saja telah dilanggar dengan volume melebihi 2,6 kali populasi AS sejak tahun 2009. Menggabungkan bahkan tingkat eksposur pertama tahunan yang konservatif selama masa dewasa 59 tahun mendorong probabilitas kumulatif menjadi sekitar 95%, yang merupakan cara sopan untuk mengatakan hampir pasti.
Yang membuat risiko pelanggaran data tidak biasa di antara entri Likelier adalah bahwa ia membalik pola ketakutan-vs-realitas yang normal. Sebagian besar ketakutan di situs ini dilebih-lebihkan. Eksposur pelanggaran data, jika ada, justru diremehkan — bukan karena orang menganggapnya jarang, tetapi karena mereka jarang menghitung aritmetika kumulatifnya. Seorang warga Amerika berusia 35 tahun pada tahun 2026 telah melewati pelanggaran Equifax (147 juta catatan), pelanggaran Yahoo (3 miliar akun), pelanggaran Change Healthcare, dan ribuan insiden yang lebih kecil. Probabilitas bahwa tidak ada data pribadi mereka yang muncul dalam salah satu peristiwa tersebut dapat diabaikan. Pemutusan emosionalnya adalah bahwa “eksposur” terasa abstrak sampai berubah menjadi pencurian identitas atau kerugian finansial, yang terjadi pada sebagian kecil orang.
Peringatan penting adalah bahwa “eksposur” bukanlah “kerugian”. Jumlah pemberitahuan korban ITRC memperlakukan alamat email yang bocor sama dengan nomor Jaminan Sosial yang bocor. Sebagian besar catatan yang dilanggar tidak pernah mengakibatkan kerugian finansial yang terukur bagi individu. FTC menerima sekitar 1,1 juta keluhan pencurian identitas pada tahun 2024 — kurang dari 0,1% dari volume pemberitahuan pelanggaran. Jadi, meskipun probabilitas eksposur data mendekati 1, probabilitas kerugian konsekuensial dari pelanggaran tertentu tetap rendah. Risikonya bersifat kumulatif dan kombinatorial: setiap eksposur tambahan menambahkan titik data lain yang dapat dirujuk silang dengan kebocoran sebelumnya, secara bertahap menyusun profil yang lebih lengkap yang lebih berguna bagi penyerang yang termotivasi.
Fakta terkait
Sekitar 95% probabilitas kumulatif sepanjang hidup dewasa bahwa data pribadi Anda terpapar dalam suatu kebocoran. Pada 2025 saja terjadi sekitar 3.322 insiden pembobolan data dan sekitar 279 juta pemberitahuan korban.
Buku besar klaim
Setiap angka di bawah ini adalah apa yang dilaporkan masing-masing sumber, dengan kutipan kata demi kata yang kami andalkan dan bagaimana kami sampai pada angka kami. Klik tautan mana saja untuk memverifikasi langsung.
-
[1] Identity Theft Resource Center — Identity Theft Resource Center 2025 Annual Data Breach Report
Identity Theft Resource Center 2025 Annual Data Breach Report- Statistik
3,322 data compromises in 2025 with 278,827,933 victim notices; 5% increase in compromises over 2024; record number of tracked compromises- Kutipan
“"The ITRC tracked a record 3,322 data compromises in 2025, a 5% increase over 2024. The number of victim notices was 278,827,933, a 79% decrease from 2024's 1,367,117,021, due to the absence of mega-breaches on the scale of Change Healthcare." ”
- Data sumber dari
- 2026-01-29
- Diakses
- 2026-04-12 · salinan arsip
- Perhitungan
- The 278.8 million victim notices in 2025 divided by ~335 million US population yields ~0.83 notices per person. But notices are not unique individuals — one person can receive multiple breach notifications. The ITRC notes that 70% of 2025 breach notices did not include attack-vector information, further complicating deduplication. The 2024 figure of 1.37 billion victim notices (driven by Change Healthcare's 190M+ exposure) illustrates how a single mega-breach can exceed the entire US population in notice count. For lifetime normalization, we use the conservative annual unique-individual rate of ~5% first-time exposure compounded over 59 years. Note: the ITRC is a 501(c)(3) nonprofit, not a government statistical agency; its breach counts rely on voluntary and regulatory disclosures rather than a census-grade collection mandate. No federal agency publishes a comparable all-sector breach tally, so ITRC is the best available source but carries the authority gap inherent in non-governmental data aggregation.
- Independensi
- ITRC compiles breach data from state attorney general notifications, SEC filings, and federal regulatory disclosures. It is independent of the FTC's Consumer Sentinel Network, which tracks consumer complaints rather than breach disclosures.
-
[2] Identity Theft Resource Center (via PR Newswire) — ITRC 2025 Annual Data Breach Report consumer survey (N=1,040)
ITRC 2025 Annual Data Breach Report consumer survey (N=1,040)- Statistik
In an ITRC consumer survey of 1,040 US adults, 80% reported receiving at least one data breach notice in the past 12 months and nearly 40% received three to five separate notices in the past year- Kutipan
“"As part of the 20th anniversary of the Data Breach Report, the ITRC asked 1,040 consumers if they had received a data breach notice in the past 12 months. The survey reveals that data breaches are a near-universal experience for consumers, with 80 percent of respondents having received a data breach notice in the last 12 months. Nearly 40 percent of people responding to the survey received three to five separate notices in the past year." ”
- Data sumber dari
- 2026-01-29
- Diakses
- 2026-06-14 · salinan arsip
- Perhitungan
- This is the first direct, individual-level measurement of annual breach-notice incidence cited in this entry — prior figures were aggregate notice counts (which double-count individuals). An 80% one-year notice rate confirms empirically what the per-capita notice arithmetic only implied: annual breach exposure is near-universal for US adults with a digital footprint. Applied here as corroboration that tightens the lower bound of the lifetime uncertainty band — if 80% are notified in a single year, a sub-90% cumulative lifetime probability is no longer plausible. The point estimate is held at 0.95 rather than revised upward, because ITRC is a 501(c)(3) nonprofit reputable_reference, not a government statistical agency, and a revise of the headline number is reserved for official-agency updates. Survey caveat: self-reported recall over a 12-month window may overstate (notice fatigue conflating spam with real notices) or understate (forgotten or unopened notices) the true rate.
- Independensi
- This is the consumer-survey component of the same ITRC 2025 report whose breach counts are cited above; it is a methodologically distinct instrument (a polled sample of individuals) rather than the aggregate breach-notice tally, so it corroborates rather than restates the count-based figure.
-
[3] Verizon Business — 2024 Data Breach Investigations Report (DBIR)
2024 Data Breach Investigations Report (DBIR)- Statistik
Verizon DBIR 2024 analyzed 30,458 security incidents and 10,626 confirmed breaches across 94 countries, confirming that the majority of breaches involve stolen credentials or human error rather than sophisticated attacks- Kutipan
“"This year's dataset includes 30,458 real-world security incidents, of which 10,626 (about one-third) were confirmed data breaches. 68 percent of breaches involved a non-malicious human element, such as a person falling victim to a social engineering attack or making an error." ”
- Data sumber dari
- 2024-05-01
- Diakses
- 2026-04-16 · salinan arsip
- Perhitungan
- Verizon DBIR does not publish a per-individual "exposure probability" — its unit of analysis is the incident/breach, not the person. Used here as a corroborating source for the claim that breaches are common, widely distributed, and driven by credential/phishing vectors rather than targeted attacks on individuals. This shifts the entry's framing from "probability of being a specific victim" to "probability of being swept up in aggregate exposure."
- Independensi
- Verizon DBIR aggregates incident data from ~100 contributing organizations (forensic firms, CSIRTs, law enforcement including US Secret Service). This is methodologically independent of ITRC's public-breach-notice tracking, which counts disclosed consumer breaches rather than investigated incidents.
-
[4] Identity Theft Resource Center — ITRC 2024 Annual Data Breach Report
ITRC 2024 Annual Data Breach Report- Statistik
3,158 data compromises in 2024 with 1,728,519,397 victim notices; 1.7 billion individuals' data compromised- Kutipan
“"The number of data breach notices issued in 2024 (1,728,519,397) increased 312 percent from 2023 (419,337,446)... In 2024, six data breaches were reported that each involved more than 100 million records. More than 1.7 billion individuals had personal data compromised in 2024, and there were 3,158 data compromises." ”
- Data sumber dari
- 2025-01-29
- Diakses
- 2026-04-12 · salinan arsip
- Perhitungan
- The 2024 figure of 1.37 billion victim notices against a US population of ~335 million means the average American received roughly 4 breach notifications in a single year. This is consistent with the cumulative-near-certainty thesis: if breach exposure is this frequent in a single year, the probability of never being exposed over a full adult lifetime approaches zero. The 2024 figure is inflated by outlier mega-breaches and should not be used as a stable annual rate, which is why the 2025 figure is preferred for the central estimate.
- Independensi
- The 2024 Annual Data Breach Report is the prior-year edition from the same ITRC methodology; included for the 72% year-over-year record count rather than as an independent estimate.
-
[5] HIPAA Journal — Healthcare Data Breach Statistics
Healthcare Data Breach Statistics- Statistik
7,357 healthcare data breaches affecting 935.5 million records between 2009 and 2025 — more than 2.6x the US population- Kutipan
“"Between 2009 and 2025, 7,357 healthcare data breaches of 500 or more records have been reported to the HHS Office for Civil Rights, resulting in the exposure of more than 935,521,931 healthcare records — more than 2.6 times the population of the United States." ”
- Data sumber dari
- 2026-03-15
- Diakses
- 2026-04-12 · salinan arsip
- Perhitungan
- Healthcare alone has exposed records equivalent to 2.6x the US population over 16 years. Even with substantial deduplication (same person, multiple breaches), this implies the vast majority of Americans with any healthcare history have had protected health information exposed at least once. Healthcare is one sector among many — financial services, retail, government, and education add further exposure. Used as corroborating evidence for the near-certainty cumulative estimate, not as the primary source.
- Independensi
- HIPAA Journal tracks breaches reported to the HHS Office for Civil Rights under the HIPAA Breach Notification Rule. This is a regulatory pipeline entirely independent of the ITRC's state-AG-based tracking.
-
[6] Federal Trade Commission (FTC) — Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach
Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach- Statistik
The 2017 Equifax data breach exposed approximately 147 million US consumers' sensitive personal information, including Social Security numbers, names, addresses, and dates of birth- Kutipan
“"In September of 2017, Equifax, a nationwide credit reporting company headquartered in Atlanta, Georgia, announced that a data breach at the company resulted in the exposure of approximately 147 million U.S. consumers' sensitive personal information, including names, addresses, social security numbers, and dates of birth." ”
- Data sumber dari
- 2019-07-22
- Diakses
- 2026-07-03 · salinan arsip
- Perhitungan
- Cited in the body prose as a concrete, named illustration of the cumulative-exposure argument — a typical American adult has very likely had some personal data exposed in at least one major named breach. Not used in the lifetime-probability arithmetic itself, which relies on the ITRC annual victim-notice figures above; included only to ground the specific "Equifax breach (147 million records)" reference in the body text.
- Independensi
- FTC/CFPB regulatory settlement documentation, independent of the ITRC's breach-notice tracking and of Verizon's DBIR incident dataset.
-
[7] Wikipedia — Yahoo data breaches
Yahoo data breaches- Statistik
Yahoo's 2013 breach, initially disclosed in December 2016 as affecting 1 billion accounts, was revised in October 2017 to confirm all 3 billion Yahoo accounts existing at the time were compromised- Kutipan
“"Almost a year later, in October 2017 they revised that estimate and reported that all three billion Yahoo accounts had been compromised in the breach." ”
- Data sumber dari
- 2017-10-03
- Diakses
- 2026-07-03 · salinan arsip
- Perhitungan
- Cited in the body prose alongside Equifax as a second concrete named mega-breach illustrating cumulative lifetime exposure. Not used in the lifetime-probability arithmetic. Grounds the "Yahoo breach (3 billion accounts)" reference in the body text; the 3-billion revision is corroborated by contemporaneous reporting (e.g. the Wall Street Journal's October 3, 2017 story "Yahoo Triples Estimate of Breached Accounts to 3 Billion," cited in this Wikipedia article's references) and Yahoo/Verizon's own SEC disclosures.
- Independensi
- Tertiary compilation source; the underlying disclosure is Yahoo's own 2017 SEC filings and contemporaneous news reporting. Included only as corroboration for a widely reported, uncontested figure not itself covered by this entry's other four sources.
-
[8] Federal Trade Commission (FTC) — Consumer Sentinel Network Data Book 2024
Consumer Sentinel Network Data Book 2024See all 4 Likelier entries citing this source →
- Statistik
FTC Consumer Sentinel Network received 6.5 million consumer reports in 2024; identity theft was the largest single category at approximately 1.1 million reports, about 17% of all reports- Kutipan
“"During 2024, Sentinel received 6.5 million consumer reports, which the FTC has sorted into 29 top categories. ... In 2024, there were more than 1.1 million reports of identity theft received through the FTC's IdentityTheft.gov website." ”
- Data sumber dari
- 2025-03-01
- Diakses
- 2026-07-03 · salinan arsip
- Perhitungan
- Grounds the body prose's and caveats' "the FTC received about 1.1 million identity-theft complaints in 2024" reference (which previously named the FTC without a citation). Both figures are now quoted verbatim in the excerpt above: the 6.5-million-report total and the >1.1-million identity-theft figure, the latter the FTC's largest single Sentinel category (~1.1M / 6.5M ≈ 17% of all reports). Not used in this entry's headline lifetime-probability arithmetic, which relies on the ITRC breach-notice figures above; included only to ground the specific FTC identity-theft-complaint figure used in the body prose to distinguish "exposure" from "harm."
- Independensi
- FTC Consumer Sentinel Network is a distinct federal consumer-complaint intake pipeline, independent of the ITRC's breach-notice tracking and Verizon's incident-investigation dataset used elsewhere in this entry.






