Qualità delle prove 4.38/5
Punteggio di revisione su otto dimensioni rispetto alla griglia di qualità . Ogni dimensione valutata da 1 a 5.
- D1 Ancoraggio alle fonti
- 5/5
- D2 Autorità delle fonti
- 4/5
- D3 Aritmetica
- 4/5
- D4 Incertezza
- 4/5
- D5 Ambito
- 4/5
- D6 Prosa
- 5/5
- D7 Onestà sulla percezione
- 4/5
- D8 Completezza degli avvertimenti
- 5/5
≈ Probabile come
Percepito
Gallup non conduce sondaggi specifici sui data breach, ma il suo proxy più vicino — il furto d'identità — è in cima alla classifica annuale delle preoccupazioni sul crimine. Nell'ondata di ottobre 2024, il 69 % degli adulti statunitensi ha dichiarato di temere frequentemente o occasionalmente il furto della propria identità, la cifra più alta del sondaggio. Poiché il furto d'identità è in gran parte a valle dei data breach, la cifra del 69 % è un proxy ragionevole per l'ansia legata ai breach. Un'indagine Pew Research del 2023 ha rilevato separatamente che il 79 % degli adulti statunitensi ha espresso preoccupazione per il modo in cui le aziende usano i loro dati personali.
Stima approssimativa: Il 69 % degli adulti statunitensi teme il furto d'identità, il proxy più vicino (Gallup 2024)
Effettivo
~3.322 compromissioni di dati nel 2025, ~279 milioni di notifiche alle vittime
Individui statunitensi con dati detenuti da organizzazioni violate
Mostra calcolo
L'Annual Data Breach Report 2025 dell'ITRC ha registrato 3.322 compromissioni di dati con 278,8 milioni di notifiche alle vittime. Nel 2024, la cifra era di 1,35 miliardi di notifiche alle vittime su 3.158 compromissioni (gonfiata da mega-breach come Change Healthcare con oltre 190 milioni di record). Usando la cifra più conservativa del 2025, circa 279 milioni di notifiche alle vittime sono state emesse a fronte di una popolazione statunitense di ~335 milioni, il che implica che ~83 % della popolazione ha ricevuto almeno una notifica di breach in un solo anno. Tuttavia, le notifiche alle vittime contano due volte gli individui colpiti da più breach. Correggendo per la sovrapposizione con un'euristica di cattura-ricattura, il tasso annuale di esposizione per individuo unico è stimato al 35–50 %. Anche al tasso annuale conservativo del 35 %, la composizione nell'arco di 59 anni di vita adulta dà 1 − (1 − 0,35)^59 ≈ effettivamente 1,0. Usando una probabilità annuale più moderata del 5 % di una primissima esposizione (per qualcuno i cui dati non sono mai stati violati prima — tenendo conto del fatto che la maggior parte degli adulti è già esposta) composta su 59 anni si ottiene 1 − (1 − 0,05)^59 ≈ 0,953. La stima centrale del 95 % riflette la quasi-certezza dell'esposizione cumulativa, con la banda di incertezza che riconosce l'ambiguità definitoria su cosa conti come esposizione dei «tuoi» dati. Il limite inferiore è stato alzato da 0,80 a 0,90 nella revisione del 2026-06-14: l'indagine sui consumatori 2025 dell'ITRC (N=1.040) ha rilevato che l'80 % dei rispondenti ha ricevuto almeno una notifica di breach negli ultimi 12 mesi e quasi il 40 % ne ha ricevute da tre a cinque — un tasso di esposizione in un solo anno quasi universale che rende implausibile una probabilità cumulativa nell'arco della vita inferiore al 90 %. La stima puntuale è deliberatamente mantenuta a 0,95 anziché rivista al rialzo, perché l'ITRC è un reputable_reference no-profit anziché un'agenzia statistica governativa e la sfuggente distinzione tra esposizione e danno sconsiglia di spingere il dato principale più vicino a 1,0.
Avvertenze: L'«esposizione da data breach» è un concetto definitoriamente sfuggente. Un brea…
L'«esposizione da data breach» è un concetto definitoriamente sfuggente. Un breach che fa trapelare il tuo nome e indirizzo email è categoricamente diverso da uno che fa trapelare il tuo Social Security number, le cartelle cliniche o le credenziali finanziarie — eppure l'ITRC li conta in modo identico nei suoi conteggi di compromissioni. Il dato del 95 % nell'arco della vita significa che praticamente ogni adulto con un'impronta digitale avrà qualche dato esposto a un certo punto; non significa che il 95 % degli adulti subirà un danno finanziario da un breach. Il tasso di conversione dall'esposizione all'effettivo furto d'identità o perdita finanziaria è molto più basso — la FTC ha ricevuto circa 1,1 milioni di reclami per furto d'identità nel 2024, una minuscola frazione della popolazione esposta ai breach. Il numero è anche statunitense-centrico nella sua normalizzazione, ma il fenomeno è globale; i tassi di breach nell'UE e nell'Asia-Pacifico sono comparabili. Infine, le «notifiche alle vittime» sovrastimano gli individui unici (una persona riceve più notifiche) e allo stesso tempo sottostimano l'esposizione (molti breach non vengono rilevati o segnalati, e il 70 % delle notifiche del 2025 ometteva del tutto i dettagli sul vettore d'attacco). Un ulteriore dettaglio è che il *volume* principale di esposizione è dominato da una manciata di mega-breach piuttosto che dalla lunga coda di incidenti. L'ITRC ha registrato un record di 3.322 compromissioni nel 2025 — in aumento del 5 % rispetto al 2024 — eppure le notifiche alle vittime sono calate del 79 %, da 1,37 miliardi nel 2024 a 279 milioni nel 2025, semplicemente perché il 2025 è stato privo di mega-breach della portata dell'incidente Change Healthcare del 2024. Questo disaccoppiamento significa che i conteggi delle notifiche sono un cattivo proxy anno su anno per il rischio individuale: il numero di breach è aumentato mentre il volume di esposizione segnalato è crollato. La probabilità che *tu* sia coinvolto nell'esposizione ogni anno è quasi universale e stabile (l'indagine ITRC la colloca all'80 % in un solo anno); il totale grezzo delle notifiche oscilla ampiamente a seconda che alcuni breach catastrofici siano capitati in quell'anno solare.
Rischi correlati
Altri rischi su temi simili — per esplorare paure correlate.
Frode con carta di credito
Quali sono le probabilità di essere vittima di una frode con carta di credito?
Perdita da truffa online
Quali sono le probabilità di perdere soldi a causa di una truffa online?
Truffa voce IA
Qual è la probabilità che tu sia bersaglio di una truffa con clonazione vocale tramite IA nel corso della vita?
Bambini e contenuti espliciti
Quali sono le probabilità che un bambino incontri contenuti espliciti o violenti online prima dei 13 anni?
Cyberbullismo adolescenziale
Quali sono le probabilità che un adolescente subisca cyberbullismo?
Deepfake intimo
Qual è la probabilità che un deepfake intimo generato dall'IA con la tua immagine venga creato o condiviso senza consenso nel corso della tua vita?
Scegli lo sfidante
La domanda non è se i tuoi dati siano stati esposti in un data breach. La domanda è quante volte. L’Identity Theft Resource Center ha registrato un record di 3.322 violazioni di dati negli Stati Uniti nel 2025, generando circa 279 milioni di notifiche alle vittime. Nel 2024, la cifra era 1,37 miliardi di notifiche — più di quattro per americano — gonfiata da mega-breach come l’incidente di Change Healthcare che da solo ha esposto oltre 190 milioni di record. I dati sanitari da soli sono stati violati per un volume che supera di 2,6 volte la popolazione statunitense dal 2009. Cumulando anche un tasso annuale conservativo di prima esposizione nell’arco di 59 anni di vita adulta, la probabilità cumulativa sale a circa il 95%, che è un modo educato per dire quasi-certezza.
Ciò che rende il rischio di data breach insolito tra le voci di Likelier è che inverte lo schema abituale paura-vs-realtà. La maggior parte delle paure su questo sito è sovrastimata. L’esposizione ai data breach è, semmai, sottostimata — non perché la gente la pensi rara, ma perché raramente fa il calcolo cumulativo. Un trentacinquenne americano nel 2026 ha vissuto il breach di Equifax (147 milioni di record), il breach di Yahoo (3 miliardi di account), il breach di Change Healthcare e migliaia di incidenti minori. La probabilità che nessuno dei propri dati personali sia comparso in nessuno di quegli eventi è trascurabile. La disconnessione emotiva sta nel fatto che “esposizione” sembra astratta finché non si converte in furto d’identità o perdita finanziaria, cosa che accade a una frazione molto più piccola.
L’avvertenza importante è che “esposizione” non è “danno”. Il conteggio delle notifiche alle vittime dell’ITRC tratta un indirizzo email trapelato allo stesso modo di un Social Security number trapelato. La maggior parte dei record violati non produce mai un danno finanziario misurabile per l’individuo. La FTC ha ricevuto circa 1,1 milioni di reclami per furto d’identità nel 2024 — meno dello 0,1% del volume delle notifiche di breach. Quindi, mentre la probabilità di esposizione dei dati si avvicina a 1, la probabilità di danno consequente da un singolo breach rimane bassa. Il rischio è cumulativo e combinatorio: ogni esposizione aggiuntiva aggiunge un altro dato che può essere incrociato con le fughe precedenti, assemblando gradualmente un profilo più completo e più utile per un attaccante motivato.
Curiosità correlate
Circa il 95% di probabilità cumulativa nell'arco di una vita adulta che i tuoi dati personali vengano esposti in una violazione. Solo nel 2025 ci sono state circa 3.322 compromissioni di dati e circa 279 milioni di notifiche alle vittime.
Registro delle fonti
Ogni numero qui sotto è ciò che ciascuna fonte ha riportato, con la citazione testuale su cui ci siamo basati e come siamo arrivati alla nostra cifra. Clicca su qualsiasi link per verificare direttamente.
-
[1] Identity Theft Resource Center — Identity Theft Resource Center 2025 Annual Data Breach Report
Identity Theft Resource Center 2025 Annual Data Breach Report- Statistica
3,322 data compromises in 2025 with 278,827,933 victim notices; 5% increase in compromises over 2024; record number of tracked compromises- Estratto
“"The ITRC tracked a record 3,322 data compromises in 2025, a 5% increase over 2024. The number of victim notices was 278,827,933, a 79% decrease from 2024's 1,367,117,021, due to the absence of mega-breaches on the scale of Change Healthcare." ”
- Dati originali da
- 2026-01-29
- Consultato
- 2026-04-12 · copia archiviata
- Calcolo
- The 278.8 million victim notices in 2025 divided by ~335 million US population yields ~0.83 notices per person. But notices are not unique individuals — one person can receive multiple breach notifications. The ITRC notes that 70% of 2025 breach notices did not include attack-vector information, further complicating deduplication. The 2024 figure of 1.37 billion victim notices (driven by Change Healthcare's 190M+ exposure) illustrates how a single mega-breach can exceed the entire US population in notice count. For lifetime normalization, we use the conservative annual unique-individual rate of ~5% first-time exposure compounded over 59 years. Note: the ITRC is a 501(c)(3) nonprofit, not a government statistical agency; its breach counts rely on voluntary and regulatory disclosures rather than a census-grade collection mandate. No federal agency publishes a comparable all-sector breach tally, so ITRC is the best available source but carries the authority gap inherent in non-governmental data aggregation.
- Indipendenza
- ITRC compiles breach data from state attorney general notifications, SEC filings, and federal regulatory disclosures. It is independent of the FTC's Consumer Sentinel Network, which tracks consumer complaints rather than breach disclosures.
-
[2] Identity Theft Resource Center (via PR Newswire) — ITRC 2025 Annual Data Breach Report consumer survey (N=1,040)
ITRC 2025 Annual Data Breach Report consumer survey (N=1,040)- Statistica
In an ITRC consumer survey of 1,040 US adults, 80% reported receiving at least one data breach notice in the past 12 months and nearly 40% received three to five separate notices in the past year- Estratto
“"As part of the 20th anniversary of the Data Breach Report, the ITRC asked 1,040 consumers if they had received a data breach notice in the past 12 months. The survey reveals that data breaches are a near-universal experience for consumers, with 80 percent of respondents having received a data breach notice in the last 12 months. Nearly 40 percent of people responding to the survey received three to five separate notices in the past year." ”
- Dati originali da
- 2026-01-29
- Consultato
- 2026-06-14 · copia archiviata
- Calcolo
- This is the first direct, individual-level measurement of annual breach-notice incidence cited in this entry — prior figures were aggregate notice counts (which double-count individuals). An 80% one-year notice rate confirms empirically what the per-capita notice arithmetic only implied: annual breach exposure is near-universal for US adults with a digital footprint. Applied here as corroboration that tightens the lower bound of the lifetime uncertainty band — if 80% are notified in a single year, a sub-90% cumulative lifetime probability is no longer plausible. The point estimate is held at 0.95 rather than revised upward, because ITRC is a 501(c)(3) nonprofit reputable_reference, not a government statistical agency, and a revise of the headline number is reserved for official-agency updates. Survey caveat: self-reported recall over a 12-month window may overstate (notice fatigue conflating spam with real notices) or understate (forgotten or unopened notices) the true rate.
- Indipendenza
- This is the consumer-survey component of the same ITRC 2025 report whose breach counts are cited above; it is a methodologically distinct instrument (a polled sample of individuals) rather than the aggregate breach-notice tally, so it corroborates rather than restates the count-based figure.
-
[3] Verizon Business — 2024 Data Breach Investigations Report (DBIR)
2024 Data Breach Investigations Report (DBIR)- Statistica
Verizon DBIR 2024 analyzed 30,458 security incidents and 10,626 confirmed breaches across 94 countries, confirming that the majority of breaches involve stolen credentials or human error rather than sophisticated attacks- Estratto
“"This year's dataset includes 30,458 real-world security incidents, of which 10,626 (about one-third) were confirmed data breaches. 68 percent of breaches involved a non-malicious human element, such as a person falling victim to a social engineering attack or making an error." ”
- Dati originali da
- 2024-05-01
- Consultato
- 2026-04-16 · copia archiviata
- Calcolo
- Verizon DBIR does not publish a per-individual "exposure probability" — its unit of analysis is the incident/breach, not the person. Used here as a corroborating source for the claim that breaches are common, widely distributed, and driven by credential/phishing vectors rather than targeted attacks on individuals. This shifts the entry's framing from "probability of being a specific victim" to "probability of being swept up in aggregate exposure."
- Indipendenza
- Verizon DBIR aggregates incident data from ~100 contributing organizations (forensic firms, CSIRTs, law enforcement including US Secret Service). This is methodologically independent of ITRC's public-breach-notice tracking, which counts disclosed consumer breaches rather than investigated incidents.
-
[4] Identity Theft Resource Center — ITRC 2024 Annual Data Breach Report
ITRC 2024 Annual Data Breach Report- Statistica
3,158 data compromises in 2024 with 1,728,519,397 victim notices; 1.7 billion individuals' data compromised- Estratto
“"The number of data breach notices issued in 2024 (1,728,519,397) increased 312 percent from 2023 (419,337,446)... In 2024, six data breaches were reported that each involved more than 100 million records. More than 1.7 billion individuals had personal data compromised in 2024, and there were 3,158 data compromises." ”
- Dati originali da
- 2025-01-29
- Consultato
- 2026-04-12 · copia archiviata
- Calcolo
- The 2024 figure of 1.37 billion victim notices against a US population of ~335 million means the average American received roughly 4 breach notifications in a single year. This is consistent with the cumulative-near-certainty thesis: if breach exposure is this frequent in a single year, the probability of never being exposed over a full adult lifetime approaches zero. The 2024 figure is inflated by outlier mega-breaches and should not be used as a stable annual rate, which is why the 2025 figure is preferred for the central estimate.
- Indipendenza
- The 2024 Annual Data Breach Report is the prior-year edition from the same ITRC methodology; included for the 72% year-over-year record count rather than as an independent estimate.
-
[5] HIPAA Journal — Healthcare Data Breach Statistics
Healthcare Data Breach Statistics- Statistica
7,357 healthcare data breaches affecting 935.5 million records between 2009 and 2025 — more than 2.6x the US population- Estratto
“"Between 2009 and 2025, 7,357 healthcare data breaches of 500 or more records have been reported to the HHS Office for Civil Rights, resulting in the exposure of more than 935,521,931 healthcare records — more than 2.6 times the population of the United States." ”
- Dati originali da
- 2026-03-15
- Consultato
- 2026-04-12 · copia archiviata
- Calcolo
- Healthcare alone has exposed records equivalent to 2.6x the US population over 16 years. Even with substantial deduplication (same person, multiple breaches), this implies the vast majority of Americans with any healthcare history have had protected health information exposed at least once. Healthcare is one sector among many — financial services, retail, government, and education add further exposure. Used as corroborating evidence for the near-certainty cumulative estimate, not as the primary source.
- Indipendenza
- HIPAA Journal tracks breaches reported to the HHS Office for Civil Rights under the HIPAA Breach Notification Rule. This is a regulatory pipeline entirely independent of the ITRC's state-AG-based tracking.
-
[6] Federal Trade Commission (FTC) — Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach
Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach- Statistica
The 2017 Equifax data breach exposed approximately 147 million US consumers' sensitive personal information, including Social Security numbers, names, addresses, and dates of birth- Estratto
“"In September of 2017, Equifax, a nationwide credit reporting company headquartered in Atlanta, Georgia, announced that a data breach at the company resulted in the exposure of approximately 147 million U.S. consumers' sensitive personal information, including names, addresses, social security numbers, and dates of birth." ”
- Dati originali da
- 2019-07-22
- Consultato
- 2026-07-03 · copia archiviata
- Calcolo
- Cited in the body prose as a concrete, named illustration of the cumulative-exposure argument — a typical American adult has very likely had some personal data exposed in at least one major named breach. Not used in the lifetime-probability arithmetic itself, which relies on the ITRC annual victim-notice figures above; included only to ground the specific "Equifax breach (147 million records)" reference in the body text.
- Indipendenza
- FTC/CFPB regulatory settlement documentation, independent of the ITRC's breach-notice tracking and of Verizon's DBIR incident dataset.
-
[7] Wikipedia — Yahoo data breaches
Yahoo data breaches- Statistica
Yahoo's 2013 breach, initially disclosed in December 2016 as affecting 1 billion accounts, was revised in October 2017 to confirm all 3 billion Yahoo accounts existing at the time were compromised- Estratto
“"Almost a year later, in October 2017 they revised that estimate and reported that all three billion Yahoo accounts had been compromised in the breach." ”
- Dati originali da
- 2017-10-03
- Consultato
- 2026-07-03 · copia archiviata
- Calcolo
- Cited in the body prose alongside Equifax as a second concrete named mega-breach illustrating cumulative lifetime exposure. Not used in the lifetime-probability arithmetic. Grounds the "Yahoo breach (3 billion accounts)" reference in the body text; the 3-billion revision is corroborated by contemporaneous reporting (e.g. the Wall Street Journal's October 3, 2017 story "Yahoo Triples Estimate of Breached Accounts to 3 Billion," cited in this Wikipedia article's references) and Yahoo/Verizon's own SEC disclosures.
- Indipendenza
- Tertiary compilation source; the underlying disclosure is Yahoo's own 2017 SEC filings and contemporaneous news reporting. Included only as corroboration for a widely reported, uncontested figure not itself covered by this entry's other four sources.
-
[8] Federal Trade Commission (FTC) — Consumer Sentinel Network Data Book 2024
Consumer Sentinel Network Data Book 2024See all 4 Likelier entries citing this source →
- Statistica
FTC Consumer Sentinel Network received 6.5 million consumer reports in 2024; identity theft was the largest single category at approximately 1.1 million reports, about 17% of all reports- Estratto
“"During 2024, Sentinel received 6.5 million consumer reports, which the FTC has sorted into 29 top categories. ... In 2024, there were more than 1.1 million reports of identity theft received through the FTC's IdentityTheft.gov website." ”
- Dati originali da
- 2025-03-01
- Consultato
- 2026-07-03 · copia archiviata
- Calcolo
- Grounds the body prose's and caveats' "the FTC received about 1.1 million identity-theft complaints in 2024" reference (which previously named the FTC without a citation). Both figures are now quoted verbatim in the excerpt above: the 6.5-million-report total and the >1.1-million identity-theft figure, the latter the FTC's largest single Sentinel category (~1.1M / 6.5M ≈ 17% of all reports). Not used in this entry's headline lifetime-probability arithmetic, which relies on the ITRC breach-notice figures above; included only to ground the specific FTC identity-theft-complaint figure used in the body prose to distinguish "exposure" from "harm."
- Indipendenza
- FTC Consumer Sentinel Network is a distinct federal consumer-complaint intake pipeline, independent of the ITRC's breach-notice tracking and Verizon's incident-investigation dataset used elsewhere in this entry.






