証拠の質 4.38/5
8次元のレビュー評価。基準は 品質ルーブリック 。各次元は1〜5で評価。
- D1 出典への根拠
- 5/5
- D2 出典の権威性
- 4/5
- D3 算術
- 4/5
- D4 不確実性
- 4/5
- D5 範囲
- 4/5
- D6 文章
- 5/5
- D7 認識の誠実性
- 4/5
- D8 注意事項の完全性
- 5/5
認知リスク
Gallupはデータ漏洩そのものを調査していませんが、最も近い代理指標である個人情報窃盗は、毎年の犯罪不安リストの首位にあります。2024年10月の調査回では、米国成人の69%が個人情報を盗まれることを頻繁にまたは時折心配していると答え、この調査で最も高い数値でした。個人情報窃盗は圧倒的にデータ漏洩の下流で起こるため、69%という数値は漏洩関連の不安の妥当な代理指標です。2023年のPew Researchの調査では、別途、米国成人の79%が企業による個人データの利用方法に懸念を示したことがわかっています。
概算: 米国成人の69%が、最も近い代理指標である個人情報窃盗を心配しています(Gallup 2024年)
実際のリスク
2025年に~3,322件のデータ侵害、~279 million件の被害者通知
漏洩した組織にデータを保有されている米国の個人
計算を表示
ITRCの2025年年次データ漏洩報告書は、3,322件のデータ侵害と278.8 million件の被害者通知を記録しました。2024年の数値は3,158件の侵害に対して1.35 billion件の被害者通知でした(190M+件の記録が流出したChange Healthcareのようなメガブリーチにより膨張)。より保守的な2025年の数値を用いると、米国の人口~335 millionに対して約279 million件の被害者通知が発行され、人口の~83%が1年間に少なくとも1件の漏洩通知を受け取ったことが示唆されます。ただし、被害者通知は複数の漏洩の影響を受けた個人を二重計上します。捕獲再捕獲のヒューリスティックで重複を調整すると、年間のユニーク個人曝露率は35~50%と推定されます。保守的な35%の年間率でも、59年間の成人生涯で複利計算すると 1 − (1 − 0.35)^59 ≈ 事実上1.0になります。より穏当な、初めての流出の年間確率5%(これまで一度もデータが漏洩したことのない人についてのもので、ほとんどの成人がすでに流出済みであるという事実を考慮)を59年間で複利計算すると、1 − (1 − 0.05)^59 ≈ 0.953となります。95%という中心推定値は累積曝露のほぼ確実性を反映しており、不確実性の幅は「あなたの」データが「流出する」とは何を指すのかという定義上の曖昧さを認めるものです。下限は2026-06-14のレビューで0.80から0.90に引き上げられました。ITRCの2025年消費者調査(N=1,040)では、回答者の80%が過去12か月間に少なくとも1件の漏洩通知を受け取り、40%近くが3~5件の通知を受け取ったことがわかりました。この単年でほぼ全員に及ぶ曝露率は、90%未満の累積生涯確率をあり得ないものにします。点推定値は意図的に上方修正せず0.95に据え置かれています。ITRCは政府の統計機関ではなく非営利のreputable_referenceであり、曝露と被害というつかみどころのない区別が、見出しを1.0に近づけることを戒めるためです。
注意事項: 「データ漏洩による曝露」は定義上つかみどころのない概念です。氏名とメールアドレスを漏らす漏洩は、社会保障番号、医療記録、金融認証情報を漏らす漏洩とはカテゴリー的…
「データ漏洩による曝露」は定義上つかみどころのない概念です。氏名とメールアドレスを漏らす漏洩は、社会保障番号、医療記録、金融認証情報を漏らす漏洩とはカテゴリー的に異なりますが、ITRCは侵害集計においてこれらを同一に数えます。95%という生涯数値は、デジタルフットプリントを持つ事実上すべての成人が、いつかの時点で何らかのデータを流出させられることを意味します。成人の95%が漏洩から金銭的被害を受けるという意味ではありません。曝露から実際の個人情報窃盗や金銭的損失への転換率ははるかに低く、FTCは2024年に約1.1 million件の個人情報窃盗の苦情を受理しましたが、これは漏洩に曝露された人口のごく一部です。この数値の正規化は米国中心ですが、現象自体は世界的であり、EUやアジア太平洋の漏洩率も同程度です。最後に、「被害者通知」はユニークな個人を過大計上し(一人が複数の通知を受け取る)、同時に曝露を過小計上します(多くの漏洩は検出も報告もされず、2025年の通知の70%は攻撃経路の詳細を完全に省略していました)。さらに厄介なのは、見出しとなる曝露の総量が、事案のロングテールではなく一握りのメガブリーチに支配されていることです。ITRCは2025年に過去最多の3,322件の侵害を追跡しましたが(2024年比5%増)、被害者通知は2024年の1.37 billion件から2025年の279 million件へと79%減少しました。これは単に、2025年には2024年のChange Healthcare事案の規模のメガブリーチがなかったためです。この乖離は、通知件数が個人リスクの年次比較の代理指標として不適切であることを意味します。漏洩件数は増加した一方で、報告された曝露量は崩落しました。「あなた」が毎年曝露に巻き込まれる確率はほぼ全員に及び安定しています(ITRCの調査では単年で80%)。通知の生の総数は、その暦年にたまたま少数の壊滅的な漏洩が発生したかどうかで大きく変動します。
関連するリスク
似たテーマの他のリスク — 関連する不安を探るために。
比較対象を選択
問題は、あなたのデータがデータ漏洩で流出したかどうかではありません。何回流出したかです。Identity Theft Resource Centerは、2025年に米国で過去最多の3,322件のデータ侵害を追跡し、約2億7,900万件の被害者通知が発行されました。2024年には13億7,000万件以上の通知が発行されました。これはアメリカ人1人あたり4件以上に相当し、Change Healthcareの事案だけで1億9,000万件以上の記録が流出するメガブリーチが主な原因です。医療データだけでも、2009年以降に米国人口の2.6倍に相当する規模の漏洩が発生しています。保守的な年間初回流出率を59年間の成人生涯にわたって累積すると、累積確率は約**95%**に達します。これは「ほぼ確実」を丁寧に表現した数値です。
Likelierのエントリーの中でデータ漏洩リスクが特異なのは、通常の恐怖と現実のパターンが逆転していることです。このサイトのほとんどの恐怖は過大評価されています。データ漏洩の曝露はむしろ過小評価されています。人々がそれを稀だと思っているからではなく、累積的な算術をほとんど計算しないためです。2026年に35歳のアメリカ人は、Equifaxの漏洩(1億4,700万件)、Yahooの漏洩(30億アカウント)、Change Healthcareの漏洩、そして数千件の小規模な事案を経験しています。これらのいずれにも自分の個人データが含まれていなかった確率は、ほぼゼロです。感情的な断絶は、「流出」が個人情報窃盗や金銭的損失に転化するまでは抽象的に感じられることにあり、それが実際に起こるのはずっと少ない割合です。
重要な注意点は、「流出」は「被害」ではないということです。ITRCの被害者通知件数は、メールアドレスの漏洩も社会保障番号の漏洩も同じように扱います。漏洩した記録のほとんどは、個人に対する測定可能な金銭的損害には至りません。FTCは2024年に約110万件の個人情報窃盗の苦情を受理しましたが、これは漏洩通知件数の0.1%未満です。したがって、データ流出の確率は1に近づきますが、特定の漏洩による実害の確率は依然として低いままです。リスクは累積的かつ組み合わせ的です。追加の流出が起きるたびに、過去の漏洩と照合可能な新たなデータポイントが加わり、動機のある攻撃者にとってより有用な、より完全なプロファイルが徐々に組み上がっていきます。
関連する豆知識
成人の生涯を通じて、あなたの個人データが漏洩で流出する累積確率は約95%。2025年だけで約3,322件のデータ侵害が発生し、約2億7,900万件の被害通知が送られた。
根拠台帳
以下の各数値は各出典が報告した内容であり、引用した原文の抜粋と算出方法を記載しています。リンクをクリックして直接確認できます。
-
[1] Identity Theft Resource Center — Identity Theft Resource Center 2025 Annual Data Breach Report
Identity Theft Resource Center 2025 Annual Data Breach Report- 統計値
3,322 data compromises in 2025 with 278,827,933 victim notices; 5% increase in compromises over 2024; record number of tracked compromises- 抜粋
“"The ITRC tracked a record 3,322 data compromises in 2025, a 5% increase over 2024. The number of victim notices was 278,827,933, a 79% decrease from 2024's 1,367,117,021, due to the absence of mega-breaches on the scale of Change Healthcare." ”
- 出典データ
- 2026-01-29
- アクセス日
- 2026-04-12 · アーカイブ版
- 計算過程
- The 278.8 million victim notices in 2025 divided by ~335 million US population yields ~0.83 notices per person. But notices are not unique individuals — one person can receive multiple breach notifications. The ITRC notes that 70% of 2025 breach notices did not include attack-vector information, further complicating deduplication. The 2024 figure of 1.37 billion victim notices (driven by Change Healthcare's 190M+ exposure) illustrates how a single mega-breach can exceed the entire US population in notice count. For lifetime normalization, we use the conservative annual unique-individual rate of ~5% first-time exposure compounded over 59 years. Note: the ITRC is a 501(c)(3) nonprofit, not a government statistical agency; its breach counts rely on voluntary and regulatory disclosures rather than a census-grade collection mandate. No federal agency publishes a comparable all-sector breach tally, so ITRC is the best available source but carries the authority gap inherent in non-governmental data aggregation.
- 独立性
- ITRC compiles breach data from state attorney general notifications, SEC filings, and federal regulatory disclosures. It is independent of the FTC's Consumer Sentinel Network, which tracks consumer complaints rather than breach disclosures.
-
[2] Identity Theft Resource Center (via PR Newswire) — ITRC 2025 Annual Data Breach Report consumer survey (N=1,040)
ITRC 2025 Annual Data Breach Report consumer survey (N=1,040)- 統計値
In an ITRC consumer survey of 1,040 US adults, 80% reported receiving at least one data breach notice in the past 12 months and nearly 40% received three to five separate notices in the past year- 抜粋
“"As part of the 20th anniversary of the Data Breach Report, the ITRC asked 1,040 consumers if they had received a data breach notice in the past 12 months. The survey reveals that data breaches are a near-universal experience for consumers, with 80 percent of respondents having received a data breach notice in the last 12 months. Nearly 40 percent of people responding to the survey received three to five separate notices in the past year." ”
- 出典データ
- 2026-01-29
- アクセス日
- 2026-06-14 · アーカイブ版
- 計算過程
- This is the first direct, individual-level measurement of annual breach-notice incidence cited in this entry — prior figures were aggregate notice counts (which double-count individuals). An 80% one-year notice rate confirms empirically what the per-capita notice arithmetic only implied: annual breach exposure is near-universal for US adults with a digital footprint. Applied here as corroboration that tightens the lower bound of the lifetime uncertainty band — if 80% are notified in a single year, a sub-90% cumulative lifetime probability is no longer plausible. The point estimate is held at 0.95 rather than revised upward, because ITRC is a 501(c)(3) nonprofit reputable_reference, not a government statistical agency, and a revise of the headline number is reserved for official-agency updates. Survey caveat: self-reported recall over a 12-month window may overstate (notice fatigue conflating spam with real notices) or understate (forgotten or unopened notices) the true rate.
- 独立性
- This is the consumer-survey component of the same ITRC 2025 report whose breach counts are cited above; it is a methodologically distinct instrument (a polled sample of individuals) rather than the aggregate breach-notice tally, so it corroborates rather than restates the count-based figure.
-
[3] Verizon Business — 2024 Data Breach Investigations Report (DBIR)
2024 Data Breach Investigations Report (DBIR)- 統計値
Verizon DBIR 2024 analyzed 30,458 security incidents and 10,626 confirmed breaches across 94 countries, confirming that the majority of breaches involve stolen credentials or human error rather than sophisticated attacks- 抜粋
“"This year's dataset includes 30,458 real-world security incidents, of which 10,626 (about one-third) were confirmed data breaches. 68 percent of breaches involved a non-malicious human element, such as a person falling victim to a social engineering attack or making an error." ”
- 出典データ
- 2024-05-01
- アクセス日
- 2026-04-16 · アーカイブ版
- 計算過程
- Verizon DBIR does not publish a per-individual "exposure probability" — its unit of analysis is the incident/breach, not the person. Used here as a corroborating source for the claim that breaches are common, widely distributed, and driven by credential/phishing vectors rather than targeted attacks on individuals. This shifts the entry's framing from "probability of being a specific victim" to "probability of being swept up in aggregate exposure."
- 独立性
- Verizon DBIR aggregates incident data from ~100 contributing organizations (forensic firms, CSIRTs, law enforcement including US Secret Service). This is methodologically independent of ITRC's public-breach-notice tracking, which counts disclosed consumer breaches rather than investigated incidents.
-
[4] Identity Theft Resource Center — ITRC 2024 Annual Data Breach Report
ITRC 2024 Annual Data Breach Report- 統計値
3,158 data compromises in 2024 with 1,728,519,397 victim notices; 1.7 billion individuals' data compromised- 抜粋
“"The number of data breach notices issued in 2024 (1,728,519,397) increased 312 percent from 2023 (419,337,446)... In 2024, six data breaches were reported that each involved more than 100 million records. More than 1.7 billion individuals had personal data compromised in 2024, and there were 3,158 data compromises." ”
- 出典データ
- 2025-01-29
- アクセス日
- 2026-04-12 · アーカイブ版
- 計算過程
- The 2024 figure of 1.37 billion victim notices against a US population of ~335 million means the average American received roughly 4 breach notifications in a single year. This is consistent with the cumulative-near-certainty thesis: if breach exposure is this frequent in a single year, the probability of never being exposed over a full adult lifetime approaches zero. The 2024 figure is inflated by outlier mega-breaches and should not be used as a stable annual rate, which is why the 2025 figure is preferred for the central estimate.
- 独立性
- The 2024 Annual Data Breach Report is the prior-year edition from the same ITRC methodology; included for the 72% year-over-year record count rather than as an independent estimate.
-
[5] HIPAA Journal — Healthcare Data Breach Statistics
Healthcare Data Breach Statistics- 統計値
7,357 healthcare data breaches affecting 935.5 million records between 2009 and 2025 — more than 2.6x the US population- 抜粋
“"Between 2009 and 2025, 7,357 healthcare data breaches of 500 or more records have been reported to the HHS Office for Civil Rights, resulting in the exposure of more than 935,521,931 healthcare records — more than 2.6 times the population of the United States." ”
- 出典データ
- 2026-03-15
- アクセス日
- 2026-04-12 · アーカイブ版
- 計算過程
- Healthcare alone has exposed records equivalent to 2.6x the US population over 16 years. Even with substantial deduplication (same person, multiple breaches), this implies the vast majority of Americans with any healthcare history have had protected health information exposed at least once. Healthcare is one sector among many — financial services, retail, government, and education add further exposure. Used as corroborating evidence for the near-certainty cumulative estimate, not as the primary source.
- 独立性
- HIPAA Journal tracks breaches reported to the HHS Office for Civil Rights under the HIPAA Breach Notification Rule. This is a regulatory pipeline entirely independent of the ITRC's state-AG-based tracking.
-
[6] Federal Trade Commission (FTC) — Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach
Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach- 統計値
The 2017 Equifax data breach exposed approximately 147 million US consumers' sensitive personal information, including Social Security numbers, names, addresses, and dates of birth- 抜粋
“"In September of 2017, Equifax, a nationwide credit reporting company headquartered in Atlanta, Georgia, announced that a data breach at the company resulted in the exposure of approximately 147 million U.S. consumers' sensitive personal information, including names, addresses, social security numbers, and dates of birth." ”
- 出典データ
- 2019-07-22
- アクセス日
- 2026-07-03 · アーカイブ版
- 計算過程
- Cited in the body prose as a concrete, named illustration of the cumulative-exposure argument — a typical American adult has very likely had some personal data exposed in at least one major named breach. Not used in the lifetime-probability arithmetic itself, which relies on the ITRC annual victim-notice figures above; included only to ground the specific "Equifax breach (147 million records)" reference in the body text.
- 独立性
- FTC/CFPB regulatory settlement documentation, independent of the ITRC's breach-notice tracking and of Verizon's DBIR incident dataset.
-
[7] Wikipedia — Yahoo data breaches
Yahoo data breaches- 統計値
Yahoo's 2013 breach, initially disclosed in December 2016 as affecting 1 billion accounts, was revised in October 2017 to confirm all 3 billion Yahoo accounts existing at the time were compromised- 抜粋
“"Almost a year later, in October 2017 they revised that estimate and reported that all three billion Yahoo accounts had been compromised in the breach." ”
- 出典データ
- 2017-10-03
- アクセス日
- 2026-07-03 · アーカイブ版
- 計算過程
- Cited in the body prose alongside Equifax as a second concrete named mega-breach illustrating cumulative lifetime exposure. Not used in the lifetime-probability arithmetic. Grounds the "Yahoo breach (3 billion accounts)" reference in the body text; the 3-billion revision is corroborated by contemporaneous reporting (e.g. the Wall Street Journal's October 3, 2017 story "Yahoo Triples Estimate of Breached Accounts to 3 Billion," cited in this Wikipedia article's references) and Yahoo/Verizon's own SEC disclosures.
- 独立性
- Tertiary compilation source; the underlying disclosure is Yahoo's own 2017 SEC filings and contemporaneous news reporting. Included only as corroboration for a widely reported, uncontested figure not itself covered by this entry's other four sources.
-
[8] Federal Trade Commission (FTC) — Consumer Sentinel Network Data Book 2024
Consumer Sentinel Network Data Book 2024See all 4 Likelier entries citing this source →
- 統計値
FTC Consumer Sentinel Network received 6.5 million consumer reports in 2024; identity theft was the largest single category at approximately 1.1 million reports, about 17% of all reports- 抜粋
“"During 2024, Sentinel received 6.5 million consumer reports, which the FTC has sorted into 29 top categories. ... In 2024, there were more than 1.1 million reports of identity theft received through the FTC's IdentityTheft.gov website." ”
- 出典データ
- 2025-03-01
- アクセス日
- 2026-07-03 · アーカイブ版
- 計算過程
- Grounds the body prose's and caveats' "the FTC received about 1.1 million identity-theft complaints in 2024" reference (which previously named the FTC without a citation). Both figures are now quoted verbatim in the excerpt above: the 6.5-million-report total and the >1.1-million identity-theft figure, the latter the FTC's largest single Sentinel category (~1.1M / 6.5M ≈ 17% of all reports). Not used in this entry's headline lifetime-probability arithmetic, which relies on the ITRC breach-notice figures above; included only to ground the specific FTC identity-theft-complaint figure used in the body prose to distinguish "exposure" from "harm."
- 独立性
- FTC Consumer Sentinel Network is a distinct federal consumer-complaint intake pipeline, independent of the ITRC's breach-notice tracking and Verizon's incident-investigation dataset used elsewhere in this entry.






