Kwaliteit van bewijs 4.38/5
Beoordelingsscore op acht dimensies volgens de kwaliteitsrubriek . Elke dimensie krijgt een score van 1 tot 5.
- D1 Verankering in bronnen
- 5/5
- D2 Autoriteit van bronnen
- 4/5
- D3 Rekenkunde
- 4/5
- D4 Onzekerheid
- 4/5
- D5 Bereik
- 4/5
- D6 Proza
- 5/5
- D7 Eerlijkheid over perceptie
- 4/5
- D8 Volledigheid van voorbehouden
- 5/5
≈ Net zo waarschijnlijk als
Waargenomen
Gallup peilt niet specifiek naar datalekken, maar zijn dichtstbijzijnde proxy — identiteitsdiefstal — staat bovenaan de jaarlijkse lijst van criminaliteitszorgen. In de golf van oktober 2024 zei 69 % van de Amerikaanse volwassenen zich vaak of af en toe zorgen te maken over het gestolen worden van hun identiteit, het hoogste cijfer in de enquête. Omdat identiteitsdiefstal overweldigend voortkomt uit datalekken, is het cijfer van 69 % een redelijke proxy voor lek-gerelateerde angst. Een Pew Research-enquête uit 2023 vond afzonderlijk dat 79 % van de Amerikaanse volwassenen bezorgdheid uitte over hoe bedrijven hun persoonlijke gegevens gebruiken.
Ruwe schatting: 69 % van de Amerikaanse volwassenen maakt zich zorgen over identiteitsdiefstal, de dichtstbijzijnde proxy (Gallup 2024)
Werkelijk
~3.322 datalekken in 2025, ~279 miljoen slachtoffermeldingen
Amerikaanse individuen met gegevens die worden bewaard door organisaties die zijn getroffen door een datalek
Berekening tonen
Het Annual Data Breach Report 2025 van het ITRC registreerde 3.322 datalekken met 278,8 miljoen slachtoffermeldingen. In 2024 was het cijfer 1,35 miljard slachtoffermeldingen over 3.158 lekken (opgeblazen door mega-lekken zoals Change Healthcare met 190M+ records). Bij gebruik van het conservatievere cijfer van 2025 werden ongeveer 279 miljoen slachtoffermeldingen uitgegeven tegen een Amerikaanse bevolking van ~335 miljoen, wat impliceert dat ~83 % van de bevolking in één jaar ten minste één lekmelding ontving. Slachtoffermeldingen tellen echter individuen die door meerdere lekken zijn getroffen dubbel. Gecorrigeerd voor overlap met een capture-recapture-heuristiek wordt het jaarlijkse blootstellingspercentage van unieke individuen geschat op 35–50 %. Zelfs bij het conservatieve jaarlijkse percentage van 35 % geeft samenstelling over een volwassen leven van 59 jaar 1 − (1 − 0,35)^59 ≈ feitelijk 1,0. Bij gebruik van een gematigder jaarlijkse kans van 5 % op een allereerste blootstelling (voor iemand van wie de gegevens nog nooit eerder zijn gelekt — rekening houdend met het feit dat de meeste volwassenen al zijn blootgesteld) samengesteld over 59 jaar geeft 1 − (1 − 0,05)^59 ≈ 0,953. De centrale schatting van 95 % weerspiegelt de bijna-zekerheid van cumulatieve blootstelling, waarbij de onzekerheidsband de definitorische dubbelzinnigheid erkent rond wat telt als «uw» gegevens die worden «blootgesteld». De ondergrens werd in de beoordeling van 2026-06-14 verhoogd van 0,80 naar 0,90: de consumentenenquête 2025 van het ITRC (N=1.040) vond dat 80 % van de respondenten in de afgelopen 12 maanden ten minste één lekmelding ontving en bijna 40 % er drie tot vijf ontving — een bijna universeel blootstellingspercentage in één jaar dat een cumulatieve levenslange kans onder de 90 % onwaarschijnlijk maakt. De puntschatting wordt bewust op 0,95 gehouden in plaats van naar boven bijgesteld, omdat het ITRC een non-profit reputable_reference is in plaats van een overheidsstatistiekbureau en het glibberige onderscheid blootstelling-versus-schade adviseert tegen het kopcijfer dichter naar 1,0 te duwen.
Kanttekeningen: «Datalekblootstelling» is een definitorisch glibberig concept. Een lek dat uw na…
«Datalekblootstelling» is een definitorisch glibberig concept. Een lek dat uw naam en e-mailadres lekt, verschilt categorisch van een lek dat uw BSN, medische dossiers of financiële inloggegevens lekt — toch telt het ITRC ze identiek in zijn leklijsten. Het levenslange cijfer van 95 % betekent dat vrijwel elke volwassene met een digitale voetafdruk op enig moment enige gegevens blootgesteld zal zien; het betekent niet dat 95 % van de volwassenen financiële schade door een lek zal lijden. De omzettingsgraad van blootstelling naar daadwerkelijke identiteitsdiefstal of financieel verlies is veel lager — de FTC ontving in 2024 ongeveer 1,1 miljoen klachten over identiteitsdiefstal, een minuscule fractie van de aan lekken blootgestelde bevolking. Het getal is in zijn normalisatie ook Amerika-gericht, maar het verschijnsel is wereldwijd; lekcijfers in de EU en Azië-Pacific zijn vergelijkbaar. Ten slotte tellen «slachtoffermeldingen» unieke individuen te veel (één persoon ontvangt meerdere meldingen) en tellen ze tegelijkertijd de blootstelling te weinig (veel lekken blijven onopgemerkt of ongemeld, en 70 % van de meldingen van 2025 liet details over de aanvalsvector volledig weg). Een verdere complicatie is dat het kop-*volume* van blootstelling wordt gedomineerd door een handvol mega-lekken in plaats van de lange staart van incidenten. Het ITRC registreerde in 2025 een record van 3.322 lekken — 5 % meer dan in 2024 — maar de slachtoffermeldingen daalden met 79 %, van 1,37 miljard in 2024 naar 279 miljoen in 2025, simpelweg omdat 2025 geen enkel mega-lek kende op de schaal van het Change Healthcare-incident van 2024. Deze ontkoppeling betekent dat meldingsaantallen een slechte jaar-op-jaar-proxy zijn voor individueel risico: het aantal lekken steeg terwijl het gerapporteerde blootstellingsvolume instortte. De kans dat *u* elk jaar in blootstelling verzeild raakt, is bijna universeel en stabiel (de ITRC-enquête zet het op 80 % in één jaar); het ruwe meldingstotaal schommelt sterk afhankelijk van of een paar catastrofale lekken toevallig in dat kalenderjaar plaatsvonden.
Gerelateerde risico’s
Andere risico’s over vergelijkbare thema’s — om gerelateerde angsten te verkennen.
AI-stemoplichting
Wat is de kans dat u tijdens uw leven het doelwit wordt van een AI-stemklooningoplichting?
Kinderen & expliciete inhoud
Wat is de kans dat een kind online expliciete of gewelddadige inhoud tegenkomt vóór de leeftijd van 13 jaar?
Intieme deepfake
Wat is de kans dat tijdens uw leven een AI-gegenereerde intieme deepfake van u zonder toestemming wordt gemaakt of gedeeld?
Kies vergelijking
De vraag is niet of uw gegevens zijn blootgesteld bij een datalek. De vraag is hoe vaak. Het Identity Theft Resource Center registreerde een record van 3.322 datalekken in de Verenigde Staten in 2025, resulterend in ruwweg 279 miljoen slachtoffermeldingen. In 2024 was het cijfer 1,37 miljard meldingen — meer dan vier per Amerikaan — opgeblazen door mega-inbreuken zoals het Change Healthcare-incident dat alleen al meer dan 190 miljoen records blootlegde. Gezondheidszorggegevens alleen zijn al gelekt in een omvang van meer dan 2,6 keer de Amerikaanse bevolking sinds 2009. Zelfs bij een conservatief jaarlijks percentage van eerste blootstelling over een volwassen levensduur van 59 jaar stijgt de cumulatieve kans naar ruwweg 95%, wat een beleefde manier is om bijna-zekerheid te zeggen.
Wat datalekrisico ongebruikelijk maakt onder Likelier-items is dat het het normale patroon van angst-versus-werkelijkheid omkeert. De meeste angsten op deze site worden overschat. Datalekblootstelling wordt, zo al, onderschat — niet omdat mensen denken dat het zeldzaam is, maar omdat ze zelden de cumulatieve rekenkunde maken. Een 35-jarige Amerikaan in 2026 heeft de Equifax-inbreuk meegemaakt (147 miljoen records), de Yahoo-inbreuk (3 miljard accounts), de Change Healthcare-inbreuk, en duizenden kleinere incidenten. De kans dat geen van hun persoonlijke gegevens in een van die gebeurtenissen verscheen is verwaarloosbaar. De emotionele ontkoppeling is dat “blootstelling” abstract aanvoelt totdat het zich vertaalt in identiteitsdiefstal of financieel verlies, wat bij een veel kleiner deel van de gevallen optreedt.
Het belangrijke voorbehoud is dat “blootstelling” niet gelijk staat aan “schade”. De slachtoffermeldingstelling van het ITRC behandelt een gelekt e-mailadres hetzelfde als een gelekt BSN-nummer. De meeste gelekte records leiden nooit tot meetbare financiële schade voor het individu. De FTC ontving ongeveer 1,1 miljoen identiteitsdiefstalklachten in 2024 — minder dan 0,1% van het volume aan lekmeldingen. Dus hoewel de kans op datablootstelling naar 1 nadert, blijft de kans op wezenlijke schade door een willekeurig lek laag. Het risico is cumulatief en combinatorisch: elke extra blootstelling voegt een datapunt toe dat kan worden gekruist met eerdere lekken, waardoor geleidelijk een completer profiel ontstaat dat nuttiger is voor een gemotiveerde aanvaller.
Gerelateerde weetjes
Ongeveer 95% cumulatieve kans gedurende een volwassen leven dat je persoonsgegevens worden blootgesteld bij een datalek. Alleen al in 2025 waren er ongeveer 3.322 datacompromittaties en zo'n 279 miljoen meldingen aan slachtoffers.
Bronnenverantwoording
Elk getal hieronder is wat elke bron rapporteerde, met het letterlijke citaat waarop we ons baseerden en hoe we tot ons cijfer kwamen. Klik op een link om rechtstreeks te verifiëren.
-
[1] Identity Theft Resource Center — Identity Theft Resource Center 2025 Annual Data Breach Report
Identity Theft Resource Center 2025 Annual Data Breach Report- Statistiek
3,322 data compromises in 2025 with 278,827,933 victim notices; 5% increase in compromises over 2024; record number of tracked compromises- Fragment
“"The ITRC tracked a record 3,322 data compromises in 2025, a 5% increase over 2024. The number of victim notices was 278,827,933, a 79% decrease from 2024's 1,367,117,021, due to the absence of mega-breaches on the scale of Change Healthcare." ”
- Brongegevens van
- 2026-01-29
- Geraadpleegd
- 2026-04-12 · gearchiveerde kopie
- Berekening
- The 278.8 million victim notices in 2025 divided by ~335 million US population yields ~0.83 notices per person. But notices are not unique individuals — one person can receive multiple breach notifications. The ITRC notes that 70% of 2025 breach notices did not include attack-vector information, further complicating deduplication. The 2024 figure of 1.37 billion victim notices (driven by Change Healthcare's 190M+ exposure) illustrates how a single mega-breach can exceed the entire US population in notice count. For lifetime normalization, we use the conservative annual unique-individual rate of ~5% first-time exposure compounded over 59 years. Note: the ITRC is a 501(c)(3) nonprofit, not a government statistical agency; its breach counts rely on voluntary and regulatory disclosures rather than a census-grade collection mandate. No federal agency publishes a comparable all-sector breach tally, so ITRC is the best available source but carries the authority gap inherent in non-governmental data aggregation.
- Onafhankelijkheid
- ITRC compiles breach data from state attorney general notifications, SEC filings, and federal regulatory disclosures. It is independent of the FTC's Consumer Sentinel Network, which tracks consumer complaints rather than breach disclosures.
-
[2] Identity Theft Resource Center (via PR Newswire) — ITRC 2025 Annual Data Breach Report consumer survey (N=1,040)
ITRC 2025 Annual Data Breach Report consumer survey (N=1,040)- Statistiek
In an ITRC consumer survey of 1,040 US adults, 80% reported receiving at least one data breach notice in the past 12 months and nearly 40% received three to five separate notices in the past year- Fragment
“"As part of the 20th anniversary of the Data Breach Report, the ITRC asked 1,040 consumers if they had received a data breach notice in the past 12 months. The survey reveals that data breaches are a near-universal experience for consumers, with 80 percent of respondents having received a data breach notice in the last 12 months. Nearly 40 percent of people responding to the survey received three to five separate notices in the past year." ”
- Brongegevens van
- 2026-01-29
- Geraadpleegd
- 2026-06-14 · gearchiveerde kopie
- Berekening
- This is the first direct, individual-level measurement of annual breach-notice incidence cited in this entry — prior figures were aggregate notice counts (which double-count individuals). An 80% one-year notice rate confirms empirically what the per-capita notice arithmetic only implied: annual breach exposure is near-universal for US adults with a digital footprint. Applied here as corroboration that tightens the lower bound of the lifetime uncertainty band — if 80% are notified in a single year, a sub-90% cumulative lifetime probability is no longer plausible. The point estimate is held at 0.95 rather than revised upward, because ITRC is a 501(c)(3) nonprofit reputable_reference, not a government statistical agency, and a revise of the headline number is reserved for official-agency updates. Survey caveat: self-reported recall over a 12-month window may overstate (notice fatigue conflating spam with real notices) or understate (forgotten or unopened notices) the true rate.
- Onafhankelijkheid
- This is the consumer-survey component of the same ITRC 2025 report whose breach counts are cited above; it is a methodologically distinct instrument (a polled sample of individuals) rather than the aggregate breach-notice tally, so it corroborates rather than restates the count-based figure.
-
[3] Verizon Business — 2024 Data Breach Investigations Report (DBIR)
2024 Data Breach Investigations Report (DBIR)- Statistiek
Verizon DBIR 2024 analyzed 30,458 security incidents and 10,626 confirmed breaches across 94 countries, confirming that the majority of breaches involve stolen credentials or human error rather than sophisticated attacks- Fragment
“"This year's dataset includes 30,458 real-world security incidents, of which 10,626 (about one-third) were confirmed data breaches. 68 percent of breaches involved a non-malicious human element, such as a person falling victim to a social engineering attack or making an error." ”
- Brongegevens van
- 2024-05-01
- Geraadpleegd
- 2026-04-16 · gearchiveerde kopie
- Berekening
- Verizon DBIR does not publish a per-individual "exposure probability" — its unit of analysis is the incident/breach, not the person. Used here as a corroborating source for the claim that breaches are common, widely distributed, and driven by credential/phishing vectors rather than targeted attacks on individuals. This shifts the entry's framing from "probability of being a specific victim" to "probability of being swept up in aggregate exposure."
- Onafhankelijkheid
- Verizon DBIR aggregates incident data from ~100 contributing organizations (forensic firms, CSIRTs, law enforcement including US Secret Service). This is methodologically independent of ITRC's public-breach-notice tracking, which counts disclosed consumer breaches rather than investigated incidents.
-
[4] Identity Theft Resource Center — ITRC 2024 Annual Data Breach Report
ITRC 2024 Annual Data Breach Report- Statistiek
3,158 data compromises in 2024 with 1,728,519,397 victim notices; 1.7 billion individuals' data compromised- Fragment
“"The number of data breach notices issued in 2024 (1,728,519,397) increased 312 percent from 2023 (419,337,446)... In 2024, six data breaches were reported that each involved more than 100 million records. More than 1.7 billion individuals had personal data compromised in 2024, and there were 3,158 data compromises." ”
- Brongegevens van
- 2025-01-29
- Geraadpleegd
- 2026-04-12 · gearchiveerde kopie
- Berekening
- The 2024 figure of 1.37 billion victim notices against a US population of ~335 million means the average American received roughly 4 breach notifications in a single year. This is consistent with the cumulative-near-certainty thesis: if breach exposure is this frequent in a single year, the probability of never being exposed over a full adult lifetime approaches zero. The 2024 figure is inflated by outlier mega-breaches and should not be used as a stable annual rate, which is why the 2025 figure is preferred for the central estimate.
- Onafhankelijkheid
- The 2024 Annual Data Breach Report is the prior-year edition from the same ITRC methodology; included for the 72% year-over-year record count rather than as an independent estimate.
-
[5] HIPAA Journal — Healthcare Data Breach Statistics
Healthcare Data Breach Statistics- Statistiek
7,357 healthcare data breaches affecting 935.5 million records between 2009 and 2025 — more than 2.6x the US population- Fragment
“"Between 2009 and 2025, 7,357 healthcare data breaches of 500 or more records have been reported to the HHS Office for Civil Rights, resulting in the exposure of more than 935,521,931 healthcare records — more than 2.6 times the population of the United States." ”
- Brongegevens van
- 2026-03-15
- Geraadpleegd
- 2026-04-12 · gearchiveerde kopie
- Berekening
- Healthcare alone has exposed records equivalent to 2.6x the US population over 16 years. Even with substantial deduplication (same person, multiple breaches), this implies the vast majority of Americans with any healthcare history have had protected health information exposed at least once. Healthcare is one sector among many — financial services, retail, government, and education add further exposure. Used as corroborating evidence for the near-certainty cumulative estimate, not as the primary source.
- Onafhankelijkheid
- HIPAA Journal tracks breaches reported to the HHS Office for Civil Rights under the HIPAA Breach Notification Rule. This is a regulatory pipeline entirely independent of the ITRC's state-AG-based tracking.
-
[6] Federal Trade Commission (FTC) — Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach
Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach- Statistiek
The 2017 Equifax data breach exposed approximately 147 million US consumers' sensitive personal information, including Social Security numbers, names, addresses, and dates of birth- Fragment
“"In September of 2017, Equifax, a nationwide credit reporting company headquartered in Atlanta, Georgia, announced that a data breach at the company resulted in the exposure of approximately 147 million U.S. consumers' sensitive personal information, including names, addresses, social security numbers, and dates of birth." ”
- Brongegevens van
- 2019-07-22
- Geraadpleegd
- 2026-07-03 · gearchiveerde kopie
- Berekening
- Cited in the body prose as a concrete, named illustration of the cumulative-exposure argument — a typical American adult has very likely had some personal data exposed in at least one major named breach. Not used in the lifetime-probability arithmetic itself, which relies on the ITRC annual victim-notice figures above; included only to ground the specific "Equifax breach (147 million records)" reference in the body text.
- Onafhankelijkheid
- FTC/CFPB regulatory settlement documentation, independent of the ITRC's breach-notice tracking and of Verizon's DBIR incident dataset.
-
[7] Wikipedia — Yahoo data breaches
Yahoo data breaches- Statistiek
Yahoo's 2013 breach, initially disclosed in December 2016 as affecting 1 billion accounts, was revised in October 2017 to confirm all 3 billion Yahoo accounts existing at the time were compromised- Fragment
“"Almost a year later, in October 2017 they revised that estimate and reported that all three billion Yahoo accounts had been compromised in the breach." ”
- Brongegevens van
- 2017-10-03
- Geraadpleegd
- 2026-07-03 · gearchiveerde kopie
- Berekening
- Cited in the body prose alongside Equifax as a second concrete named mega-breach illustrating cumulative lifetime exposure. Not used in the lifetime-probability arithmetic. Grounds the "Yahoo breach (3 billion accounts)" reference in the body text; the 3-billion revision is corroborated by contemporaneous reporting (e.g. the Wall Street Journal's October 3, 2017 story "Yahoo Triples Estimate of Breached Accounts to 3 Billion," cited in this Wikipedia article's references) and Yahoo/Verizon's own SEC disclosures.
- Onafhankelijkheid
- Tertiary compilation source; the underlying disclosure is Yahoo's own 2017 SEC filings and contemporaneous news reporting. Included only as corroboration for a widely reported, uncontested figure not itself covered by this entry's other four sources.
-
[8] Federal Trade Commission (FTC) — Consumer Sentinel Network Data Book 2024
Consumer Sentinel Network Data Book 2024See all 4 Likelier entries citing this source →
- Statistiek
FTC Consumer Sentinel Network received 6.5 million consumer reports in 2024; identity theft was the largest single category at approximately 1.1 million reports, about 17% of all reports- Fragment
“"During 2024, Sentinel received 6.5 million consumer reports, which the FTC has sorted into 29 top categories. ... In 2024, there were more than 1.1 million reports of identity theft received through the FTC's IdentityTheft.gov website." ”
- Brongegevens van
- 2025-03-01
- Geraadpleegd
- 2026-07-03 · gearchiveerde kopie
- Berekening
- Grounds the body prose's and caveats' "the FTC received about 1.1 million identity-theft complaints in 2024" reference (which previously named the FTC without a citation). Both figures are now quoted verbatim in the excerpt above: the 6.5-million-report total and the >1.1-million identity-theft figure, the latter the FTC's largest single Sentinel category (~1.1M / 6.5M ≈ 17% of all reports). Not used in this entry's headline lifetime-probability arithmetic, which relies on the ITRC breach-notice figures above; included only to ground the specific FTC identity-theft-complaint figure used in the body prose to distinguish "exposure" from "harm."
- Onafhankelijkheid
- FTC Consumer Sentinel Network is a distinct federal consumer-complaint intake pipeline, independent of the ITRC's breach-notice tracking and Verizon's incident-investigation dataset used elsewhere in this entry.






