Качество доказательств 4.38/5
Оценка по восьми измерениям согласно рубрике качества . Каждое измерение оценивается от 1 до 5.
- D1 Обоснованность источниками
- 5/5
- D2 Авторитетность источника
- 4/5
- D3 Арифметика
- 4/5
- D4 Неопределённость
- 4/5
- D5 Охват
- 4/5
- D6 Текст
- 5/5
- D7 Честность восприятия
- 4/5
- D8 Полнота оговорок
- 5/5
≈ Так же вероятно, как
Воспринимаемый
Gallup не опрашивает об утечках данных конкретно, но её ближайший заменитель — кража личных данных — возглавляет ежегодный список опасений о преступности. В октябрьской волне 2024 года 69 % взрослых американцев сказали, что часто или иногда беспокоятся о краже их личности — наивысший показатель в опросе. Поскольку кража личных данных подавляюще является следствием утечек данных, показатель 69 % — разумный заменитель для тревоги, связанной с утечками. Отдельный опрос Pew Research 2023 года показал, что 79 % взрослых американцев выразили обеспокоенность тем, как компании используют их личные данные.
Грубая оценка: 69 % взрослых американцев беспокоятся о краже личных данных — ближайший заменитель (Gallup 2024)
Фактический
~3 322 случая компрометации данных в 2025 году, ~279 миллионов уведомлений жертвам
жители США, чьи данные хранились у организаций, подвергшихся утечке
Показать вычисления
Годовой отчёт ITRC об утечках данных за 2025 год зафиксировал 3 322 случая компрометации данных с 278,8 миллиона уведомлений жертвам. В 2024 году эта цифра составила 1,35 миллиарда уведомлений жертвам по 3 158 случаям компрометации (завышена мега-утечками вроде Change Healthcare с 190 млн+ записей). Используя более консервативную цифру 2025 года, примерно 279 миллионов уведомлений жертвам были разосланы против населения США в ~335 миллионов, что подразумевает, что ~83 % населения получили хотя бы одно уведомление об утечке за один год. Однако уведомления жертвам дважды считают людей, затронутых несколькими утечками. С поправкой на пересечение по эвристике повторного захвата годовая частота раскрытия по уникальным лицам оценивается в 35–50 %. Даже при консервативной годовой ставке 35 % сложение за 59-летнюю взрослую жизнь даёт 1 − (1 − 0,35)^59 ≈ фактически 1,0. Использование более умеренной 5-процентной годовой вероятности первого в жизни раскрытия (для того, чьи данные никогда ранее не были раскрыты, — с учётом того, что большинство взрослых уже раскрыты), сложенной за 59 лет, даёт 1 − (1 − 0,05)^59 ≈ 0,953. Центральная оценка 95 % отражает почти-неизбежность кумулятивного раскрытия, а диапазон неопределённости признаёт определительную неоднозначность вокруг того, что считается раскрытием «ваших» данных. Нижняя граница была поднята с 0,80 до 0,90 в обзоре от 2026-06-14: потребительский опрос ITRC 2025 года (N=1 040) показал, что 80 % респондентов получили хотя бы одно уведомление об утечке за последние 12 месяцев, а почти 40 % получили от трёх до пяти — почти всеобщая одногодичная частота раскрытия, которая делает кумулятивную пожизненную вероятность ниже 90 % неправдоподобной. Точечная оценка намеренно удерживается на 0,95, а не пересмотрена вверх, потому что ITRC — некоммерческий reputable_reference, а не государственное статистическое ведомство, и скользкое различие между раскрытием и вредом предостерегает от приближения заголовка к 1,0.
Оговорки: «Раскрытие данных в утечке» — определительно скользкое понятие. Утечка, раскрыва…
«Раскрытие данных в утечке» — определительно скользкое понятие. Утечка, раскрывающая ваше имя и адрес электронной почты, категорически отличается от той, что раскрывает номер социального страхования, медицинские записи или финансовые учётные данные, — однако ITRC считает их одинаково в своих подсчётах компрометаций. Пожизненная цифра 95 % означает, что практически каждый взрослый с цифровым следом когда-нибудь получит раскрытие каких-то данных; она не означает, что 95 % взрослых понесут финансовый вред от утечки. Коэффициент конверсии из раскрытия в фактическую кражу личных данных или финансовые потери гораздо ниже — FTC получила около 1,1 миллиона жалоб на кражу личных данных в 2024 году, крошечную долю от населения, затронутого утечками. Цифра также ориентирована на США в своей нормализации, но явление глобально; частота утечек в ЕС и Азиатско-Тихоокеанском регионе сопоставима. Наконец, «уведомления жертвам» переоценивают уникальных лиц (один человек получает несколько уведомлений) и одновременно недооценивают раскрытие (многие утечки остаются необнаруженными или незарегистрированными, и 70 % уведомлений 2025 года вовсе опустили детали вектора атаки). Ещё одна тонкость в том, что заголовочный объём раскрытия определяется горсткой мега-утечек, а не длинным хвостом инцидентов. ITRC зафиксировал рекордные 3 322 компрометации в 2025 году — рост на 5 % против 2024 года, — однако уведомления жертвам упали на 79 %, с 1,37 миллиарда в 2024 году до 279 миллионов в 2025 году, просто потому что в 2025 году не было ни одной мега-утечки масштаба инцидента Change Healthcare 2024 года. Это расцепление означает, что подсчёты уведомлений — плохой год-к-году заменитель индивидуального риска: число утечек выросло, тогда как заявленный объём раскрытия обрушился. Вероятность того, что вы попадаете в раскрытие каждый год, почти всеобща и стабильна (опрос ITRC оценивает её в 80 % за один год); необработанное итоговое число уведомлений сильно колеблется в зависимости от того, довелось ли нескольким катастрофическим утечкам прийтись на этот календарный год.
Связанные риски
Другие риски на схожие темы — для изучения связанных страхов.
Мошенничество с кредитными картами
Каковы шансы стать жертвой мошенничества с кредитными картами?
Потери от онлайн-мошенничества
Какова вероятность потерять деньги из-за онлайн-мошенничества?
Мошенничество с клоном голоса
Каковы шансы, что вы станете мишенью мошенничества с клонированием голоса ИИ в течение жизни?
Дети и откровенный контент
Каковы шансы ребенка столкнуться с откровенным или насильственным контентом онлайн до 13 лет?
Интимный дипфейк
Каковы шансы, что интимный дипфейк с вашим участием будет создан или распространён без согласия в течение вашей жизни?
Выбрать сравниваемый
Вопрос не в том, были ли ваши данные скомпрометированы в результате утечки. Вопрос в том, сколько раз. Центр ресурсов по краже личных данных (Identity Theft Resource Center) зафиксировал рекордные 3 322 случая компрометации данных в США в 2025 году, что привело к рассылке примерно 279 миллионов уведомлений жертвам. В 2024 году эта цифра составила 1,37 миллиарда уведомлений — более четырех на каждого американца — что было завышено мега-утечками, такими как инцидент с Change Healthcare, который сам по себе раскрыл более 190 миллионов записей. Только медицинские данные были скомпрометированы в объеме, превышающем 2,6 раза население США с 2009 года. Даже консервативная годовая частота первого раскрытия, накапливаясь за 59-летний период взрослой жизни, доводит кумулятивную вероятность примерно до 95%, что является вежливым способом сказать «почти полная уверенность».
Что делает риск утечки данных необычным среди записей Likelier, так это то, что он инвертирует обычную модель «страх против реальности». Большинство страхов на этом сайте переоцениваются. Компрометация данных, если уж на то пошло, недооценивается — не потому, что люди считают ее редкой, а потому, что они редко рассчитывают кумулятивную арифметику. 35-летний американец в 2026 году пережил утечку Equifax (147 миллионов записей), утечку Yahoo (3 миллиарда учетных записей), утечку Change Healthcare и тысячи более мелких инцидентов. Вероятность того, что ни одни из его личных данных не фигурировали ни в одном из этих событий, ничтожно мала. Эмоциональный разрыв заключается в том, что «компрометация» кажется абстрактной, пока она не превратится в кражу личных данных или финансовые потери, что происходит с гораздо меньшей долей людей.
Важное замечание заключается в том, что «компрометация» — это не «вред». Подсчет уведомлений жертвам ITRC рассматривает утечку адреса электронной почты так же, как и утечку номера социального страхования. Большинство скомпрометированных записей никогда не приводят к измеримому финансовому ущербу для человека. FTC получила около 1,1 миллиона жалоб на кражу личных данных в 2024 году — менее 0,1% от объема уведомлений об утечках. Таким образом, хотя вероятность компрометации данных приближается к 1, вероятность значительного вреда от любой конкретной утечки остается низкой. Риск является кумулятивным и комбинаторным: каждая дополнительная компрометация добавляет еще одну точку данных, которую можно перекрестно сопоставить с предыдущими утечками, постепенно собирая более полный профиль, который более полезен для мотивированного злоумышленника.
Связанные факты
Около 95% накопленной вероятности за взрослую жизнь, что ваши персональные данные будут раскрыты при утечке. Только в 2025 году произошло около 3 322 компрометаций данных и было направлено около 279 миллионов уведомлений пострадавшим.
Реестр утверждений
Каждое число ниже — это то, что сообщил источник, с дословной цитатой, на которую мы опирались, и тем, как мы пришли к нашей цифре. Нажмите на ссылку, чтобы проверить самостоятельно.
-
[1] Identity Theft Resource Center — Identity Theft Resource Center 2025 Annual Data Breach Report
Identity Theft Resource Center 2025 Annual Data Breach Report- Статистика
3,322 data compromises in 2025 with 278,827,933 victim notices; 5% increase in compromises over 2024; record number of tracked compromises- Выдержка
“"The ITRC tracked a record 3,322 data compromises in 2025, a 5% increase over 2024. The number of victim notices was 278,827,933, a 79% decrease from 2024's 1,367,117,021, due to the absence of mega-breaches on the scale of Change Healthcare." ”
- Данные источника:
- 2026-01-29
- Дата обращения
- 2026-04-12 · архивная копия
- Расчёт
- The 278.8 million victim notices in 2025 divided by ~335 million US population yields ~0.83 notices per person. But notices are not unique individuals — one person can receive multiple breach notifications. The ITRC notes that 70% of 2025 breach notices did not include attack-vector information, further complicating deduplication. The 2024 figure of 1.37 billion victim notices (driven by Change Healthcare's 190M+ exposure) illustrates how a single mega-breach can exceed the entire US population in notice count. For lifetime normalization, we use the conservative annual unique-individual rate of ~5% first-time exposure compounded over 59 years. Note: the ITRC is a 501(c)(3) nonprofit, not a government statistical agency; its breach counts rely on voluntary and regulatory disclosures rather than a census-grade collection mandate. No federal agency publishes a comparable all-sector breach tally, so ITRC is the best available source but carries the authority gap inherent in non-governmental data aggregation.
- Независимость
- ITRC compiles breach data from state attorney general notifications, SEC filings, and federal regulatory disclosures. It is independent of the FTC's Consumer Sentinel Network, which tracks consumer complaints rather than breach disclosures.
-
[2] Identity Theft Resource Center (via PR Newswire) — ITRC 2025 Annual Data Breach Report consumer survey (N=1,040)
ITRC 2025 Annual Data Breach Report consumer survey (N=1,040)- Статистика
In an ITRC consumer survey of 1,040 US adults, 80% reported receiving at least one data breach notice in the past 12 months and nearly 40% received three to five separate notices in the past year- Выдержка
“"As part of the 20th anniversary of the Data Breach Report, the ITRC asked 1,040 consumers if they had received a data breach notice in the past 12 months. The survey reveals that data breaches are a near-universal experience for consumers, with 80 percent of respondents having received a data breach notice in the last 12 months. Nearly 40 percent of people responding to the survey received three to five separate notices in the past year." ”
- Данные источника:
- 2026-01-29
- Дата обращения
- 2026-06-14 · архивная копия
- Расчёт
- This is the first direct, individual-level measurement of annual breach-notice incidence cited in this entry — prior figures were aggregate notice counts (which double-count individuals). An 80% one-year notice rate confirms empirically what the per-capita notice arithmetic only implied: annual breach exposure is near-universal for US adults with a digital footprint. Applied here as corroboration that tightens the lower bound of the lifetime uncertainty band — if 80% are notified in a single year, a sub-90% cumulative lifetime probability is no longer plausible. The point estimate is held at 0.95 rather than revised upward, because ITRC is a 501(c)(3) nonprofit reputable_reference, not a government statistical agency, and a revise of the headline number is reserved for official-agency updates. Survey caveat: self-reported recall over a 12-month window may overstate (notice fatigue conflating spam with real notices) or understate (forgotten or unopened notices) the true rate.
- Независимость
- This is the consumer-survey component of the same ITRC 2025 report whose breach counts are cited above; it is a methodologically distinct instrument (a polled sample of individuals) rather than the aggregate breach-notice tally, so it corroborates rather than restates the count-based figure.
-
[3] Verizon Business — 2024 Data Breach Investigations Report (DBIR)
2024 Data Breach Investigations Report (DBIR)- Статистика
Verizon DBIR 2024 analyzed 30,458 security incidents and 10,626 confirmed breaches across 94 countries, confirming that the majority of breaches involve stolen credentials or human error rather than sophisticated attacks- Выдержка
“"This year's dataset includes 30,458 real-world security incidents, of which 10,626 (about one-third) were confirmed data breaches. 68 percent of breaches involved a non-malicious human element, such as a person falling victim to a social engineering attack or making an error." ”
- Данные источника:
- 2024-05-01
- Дата обращения
- 2026-04-16 · архивная копия
- Расчёт
- Verizon DBIR does not publish a per-individual "exposure probability" — its unit of analysis is the incident/breach, not the person. Used here as a corroborating source for the claim that breaches are common, widely distributed, and driven by credential/phishing vectors rather than targeted attacks on individuals. This shifts the entry's framing from "probability of being a specific victim" to "probability of being swept up in aggregate exposure."
- Независимость
- Verizon DBIR aggregates incident data from ~100 contributing organizations (forensic firms, CSIRTs, law enforcement including US Secret Service). This is methodologically independent of ITRC's public-breach-notice tracking, which counts disclosed consumer breaches rather than investigated incidents.
-
[4] Identity Theft Resource Center — ITRC 2024 Annual Data Breach Report
ITRC 2024 Annual Data Breach Report- Статистика
3,158 data compromises in 2024 with 1,728,519,397 victim notices; 1.7 billion individuals' data compromised- Выдержка
“"The number of data breach notices issued in 2024 (1,728,519,397) increased 312 percent from 2023 (419,337,446)... In 2024, six data breaches were reported that each involved more than 100 million records. More than 1.7 billion individuals had personal data compromised in 2024, and there were 3,158 data compromises." ”
- Данные источника:
- 2025-01-29
- Дата обращения
- 2026-04-12 · архивная копия
- Расчёт
- The 2024 figure of 1.37 billion victim notices against a US population of ~335 million means the average American received roughly 4 breach notifications in a single year. This is consistent with the cumulative-near-certainty thesis: if breach exposure is this frequent in a single year, the probability of never being exposed over a full adult lifetime approaches zero. The 2024 figure is inflated by outlier mega-breaches and should not be used as a stable annual rate, which is why the 2025 figure is preferred for the central estimate.
- Независимость
- The 2024 Annual Data Breach Report is the prior-year edition from the same ITRC methodology; included for the 72% year-over-year record count rather than as an independent estimate.
-
[5] HIPAA Journal — Healthcare Data Breach Statistics
Healthcare Data Breach Statistics- Статистика
7,357 healthcare data breaches affecting 935.5 million records between 2009 and 2025 — more than 2.6x the US population- Выдержка
“"Between 2009 and 2025, 7,357 healthcare data breaches of 500 or more records have been reported to the HHS Office for Civil Rights, resulting in the exposure of more than 935,521,931 healthcare records — more than 2.6 times the population of the United States." ”
- Данные источника:
- 2026-03-15
- Дата обращения
- 2026-04-12 · архивная копия
- Расчёт
- Healthcare alone has exposed records equivalent to 2.6x the US population over 16 years. Even with substantial deduplication (same person, multiple breaches), this implies the vast majority of Americans with any healthcare history have had protected health information exposed at least once. Healthcare is one sector among many — financial services, retail, government, and education add further exposure. Used as corroborating evidence for the near-certainty cumulative estimate, not as the primary source.
- Независимость
- HIPAA Journal tracks breaches reported to the HHS Office for Civil Rights under the HIPAA Breach Notification Rule. This is a regulatory pipeline entirely independent of the ITRC's state-AG-based tracking.
-
[6] Federal Trade Commission (FTC) — Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach
Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach- Статистика
The 2017 Equifax data breach exposed approximately 147 million US consumers' sensitive personal information, including Social Security numbers, names, addresses, and dates of birth- Выдержка
“"In September of 2017, Equifax, a nationwide credit reporting company headquartered in Atlanta, Georgia, announced that a data breach at the company resulted in the exposure of approximately 147 million U.S. consumers' sensitive personal information, including names, addresses, social security numbers, and dates of birth." ”
- Данные источника:
- 2019-07-22
- Дата обращения
- 2026-07-03 · архивная копия
- Расчёт
- Cited in the body prose as a concrete, named illustration of the cumulative-exposure argument — a typical American adult has very likely had some personal data exposed in at least one major named breach. Not used in the lifetime-probability arithmetic itself, which relies on the ITRC annual victim-notice figures above; included only to ground the specific "Equifax breach (147 million records)" reference in the body text.
- Независимость
- FTC/CFPB regulatory settlement documentation, independent of the ITRC's breach-notice tracking and of Verizon's DBIR incident dataset.
-
[7] Wikipedia — Yahoo data breaches
Yahoo data breaches- Статистика
Yahoo's 2013 breach, initially disclosed in December 2016 as affecting 1 billion accounts, was revised in October 2017 to confirm all 3 billion Yahoo accounts existing at the time were compromised- Выдержка
“"Almost a year later, in October 2017 they revised that estimate and reported that all three billion Yahoo accounts had been compromised in the breach." ”
- Данные источника:
- 2017-10-03
- Дата обращения
- 2026-07-03 · архивная копия
- Расчёт
- Cited in the body prose alongside Equifax as a second concrete named mega-breach illustrating cumulative lifetime exposure. Not used in the lifetime-probability arithmetic. Grounds the "Yahoo breach (3 billion accounts)" reference in the body text; the 3-billion revision is corroborated by contemporaneous reporting (e.g. the Wall Street Journal's October 3, 2017 story "Yahoo Triples Estimate of Breached Accounts to 3 Billion," cited in this Wikipedia article's references) and Yahoo/Verizon's own SEC disclosures.
- Независимость
- Tertiary compilation source; the underlying disclosure is Yahoo's own 2017 SEC filings and contemporaneous news reporting. Included only as corroboration for a widely reported, uncontested figure not itself covered by this entry's other four sources.
-
[8] Federal Trade Commission (FTC) — Consumer Sentinel Network Data Book 2024
Consumer Sentinel Network Data Book 2024See all 4 Likelier entries citing this source →
- Статистика
FTC Consumer Sentinel Network received 6.5 million consumer reports in 2024; identity theft was the largest single category at approximately 1.1 million reports, about 17% of all reports- Выдержка
“"During 2024, Sentinel received 6.5 million consumer reports, which the FTC has sorted into 29 top categories. ... In 2024, there were more than 1.1 million reports of identity theft received through the FTC's IdentityTheft.gov website." ”
- Данные источника:
- 2025-03-01
- Дата обращения
- 2026-07-03 · архивная копия
- Расчёт
- Grounds the body prose's and caveats' "the FTC received about 1.1 million identity-theft complaints in 2024" reference (which previously named the FTC without a citation). Both figures are now quoted verbatim in the excerpt above: the 6.5-million-report total and the >1.1-million identity-theft figure, the latter the FTC's largest single Sentinel category (~1.1M / 6.5M ≈ 17% of all reports). Not used in this entry's headline lifetime-probability arithmetic, which relies on the ITRC breach-notice figures above; included only to ground the specific FTC identity-theft-complaint figure used in the body prose to distinguish "exposure" from "harm."
- Независимость
- FTC Consumer Sentinel Network is a distinct federal consumer-complaint intake pipeline, independent of the ITRC's breach-notice tracking and Verizon's incident-investigation dataset used elsewhere in this entry.






