Якість доказів 4.38/5
Восьмивимірна оцінка перевірки за рубрикою якості . Кожен вимір оцінений 1–5.
- D1 Прив’язка до джерел
- 5/5
- D2 Авторитет джерела
- 4/5
- D3 Арифметика
- 4/5
- D4 Невизначеність
- 4/5
- D5 Сфера
- 4/5
- D6 Проза
- 5/5
- D7 Чесність сприйняття
- 4/5
- D8 Повнота застережень
- 5/5
≈ Так само ймовірно, як
Сприйнятий
Gallup не опитує безпосередньо про витоки даних, але його найближчий проксі — крадіжка особистих даних — очолює річний список побоювань щодо злочинності. У хвилі опитування в жовтні 2024 року 69 % дорослих американців сказали, що часто або іноді турбуються про крадіжку своєї особистості — найвищий показник у опитуванні. Оскільки крадіжка особистих даних переважно є наслідком витоків даних, показник 69 % є розумним проксі для тривоги, пов'язаної з витоками. Окреме опитування Pew Research 2023 року виявило, що 79 % дорослих американців висловили занепокоєння щодо того, як компанії використовують їхні особисті дані.
Грубна оцінка: 69 % дорослих американців турбуються про крадіжку особистих даних, найближчий проксі (Gallup 2024)
Фактичний
~3 322 компрометації даних у 2025 році, ~279 мільйонів повідомлень жертвам
Особи в США, чиї дані зберігаються організаціями, що зазнали витоку
Показати обчислення
Річний звіт ITRC про витоки даних за 2025 рік зафіксував 3 322 компрометації даних із 278,8 мільйона повідомлень жертвам. У 2024 році ця цифра становила 1,35 мільярда повідомлень жертвам по 3 158 компрометаціях (роздута мега-витоками на кшталт Change Healthcare із 190 млн+ записів). Використовуючи консервативнішу цифру 2025 року, приблизно 279 мільйонів повідомлень жертвам було видано щодо населення США ~335 мільйонів, що означає, що ~83 % населення отримали принаймні одне повідомлення про витік за один рік. Однак повідомлення жертвам двічі рахують осіб, постраждалих від кількох витоків. З поправкою на перекриття за евристикою повторного захоплення річний показник експозиції унікальних осіб оцінюється в 35–50 %. Навіть за консервативної річної частоти 35 % накопичення протягом 59-річного дорослого життя дає 1 − (1 − 0,35)^59 ≈ фактично 1,0. Використовуючи помірнішу річну ймовірність 5 % першого в житті витоку (для того, чиї дані ще ніколи не зазнавали витоку — з урахуванням того, що більшість дорослих уже скомпрометовані), накопичену протягом 59 років, дає 1 − (1 − 0,05)^59 ≈ 0,953. Центральна оцінка 95 % відображає майже впевненість кумулятивної експозиції, а смуга невизначеності визнає визначальну неоднозначність щодо того, що вважається «вашими» даними, які «скомпрометовані». Нижню межу було піднято з 0,80 до 0,90 в огляді від 2026-06-14: споживче опитування ITRC 2025 року (N=1 040) виявило, що 80 % респондентів отримали принаймні одне повідомлення про витік за останні 12 місяців, а майже 40 % отримали від трьох до п'яти — майже загальна річна частота експозиції, яка робить кумулятивну ймовірність за все життя нижче 90 % неправдоподібною. Точкову оцінку навмисно тримають на рівні 0,95, а не переглядають угору, бо ITRC — це неприбуткова організація типу reputable_reference, а не державне статистичне агентство, і слизьке розрізнення експозиції та шкоди застерігає від наближення заголовка до 1,0.
Застереження: «Компрометація внаслідок витоку даних» — визначально слизьке поняття. Витік, яки…
«Компрометація внаслідок витоку даних» — визначально слизьке поняття. Витік, який розкриває ваше ім'я та адресу електронної пошти, категорично відрізняється від того, який розкриває ваш номер соціального страхування, медичні записи чи фінансові облікові дані — проте ITRC рахує їх однаково у своїх підрахунках компрометацій. Показник 95 % за все життя означає, що практично кожен дорослий із цифровим слідом матиме деякі дані скомпрометованими в певний момент; це не означає, що 95 % дорослих зазнають фінансової шкоди від витоку. Коефіцієнт конверсії від експозиції до фактичної крадіжки особистих даних чи фінансових втрат значно нижчий — FTC отримала близько 1,1 мільйона скарг на крадіжку особистих даних у 2024 році, крихітну частку від популяції, скомпрометованої витоками. Число також орієнтоване на США у своїй нормалізації, але явище є глобальним; частота витоків у ЄС та Азіатсько-Тихоокеанському регіоні є порівнянною. Нарешті, «повідомлення жертвам» переоцінюють унікальних осіб (одна людина отримує кілька повідомлень) і водночас недооцінюють експозицію (багато витоків залишаються невиявленими чи незадокументованими, а 70 % повідомлень 2025 року взагалі не містили деталей про вектор атаки). Ще одна тонкість у тому, що заголовний *обсяг* експозиції визначається жменькою мега-витоків, а не довгим хвостом інцидентів. ITRC зафіксувала рекордні 3 322 компрометації у 2025 році — зростання на 5 % порівняно з 2024 роком — проте повідомлення жертвам впали на 79 %, з 1,37 мільярда у 2024 році до 279 мільйонів у 2025 році, просто тому, що у 2025 році не було жодного мега-витоку масштабу інциденту з Change Healthcare 2024 року. Це роз'єднання означає, що підрахунки повідомлень є поганим проксі для індивідуального ризику з року в рік: кількість витоків зросла, тоді як задокументований обсяг експозиції обвалився. Ймовірність того, що *ви* потрапите в експозицію щороку, майже загальна і стабільна (опитування ITRC оцінює її у 80 % за один рік); загальна сира кількість повідомлень різко коливається залежно від того, чи трапилося кілька катастрофічних витоків саме в цьому календарному році.
Пов’язані ризики
Інші ризики на схожі теми — для вивчення пов’язаних страхів.
Шахрайство з клонуванням голосу
Які шанси, що ви станете мішенню шахрайства зі штучним клонуванням голосу протягом свого життя?
Діти та відвертий контент
Які шанси дитини зіткнутися з відвертим або насильницьким контентом онлайн до 13 років?
Інтимний дипфейк
Які шанси, що штучно створений інтимний дипфейк з вашим зображенням буде створено або поширено без вашої згоди протягом життя?
Обрати порівнюваний
Питання не в тому, чи були ваші дані скомпрометовані внаслідок витоку. Питання в тому, скільки разів. Центр ресурсів з крадіжки особистих даних зафіксував рекордні 3 322 компрометації даних у Сполучених Штатах у 2025 році, що призвело до приблизно 279 мільйонів повідомлень жертвам. У 2024 році ця цифра становила 1,37 мільярда повідомлень — понад чотири на кожного американця — роздута мега-витоками, такими як інцидент з Change Healthcare, який сам по собі скомпрометував понад 190 мільйонів записів. Лише медичні дані були скомпрометовані в обсязі, що перевищує 2,6 рази населення США з 2009 року. Навіть консервативна річна частота першого витоку, накопичена протягом 59-річного дорослого життя, підвищує кумулятивну ймовірність до приблизно 95%, що є ввічливим способом сказати “майже повна впевненість”.
Що робить ризик витоку даних незвичайним серед записів Likelier, так це те, що він інвертує звичайну модель “страх проти реальності”. Більшість страхів на цьому сайті переоцінені. Компрометація даних, якщо що, недооцінена — не тому, що люди вважають її рідкісною, а тому, що вони рідко обчислюють кумулятивну арифметику. 35-річний американець у 2026 році пережив витік даних Equifax (147 мільйонів записів), витік Yahoo (3 мільярди облікових записів), витік Change Healthcare та тисячі менших інцидентів. Ймовірність того, що жодні їхні особисті дані не з’явилися в жодній з цих подій, є незначною. Емоційний розрив полягає в тому, що “компрометація” здається абстрактною, доки вона не перетвориться на крадіжку особистих даних або фінансові втрати, що відбувається зі значно меншою часткою людей.
Важливе застереження полягає в тому, що “компрометація” — це не “шкода”. Підрахунок повідомлень жертвам ITRC розглядає витік електронної пошти так само, як і витік номера соціального страхування. Більшість скомпрометованих записів ніколи не призводять до відчутних фінансових збитків для особи. FTC отримала близько 1,1 мільйона скарг на крадіжку особистих даних у 2024 році — менше 0,1% від обсягу повідомлень про витоки. Отже, хоча ймовірність компрометації даних наближається до 1, ймовірність значної шкоди від будь-якого конкретного витоку залишається низькою. Ризик є кумулятивним та комбінаторним: кожен додатковий витік додає ще одну точку даних, яку можна перехресно порівняти з попередніми витоками, поступово збираючи більш повний профіль, який є більш корисним для мотивованого зловмисника.
Пов’язані факти
Близько 95% накопиченої ймовірності протягом дорослого життя, що ваші персональні дані будуть розкриті під час витоку. Лише у 2025 році сталося близько 3 322 компрометацій даних і було надіслано близько 279 мільйонів повідомлень постраждалим.
Реєстр тверджень
Кожне число нижче — це те, що повідомило джерело, з дослівною цитатою, на яку ми спиралися, та тим, як ми дійшли до нашої цифри. Натисніть на посилання, щоб перевірити самостійно.
-
[1] Identity Theft Resource Center — Identity Theft Resource Center 2025 Annual Data Breach Report
Identity Theft Resource Center 2025 Annual Data Breach Report- Статистика
3,322 data compromises in 2025 with 278,827,933 victim notices; 5% increase in compromises over 2024; record number of tracked compromises- Витяг
“"The ITRC tracked a record 3,322 data compromises in 2025, a 5% increase over 2024. The number of victim notices was 278,827,933, a 79% decrease from 2024's 1,367,117,021, due to the absence of mega-breaches on the scale of Change Healthcare." ”
- Дані джерела:
- 2026-01-29
- Дата звернення
- 2026-04-12 · архівна копія
- Розрахунок
- The 278.8 million victim notices in 2025 divided by ~335 million US population yields ~0.83 notices per person. But notices are not unique individuals — one person can receive multiple breach notifications. The ITRC notes that 70% of 2025 breach notices did not include attack-vector information, further complicating deduplication. The 2024 figure of 1.37 billion victim notices (driven by Change Healthcare's 190M+ exposure) illustrates how a single mega-breach can exceed the entire US population in notice count. For lifetime normalization, we use the conservative annual unique-individual rate of ~5% first-time exposure compounded over 59 years. Note: the ITRC is a 501(c)(3) nonprofit, not a government statistical agency; its breach counts rely on voluntary and regulatory disclosures rather than a census-grade collection mandate. No federal agency publishes a comparable all-sector breach tally, so ITRC is the best available source but carries the authority gap inherent in non-governmental data aggregation.
- Незалежність
- ITRC compiles breach data from state attorney general notifications, SEC filings, and federal regulatory disclosures. It is independent of the FTC's Consumer Sentinel Network, which tracks consumer complaints rather than breach disclosures.
-
[2] Identity Theft Resource Center (via PR Newswire) — ITRC 2025 Annual Data Breach Report consumer survey (N=1,040)
ITRC 2025 Annual Data Breach Report consumer survey (N=1,040)- Статистика
In an ITRC consumer survey of 1,040 US adults, 80% reported receiving at least one data breach notice in the past 12 months and nearly 40% received three to five separate notices in the past year- Витяг
“"As part of the 20th anniversary of the Data Breach Report, the ITRC asked 1,040 consumers if they had received a data breach notice in the past 12 months. The survey reveals that data breaches are a near-universal experience for consumers, with 80 percent of respondents having received a data breach notice in the last 12 months. Nearly 40 percent of people responding to the survey received three to five separate notices in the past year." ”
- Дані джерела:
- 2026-01-29
- Дата звернення
- 2026-06-14 · архівна копія
- Розрахунок
- This is the first direct, individual-level measurement of annual breach-notice incidence cited in this entry — prior figures were aggregate notice counts (which double-count individuals). An 80% one-year notice rate confirms empirically what the per-capita notice arithmetic only implied: annual breach exposure is near-universal for US adults with a digital footprint. Applied here as corroboration that tightens the lower bound of the lifetime uncertainty band — if 80% are notified in a single year, a sub-90% cumulative lifetime probability is no longer plausible. The point estimate is held at 0.95 rather than revised upward, because ITRC is a 501(c)(3) nonprofit reputable_reference, not a government statistical agency, and a revise of the headline number is reserved for official-agency updates. Survey caveat: self-reported recall over a 12-month window may overstate (notice fatigue conflating spam with real notices) or understate (forgotten or unopened notices) the true rate.
- Незалежність
- This is the consumer-survey component of the same ITRC 2025 report whose breach counts are cited above; it is a methodologically distinct instrument (a polled sample of individuals) rather than the aggregate breach-notice tally, so it corroborates rather than restates the count-based figure.
-
[3] Verizon Business — 2024 Data Breach Investigations Report (DBIR)
2024 Data Breach Investigations Report (DBIR)- Статистика
Verizon DBIR 2024 analyzed 30,458 security incidents and 10,626 confirmed breaches across 94 countries, confirming that the majority of breaches involve stolen credentials or human error rather than sophisticated attacks- Витяг
“"This year's dataset includes 30,458 real-world security incidents, of which 10,626 (about one-third) were confirmed data breaches. 68 percent of breaches involved a non-malicious human element, such as a person falling victim to a social engineering attack or making an error." ”
- Дані джерела:
- 2024-05-01
- Дата звернення
- 2026-04-16 · архівна копія
- Розрахунок
- Verizon DBIR does not publish a per-individual "exposure probability" — its unit of analysis is the incident/breach, not the person. Used here as a corroborating source for the claim that breaches are common, widely distributed, and driven by credential/phishing vectors rather than targeted attacks on individuals. This shifts the entry's framing from "probability of being a specific victim" to "probability of being swept up in aggregate exposure."
- Незалежність
- Verizon DBIR aggregates incident data from ~100 contributing organizations (forensic firms, CSIRTs, law enforcement including US Secret Service). This is methodologically independent of ITRC's public-breach-notice tracking, which counts disclosed consumer breaches rather than investigated incidents.
-
[4] Identity Theft Resource Center — ITRC 2024 Annual Data Breach Report
ITRC 2024 Annual Data Breach Report- Статистика
3,158 data compromises in 2024 with 1,728,519,397 victim notices; 1.7 billion individuals' data compromised- Витяг
“"The number of data breach notices issued in 2024 (1,728,519,397) increased 312 percent from 2023 (419,337,446)... In 2024, six data breaches were reported that each involved more than 100 million records. More than 1.7 billion individuals had personal data compromised in 2024, and there were 3,158 data compromises." ”
- Дані джерела:
- 2025-01-29
- Дата звернення
- 2026-04-12 · архівна копія
- Розрахунок
- The 2024 figure of 1.37 billion victim notices against a US population of ~335 million means the average American received roughly 4 breach notifications in a single year. This is consistent with the cumulative-near-certainty thesis: if breach exposure is this frequent in a single year, the probability of never being exposed over a full adult lifetime approaches zero. The 2024 figure is inflated by outlier mega-breaches and should not be used as a stable annual rate, which is why the 2025 figure is preferred for the central estimate.
- Незалежність
- The 2024 Annual Data Breach Report is the prior-year edition from the same ITRC methodology; included for the 72% year-over-year record count rather than as an independent estimate.
-
[5] HIPAA Journal — Healthcare Data Breach Statistics
Healthcare Data Breach Statistics- Статистика
7,357 healthcare data breaches affecting 935.5 million records between 2009 and 2025 — more than 2.6x the US population- Витяг
“"Between 2009 and 2025, 7,357 healthcare data breaches of 500 or more records have been reported to the HHS Office for Civil Rights, resulting in the exposure of more than 935,521,931 healthcare records — more than 2.6 times the population of the United States." ”
- Дані джерела:
- 2026-03-15
- Дата звернення
- 2026-04-12 · архівна копія
- Розрахунок
- Healthcare alone has exposed records equivalent to 2.6x the US population over 16 years. Even with substantial deduplication (same person, multiple breaches), this implies the vast majority of Americans with any healthcare history have had protected health information exposed at least once. Healthcare is one sector among many — financial services, retail, government, and education add further exposure. Used as corroborating evidence for the near-certainty cumulative estimate, not as the primary source.
- Незалежність
- HIPAA Journal tracks breaches reported to the HHS Office for Civil Rights under the HIPAA Breach Notification Rule. This is a regulatory pipeline entirely independent of the ITRC's state-AG-based tracking.
-
[6] Federal Trade Commission (FTC) — Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach
Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach- Статистика
The 2017 Equifax data breach exposed approximately 147 million US consumers' sensitive personal information, including Social Security numbers, names, addresses, and dates of birth- Витяг
“"In September of 2017, Equifax, a nationwide credit reporting company headquartered in Atlanta, Georgia, announced that a data breach at the company resulted in the exposure of approximately 147 million U.S. consumers' sensitive personal information, including names, addresses, social security numbers, and dates of birth." ”
- Дані джерела:
- 2019-07-22
- Дата звернення
- 2026-07-03 · архівна копія
- Розрахунок
- Cited in the body prose as a concrete, named illustration of the cumulative-exposure argument — a typical American adult has very likely had some personal data exposed in at least one major named breach. Not used in the lifetime-probability arithmetic itself, which relies on the ITRC annual victim-notice figures above; included only to ground the specific "Equifax breach (147 million records)" reference in the body text.
- Незалежність
- FTC/CFPB regulatory settlement documentation, independent of the ITRC's breach-notice tracking and of Verizon's DBIR incident dataset.
-
[7] Wikipedia — Yahoo data breaches
Yahoo data breaches- Статистика
Yahoo's 2013 breach, initially disclosed in December 2016 as affecting 1 billion accounts, was revised in October 2017 to confirm all 3 billion Yahoo accounts existing at the time were compromised- Витяг
“"Almost a year later, in October 2017 they revised that estimate and reported that all three billion Yahoo accounts had been compromised in the breach." ”
- Дані джерела:
- 2017-10-03
- Дата звернення
- 2026-07-03 · архівна копія
- Розрахунок
- Cited in the body prose alongside Equifax as a second concrete named mega-breach illustrating cumulative lifetime exposure. Not used in the lifetime-probability arithmetic. Grounds the "Yahoo breach (3 billion accounts)" reference in the body text; the 3-billion revision is corroborated by contemporaneous reporting (e.g. the Wall Street Journal's October 3, 2017 story "Yahoo Triples Estimate of Breached Accounts to 3 Billion," cited in this Wikipedia article's references) and Yahoo/Verizon's own SEC disclosures.
- Незалежність
- Tertiary compilation source; the underlying disclosure is Yahoo's own 2017 SEC filings and contemporaneous news reporting. Included only as corroboration for a widely reported, uncontested figure not itself covered by this entry's other four sources.
-
[8] Federal Trade Commission (FTC) — Consumer Sentinel Network Data Book 2024
Consumer Sentinel Network Data Book 2024See all 4 Likelier entries citing this source →
- Статистика
FTC Consumer Sentinel Network received 6.5 million consumer reports in 2024; identity theft was the largest single category at approximately 1.1 million reports, about 17% of all reports- Витяг
“"During 2024, Sentinel received 6.5 million consumer reports, which the FTC has sorted into 29 top categories. ... In 2024, there were more than 1.1 million reports of identity theft received through the FTC's IdentityTheft.gov website." ”
- Дані джерела:
- 2025-03-01
- Дата звернення
- 2026-07-03 · архівна копія
- Розрахунок
- Grounds the body prose's and caveats' "the FTC received about 1.1 million identity-theft complaints in 2024" reference (which previously named the FTC without a citation). Both figures are now quoted verbatim in the excerpt above: the 6.5-million-report total and the >1.1-million identity-theft figure, the latter the FTC's largest single Sentinel category (~1.1M / 6.5M ≈ 17% of all reports). Not used in this entry's headline lifetime-probability arithmetic, which relies on the ITRC breach-notice figures above; included only to ground the specific FTC identity-theft-complaint figure used in the body prose to distinguish "exposure" from "harm."
- Незалежність
- FTC Consumer Sentinel Network is a distinct federal consumer-complaint intake pipeline, independent of the ITRC's breach-notice tracking and Verizon's incident-investigation dataset used elsewhere in this entry.






