Chất lượng bằng chứng 4.38/5
Điểm đánh giá tám chiều theo tiêu chí chất lượng . Mỗi chiều được chấm từ 1–5.
- D1 Cơ sở nguồn
- 5/5
- D2 Uy tín nguồn
- 4/5
- D3 Tính toán
- 4/5
- D4 Sự không chắc chắn
- 4/5
- D5 Phạm vi
- 4/5
- D6 Văn bản
- 5/5
- D7 Sự trung thực về nhận thức
- 4/5
- D8 Tính đầy đủ của lưu ý
- 5/5
≈ Khả năng tương đương
Nhận thức
Gallup không thăm dò cụ thể về vi phạm dữ liệu, nhưng đại diện gần nhất của nó — trộm cắp danh tính — đứng đầu danh sách lo lắng về tội phạm hàng năm. Trong đợt khảo sát tháng 10 năm 2024, 69 % người trưởng thành Mỹ cho biết họ thường xuyên hoặc thỉnh thoảng lo lắng về việc bị đánh cắp danh tính, con số cao nhất trong khảo sát. Vì trộm cắp danh tính chủ yếu là hệ quả xuôi dòng của vi phạm dữ liệu, con số 69 % là một đại diện hợp lý cho sự lo lắng liên quan đến vi phạm. Một khảo sát Pew Research 2023 riêng biệt phát hiện rằng 79 % người trưởng thành Mỹ bày tỏ lo ngại về cách các công ty sử dụng dữ liệu cá nhân của họ.
Ước tính sơ bộ: 69 % người trưởng thành Mỹ lo lắng về trộm cắp danh tính, đại diện gần nhất (Gallup 2024)
Thực tế
~3.322 vụ xâm phạm dữ liệu vào năm 2025, ~279 triệu thông báo nạn nhân
Các cá nhân Mỹ có dữ liệu được lưu giữ bởi các tổ chức bị vi phạm
Hiện cách tính
Báo cáo Vi phạm Dữ liệu Thường niên 2025 của ITRC đã ghi nhận 3.322 vụ xâm phạm dữ liệu với 278,8 triệu thông báo nạn nhân. Vào năm 2024, con số là 1,35 tỷ thông báo nạn nhân trên 3.158 vụ xâm phạm (tăng vọt bởi các vụ vi phạm lớn như Change Healthcare với hơn 190M hồ sơ). Sử dụng con số thận trọng hơn của 2025, khoảng 279 triệu thông báo nạn nhân được phát hành so với dân số Mỹ ~335 triệu, ngụ ý ~83 % dân số nhận được ít nhất một thông báo vi phạm trong một năm. Tuy nhiên, các thông báo nạn nhân đếm trùng những cá nhân bị ảnh hưởng bởi nhiều vụ vi phạm. Điều chỉnh cho sự chồng lấn bằng một heuristic bắt-bắt-lại, tỷ lệ phơi nhiễm cá nhân duy nhất hàng năm được ước tính ở mức 35–50 %. Ngay cả ở mức thận trọng 35 % hàng năm, gộp lũy qua một tuổi trưởng thành 59 năm cho 1 − (1 − 0,35)^59 ≈ thực tế 1,0. Sử dụng một xác suất phơi nhiễm lần đầu hàng năm ôn hòa hơn là 5 % (cho một người có dữ liệu chưa từng bị vi phạm — tính đến việc hầu hết người lớn đã bị lộ) gộp lũy qua 59 năm cho 1 − (1 − 0,05)^59 ≈ 0,953. Ước tính trung tâm 95 % phản ánh sự gần như chắc chắn của phơi nhiễm tích lũy, với dải bất định thừa nhận sự mơ hồ định nghĩa quanh việc điều gì được tính là dữ liệu «của bạn» bị «lộ». Cận dưới đã được nâng từ 0,80 lên 0,90 trong đợt rà soát 2026-06-14: khảo sát người tiêu dùng 2025 của ITRC (N=1.040) phát hiện rằng 80 % người trả lời nhận được ít nhất một thông báo vi phạm trong 12 tháng qua và gần 40 % nhận được ba đến năm thông báo — một tỷ lệ phơi nhiễm trong một năm gần như phổ quát khiến một xác suất trọn đời tích lũy dưới 90 % là khó tin. Ước tính điểm được cố ý giữ ở 0,95 thay vì điều chỉnh tăng lên, vì ITRC là một reputable_reference phi lợi nhuận chứ không phải một cơ quan thống kê chính phủ và sự phân biệt trơn trượt giữa phơi nhiễm và tổn hại khuyên không nên đẩy con số tiêu đề gần hơn tới 1,0.
Lưu ý: «Việc dữ liệu bị lộ trong vi phạm» là một khái niệm trơn trượt về mặt định nghĩa…
«Việc dữ liệu bị lộ trong vi phạm» là một khái niệm trơn trượt về mặt định nghĩa. Một vụ vi phạm làm lộ tên và địa chỉ email của bạn khác về bản chất với một vụ làm lộ số An sinh Xã hội, hồ sơ y tế hoặc thông tin đăng nhập tài chính của bạn — nhưng ITRC đếm chúng như nhau trong các bảng tổng hợp vụ xâm phạm. Con số trọn đời 95 % có nghĩa là hầu như mọi người lớn có dấu chân số sẽ có một số dữ liệu bị lộ vào một thời điểm nào đó; nó không có nghĩa là 95 % người lớn sẽ chịu tổn hại tài chính từ một vụ vi phạm. Tỷ lệ chuyển đổi từ phơi nhiễm sang trộm cắp danh tính hoặc mất mát tài chính thực tế thấp hơn nhiều — FTC đã nhận được khoảng 1,1 triệu khiếu nại về trộm cắp danh tính vào năm 2024, một phần rất nhỏ của dân số bị lộ dữ liệu. Con số này cũng lấy Mỹ làm trung tâm trong việc chuẩn hóa nhưng hiện tượng là toàn cầu; tỷ lệ vi phạm ở EU và Châu Á - Thái Bình Dương là tương đương. Cuối cùng, «thông báo nạn nhân» đếm thừa các cá nhân duy nhất (một người nhận nhiều thông báo) và đồng thời đếm thiếu phơi nhiễm (nhiều vụ vi phạm không bị phát hiện hoặc không được báo cáo, và 70 % thông báo năm 2025 bỏ qua hoàn toàn chi tiết vector tấn công). Một điểm phức tạp nữa là *khối lượng* phơi nhiễm tiêu đề bị chi phối bởi một số ít vụ vi phạm lớn chứ không phải phần đuôi dài của các sự cố. ITRC đã ghi nhận kỷ lục 3.322 vụ xâm phạm vào năm 2025 — tăng 5 % so với 2024 — nhưng các thông báo nạn nhân giảm 79 %, từ 1,37 tỷ vào năm 2024 xuống 279 triệu vào năm 2025, đơn giản vì 2025 thiếu bất kỳ vụ vi phạm lớn nào ở quy mô của sự cố Change Healthcare năm 2024. Sự tách rời này có nghĩa là số đếm thông báo là một đại diện kém cho rủi ro cá nhân theo từng năm: số vụ vi phạm tăng trong khi khối lượng phơi nhiễm được báo cáo sụp đổ. Xác suất *bạn* bị cuốn vào phơi nhiễm mỗi năm là gần như phổ quát và ổn định (khảo sát ITRC đặt nó ở 80 % trong một năm); tổng số thông báo thô dao động dữ dội tùy thuộc vào việc một vài vụ vi phạm thảm khốc có tình cờ rơi vào năm dương lịch đó hay không.
Rủi ro liên quan
Các rủi ro khác về chủ đề tương tự — để khám phá những nỗi sợ liên quan.
Lừa đảo nhân bản giọng nói AI
Tỷ lệ bạn bị nhắm mục tiêu bởi một vụ lừa đảo nhân bản giọng nói AI trong đời là bao nhiêu?
Trẻ em & nội dung khiêu dâm
Xác suất một đứa trẻ bắt gặp nội dung khiêu dâm hoặc bạo lực trực tuyến trước 13 tuổi là bao nhiêu?
Deepfake thân mật
Tỷ lệ một deepfake thân mật do AI tạo ra của bạn sẽ được tạo hoặc chia sẻ mà không có sự đồng ý trong đời bạn là bao nhiêu?
Chọn đối thủ
Câu hỏi không phải là liệu dữ liệu của bạn đã bị lộ trong một vụ vi phạm hay chưa. Câu hỏi là đã bị lộ bao nhiêu lần. Trung tâm Tài nguyên Chống Trộm cắp Danh tính (Identity Theft Resource Center) đã ghi nhận kỷ lục 3.322 vụ xâm phạm dữ liệu tại Hoa Kỳ vào năm 2025, tạo ra khoảng 279 triệu thông báo nạn nhân. Vào năm 2024, con số này là 1,37 tỷ thông báo — hơn bốn thông báo cho mỗi người Mỹ — tăng vọt do các vụ vi phạm lớn như sự cố Change Healthcare mà riêng nó đã làm lộ hơn 190 triệu hồ sơ. Chỉ riêng dữ liệu y tế đã bị vi phạm với khối lượng vượt quá 2,6 lần dân số Hoa Kỳ kể từ năm 2009. Ngay cả khi tính toán tỷ lệ phơi nhiễm lần đầu hàng năm một cách thận trọng trong suốt 59 năm tuổi trưởng thành, xác suất tích lũy cũng lên tới khoảng 95%, một cách nói lịch sự cho sự gần như chắc chắn.
Điều làm cho rủi ro vi phạm dữ liệu trở nên bất thường trong số các mục của Likelier là nó đảo ngược mô hình sợ hãi so với thực tế thông thường. Hầu hết các nỗi sợ hãi trên trang này đều bị đánh giá quá cao. Ngược lại, việc dữ liệu bị lộ, nếu có, lại bị đánh giá thấp — không phải vì mọi người nghĩ nó hiếm, mà vì họ hiếm khi tính toán số học tích lũy. Một người Mỹ 35 tuổi vào năm 2026 đã trải qua vụ vi phạm Equifax (147 triệu hồ sơ), vụ vi phạm Yahoo (3 tỷ tài khoản), vụ vi phạm Change Healthcare và hàng ngàn sự cố nhỏ hơn. Xác suất không có dữ liệu cá nhân nào của họ xuất hiện trong bất kỳ sự kiện nào trong số đó là không đáng kể. Sự ngắt kết nối cảm xúc là “việc bị lộ” cảm thấy trừu tượng cho đến khi nó chuyển thành hành vi trộm cắp danh tính hoặc mất mát tài chính, điều này xảy ra với một tỷ lệ nhỏ hơn nhiều.
Lưu ý quan trọng là “việc bị lộ” không phải là “tổn hại”. Số lượng thông báo nạn nhân của ITRC coi một địa chỉ email bị lộ giống như một số An sinh Xã hội bị lộ. Hầu hết các hồ sơ bị vi phạm không bao giờ dẫn đến thiệt hại tài chính đáng kể cho cá nhân. FTC đã nhận được khoảng 1,1 triệu khiếu nại về trộm cắp danh tính vào năm 2024 — ít hơn 0,1% tổng số thông báo vi phạm. Vì vậy, trong khi xác suất dữ liệu bị lộ gần bằng 1, xác suất xảy ra tổn hại đáng kể từ bất kỳ vụ vi phạm nào vẫn thấp. Rủi ro là tích lũy và mang tính tổ hợp: mỗi lần bị lộ bổ sung thêm một điểm dữ liệu có thể được đối chiếu với các vụ rò rỉ trước đó, dần dần tạo thành một hồ sơ hoàn chỉnh hơn, hữu ích hơn cho một kẻ tấn công có động cơ.
Thông tin liên quan
Khoảng 95% xác suất tích lũy trong đời người trưởng thành rằng dữ liệu cá nhân của bạn bị lộ trong một vụ rò rỉ. Chỉ riêng năm 2025 đã có khoảng 3.322 vụ xâm phạm dữ liệu và khoảng 279 triệu thông báo cho nạn nhân.
Sổ cái xác nhận
Mỗi con số dưới đây là những gì mỗi nguồn đã báo cáo, cùng với trích dẫn nguyên văn mà chúng tôi dựa vào và cách chúng tôi đưa ra con số của mình. Nhấp vào bất kỳ liên kết nào để xác minh trực tiếp.
-
[1] Identity Theft Resource Center — Identity Theft Resource Center 2025 Annual Data Breach Report
Identity Theft Resource Center 2025 Annual Data Breach Report- Thống kê
3,322 data compromises in 2025 with 278,827,933 victim notices; 5% increase in compromises over 2024; record number of tracked compromises- Trích đoạn
“"The ITRC tracked a record 3,322 data compromises in 2025, a 5% increase over 2024. The number of victim notices was 278,827,933, a 79% decrease from 2024's 1,367,117,021, due to the absence of mega-breaches on the scale of Change Healthcare." ”
- Dữ liệu nguồn từ
- 2026-01-29
- Truy cập
- 2026-04-12 · bản sao lưu trữ
- Tính toán
- The 278.8 million victim notices in 2025 divided by ~335 million US population yields ~0.83 notices per person. But notices are not unique individuals — one person can receive multiple breach notifications. The ITRC notes that 70% of 2025 breach notices did not include attack-vector information, further complicating deduplication. The 2024 figure of 1.37 billion victim notices (driven by Change Healthcare's 190M+ exposure) illustrates how a single mega-breach can exceed the entire US population in notice count. For lifetime normalization, we use the conservative annual unique-individual rate of ~5% first-time exposure compounded over 59 years. Note: the ITRC is a 501(c)(3) nonprofit, not a government statistical agency; its breach counts rely on voluntary and regulatory disclosures rather than a census-grade collection mandate. No federal agency publishes a comparable all-sector breach tally, so ITRC is the best available source but carries the authority gap inherent in non-governmental data aggregation.
- Độc lập
- ITRC compiles breach data from state attorney general notifications, SEC filings, and federal regulatory disclosures. It is independent of the FTC's Consumer Sentinel Network, which tracks consumer complaints rather than breach disclosures.
-
[2] Identity Theft Resource Center (via PR Newswire) — ITRC 2025 Annual Data Breach Report consumer survey (N=1,040)
ITRC 2025 Annual Data Breach Report consumer survey (N=1,040)- Thống kê
In an ITRC consumer survey of 1,040 US adults, 80% reported receiving at least one data breach notice in the past 12 months and nearly 40% received three to five separate notices in the past year- Trích đoạn
“"As part of the 20th anniversary of the Data Breach Report, the ITRC asked 1,040 consumers if they had received a data breach notice in the past 12 months. The survey reveals that data breaches are a near-universal experience for consumers, with 80 percent of respondents having received a data breach notice in the last 12 months. Nearly 40 percent of people responding to the survey received three to five separate notices in the past year." ”
- Dữ liệu nguồn từ
- 2026-01-29
- Truy cập
- 2026-06-14 · bản sao lưu trữ
- Tính toán
- This is the first direct, individual-level measurement of annual breach-notice incidence cited in this entry — prior figures were aggregate notice counts (which double-count individuals). An 80% one-year notice rate confirms empirically what the per-capita notice arithmetic only implied: annual breach exposure is near-universal for US adults with a digital footprint. Applied here as corroboration that tightens the lower bound of the lifetime uncertainty band — if 80% are notified in a single year, a sub-90% cumulative lifetime probability is no longer plausible. The point estimate is held at 0.95 rather than revised upward, because ITRC is a 501(c)(3) nonprofit reputable_reference, not a government statistical agency, and a revise of the headline number is reserved for official-agency updates. Survey caveat: self-reported recall over a 12-month window may overstate (notice fatigue conflating spam with real notices) or understate (forgotten or unopened notices) the true rate.
- Độc lập
- This is the consumer-survey component of the same ITRC 2025 report whose breach counts are cited above; it is a methodologically distinct instrument (a polled sample of individuals) rather than the aggregate breach-notice tally, so it corroborates rather than restates the count-based figure.
-
[3] Verizon Business — 2024 Data Breach Investigations Report (DBIR)
2024 Data Breach Investigations Report (DBIR)- Thống kê
Verizon DBIR 2024 analyzed 30,458 security incidents and 10,626 confirmed breaches across 94 countries, confirming that the majority of breaches involve stolen credentials or human error rather than sophisticated attacks- Trích đoạn
“"This year's dataset includes 30,458 real-world security incidents, of which 10,626 (about one-third) were confirmed data breaches. 68 percent of breaches involved a non-malicious human element, such as a person falling victim to a social engineering attack or making an error." ”
- Dữ liệu nguồn từ
- 2024-05-01
- Truy cập
- 2026-04-16 · bản sao lưu trữ
- Tính toán
- Verizon DBIR does not publish a per-individual "exposure probability" — its unit of analysis is the incident/breach, not the person. Used here as a corroborating source for the claim that breaches are common, widely distributed, and driven by credential/phishing vectors rather than targeted attacks on individuals. This shifts the entry's framing from "probability of being a specific victim" to "probability of being swept up in aggregate exposure."
- Độc lập
- Verizon DBIR aggregates incident data from ~100 contributing organizations (forensic firms, CSIRTs, law enforcement including US Secret Service). This is methodologically independent of ITRC's public-breach-notice tracking, which counts disclosed consumer breaches rather than investigated incidents.
-
[4] Identity Theft Resource Center — ITRC 2024 Annual Data Breach Report
ITRC 2024 Annual Data Breach Report- Thống kê
3,158 data compromises in 2024 with 1,728,519,397 victim notices; 1.7 billion individuals' data compromised- Trích đoạn
“"The number of data breach notices issued in 2024 (1,728,519,397) increased 312 percent from 2023 (419,337,446)... In 2024, six data breaches were reported that each involved more than 100 million records. More than 1.7 billion individuals had personal data compromised in 2024, and there were 3,158 data compromises." ”
- Dữ liệu nguồn từ
- 2025-01-29
- Truy cập
- 2026-04-12 · bản sao lưu trữ
- Tính toán
- The 2024 figure of 1.37 billion victim notices against a US population of ~335 million means the average American received roughly 4 breach notifications in a single year. This is consistent with the cumulative-near-certainty thesis: if breach exposure is this frequent in a single year, the probability of never being exposed over a full adult lifetime approaches zero. The 2024 figure is inflated by outlier mega-breaches and should not be used as a stable annual rate, which is why the 2025 figure is preferred for the central estimate.
- Độc lập
- The 2024 Annual Data Breach Report is the prior-year edition from the same ITRC methodology; included for the 72% year-over-year record count rather than as an independent estimate.
-
[5] HIPAA Journal — Healthcare Data Breach Statistics
Healthcare Data Breach Statistics- Thống kê
7,357 healthcare data breaches affecting 935.5 million records between 2009 and 2025 — more than 2.6x the US population- Trích đoạn
“"Between 2009 and 2025, 7,357 healthcare data breaches of 500 or more records have been reported to the HHS Office for Civil Rights, resulting in the exposure of more than 935,521,931 healthcare records — more than 2.6 times the population of the United States." ”
- Dữ liệu nguồn từ
- 2026-03-15
- Truy cập
- 2026-04-12 · bản sao lưu trữ
- Tính toán
- Healthcare alone has exposed records equivalent to 2.6x the US population over 16 years. Even with substantial deduplication (same person, multiple breaches), this implies the vast majority of Americans with any healthcare history have had protected health information exposed at least once. Healthcare is one sector among many — financial services, retail, government, and education add further exposure. Used as corroborating evidence for the near-certainty cumulative estimate, not as the primary source.
- Độc lập
- HIPAA Journal tracks breaches reported to the HHS Office for Civil Rights under the HIPAA Breach Notification Rule. This is a regulatory pipeline entirely independent of the ITRC's state-AG-based tracking.
-
[6] Federal Trade Commission (FTC) — Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach
Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach- Thống kê
The 2017 Equifax data breach exposed approximately 147 million US consumers' sensitive personal information, including Social Security numbers, names, addresses, and dates of birth- Trích đoạn
“"In September of 2017, Equifax, a nationwide credit reporting company headquartered in Atlanta, Georgia, announced that a data breach at the company resulted in the exposure of approximately 147 million U.S. consumers' sensitive personal information, including names, addresses, social security numbers, and dates of birth." ”
- Dữ liệu nguồn từ
- 2019-07-22
- Truy cập
- 2026-07-03 · bản sao lưu trữ
- Tính toán
- Cited in the body prose as a concrete, named illustration of the cumulative-exposure argument — a typical American adult has very likely had some personal data exposed in at least one major named breach. Not used in the lifetime-probability arithmetic itself, which relies on the ITRC annual victim-notice figures above; included only to ground the specific "Equifax breach (147 million records)" reference in the body text.
- Độc lập
- FTC/CFPB regulatory settlement documentation, independent of the ITRC's breach-notice tracking and of Verizon's DBIR incident dataset.
-
[7] Wikipedia — Yahoo data breaches
Yahoo data breaches- Thống kê
Yahoo's 2013 breach, initially disclosed in December 2016 as affecting 1 billion accounts, was revised in October 2017 to confirm all 3 billion Yahoo accounts existing at the time were compromised- Trích đoạn
“"Almost a year later, in October 2017 they revised that estimate and reported that all three billion Yahoo accounts had been compromised in the breach." ”
- Dữ liệu nguồn từ
- 2017-10-03
- Truy cập
- 2026-07-03 · bản sao lưu trữ
- Tính toán
- Cited in the body prose alongside Equifax as a second concrete named mega-breach illustrating cumulative lifetime exposure. Not used in the lifetime-probability arithmetic. Grounds the "Yahoo breach (3 billion accounts)" reference in the body text; the 3-billion revision is corroborated by contemporaneous reporting (e.g. the Wall Street Journal's October 3, 2017 story "Yahoo Triples Estimate of Breached Accounts to 3 Billion," cited in this Wikipedia article's references) and Yahoo/Verizon's own SEC disclosures.
- Độc lập
- Tertiary compilation source; the underlying disclosure is Yahoo's own 2017 SEC filings and contemporaneous news reporting. Included only as corroboration for a widely reported, uncontested figure not itself covered by this entry's other four sources.
-
[8] Federal Trade Commission (FTC) — Consumer Sentinel Network Data Book 2024
Consumer Sentinel Network Data Book 2024See all 4 Likelier entries citing this source →
- Thống kê
FTC Consumer Sentinel Network received 6.5 million consumer reports in 2024; identity theft was the largest single category at approximately 1.1 million reports, about 17% of all reports- Trích đoạn
“"During 2024, Sentinel received 6.5 million consumer reports, which the FTC has sorted into 29 top categories. ... In 2024, there were more than 1.1 million reports of identity theft received through the FTC's IdentityTheft.gov website." ”
- Dữ liệu nguồn từ
- 2025-03-01
- Truy cập
- 2026-07-03 · bản sao lưu trữ
- Tính toán
- Grounds the body prose's and caveats' "the FTC received about 1.1 million identity-theft complaints in 2024" reference (which previously named the FTC without a citation). Both figures are now quoted verbatim in the excerpt above: the 6.5-million-report total and the >1.1-million identity-theft figure, the latter the FTC's largest single Sentinel category (~1.1M / 6.5M ≈ 17% of all reports). Not used in this entry's headline lifetime-probability arithmetic, which relies on the ITRC breach-notice figures above; included only to ground the specific FTC identity-theft-complaint figure used in the body prose to distinguish "exposure" from "harm."
- Độc lập
- FTC Consumer Sentinel Network is a distinct federal consumer-complaint intake pipeline, independent of the ITRC's breach-notice tracking and Verizon's incident-investigation dataset used elsewhere in this entry.






