Worst Data Breaches of 2018

It seemed like data breaches were everywhere in 2018, affecting everyone from a Canadian cannabis store to Chili's to the U.S. Postal Service. Here are a few of the biggest data breaches of the year.

It seemed like data breaches were everywhere in 2018, affecting everyone from a Canadian cannabis store to Chili’s restaurants. Yale even discovered and disclosed a 2008 data breach this year. The amount and types of data accessed varied, but each incident was another reminder of the importance of data security.

We’ve rounded up a few of the biggest data breaches from 2018 below.

Marriott

One of the biggest data breaches of the year—and potentially of all time—was disclosed earlier this month. Marriott International, the world’s largest hotel chain, announced a breach of its Starwood guest reservation database and said that as many as 500 million guests could be affected. Upon investigation, Marriott found that there had been unauthorized access since 2014 and that an “unauthorized party” had copied and encrypted some information and “took steps toward removing it,” but the company did not specify how much data was removed.

Marriott said that for about 327 million of affected guests, accessed information included some combination of a name, address, phone number, email, passport number, Starwood Preferred Guest account information, date of birth, gender, arrival and departure information, reservation data and communication preferences.

My Fitness Pal

Under Armor said about 150 million users were affected by a data leak in the company’s MyFitnessPal app that occurred in February. Under Armor said notified users via email and in-app messages, and it was “working with leading data security firms to assist in its investigation.”

The company said “an unauthorized party acquired data associated with MyFitnessPal user accounts,” such as usernames, passwords and email addresses.

Quora

About 100 million Quora users were affected by authorized access to one of its systems by a “malicious third party,” according to the site. Quora said it was logging out all users who might have been affected in order to prevent further damage and notifying users whose data had been compromised.

Compromised information may include names, emails, encrypted password and data imported from linked networks.

USPS

A security vulnerability in the U.S. Postal Service’s “Informed Visibility” mail tracking and reporting service potentially exposed the data of more than 60 million customers. The postal service said it is not aware of anyone’s records being accessed, but the security hole has been fixed.

The service’s API could have allowed almost anyone with a USPS account to view other users’ account details and even access information such as when critical documents and checks were scheduled to be delivered to their mailboxes.

Facebook

Among the many unfortunate headlines for Facebook this year was a massive data breach that exposed the account details and personal information of almost 50 million users. Facebook said they have fixed the security vulnerability and alerted authorities of the breach.

The hack was possible due to Facebook’s “View As” feature, which lets users view their own account as if they were a stranger in order to check post privacy settings, etc. The feature gives the user an “access token,” which allows them to log back into their account without resubmitting information, and hackers exploited this to harvest other users’ access tokens.

 

 

If you use the same login information and password for accounts across many different websites, hackers could potentially find your login in a data breach of a lower-stakes app and use it to access your account on something more important and private, like a bank account. Read more about protecting yourself from hackers here.

If you’ve been hacked, here are some steps you can take to protect yourself after the fact.

Featured

  • Pragmatism, Productivity, and the Push for Accountability in 2025-2026

    Every year, the security industry debates whether artificial intelligence is a disruption, an enabler, or a distraction. By 2025, that conversation matured, where AI became a working dimension in physical identity and access management (PIAM) programs. Observations from 2025 highlight this turning point in AI’s role in access control and define how security leaders are being distinguished based on how they apply it. Read Now

  • Report: Cyber Attackers Continue to Turn to AI-Based Tools to Avoid Detection

    Comcast Business recently released its 2025 Cybersecurity Threat Report, a comprehensive analysis of 34.6 billion cybersecurity events detected between June 1,2024 and May 31, 2025. Now in its third year, the report offers business leaders a unique perspective into the evolving threat landscape and provides actionable insights to help organizations strengthen their defenses and align cybersecurity with business risk. Read Now

  • Axis Communications Creates AI-powered Video Surveillance Orchestra

    What if cameras could not only see the world, but interpret it—and respond like orchestra musicians reading sheet music: instantly, precisely, and in perfect harmony? That’s what global network technology leader Axis Communications set to find out. Read Now

  • Just as Expected

    GSX produced a wonderful tradeshow earlier this week. Monday was surprisingly strong in the morning, and the afternoon wasn’t bad at all. That’s Monday’s results and asking attendees to travel on Sunday. Just a quick hint, no one wants to give up their weekend to travel and set up an exhibit booth. I’m just saying. Read Now

    • Industry Events
    • GSX
  • NOLA: The Crescent City

    Twenty years later we finds ourselves in New Orleans. Twenty years ago the aftermath of Hurricane Katrina forced exhibitors and attendees to look elsewhere for tradeshow floor space. Read Now

    • Industry Events
    • GSX

New Products

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge.

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.