Apple Data Breach History
WebsiteApple Inc. is an American technology company (iPhone, Mac, services). Fortune 500.
This page shows all data breaches of Apple. View the complete breach timeline, records exposed, root causes, and AI breach risk score. BreachHistory tracks disclosed data breaches worldwide.
Data Breach Timeline — All Apple Breaches
- 2026 2026 Apple — Tata Electronics supply-chain leak; iPhone 18 Pro supplier list & drop-test photos alleged (unverified by Apple) Unknown records Share
- 2023 July 2023 — Rapid Security Response for WebKit zero-day (CVE-2023-37450) Unknown records Share
- 2022 September 2022 — Zero-day kernel vulnerability (CVE-2022-32917) Unknown records Share
- 2022 August 2022 — WebKit and kernel zero-days (CVE-2022-32893, CVE-2022-32894) Unknown records Share
- 2021 September 2021 — Pegasus spyware zero-click exploit (FORCEDENTRY) Unknown records Share
Apple Data Breach Summary
This page tracks the Apple data breach history and cybersecurity incidents affecting Apple (United States). BreachHistory currently indexes 16 publicly disclosed or catalogued incidents spanning 2010 through 2026, with approximately 153.6 million records reported as exposed across all indexed events. These totals may include overlapping datasets or third-party estimates and should not be interpreted as unique affected users.
The Apple breach timeline includes major data breaches, cyber attacks, data leaks, credential exposures, API abuse, and other security incidents. Each incident provides details on the estimated records exposed, attack method, affected data types, and supporting public sources. Currently, 0 incidents are company-confirmed, while 3 remain unverified claims pending independent verification.
Largest Apple Data Breaches
The largest indexed incidents include the 2015 September 2015 — XcodeGhost malware, 128M iPhones via infected App Store apps, the 2021 — Apple, Inc./BlueToad: Accidentally published, 12,367,232 records, and the 2012 August 2012 — BlueToad leak exposes 12M Apple device UDIDs, along with additional historical incidents involving exposed passwords, public databases, and large-scale data scraping. Record counts originating from threat actors or leak sites should be treated as estimates unless confirmed by Apple or a regulator. Below is the list of large data breaches:
- 2015 September 2015 — XcodeGhost malware, 128M iPhones via infected App Store apps — about 128.0M records exposed · Catalogued incident
- 2021 2021 — Apple, Inc./BlueToad: Accidentally published, 12,367,232 records — about 12.4M records exposed · Catalogued incident
- 2012 August 2012 — BlueToad leak exposes 12M Apple device UDIDs — about 12.4M records exposed · Unverified claim
- 2021 2021 — Apple: Hacking, 275,000 records — about 275.0K records exposed · Catalogued incident
- 2013 July 2013 — iOS Developer Center hacked, 275K developers exposed — about 275.0K records exposed · Unverified claim
- 2015 August 2015 — KeyRaider malware steals 225K Apple accounts from jailbroken iPhones — about 225.0K records exposed · Catalogued incident
- 2010 June 2010 — AT&T breach exposes 114K iPad users' email addresses — about 114.0K records exposed · Catalogued incident
- 2014 December 2014 — Payment card system breach (27 records) — about 27 records exposed · Catalogued incident
What Information Was Exposed?
Depending on the incident, exposed data may include email addresses, passwords and login credentials, Social Security numbers and national IDs, phone numbers, names, physical addresses, and other personal information (PII). The exact data varies between incidents, so review each breach page before assuming your information was affected.
Apple Data Breach 2026
At the time of this update, BreachHistory catalogues 1 2026 incident related to Apple. Most recent entry: 2026 Apple — Tata Electronics supply-chain leak; iPhone 18 Pro supplier list & drop-test photos alleged (unverified by Apple). New incidents are added as official disclosures, regulatory filings, or credible cybersecurity reports become available.
What To Do If You Were Affected
If you believe your account may have been involved in a Apple data breach, change any reused passwords, enable multi-factor authentication (MFA), monitor your account for suspicious activity, and be cautious of phishing emails or fake breach notifications.
This Apple breach history is maintained by BreachHistory using public disclosures, regulatory filings, security research, and clearly labelled third-party claims. For the complete breach timeline, records exposed, incident details, and AI Breach Risk Score, explore the sections on this page.