← Blog

Apple Data Breaches: Full Timeline Through 2026

Share on X

Searching for an Apple data breach timeline or asking has Apple ever been hacked? Apple markets privacy as a product, yet the world's most valuable technology company sits at the center of recurring security crises—credential thefts, supply-chain malware, nation-state spyware, and third-party leaks spanning more than a decade. BreachHistory indexes 16 Apple-linked incidents; this page walks through each attested event through 2026 with links to canonical records.

Why Apple breaches look different

Unlike retailers that lose payment databases, Apple incidents often fall into distinct buckets: ecosystem malware (XcodeGhost, KeyRaider), credential phishing (Celebgate), third-party developer leaks (BlueToad UDIDs), zero-day exploitation (Pegasus, kernel bugs), and supply-chain intelligence (2026 Tata leak). Consumer Apple IDs are rarely stolen from Apple.com servers directly—but the downstream harm to users is real.

Full timeline: Apple data incidents through 2026

2026 — Tata supply-chain leak (iPhone 18 Pro intelligence)

June 2026: Reuters reported new files in the World Leaks archive from Tata Electronics allegedly map hundreds of iPhone 18 Pro components to named suppliers and include drop-test photos with Apple confidential watermarks. Apple is investigating; the company had not publicly confirmed document authenticity at initial reporting. This is industrial espionage risk, not consumer iCloud PII—indexed as unverified by Apple.

2023 — WebKit zero-day (CVE-2023-37450)

Apple issued a Rapid Security Response for an actively exploited WebKit flaw (July 2023 zero-day). No confirmed mass data theft, but the patch cycle illustrates ongoing nation-state and criminal interest in iOS attack surface.

2022 — Kernel and WebKit zero-days

Multiple emergency patches: CVE-2022-32917 kernel zero-day (September 2022) and CVE-2022-32893 / CVE-2022-32894 WebKit and kernel flaws (August 2022). These enabled arbitrary code execution on patched-late devices—typical precursors to spyware deployment.

2021 — Pegasus FORCEDENTRY and catalog leaks

The Pegasus zero-click exploit (FORCEDENTRY) let NSO Group spyware compromise iPhones without user interaction—accessing calls, messages, camera, and microphone. Separately, BreachHistory indexes large BlueToad-related and hacking-attributed dataset rows from 2021 aggregators; treat overlapping counts carefully.

2019 — In-the-wild iOS exploit chain

Google Project Zero disclosed a sophisticated watering-hole attack chain stealing passwords, contacts, messages, and location from iPhones visiting compromised sites—demonstrating that even fully patched iOS could be owned by well-resourced actors.

2015 — XcodeGhost and KeyRaider (ecosystem scale)

XcodeGhost infected Apple's App Store toolchain pipeline, putting malicious code into legitimate apps downloaded by an estimated 128 million iPhones—one of the largest mobile supply-chain incidents ever. KeyRaider stole 225,000 Apple IDs from jailbroken devices via malware—not Apple's fault, but users blamed the ecosystem.

Apple also disclosed a third-party vendor lost a USB drive with employee payroll SSNs—a classic contractor failure.

2014 — Celebgate and payment cards

Celebgate: attackers spear-phished celebrity iCloud credentials and leaked private photos—Apple strengthened 2FA messaging afterward. A separate payment-card breach affected 27 records via hacking of a payment system.

2013 — iOS Developer Center

Apple confirmed hackers accessed the iOS Developer Center, exposing 275,000 developer names, IDs, and emails—a who-is-who list for targeting app publishers.

2012 — BlueToad UDID leak

AntiSec published 12 million Apple device UDIDs sourced from app developer BlueToad—not Apple's servers, but identifiers Apple once allowed apps to collect.

2010 — AT&T iPad email exposure

AT&T's web portal flaw exposed 114,000 iPad user email addresses and ICC-IDs during iPad 3G launch—carrier breach, Apple brand impact.

Patterns across the timeline

  • Third parties amplify risk: BlueToad, XcodeGhost authors, Tata suppliers, and AT&T show Apple's attack surface extends beyond Cupertino data centers.
  • Credentials beat crypto: Celebgate succeeded via phishing, not iCloud encryption breaks.
  • Zero-days target VIPs: Pegasus and Project Zero chains focus on journalists, executives, and dissidents—not mass consumer DB dumps.
  • 2026 shift: Supply-chain leaks of unreleased hardware intelligence are the new frontier alongside traditional PII events.

What Apple users should do

  1. Enable Advanced Data Protection for iCloud where available.
  2. Use hardware security keys or trusted-device 2FA for Apple ID.
  3. Never reuse Apple ID passwords on third-party sites (Celebgate lesson).
  4. Avoid jailbreaking—KeyRaider-class malware depends on it.
  5. Update iOS immediately when Rapid Security Responses ship.

Canonical BreachHistory records

Explore every indexed row: Apple company page on BreachHistory. Key 2026 entry: Apple Tata supply-chain leak 2026.

Sources: BreachHistory catalog, Reuters (June 2026 Tata leak), Apple security advisories, Google Project Zero research.