Looking for a complete Apple data breaches list? This page answers common searches like "Apple hacked," "Apple breach history," and "list of Apple data breaches" with a verified timeline, record counts, root causes, and step-by-step guidance if you may have been affected.
Apple data breach history: From XcodeGhost on 128 million iPhones to developer-center hacks, Apple’s walled garden has still seen serious data incidents. BreachHistory indexes 13 verified or attested incidents tied to Apple, spanning 2010–2023. This page is a complete, searchable timeline—not a single event—linking every catalog row with context on scale, root cause, and what users should do when a new Apple notice drops.
Why Apple stays on breach trackers
Global tech brands combine massive user bases, high-value intellectual property, and complex supply chains. Attackers target Apple for credentials, source code, CRM exports, and employee directories. When you read headlines about "Apple hacked," the incident may be a consumer PII leak, a developer artifact exposure, or a third-party SaaS tenant breach—each with different remediation steps.
Data breaches list — Apple
Below are the major incidents in our catalog, newest first. Record counts use company, regulator, or Have I Been Pwned attestation where available; actor-only marketing shows as "Unverified / not disclosed."
- 2023 — July 2023 — Rapid Security Response for WebKit zero-day (CVE-2023-37450) (Unverified / not disclosed records)
- 2022 — September 2022 — Zero-day kernel vulnerability (CVE-2022-32917) (Unverified / not disclosed records)
- 2022 — August 2022 — WebKit and kernel zero-days (CVE-2022-32893, CVE-2022-32894) (Unverified / not disclosed records)
- 2021 — September 2021 — Pegasus spyware zero-click exploit (FORCEDENTRY) (Unverified / not disclosed records)
- 2019 — January 2019 — Google Project Zero finds in-the-wild iOS exploit chain (Unverified / not disclosed records)
- 2015 — September 2015 — XcodeGhost malware, 128M iPhones via infected App Store apps (128M+ records)
- 2015 — August 2015 — KeyRaider malware steals 225K Apple accounts from jailbroken iPhones (225K+ records)
- 2015 — March 2015 — Third-party vendor lost USB drive with employee payroll data (Unverified / not disclosed records)
- 2014 — December 2014 — Payment card system breach (27 records) (27 records)
- 2014 — September 2014 — Celebrity iCloud photos leaked (Celebgate) (Unverified / not disclosed records)
- 2013 — July 2013 — iOS Developer Center hacked, 275K developers exposed (275K+ records)
- 2012 — August 2012 — BlueToad leak exposes 12M Apple device UDIDs (12.4M+ records)
- 2010 — June 2010 — AT&T breach exposes 114K iPad users' email addresses (114K+ records)
Biggest and most consequential incidents
September 2015 — XcodeGhost malware, 128M iPhones via infected App Store apps
Malicious Xcode used by developers in China; 4k+ apps on App Store; 128M users (18M US). Apple did not disclose to users; extent revealed in Epic lawsuit 2021. Full incident record →
August 2012 — BlueToad leak exposes 12M Apple device UDIDs
Hacking group AntiSec claimed they hacked an FBI laptop in March 2012 accessing a file of more than 12 million Apple Unique Device Identifiers (UDIDs). Subsequently, it was discovered that app developer BlueToad was the source of the breach. The list contained personal information such as full names, phone numbers and addresses. AntiSec published a million of these UDIDs online. Full incident record →
July 2013 — iOS Developer Center hacked, 275K developers exposed
Unauthorized access to developer portal; names, IDs, possibly email/mailing addresses. Claimant said goal was to expose bugs; Apple confirmed access; some password resets. Full incident record →
August 2015 — KeyRaider malware steals 225K Apple accounts from jailbroken iPhones
KeyRaider stole credentials, keys, certificates, receipts from jailbroken iPhones; enabled unauthorized purchases and data access. Full incident record →
By the numbers (catalog snapshot)
- 13 incidents indexed under Apple on BreachHistory
- 141M+ combined attested records across rows with disclosed numerators (many incidents overlap or count emails—not unique people)
- 2015 — year of the largest attested row in our catalog
Patterns in Apple's breach history
- Credential and session theft — Phishing, stuffing, and OAuth token abuse recur across tech platforms.
- Cloud misconfiguration — S3 buckets, misconfigured APIs, and file shares expose data without a traditional "hack."
- Extortion without precise counts — Ransomware and leak-site actors often publish before victims confirm scope.
- Supply-chain spillover — npm, SDK, and CRM tenant breaches affect Apple customers even when corporate HQ databases stay intact.
What to do if you used Apple
- Enable multi-factor authentication on every Apple account and linked SSO identity.
- Check Have I Been Pwned when new Apple headlines appear.
- Rotate passwords that were reused on email, banking, or work SSO.
- Watch for phishing that cites real breach details (order numbers, usernames) to appear legitimate.
- Follow official Apple security communications—not SMS links from unknown numbers.
Related searches
- Apple data breach list
- Has Apple been hacked?
- Apple hack history
- Apple data leak timeline
- How many times has Apple been breached?
- Apple breach records on BreachHistory
FAQ
How many data breaches has Apple had?
BreachHistory indexes 13 verified or attested Apple data breaches spanning 2010–2023. Counts vary when researchers merge scraping, misconfiguration, and ransomware as separate events.
What is the biggest Apple data breach?
The largest attested incident in our catalog is 128M+ records (September 2015 — XcodeGhost malware, 128M iPhones via infected App Store). See the full timeline for sources and remediation details.
Has Apple been hacked?
Yes — Apple appears on breach trackers with 13 indexed incidents including September 2015 — XcodeGhost malware, 128M iPhones via infected App Store. This page links every catalog row with primary sources and what users should do if affected.
Does Apple send data breach notifications?
Regulated markets require consumer notices for many PII events. Not every source-code or scraping story triggers email alerts—read each incident row for notification status.
Explore every Apple incident on BreachHistory
Browse the full catalog: Apple breach records
Compiled from BreachHistory data/breaches.json and primary sources linked on each incident page. Updated 2026-06-15.