People search Three data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 4 Three-linked incidents, with headline counts up to 200K+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.
Why Three breach history matters
Three operates in Technology. Across indexed rows, recurring themes include mixed intrusion and disclosure events. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.
Full timeline through 2026
2017 — — Three: Hackers broke into Three's customer database with…
Cataloged incident. Hackers broke into Three's customer database with the intention of fraudulently ordering handsets to sell on. They stole personal details, but no financial records or passwords were stored on the hacked system. BreachHistory cites approximately 200K+ affected records in this row. See the threeu and canonical BreachHistory entry.
2016 — — Three: Hackers broke into Three's customer database with…
Cataloged incident. Nov 2016. Hackers broke into Three's customer database with the intention of fraudulently ordering handsets to sell on. They stole personal details, but no financial records or passwords were stored on the hacked system. BreachHistory cites approximately 200K+ affected records in this row. See the three2016 and canonical BreachHistory entry.
2012 — — Three: Hackers were able to access the user names and…
Cataloged incident. Hackers were able to access the user names and passwords located on the Three Rivers Park District database. Anyone who has ever made a reservation or registered for a program associated with with the districts 21 parks was affected. No financial information, names, or addresses was exposed. The breach was discovered on April 19 and immediately addressed. Exposed categories include Personal information. BreachHistory cites approximately 82K+ affected records in this row. See the three2012 and canonical BreachHistory entry.
2010 — — Three: Three Rivers Community College may have suffered a…
Cataloged incident. Three Rivers Community College may have suffered a security breach due to unauthorized access to its computer network. Data made vulnerable in the breach included names and Social Security numbers. Those affected would have been involved in the following programs during these years: 1997-2009: Participants in the Real Estate programs2004-2009: Participants in the Life Long Learners programs 2003-2006: Participants in the Patient Care Technicians programs2004-2006: Participants in the Certified N Exposed categories include Personal information. No attested victim count is published for this row yet. See the three2010 and canonical BreachHistory entry.
Patterns and analysis
- Mixed intrusion and disclosure events — appears across multiple Three catalog entries; prioritize controls that address this class of failure.
- Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
- 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.
What to do if you may be affected
- Step 1: Enable phishing-resistant MFA on every account tied to this brand.
- Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
- Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
- Step 4: Review OAuth app permissions and revoke unused third-party integrations.
- Step 5: Bookmark the Three company page for new 2026+ disclosures.
Canonical BreachHistory hub
Explore every indexed row: breachhistory.com/three · Latest: threeu.
Sources: BreachHistory catalog (4 rows for Three), company and regulator disclosures cited in individual breach records.