In many routes, forces-out were already in motion to stimulate 2016 the biggest year of corporate and government hacks yet. Company violates have been on the rise for a decade, and an election year always invites drama. The reality of what hackers–both state-sponsored and independent–delivered in 2016, though, still managed to outstrip expectations.

Not all of the hackers on such lists has just taken place in the last 12 months, but all were disclosed in 2016. And each expanded the scale and scope of what the average person expects from digital meddling in practice. A handful of corporate violates included half a billion records, and one was a full billion. Meanwhile on the political side, Russian state-sponsored hackers used leaks, probes, and disinformation campaigns to undermine and destabilize campaign discourse leading up to the US presidential election.

In short, there was a lot going on, so heres WIREDs look back at the biggest hacks in 2016.

Yahoo

In words of sheer magnitude the second Yahoo violate, committed in fall 2013 and disclosed earlier this month, is the biggest hack of 2016( and all day) impacting one billion accounts. Yahoo says it doesn't yet know who committed this intrusion, which compromised data like names, email addresses, telephone number, birthdays, hashed passwords, and a mixture of encrypted and unencrypted security questions and answers. The violate doesn't include unencrypted passwords, credit card numbers, or bank account information. Yahoo is working with law enforcement and a third-party security firm to analyze the breach.

But wasn't there also a Yahoo hack announcement back in September? Big question! Yes. Yahoo announced this fall that it was hacked in late 2014 by an as-yet unnamed” state-sponsored performer ,” which accessed 500 million user accounts. When it disclosed the other hack a few weeks ago, Yahoo said that the two incidents are most likely separate and not part of an over-arching operation…which is kinda worse in the sense that the company get devastatingly owned two separate times by two different attackers. There is probably substantial overlap between the one billion records accessed in the 2013 breach and the 500 million compromised in 2014, but regardless this is a staggering quantity of user data that Yahoo lost control of. There are only a few other tech companies that even have a billion user accounts to lose.

Democratic National Committee, Democratic Congressional Campaign Committee, Podesta Emails

While the Yahoo hack was the biggest in scope, Russia's hack of various Democratic Party correspondences had the largest impact of any breach this year. The release of private emails through Wikileaks devoted Hillary Clinton's presidential campaign numerous distractions( and occasional embarrassments) in the final stretch of the 2016 election, and more importantly, signals an emboldened Russia that may attempt similarly disruptive the initiatives in upcoming European elections as well. Similar initiatives have already wreaked havoc in other elections, like Ukraine's 2014 presidential race.

MySpace, LinkedIn, Tumblr

The ghosts of violates past rose again this year. While obtained during separate hackers, credentials from years-old MySpace, LinkedIn, and Tumblr accounts started circulating in data sale forums at the same time in 2016 thanks to the hacker known as Peace_of_mind or merely “Peace.” With top ratings on his or her dark web storefront, Peace has hundreds of millions of credentials for sale, some dating back as far as 2012 breaches. He or she told WIRED in June,” Well,[ the] main use is for spamming. There is a lot of money to be made there, as[ well as] in selling to private buyers go looking for specific targets. As well, password reuse–as seen in recent headlines of account takeovers of high profile people .” Data from the old violates was successfully used to take over accounts of celebrities like Lana Del Rey, Mark Zuckerberg, and Biz Stone.

FriendFinder

A breach of the hookup and dating firm FriendFinder exposed 412 million user accounts when they were released this fall and published by the breach notification service LeakedSource. 339 million accounts came from AdultFriendFinder.com, which describes itself as the the worlds largest sex& swinger community, and tens of millions came from Penthouse.com and Stripshow.com. A problematic facet of this breach was that even people who made an account on one of the sites and then deleted it were still at risk, because a trove of accounts that were marked to be removed was alsoes compromised. Overall, data impacted by the hacker included usernames, passwords, and email addresses. Details about the users of sexuality sites can be especially upsetting or damaging for people when released, and the FriendFinder hack was regrettably virtually 13 times the size of last year's devastating Ashley Madison breach.

Shadow Brokers

In August, a group calling itself the Shadow Brokers claimed to have breached the operation known as the Equation Group, a cyber espionage team with NSA connections. The Shadow Brokers released a sample of stolen zero-day exploits( undisclosed software bugs that haven't been patched) that Equation Group allegedly used to break into and surveil international targets. The Shadow Brokers also promised that more exploits were in an encrypted file that they put up for sale in a( poorly attended) bitcoin auction. The sample exploits were real, though, and caused problems for companies like Cisco, Juniper, and Fortigate whose software was affected.

The Shadow Brokers leak served as a reminder of the complicated balance between the necessity of achieving government intelligence gathering and the danger of hoarding exploits for many years instead of notifying software manufacturers and allowing them to fix the glitches. It is also unclear who the Shadow Brokers are and how they infiltrated the NSA. Officials thought they had a leading when they discovered that a Booz Allen Hamilton employee Harold Martin, who worked at the agency for years and had top secret clearance, had pilfered 50 terabytes of categorized data during his tenure and was stockpiling it at his home. Examiners have so far been unable to connect Martin to the Shadow Brokers, though. He has been charged with mishandling categorized data and stealing government documents, and will face additional charges under the Espionage Act.

Dropbox

Another old hack with new repercussions. In 2012, invaders compromised Dropbox and procured credentials–including email addresses and their associated salted and hashed passwords–of over 68 million accounts. The good news is the passwords all had a layer of protection, and Dropbox automatically induced users reset theirs. The bad news? That's a lot of years in the open, and a lot of users uncovered during that intervening time.

Read more: