Most of what we know about data breaches comes from companies admitting they've been breached. That's a bit like measuring crime by counting confessions.
This is the problem Proton set out to work around when it launched its Data Breach Observatory in October 2025. Rather than waiting for corporate disclosures or regulatory filings, the Observatory looks at where stolen data actually ends up: dark web marketplaces and forums where criminals buy, sell, and trade the contents of hacked databases. If a company's customer records are being auctioned off, that shows up whether or not anyone has issued a press release.
Proton has now published an update and the picture it paints is less about corporate Megabreaches and more about the small businesses quietly getting flattened.
Since the start of 2025, the Observatory has catalogued 512 breaches exposing more than 902 million records. In 2026 alone, dozens of incidents have already exposed close to 100 million records.
Retail is the most frequently hit sector, making up a quarter of breached companies, followed by technology at 12% and media and entertainment at 11%. That ordering makes intuitive sense. Retail sits on payment data, loyalty accounts, and addresses, and it operates through sprawling networks of point-of-sale systems, e-commerce plugins, and third-party vendors. Lots of doors, lots of locks, not always someone checking them. But the sector breakdown isn't the most interesting finding here. The company-size breakdown is.
Proton defines small and medium businesses as organisations with 1 to 249 employees. Those companies account for 63% of all breaches tracked since January 2025, representing over 352 million leaked records.
You might expect that. There are far more small businesses than large ones, so of course they show up more often in absolute terms. What's harder to shrug off is the severity data.
Proton classifies a breach as "critical" when it exposes highly sensitive material such as authentication credentials, personal identifiers, financial details etc. SMBs account for 61% of these critical breaches. Narrow it further to genuinely small businesses of 1 to 49 employees, and that group alone accounts for 48% of all critical incidents. Nearly half of the worst breaches are happening at companies that might not employ a single full-time IT person.
The same pattern holds for scale. Among breaches exposing more than 100,000 records, SMBs make up 60%, with the smallest businesses representing 42%.
So small organisations aren't just breached more often, the breaches they suffer tend to be worse. That runs against the intuition that a small company is a small target with small consequences. A twelve-person business processing customer payments can be sitting on a database that's just as valuable to a criminal as one held by a company a hundred times its size, and it's defending that database with a fraction of the resources.
The update also flags a resurgence in something delightfully low-tech: voice phishing, or "vishing." Instead of sending a fraudulent email and hoping someone clicks, the attacker simply phones an employee and talks their way in by posing as IT support, a vendor, or an executive, and walking the target through handing over credentials or approving a login.
Proton points to a campaign run in early 2026 by the group ShinyHunters, which targeted several major technology companies and produced breaches affecting Bumble, Match Group, and SoundCloud. Together those incidents exposed tens of millions of records.
The lesson is uncomfortable for anyone who thinks of security as a technology purchase. These were not small companies with weak infrastructure. They were well-resourced tech firms, compromised because a person on the other end of a phone call was persuaded to help. No firewall has a setting for that.
Proton's analysis of the leaked datasets themselves is worth sitting with, because it explains why breaches at companies you've never heard of still matter to you personally. Names and email addresses show up in nearly nine out of ten breaches. Contact details like phone numbers and physical addresses appear in 75%. Passwords are exposed in 47% (roughly half).
That password figure is the one that should make you uneasy, and not because of the breached company. Because of everywhere else. Criminals take credentials from one breach and systematically test them against other services, a technique called credential stuffing. If you reused a password, a breach at a small online retailer becomes a breach of your email, your cloud storage, and anything protected by them.
Beyond that, 42% of incidents exposed both a person's name and their physical address together. A combination that powers convincing targeted scams and identity theft. Highly sensitive material like government-issued IDs, health records, and other personal identifiers turned up in 37% of breaches. Financial data appeared in about 5%, which sounds low until you consider what 5% of 902 million records looks like in practice.
Proton cites an average breach cost of $4.88 million in losses and fines, with smaller organisations facing damage in the hundreds of thousands. That is enough to end some businesses outright.
The defences Proton recommends are unglamorous and well-worn: turn on two-factor authentication everywhere, enforce genuine password policies, and train staff to recognise social engineering. There's nothing novel there, and that's rather the point. The Observatory data doesn't suggest attackers are defeating sophisticated defences. It suggests they're mostly walking through doors that were left open, at organisations that never had the budget to close them.
The broader value of a project like this is simply visibility. A breach-tracking system built on voluntary disclosure will always undercount, because disclosure is embarrassing, sometimes legally fraught, and occasionally optional. Watching the resale market instead produces an uglier but more honest picture. One in which the typical victim isn't a household-name corporation, but a small company that had no idea its customer database was already for sale.