33.7 million accounts in South Korea at 25-1130. 6.5 million Co-op members — all of them — at 25-0501. 6.4 million at one French carrier and a second carrier weeks later, at 25-0804 and 25-0909. 5,556,702 patients at one US health system at 25-0308.
Remediation Assumes The Affected Are A Minority
Credit monitoring, identity alerts and enhanced verification all work by treating the affected as an exception requiring extra scrutiny. That logic depends on most people not being in the set.
When a substantial fraction of a national population is affected, the exception becomes the norm. Enhanced verification for everyone is just verification. An alert triggered by a population is not a signal.
And The Fraud Economics Change With Saturation
This desk filed the uncomfortable version at 25-1010: at sufficient volume, marginal exposure from one more breach is genuinely lower because the data is already circulating.
That argument is a reason to stop trying and nobody should be allowed to make it out loud. It is also, at national scale, arithmetically difficult to dismiss — which is a problem the corpus can state and cannot resolve.
What Actually Follows
If identity data is assumed compromised for most of a population, systems that authenticate on knowledge of that data are broken as a class — which is the argument for possession- and device-bound authentication, and against knowledge-based verification of the kind still used across banking and government services.
That is an expensive, slow, infrastructural response. It is also the only one that survives the premise. Graded medium: this is reasoning from the incident record rather than a finding from a source.
It reasons from the population-scale incidents recorded in this database against the national populations involved. Sources below support the underlying incidents. Corrections: corrections@forensicpost.com.
- Top data breaches in 2025, month-wiseSecurity Boulevard
- Wrapping up 2025: global data breach statisticsSurfshark