3. South Carolina
Approximately 3.8 million tax records and nearly 400,000 credit card numbers were stolen from the South Carolina Department of Revenue. Over 2 million incidents of information theft were also nabbed through the same spearphishing exploit that stole employee usernames and passwords to gain access to the sensitive data. Improper password policies and failure to encrypt social security numbers were key enablers of the operation, which also led to the resignation of the agency's director. It's believed to be the largest data theft from a state government.