Blog

The Age of Data Breaches Isn't Slowing Down


Data breaches are getting bigger, more frequent, and harder to contain. Here's what's driving the trend and what you can do about it.



In 2024, the average cost of a data breach reached $4.88 million, according to IBM's annual Cost of a Data Breach report. Over one billion records were exposed in the first half of the year alone. These are not outliers. They are the continuation of a trend that has been accelerating for years, and there is little reason to expect it will reverse on its own.

The breaches making headlines are no longer limited to small companies with poor security hygiene. They are hitting large, well-resourced organisations. They are affecting hundreds of millions of people at a time. And the root causes are becoming more structural, tied to the way modern software is built, connected, and deployed.

Understanding why this is happening, and what practical steps exist, matters more than it did five years ago. The surface area for attacks has grown. So has the volume of data sitting behind it.


The scale of recent breaches

A few incidents from 2023 and 2024 illustrate the trajectory.

The MOVEit breach in mid-2023 exploited a vulnerability in a widely used file transfer tool. Because MOVEit was embedded in the workflows of thousands of organisations, a single vulnerability cascaded across more than 2,600 companies and government agencies. It was a textbook supply chain attack: the target was not any one company but the infrastructure that many companies relied on.

In early 2024, AT&T disclosed that records belonging to roughly 73 million current and former customers had been exposed. The data included names, addresses, Social Security numbers, and account details. For a company of AT&T's size and resources, the breach underscored that scale alone does not equal security.

The National Public Data breach in 2024 was staggering in its scope. Approximately 2.9 billion records were compromised, including Social Security numbers, addresses, and other personal identifiers. National Public Data, a background check and data broker service, held vast quantities of sensitive information about people who had never directly interacted with the company. Most of the individuals affected had no idea their data was there in the first place.

Then came the Snowflake-related breaches. Snowflake, a cloud data platform, was not itself breached in the traditional sense. Instead, attackers used stolen credentials to access customer accounts that lacked multi-factor authentication. The fallout hit Ticketmaster, Santander, and other major companies. It was a reminder that security is only as strong as its weakest authentication layer.


Why it keeps getting worse

Several structural forces are driving the increase in breach frequency and severity.

The first is the sheer volume of data being collected. Companies gather more information about their users than ever before, often far more than they need for the services they provide. Every additional data point stored is another data point that can be stolen. Data minimisation, the practice of collecting only what is necessary, remains an aspiration more than a norm.

The second is the proliferation of third-party integrations. Modern software rarely operates in isolation. Applications connect to other applications through APIs, plugins, and data pipelines. Each integration introduces a potential entry point. The MOVEit breach is a clear example: organisations that had never heard of MOVEit were affected because a vendor or partner used it somewhere in their supply chain.

Supply chain attacks more broadly are following the pattern established by the SolarWinds breach in 2020. Rather than attacking a target directly, adversaries compromise a tool or service that the target depends on. This approach scales well for attackers because a single compromised dependency can unlock access to thousands of downstream organisations.

Credential stuffing remains a persistent problem. When credentials from one breach are reused across services, attackers can automate login attempts at enormous scale. The Snowflake incidents were largely enabled by stolen credentials and the absence of multi-factor authentication. Despite years of guidance on this topic, credential reuse and weak authentication practices remain widespread.

And then there is the expanding attack surface created by AI. AI agents, which connect to accounts, read files, send messages, and take actions on behalf of users, introduce new vectors. Every agent that connects to your email, your cloud storage, or your project management tool is another point of access that needs to be secured. The permissions granted to these agents are often broad, because they need access to be useful. But broad permissions also mean broad exposure if the agent, or the service providing it, is compromised.


The agent problem

The rise of AI agents deserves particular attention, because it represents a qualitative shift in how data is accessed and moved.

Traditional software accesses data in relatively predictable ways. An email client reads your inbox. A spreadsheet app reads your files. The data flows are understood, and the access patterns are well defined.

AI agents, by contrast, often need open-ended access. An agent that helps you manage your schedule might need access to your calendar, your email, your task manager, and your contacts. An agent that helps you with research might need access to your documents, your browser history, and your notes. The more capable the agent, the more access it requires.

This creates a compounding problem. Each agent is a new integration point. Each integration point is a potential vector. And unlike traditional software, agents often operate with a degree of autonomy, making decisions about what data to access and how to use it. If an agent's credentials are compromised, or if the agent's provider suffers a breach, the blast radius can be significant.

The industry has not yet developed robust standards for agent authentication, permission scoping, or audit logging. These standards will come, but in the interim, every new agent connection is a bet on the security of the provider behind it.


What individuals and teams can do

There is no way to eliminate breach risk entirely. But there are concrete steps that reduce your exposure.

The most effective step is also the simplest: reduce your data footprint. The fewer places your data lives, the fewer places it can be stolen from. This means consolidating files and information into fewer systems rather than scattering them across dozens of services. It means deleting accounts you no longer use. It means being selective about which services you sign up for and which permissions you grant.

Choosing tools with strong encryption and clear privacy policies matters more than it once did. Not all cloud services handle your data the same way. Some encrypt data at rest and in transit. Some do not. Some retain your data indefinitely. Some allow you to delete it. Reading the fine print is tedious, but the differences between services are material.

Keeping files in systems you control, rather than leaving them scattered across platforms you have limited visibility into, is a meaningful risk reduction. When your files live in a single, well-secured environment, you can enforce consistent access controls, monitor for unusual activity, and respond quickly if something goes wrong. When your files are spread across fifteen different services, each with its own security posture, your risk is determined by the weakest link in the chain.

Multi-factor authentication remains one of the most effective defences available. The Snowflake-related breaches would have been largely prevented by it. Enabling MFA on every service that supports it is a small investment of time with an outsised return.

For teams, establishing clear policies about which tools are approved, how data is shared, and how agents are authorised can reduce the organisational attack surface. Shadow IT, the use of unapproved tools and services by individual team members, is one of the most common sources of unmanaged risk.


Building on a security-conscious foundation

Fabric approaches these problems with a privacy-first architecture. Data is encrypted, and your files stay yours. The platform does not train AI models on your data. When you use Fabric's AI assistant, it works on your files without sending them elsewhere for processing.

The bring-your-own-storage model means you control where your files live physically. You can connect Google Drive, Dropbox, and other services, but your data remains in the storage you choose. This is a meaningful distinction from platforms that require you to upload everything to their servers.

Consolidating your files into a single cloud workspace also reduces the number of integration points you need to manage. Rather than granting access across a dozen different tools, you can work from one environment with consistent security controls. Fabric's smart organisation auto-categorises files by content, so consolidation does not come at the cost of findability.

For teams working with sensitive materials, having a platform with clear data handling policies is a baseline requirement, not a luxury. The collaboration features in Fabric are designed with this in mind, enabling teams to share and publish work without compromising on security.


The trend is clear

The age of data breaches is not slowing down because the conditions that produce them are intensifying. More data is being collected. More systems are being connected. More agents are being granted access to more accounts. The attack surface grows with each new integration, each new service, each new AI tool.

This does not mean you should stop using technology. It means you should be deliberate about which technology you use, how much data you expose, and where that data lives. The organisations and individuals who fare best in this environment will be those who treat data security not as a feature to evaluate but as a principle to build around.

The breaches will continue. Your exposure to them does not have to grow at the same rate.


Frequently asked questions

How many data breaches happened in 2024?

The exact count varies by source and definition, but tracking organisations recorded thousands of publicly disclosed breaches in 2024. The more significant metric is the scale: over one billion records were exposed in the first half of the year alone, with several individual incidents each affecting tens of millions or even billions of records.

What was the biggest data breach in 2024?

The National Public Data breach exposed approximately 2.9 billion records, making it one of the largest breaches ever recorded. The Snowflake-related breaches, which affected Ticketmaster, Santander, and other companies through compromised credentials, were also among the most significant in terms of the number of organisations and individuals affected.

What is a supply chain attack?

A supply chain attack targets a tool, service, or software component that other organisations depend on. Rather than attacking the final target directly, attackers compromise a supplier or dependency. The MOVEit breach in 2023 is a clear example: a vulnerability in one file transfer tool cascaded across more than 2,600 organisations that used it directly or through their vendors.

How do AI agents increase breach risk?

AI agents typically require broad access to your accounts, files, and services in order to function. Each agent connection is an additional integration point that must be secured. If an agent's provider is compromised, or if the agent's credentials are stolen, the attacker gains access to everything the agent could access. Standards for agent authentication and permission scoping are still developing.

What is credential stuffing?

Credential stuffing is an attack method where stolen username and password pairs from one breach are used to attempt logins on other services. Because many people reuse passwords across accounts, these automated attacks frequently succeed. The Snowflake-related breaches in 2024 were largely enabled by stolen credentials and the absence of multi-factor authentication.

Does encryption prevent data breaches?

Encryption does not prevent breaches, but it significantly limits their impact. If stolen data is properly encrypted, attackers cannot read the contents without the encryption keys. Encryption at rest (when data is stored) and in transit (when data is being transferred) are both important. Not all services implement both.

How can I reduce my personal data exposure?

Consolidate your files into fewer, well-secured systems rather than spreading them across many services. Delete accounts you no longer use. Enable multi-factor authentication everywhere it is available. Read the privacy policies of services you use, particularly around data retention and AI training. Be selective about which apps and agents you grant access to your accounts.

What should teams do to reduce breach risk?

Establish clear policies about approved tools and data sharing. Minimise the number of third-party integrations and agent connections. Use platforms with strong encryption and transparent data handling. Enable multi-factor authentication across all services. Regularly audit access permissions, particularly for AI agents and automated workflows. Consolidating files into a single workspace with consistent security controls reduces the number of potential entry points.


Related pages

The workspace that thinks with you.

Ready when you are.

The workspace that thinks with you.

Ready when you are.

The workspace that thinks with you.

Ready when you are.