Learn

Understanding Data Breaches


A data breach occurs when someone gains unauthorised access to information held by an organisation. That information might be passwords, email addresses, financial records, personal documents, or anything else a company stores about its users. The breach might be the result of a deliberate attack, an internal mistake, or a misconfigured system that leaves data exposed to the open internet.

Breaches have become routine. Billions of records are compromised every year, and the scale continues to grow. Understanding how they work, and what you can do in response, is one of the more useful things you can learn about digital security.


How breaches happen

There is no single method behind most data breaches. Attackers exploit whatever vulnerability is available, and organisations create those vulnerabilities in different ways.

Hacking in the traditional sense, where an attacker finds and exploits a flaw in a system, accounts for a large share of breaches. But the term covers a wide range of techniques. An attacker might exploit an unpatched vulnerability in a web application, use SQL injection to extract a database, or find an exposed API that returns data it should not.

Credential stuffing is one of the more common and least dramatic methods. Attackers take username and password combinations leaked in previous breaches and try them against other services. Because people reuse passwords across sites, this works more often than it should. A single leaked password from a minor service can unlock accounts on banking, email, or cloud storage platforms.

Phishing remains effective despite decades of awareness campaigns. A well-crafted email that mimics a login page can capture credentials from even cautious users. Spear phishing, which targets specific individuals with personalised messages, is harder to detect and frequently used against employees with access to sensitive systems.

Insider threats cover a broad category. A disgruntled employee might exfiltrate data deliberately. More often, an employee makes a mistake: sends a file to the wrong recipient, misconfigures a permission, or falls for a social engineering attack. The result is the same.

Misconfigured databases and cloud storage represent a growing category of breach. Organisations migrate data to cloud platforms and leave storage buckets publicly accessible, or deploy databases without authentication. Security researchers regularly discover exposed Elasticsearch or MongoDB instances containing millions of records, sitting open on the internet with no password required.

Supply chain attacks target the software and services that organisations depend on. Rather than attacking a company directly, an attacker compromises a vendor or tool that company uses. The MOVEit breach in 2023 exploited a vulnerability in a widely used file transfer tool, giving attackers access to data from hundreds of organisations that used the software. The Snowflake-related breaches in 2024 followed a similar pattern: attackers used stolen credentials to access data stored in a cloud data platform used by major companies including Ticketmaster and AT&T.


What data gets exposed

The specific data compromised depends on what the breached organisation collected and stored. This is one reason data minimisation matters: an organisation that collects less data exposes less data when something goes wrong.

Credentials (email addresses and passwords) are the most commonly exposed data type. If passwords were stored with strong hashing, attackers may not be able to use them directly. If they were stored in plain text or with weak hashing, every account is immediately compromised.

Personal information such as names, addresses, phone numbers, dates of birth, and national identification numbers appears in many breaches. The 2024 National Public Data breach exposed approximately 2.9 billion records containing names, addresses, and Social Security numbers, much of it collected without the knowledge of the individuals affected.

Financial data, including credit card numbers, bank account details, and transaction histories, carries the most immediate risk. Payment card data from breaches often appears for sale on dark web marketplaces within days.

Files and documents are increasingly part of breaches, particularly when cloud storage or collaboration platforms are compromised. This can include contracts, medical records, legal documents, internal communications, or personal files. For individuals who store sensitive documents across multiple cloud services, the exposure surface grows with every additional account. Consolidating files into a service that prioritises encryption and security reduces the number of places where documents can be accessed if credentials are compromised.


What happens to stolen data

Stolen data follows a fairly predictable path. Shortly after a breach, the data may appear on dark web forums or marketplaces. Sometimes it is sold to buyers who specialise in identity theft or financial fraud. Sometimes it is released freely, either by hacktivists making a point or by attackers who failed to extract a ransom.

Credentials are tested against other services through credential stuffing. Personal information is used for identity theft, including opening new credit accounts, filing fraudulent tax returns, or impersonating victims. Financial data is used for direct fraud. Medical records are particularly valuable because they contain enough information for comprehensive identity theft and are harder to change than a credit card number.

Data from breaches also accumulates. An attacker who combines your email and password from one breach with your date of birth and address from another can build a detailed profile. Each individual breach contributes to a growing dossier, which is why the cumulative effect of breaches over time matters more than any single incident.


How to check if you've been affected

The most widely used tool for checking breach exposure is Have I Been Pwned, created by security researcher Troy Hunt. Enter your email address and it will show you which known breaches included that address, along with what data was exposed. The site covers billions of breached records and is regularly updated.

Many organisations are required by law to notify affected individuals after a breach. If a service you use is breached, you should receive an email or notification explaining what happened and what data was involved. In practice, these notifications are sometimes delayed, vague, or easy to miss. Checking Have I Been Pwned gives you an independent view.

Some password managers also include breach monitoring features that alert you if credentials stored in your vault appear in known breaches.

If you use many online services, you have almost certainly appeared in at least one breach. This is not cause for panic, but it is worth knowing which credentials have been exposed so you can take appropriate action.


What to do if you're in a breach

If you discover that your data appeared in a breach, the response depends on what was exposed.

If credentials were compromised, change the password for the affected service immediately. If you used the same password on other services, change it everywhere. This is the most urgent step because credential stuffing attacks begin quickly after a breach becomes known.

Enable two-factor authentication on every account that supports it, prioritising email, banking, and cloud storage. Even if an attacker has your password, two-factor authentication provides an additional barrier. Hardware security keys offer the strongest protection, but app-based codes are significantly better than SMS.

Monitor your financial accounts for unauthorised transactions. Set up alerts if your bank offers them. Review credit card statements more carefully than usual for several months after a breach involving financial data.

If personal information such as your Social Security number or national identification was exposed, consider placing a credit freeze with the major credit bureaus. A freeze prevents new credit accounts from being opened in your name and can be lifted temporarily when you need to apply for credit yourself.

Review your accounts and permissions periodically. Auditing which services have access to your data and revoking unused connections reduces the number of places where your information is stored.


Reducing your exposure going forward

The most effective long-term strategy is reducing the number of places your data exists. Every account you create is a potential breach surface. Every service that stores your email, password, personal details, or files is an organisation that could be compromised.

Use a password manager and generate unique passwords for every service. This eliminates the risk of credential stuffing entirely. If one service is breached, the damage is contained to that single account.

Be selective about which services you sign up for. Before creating an account, consider whether you need the service and whether the data it collects is proportionate to what it offers. A service that requires your phone number, date of birth, and home address to provide a basic function is collecting more than it needs.

Consolidate files and data where possible. Having documents scattered across a dozen cloud services means a dozen potential points of exposure. A centralised cloud workspace that encrypts your data and gives you control over where it is stored reduces that surface area. The concept of a personal data vault, where your files and information live in one encrypted place under your control, is becoming more relevant as breach frequency increases.

Understand how end-to-end encryption works and prefer services that implement it. With proper encryption, even if a service is breached, the attacker gets encrypted data they cannot read. Zero-knowledge encryption goes further: the service provider itself cannot access your data, so there is nothing useful for an attacker to take from the provider's servers.

Review app permissions on your phone and revoke access you no longer need. Many apps request access to contacts, location, camera, and storage that has no connection to their core function. This data is collected, stored, and potentially exposed in a breach.

Consider who owns your data in the services you use and whether data portability is supported. If a service makes it easy to export your data and leave, you have more control over your exposure.

None of this eliminates risk entirely. Breaches will continue to happen, and some of your data is held by organisations you have never directly interacted with (as the National Public Data breach demonstrated). But reducing the number of accounts, using strong unique passwords, enabling two-factor authentication, and choosing services that handle data responsibly makes a meaningful difference.


Frequently asked questions

What counts as a data breach?

A data breach is any incident where data is accessed by someone who is not authorised to see it. This includes external hacking, but also internal mistakes like a misconfigured database, an employee sending data to the wrong person, or a cloud storage bucket left open to the public. The defining element is unauthorised access, regardless of whether the data was deliberately stolen or merely exposed.

How do I know if my data has been leaked?

Check your email address on Have I Been Pwned, which tracks billions of records from known breaches. Many services will also notify you directly if they experience a breach, though notifications can be delayed. Some password managers include breach monitoring that alerts you if stored credentials appear in new leaks.

What should I do first after learning I'm in a breach?

Change the password for the affected service immediately. If you used that same password anywhere else, change it on those services too. Then enable two-factor authentication. If financial data or identification numbers were exposed, monitor your accounts and consider a credit freeze.

Does two-factor authentication protect me if my password is leaked?

It significantly reduces the risk. An attacker with your password still cannot access your account without the second factor. Hardware security keys are the strongest option, followed by authenticator apps. SMS-based codes are better than nothing but are vulnerable to SIM-swapping attacks.

Can I remove my data from the dark web after a breach?

No. Once data is leaked and distributed, it cannot be recalled or deleted. This is why prevention and damage limitation matter more than attempting to recover data after the fact. Focus on changing compromised credentials and monitoring for misuse.

Why do companies collect so much data if breaches are this common?

Data collection is driven by business incentives: advertising, analytics, product development, and speculative future use. The principle of data minimisation holds that organisations should collect only what they need, but enforcement is inconsistent and the incentives often push in the opposite direction.

Are small companies less likely to be breached?

Not necessarily. Small companies are less likely to be targeted by sophisticated attackers, but they are also less likely to have dedicated security teams, incident response plans, or robust infrastructure. Automated attacks like credential stuffing and vulnerability scanning do not discriminate by company size.

What is the difference between a data breach and a data leak?

The terms are often used interchangeably, but a breach typically implies some form of attack or intrusion, while a leak may refer to accidental exposure, such as a misconfigured database. Both result in unauthorised access to data, and the practical consequences for affected individuals are the same.

How long does it take for a company to discover a breach?

The average is several months. IBM's annual Cost of a Data Breach report consistently finds that organisations take over 200 days on average to identify a breach. Some breaches are discovered only when the stolen data appears publicly or when a security researcher notifies the organisation.

Should I use a different email for sensitive accounts?

Using a dedicated email address for banking, healthcare, and other sensitive services reduces your exposure. If your primary email appears in a breach, your sensitive accounts remain unlinked to it. This is a practical step that complements using unique passwords and two-factor authentication.


Related pages

The workspace that thinks with you.

Ready when you are.

The workspace that thinks with you.

Ready when you are.

The workspace that thinks with you.

Ready when you are.