What is a data breach and what should you do after one?

A data breach happens when personal information is accessed or taken without permission. Here is exactly what that means and how to protect yourself.

ThreatVectr Newsdesk· 5 min read
Photoreal news-editorial style 16:9 photograph of rows of server racks inside a large data centre, bathed in cool blue and white light, with a single rack door
Share

A data breach occurs when someone gains unauthorised access to personal information stored by a company or organisation. That information can be read, copied, or stolen. Regulators including the FTC and the UK's ICO treat any such access as a breach, even when the data is never published.

What counts as personal information in a breach?

Personal information (called PII, short for personally identifiable information) is any detail that can identify you on its own or when combined with other data. Full names paired with email addresses qualify. So do Social Security numbers, passport numbers, health records, payment card numbers, and account passwords.

NIST defines PII as information that can be used to distinguish or trace an individual's identity, either alone or combined with other data. That definition matters because a company that leaks only job titles has probably not breached your PII. One that leaks your name plus your date of birth almost certainly has.

How do breaches actually happen?

Most breaches trace back to one of four causes: stolen or guessed login credentials, unpatched software vulnerabilities (security flaws that the vendor has not yet fixed), misconfigured cloud storage left open to the public internet, or an insider who copies data they are not supposed to take.

Credentials are the leading cause. The Verizon Data Breach Investigations Report methodology tracks attack patterns across thousands of incidents each year and consistently places stolen credentials at the top. A misconfigured Amazon S3 storage bucket (a type of cloud file store) is a classic example of the third category: no hacking required, just a bucket set to "public" by accident.

How will you know if your data was exposed?

In most jurisdictions, companies are legally required to tell you. The FTC's Health Breach Notification Rule and equivalent state laws in the US mandate notification within set timeframes. The EU's GDPR Article 34 requires notification to affected individuals without undue delay when the breach is likely to cause high risk. Australia's Notifiable Data Breaches scheme sits under the OAIC.

In practice, you may receive an email from the breached company, a letter by post, or a notice posted on their website. Treat any breach notification email with caution: check the sender domain matches the company's official site before clicking any link inside it.

What data is typically stolen and why does it matter?

Different data types carry different risks. The table below shows what is commonly taken and what a thief can do with it.

Data type What a thief can do
Email address plus password Log into other accounts where you reused that password
Social Security or national ID number Open fraudulent credit lines in your name
Payment card number plus CVV Make unauthorised purchases before the card is cancelled
Date of birth plus address Combine with other data to pass identity checks
Medical records Commit insurance fraud or sell data to brokers

What should you do immediately after a breach?

Act on the four steps below as soon as you are notified, or as soon as you suspect exposure.

First, change the exposed password everywhere you used it. A password manager (software that generates and stores unique passwords) makes this practical. Second, enable multi-factor authentication (MFA) on the affected account and on any account that shares that password. MFA requires a second proof of identity, usually a code sent to your phone, so a stolen password alone is no longer enough to get in.

Third, if financial account numbers or Social Security numbers were exposed, place a credit freeze with each of the three major US credit bureaus: Equifax, Experian, and TransUnion. A credit freeze is free and stops any lender from opening new credit in your name until you lift it. Fourth, watch your bank and card statements weekly for at least three months.

Do you have any legal rights after a breach?

Yes, and they depend on where you live. EU and UK residents can complain directly to their data protection authority: the ICO in the UK, or the relevant national supervisory authority listed at edpb.europa.eu. US residents can report to the FTC at reportfraud.ftc.gov. Some US states, including California under the CCPA, give you the right to sue a company directly for statutory damages after a breach of unencrypted personal data.

Filing a complaint does not guarantee compensation, but regulators use complaint volumes to prioritise enforcement investigations.

Common questions

Does a data breach always mean your information was misused?

No. Many breaches are discovered before the attacker has time to use or sell the data, and companies often notify affected users out of legal obligation even when misuse has not been confirmed. Acting on the protective steps above reduces your exposure regardless.

Is a data leak the same thing as a data breach?

Not quite. A data leak usually refers to accidental exposure, such as a misconfigured database left publicly accessible, while a breach typically implies an active intruder. Both expose your information and trigger the same notification obligations under most regulations.

How long does a company have to tell you about a breach?

Timeframes vary by jurisdiction: GDPR requires notifying the regulator within 72 hours of discovery, and affected individuals without undue delay if risk is high. US state laws range from 30 to 90 days depending on the state.

© 2026 Threat Vectr