Data Breach
CybersecurityA data breach is any incident in which information that was supposed to stay private — customer records, passwords, medical files, source code — is accessed, copied or exposed by someone who was not meant to have it.
The word suggests a dramatic break-in, and sometimes it is one. Just as often it is a database left open on the internet with no password, an employee emailing a spreadsheet to the wrong address, a laptop stolen from a car, or a supplier that was breached and took your data with it. The law usually does not care how it happened. If personal data got out, it is a breach, and the clock starts.
That clock is the part organisations underestimate. Under rules such as Europe’s GDPR, a breach affecting personal data has to be reported to the regulator within 72 hours of discovery, and to the affected people when the risk to them is high. “Discovery” is the moment someone in the company knew, not the moment legal signed off.
Why it matters
The stolen data does not stay stolen. Passwords are tried against every other service, because people reuse them. Names, addresses and dates of birth feed identity fraud for years. Email lists feed the next round of phishing, made more convincing by real details. A breach at one company is raw material for attacks on its customers everywhere else, which is why the standard advice after any breach notice is to change the password there and anywhere else it was used, and to turn on multi-factor authentication.
For the organisation, the direct cost is investigation, notification and legal work; the lasting cost is trust. Studies put the average cost of a breach in the millions, but the figure hides the spread: a small company with no cyber insurance and no plan can be ended by one.
In practice
Most breaches are found late, often by an outsider: a researcher who stumbles on the open server, a journalist, or the attacker announcing it. The organisations that come out best are the ones that already knew what data they held and where, had a written plan for the first 72 hours, and had encrypted the sensitive fields so that what leaked was unreadable. The ones that come out worst are the ones that first learn how much data they had by reading about it in the news.