What is a data breach?

A data breach is an incident where personal information held by a company or institution is accessed, copied or published by someone who was not authorized to have it — through a hack, a misconfigured server, a stolen device or an insider. The records then circulate and get resold for years.

ByNikita Silianov· Founder & CEO ·LinkedIn
Quick answer

A data breach is any incident in which personal data held by an organization ends up in the hands of someone not authorized to have it. Most breaches start with stolen or reused passwords, phishing, an unpatched system or a third-party vendor — not with a lone genius hacker. Once records are out they are copied and resold indefinitely, so you cannot undo a breach; you can only find out what leaked, change what is changeable, freeze what is not, and reduce what is publicly available about you.

What the record looks like

Our own catalogue tracks 877 known breaches going back to 2007, covering roughly 13 billion exposed accounts in total. Across those incidents, 99% exposed email addresses, 66% exposed passwords, 38% exposed phone numbers and 6% exposed financial details, with an average of 5.2 categories of personal data per breach. The median breach exposed 880,331 accounts — the giant headline leaks are the exception; the routine ones are what quietly accumulate against your name.

Figures from the PersProtect breach catalogue, compiled from known breach databases and updated weekly. Browse it at /breaches.

Breach, leak, hack — what is the difference?

These get used interchangeably, and the distinction matters less than people think. A hack describes the method: somebody broke in. A leak usually means nobody had to break in — a database was left open, a file was published by mistake. A data breach is the umbrella term for the outcome: personal records reached someone who was not supposed to have them. Regulators and notification laws care about that outcome, which is why your letter says “breach” even when the cause was a misconfigured server.

How do data breaches actually happen?

The common causes are unglamorous. Stolen and reused credentials come first: passwords leaked in an earlier breach get replayed in bulk against other services, and any account sharing that password falls over. Phishing gets one employee to hand over a login or approve a prompt. Unpatched software gives attackers a known hole to walk through. Misconfigured cloud storage exposes data with no attacker at all. And third-party vendors are the multiplier — compromise one company that processes payroll, claims or benefits for hundreds of others, and every one of them sends notification letters. That is why so many people get a letter naming a company they have never heard of.

What data gets exposed?

It depends on what the organization held. The most common item is your email address, followed by passwords, names, usernames and phone numbers. Worse categories show up less often but hurt far more: Social Security numbers, dates of birth, government ID numbers, financial and health records. The dividing line is simple — a password can be changed, a Social Security number and a date of birth cannot. When those leak you are not resetting anything; you are blocking their use with a credit freeze and long-term watching.

What happens to the data afterwards?

It does not expire. Stolen records get copied, merged with older leaks and resold across criminal forums and dark-web markets for years, which is why a breach from 2019 can still produce a convincing phone call today. Each new leak gets combined with the last, so an email and password from one incident plus a date of birth from another plus your current address from a data broker add up to a profile complete enough to impersonate you.

How do you find out if you were in one?

Either the company tells you or you check yourself. U.S. state laws require notification, but letters are slow, they go to the address the company has on file, and vendor breaches arrive under a name you do not recognize. Checking your own email address against known breach databases is faster and covers incidents nobody mailed you about. Our free breach check does it in seconds with no signup, and if a letter did arrive there is a separate guide on telling a real notice from a fake one.

What to do if your data was exposed

In order: find out what leaked, because that decides everything else; change the exposed password and every place you reused it; turn on two-factor authentication on email and banking; freeze your credit if a Social Security number or date of birth was involved; expect phishing that quotes the real breach to sound credible; and remove the public half of your profile from broker sites. The full walkthrough is in what to do after a data breach.

Can you sue — and what do settlements pay?

Individual suits are difficult, because you generally have to show concrete harm. What happens in practice is a class action that ends in a settlement fund: reimbursement for documented losses, a flat payment for time spent, and a stretch of credit monitoring. Claims have hard deadlines and the money arrives a year or more later, usually modest. Worth filing — but a settlement compensates you for the leak, it does not delete anything, and your records keep circulating either way. Rules vary by state and by case, so treat this as background rather than legal advice.

Can breaches be prevented?

Not by you — the breach happens inside somebody else’s systems. What you control is how much damage one gets to do: a unique password per account keeps a single leak contained, two-factor authentication makes a stolen password insufficient, a credit freeze neutralizes a leaked Social Security number, and handing over less data means less to lose. The one piece of prevention that is genuinely yours is shrinking your public footprint — opting out of data brokers removes the address, phone and relatives that turn leaked credentials into full identity theft.

Are you in one of them?

Check your email against 877 known breaches in seconds — free, no signup, and it tells you exactly which categories of your data were exposed.

Run my free breach check →
Common questions

Data breaches, explained

What does “data breach” actually mean?

A data breach is any incident where personal information held by an organization is accessed, copied or published by someone who was not authorized to have it. That covers a hacked customer database, a misconfigured cloud server left open to the internet, a stolen laptop, a contractor exporting records, and an employee emailing a spreadsheet to the wrong address. The defining part is not how it happened but the result: data about people ends up outside the walls it was supposed to stay inside.

What is the difference between a data breach, a data leak and a hack?

A hack describes the method — someone broke in. A leak usually means the data was exposed by mistake, with no attacker needed, like a database left public. A breach is the umbrella term for the outcome in both cases: personal records were exposed to someone who should not have them. In practice the words get used interchangeably, and for you the response is the same either way.

How do most data breaches happen?

Far more often through stolen or reused passwords and phishing than through anything cinematic. Attackers take credentials leaked in an earlier breach and replay them against other services, or they trick one employee into handing over a login. After that come vulnerable or unpatched software, misconfigured cloud storage, and third-party vendors: break into one company that processes data for hundreds of others and you reach all of them at once.

How do I know if I was in a data breach?

Two ways. You get a notification letter or email from the company, which is required by state law in the U.S. — or you check your address against known breach databases yourself, which is faster and does not depend on the company finding your current address. Our free breach check does the second in a few seconds without a signup.

Can I get my data removed after a breach?

Not the breached file. Once records are copied and traded there is no recall, and any service promising to erase them is selling something that does not exist. What you can remove is the public half of your profile — the address, phone, relatives and employment history published by data brokers and people-search sites. That is the material that gets combined with breach data to make fraud convincing, and it genuinely comes down.

Can you sue a company for a data breach?

Individual lawsuits are rare and hard; what usually happens is a class action that ends in a settlement fund covering documented losses, some payment for time spent, and a period of credit monitoring. You file a claim before the deadline and the money arrives a year or more later, typically modest. Whether you have a case depends on your state and the specific facts, so this is a question for a lawyer — not something to decide from an article.

How can I prevent being caught in a data breach?

You cannot prevent the breach itself — that is the company’s job. What you control is the blast radius: a unique password for every account so one leak stays contained, two-factor authentication on email and banking, a credit freeze so a leaked Social Security number cannot open accounts, and giving out less data in the first place. Removing yourself from data brokers shrinks the profile that can be assembled about you afterwards.