GeneratePass
Privacy • 13 min read

Data Breaches Explained: How They Happen and What to Do

By GeneratePass Developers | Published: July 08, 2026 | Last Updated: July 08, 2026

The Scale of the Data Breach Crisis

Data breaches have become so routine that they barely make the news anymore. Every year, thousands of publicly disclosed data breaches affect billions of individual records.

The uncomfortable reality is that your personal data — your name, email address, phone number, password, credit card details, and even your Social Security number — has very likely already been exposed in one or more breaches. The question is not “will my data be breached?” but “when was it last breached, and have I taken steps to protect myself?”

This article explains what data breaches actually are, how they happen, what famous examples have taught us, what data gets exposed, and the exact steps to take using GeneratePass tools.


What Is a Data Breach?

A data breach occurs when an unauthorized party gains access to a database, system, or network containing sensitive information. The unauthorized party — whether a criminal hacker, a nation-state actor, or a careless insider — copies, steals, or exposes data that was supposed to be protected.

Data breaches are not always the result of sophisticated hacking. They can occur through:

  • External attacks: Hacking, SQL injection, brute-force attacks, phishing
  • Insider threats: Employees accessing data they should not, or accidentally exposing it
  • System misconfigurations: Databases left unsecured, cloud storage exposed to the public
  • Physical theft: Stolen laptops, hard drives, or backup tapes
  • Supply chain attacks: Compromising a third-party vendor to access the primary target

What data is typically exposed?

The type of data exposed varies by breach, but common categories include:

Data TypeRisk LevelPotential Impact
Email addressesMediumPhishing, spam, account enumeration
PasswordsCriticalAccount takeover, credential stuffing
Phone numbersMediumSmishing, vishing, SIM swapping
Full namesLow-MediumIdentity theft, social engineering
Physical addressesMediumIdentity theft, physical theft
Credit card numbersCriticalFinancial fraud, unauthorized purchases
Social Security numbersCriticalFull identity theft, tax fraud
Health recordsCriticalInsurance fraud, discrimination
Dates of birthMediumIdentity theft, security question answers
IP addressesLow-MediumTracking, targeted attacks

How Data Breaches Happen

1. External hacking and network intrusions

Attackers exploit vulnerabilities in web applications, APIs, and network infrastructure to gain unauthorized access. This includes SQL injection, exploitation of unpatched software, and API vulnerabilities. Many high-profile breaches stem from known vulnerabilities that organizations failed to patch in time.

2. Misconfigured databases and cloud storage

A surprisingly large number of breaches occur not because of sophisticated attacks, but because of simple misconfigurations. Unsecured Amazon S3 buckets, Elasticsearch databases without authentication, and MongoDB instances exposed to the public internet have all led to massive data exposures.

3. Phishing and social engineering

Many breaches begin with a single employee clicking a malicious link or downloading an infected file. Spear phishing attacks targeting specific employees with access to sensitive systems have been the initial vector in some of the largest breaches in history.

4. Supply chain attacks

When a company’s vendor or service provider is compromised, the attacker may gain access to the company’s data through that trusted connection. The 2020 SolarWinds attack demonstrated how a single supply chain compromise can affect thousands of organizations.

5. Insider threats

Not all breaches are external. Disgruntled employees, careless contractors, or negligent staff can expose data through intentional theft, accidental sharing, or failure to follow security protocols.

6. Ransomware attacks

Ransomware has evolved beyond simple encryption. Modern “double extortion” attacks exfiltrate sensitive data before encrypting systems, threatening to publish it unless a ransom is paid. Healthcare, education, and government sectors have been heavily targeted, with some ransomware groups demanding tens of millions of dollars.


Notable Data Breaches: A Timeline

YearCompanyRecords ExposedPrimary Cause
2013Adobe153 millionSQL injection
2014Yahoo3 billionCredential theft
2016LinkedIn164 millionPassword cracking
2017Equifax147 millionUnpatched vulnerability
2018Facebook533 millionData scraping
2019Capital One106 millionMisconfigured cloud storage
2020Marriott5.2 millionCredential compromise
2021T-Mobile76.6 millionServer breach
2022Twitter5.4 millionAPI vulnerability
2023MOVEit77 millionZero-day vulnerability
2024National Public Data2.9 billionDatabase breach
2025Various healthcare100+ million combinedRansomware attacks

Lessons from these breaches

Equifax (2017): A known vulnerability in Apache Struts went unpatched for months. When Equifax finally patched it, the breach had already occurred. Lesson: patch management is critical.

Capital One (2019): A misconfigured web application firewall allowed an attacker to access data stored in AWS. Lesson: cloud security requires careful configuration.

T-Mobile (2021): Attackers used stolen credentials to access internal systems. Lesson: strong authentication and access controls are essential.


What Happens After a Breach

A breach is not the endpoint—it is the beginning of a chain of exploitation. Once data is exposed, attackers move through several stages:

Credential stuffing and account takeover

Leaked username/password pairs are automatically tested across hundreds of other websites. Because password reuse is rampant, a single breach cascades into compromises across banking, email, social media, and cloud storage accounts. This is how a breach at one retailer can lead to your email being hijacked weeks later.

Identity theft

When personal data like full names, dates of birth, Social Security numbers, and addresses are exposed, criminals open new credit accounts, file fraudulent tax returns, and apply for loans in victims’ names. The Identity Theft Resource Center reported over 1.4 million identity theft reports in 2024 alone.

Financial fraud

Exposed credit card numbers and banking details lead to unauthorized purchases, wire transfers, and fund draining. Even partial information (name + card number + expiration date) is sufficient for online fraud.

Corporate espionage and ransomware

Exposed corporate credentials enable lateral movement within networks, deployment of ransomware, and theft of intellectual property. Nation-state actors may use breached data for intelligence gathering rather than immediate financial gain.

Sold on dark web markets

Stolen data is packaged and sold in tiers: basic credentials ($1-$10), financial account access ($50-$200), full identity packages ($100-$500+), and corporate network access ($1,000-$10,000+).


How to Check If Your Data Has Been Breached

Using Have I Been Pwned (HIBP)

Have I Been Pwned (haveibeenpwned.com) is the most widely used free tool for checking whether your data has appeared in known breaches. Created by security researcher Troy Hunt, it aggregates data from hundreds of breaches and allows you to search by email address.

How to use HIBP:

  1. Visit haveibeenpwned.com
  2. Enter your email address
  3. Review the list of breaches your email appeared in
  4. Note the type of data exposed in each breach

Using GeneratePass Breach Checker

Our Breach Checker allows you to check if your email or credentials have appeared in known data breaches. All checks are performed client-side — your data never leaves your browser.

Other breach notification services

  • Google’s Password Checkup (built into Chrome): Checks saved passwords against known breaches
  • Firefox Monitor: Sends alerts when your email appears in new breaches
  • DeHashed: Advanced search tool for leaked credentials

What to do when you find your data in a breach

Finding your data in a breach is alarming but not hopeless. The key is to act quickly and systematically.


What to Do After a Data Breach: Step-by-Step

Step 1: Change compromised passwords immediately

Go to every account that used the breached password and change it. Use a strong, unique password for each account. Generate new passwords with our Password Generator and verify their strength with our Password Strength Checker.

Step 2: Enable two-factor authentication

Enable 2FA on every account that supports it. Use an authenticator app (Google Authenticator, Authy) or a hardware security key. Avoid SMS-based 2FA when possible, as it is vulnerable to SIM-swapping attacks.

Step 3: Check for unauthorized activity

Review your accounts for signs of unauthorized access:

  • Check email for password reset confirmations you did not initiate
  • Review financial statements for unauthorized transactions
  • Check social media for posts or messages you did not send
  • Review account settings for changes you did not make

Step 4: Monitor your credit

If financial data or your Social Security number was exposed:

  • Place a fraud alert with the three credit bureaus (Equifax, Experian, TransUnion)
  • Consider a credit freeze to prevent new accounts from being opened in your name
  • Review your credit reports for unauthorized accounts

Step 5: Watch for targeted phishing

After a breach, you are more likely to receive targeted phishing emails. Attackers may use information from the breach to craft convincing messages. Be extra vigilant about any communication that references your personal information.

Step 6: Update security questions

If security questions were exposed, update them on all accounts. Use nonsensical answers stored in your password manager rather than truthful answers that could be found on social media.


Breach Notification Laws

When a breach occurs, organizations have legal obligations to notify affected individuals and authorities. These laws set strict timelines and penalties:

GDPR (European Union)

The General Data Protection Regulation requires organizations to notify the relevant supervisory authority within 72 hours of becoming aware of a breach. If the breach poses a high risk to individuals, those individuals must also be notified “without undue delay.” Non-compliance can result in fines of up to €20 million or 4% of global annual turnover, whichever is higher.

United States — State Breach Laws

The U.S. has no single federal breach notification law. Instead, all 50 states, plus Washington D.C. and U.S. territories, have their own breach notification statutes. Key variations include:

  • Notification timelines range from 30 days (Colorado, Ohio) to 60 days (Massachusetts) to “without unreasonable delay” (California, New York)
  • Definition of personal information varies by state — some include health data, biometrics, and genetic information
  • Attorney General notification is required in most states; some also require notification to credit reporting agencies

HIPAA (U.S. Healthcare)

The Health Insurance Portability and Accountability Act requires covered entities to notify affected individuals within 60 days of discovering a breach affecting protected health information (PHI). Breaches affecting 500+ individuals require notification to the Department of Health and Human Services and prominent media outlets. Penalties range from $100 to $50,000 per violation, with annual maximums of $1.5 million per category.

Other notable frameworks

  • PCI DSS: Payment card industry requires immediate notification of cardholder data breaches
  • CCPA/CPRA (California): Requires notification and provides consumers with a private right of action for certain breaches ($100-$750 per consumer per incident)
  • PIPEDA (Canada): Requires notification “as soon as feasible” to the Privacy Commissioner and affected individuals

How to Protect Yourself

After understanding breaches and their consequences, here are practical steps to reduce your risk:

Use a password manager

A password manager generates and stores unique, high-entropy passwords for every account. If one service is breached, your other accounts remain secure. Recommended options include Bitwarden (open-source, free tier), 1Password, and KeePassXC (offline, local storage).

Enable multi-factor authentication everywhere

Enable 2FA on every account that supports it. Use an authenticator app (Google Authenticator, Authy) or a hardware security key. Avoid SMS-based 2FA when possible—it is vulnerable to SIM-swapping attacks. Hardware security keys (YubiKey, Google Titan) provide the strongest protection.

Monitor for breaches proactively

Set up automatic breach notifications through Have I Been Pwned (HIBP), Firefox Monitor, or your password manager’s built-in monitoring. After any major news of a breach at a service you use, check immediately. You can also use our Breach Checker to verify credentials client-side.

Minimize your digital footprint

Reduce the number of accounts you maintain. Delete old accounts you no longer use. Provide minimal personal information when creating new accounts. The less data a company has about you, the less can be exposed in a breach.

Keep software updated

Enable automatic updates for your operating system, browsers, and applications. Many breaches exploit known vulnerabilities that already have patches available. The Equifax breach (147 million records) occurred because a known Apache Struts vulnerability went unpatched for months.

Use secure DNS and email filtering

DNS filtering (NextDNS, Quad9) blocks connections to known malicious domains. Email filtering services catch phishing attempts before they reach your inbox. Combined with browser-level protections, these create multiple layers of defense.

Freeze your credit

Place a credit freeze with all three major credit bureaus (Equifax, Experian, TransUnion). A credit freeze prevents new accounts from being opened in your name and is free under federal law. This is one of the most effective defenses against identity theft.


Frequently Asked Questions

How do I know which passwords to change after a breach? Start with the specific account that was breached. Then change any other accounts where you used the same or a similar password. Use our [Breach Checker](/breach-checker/) to identify which of your credentials have appeared in known breaches. Prioritize email, banking, and social media accounts.
Is it safe to continue using a service after it has been breached? In most cases, yes — provided the company has addressed the vulnerability and you have taken protective steps (changing passwords, enabling 2FA). Check the company's breach response: did they notify users promptly? Did they offer remediation? Did they patch the vulnerability? If the company has a history of multiple breaches, consider whether the service is worth the risk.
Should I pay for identity theft protection after a breach? Many breached companies offer free identity theft monitoring to affected users. Take advantage of these offers. For ongoing protection, monitor your credit reports directly through AnnualCreditReport.com (free weekly reports) and consider placing a credit freeze, which is free and provides stronger protection than monitoring alone.
Can I remove my data from breach databases? Once data has been exposed in a breach, it cannot be removed from breach notification databases like HIBP — the data is already in the hands of attackers. However, you can limit the damage by rotating compromised credentials, enabling 2FA on affected accounts, and monitoring for further exposure. Use our [Breach Checker](/breach-checker/) to track whether your credentials surface in new breaches.
How often should I check for breaches? Set up automatic breach notifications through HIBP, Firefox Monitor, or your password manager's built-in monitoring. Additionally, manually check your email and critical accounts every 3-6 months. After any major news of a breach at a service you use, check immediately.

References

  1. Identity Theft Resource Center. “Annual Data Breach Report 2025.” https://www.idtheftcenter.org/
  2. Have I Been Pwned. “Breaches, Passwords, and Compromised Accounts.” https://haveibeenpwned.com/
  3. SpyCloud. “2024 Annual Identity Exposure Report.” https://www.spycloud.com/
  4. NIST. “Guide to Protecting the Confidentiality of Personally Identifiable Information (PII).” SP 800-122. https://csrc.nist.gov/
  5. Verizon. “2025 Data Breach Investigations Report (DBIR).” https://www.verizon.com/business/resources/reports/dbir/
  6. Troy Hunt. “Lessons from the Trenches of Data Breaches.” https://www.troyhunt.com/

See Also


About the Author

The GeneratePass Editorial Team builds privacy-first security tools that run entirely in your browser. Every tool on GeneratePass processes data locally — nothing is ever sent to a server. Visit generatepass.me to try our free Password Generator, Entropy Calculator, and Breach Checker.

GeneratePass Developers

Developers of GeneratePass, building client-side security tools and educational content focused on local execution, zero-trust patterns, and client-side data sovereignty.

Focus: Cryptography • Standard: zero-trust