Data Breaches Explained: How They Happen and What to Do
The Scale of the Data Breach Crisis
Data breaches have become so routine that they barely make the news anymore. Every year, thousands of publicly disclosed data breaches affect billions of individual records.
The uncomfortable reality is that your personal data — your name, email address, phone number, password, credit card details, and even your Social Security number — has very likely already been exposed in one or more breaches. The question is not “will my data be breached?” but “when was it last breached, and have I taken steps to protect myself?”
This article explains what data breaches actually are, how they happen, what famous examples have taught us, what data gets exposed, and the exact steps to take using GeneratePass tools.
What Is a Data Breach?
A data breach occurs when an unauthorized party gains access to a database, system, or network containing sensitive information. The unauthorized party — whether a criminal hacker, a nation-state actor, or a careless insider — copies, steals, or exposes data that was supposed to be protected.
Data breaches are not always the result of sophisticated hacking. They can occur through:
- External attacks: Hacking, SQL injection, brute-force attacks, phishing
- Insider threats: Employees accessing data they should not, or accidentally exposing it
- System misconfigurations: Databases left unsecured, cloud storage exposed to the public
- Physical theft: Stolen laptops, hard drives, or backup tapes
- Supply chain attacks: Compromising a third-party vendor to access the primary target
What data is typically exposed?
The type of data exposed varies by breach, but common categories include:
| Data Type | Risk Level | Potential Impact |
|---|---|---|
| Email addresses | Medium | Phishing, spam, account enumeration |
| Passwords | Critical | Account takeover, credential stuffing |
| Phone numbers | Medium | Smishing, vishing, SIM swapping |
| Full names | Low-Medium | Identity theft, social engineering |
| Physical addresses | Medium | Identity theft, physical theft |
| Credit card numbers | Critical | Financial fraud, unauthorized purchases |
| Social Security numbers | Critical | Full identity theft, tax fraud |
| Health records | Critical | Insurance fraud, discrimination |
| Dates of birth | Medium | Identity theft, security question answers |
| IP addresses | Low-Medium | Tracking, targeted attacks |
How Data Breaches Happen
1. External hacking and network intrusions
Attackers exploit vulnerabilities in web applications, APIs, and network infrastructure to gain unauthorized access. This includes SQL injection, exploitation of unpatched software, and API vulnerabilities. Many high-profile breaches stem from known vulnerabilities that organizations failed to patch in time.
2. Misconfigured databases and cloud storage
A surprisingly large number of breaches occur not because of sophisticated attacks, but because of simple misconfigurations. Unsecured Amazon S3 buckets, Elasticsearch databases without authentication, and MongoDB instances exposed to the public internet have all led to massive data exposures.
3. Phishing and social engineering
Many breaches begin with a single employee clicking a malicious link or downloading an infected file. Spear phishing attacks targeting specific employees with access to sensitive systems have been the initial vector in some of the largest breaches in history.
4. Supply chain attacks
When a company’s vendor or service provider is compromised, the attacker may gain access to the company’s data through that trusted connection. The 2020 SolarWinds attack demonstrated how a single supply chain compromise can affect thousands of organizations.
5. Insider threats
Not all breaches are external. Disgruntled employees, careless contractors, or negligent staff can expose data through intentional theft, accidental sharing, or failure to follow security protocols.
6. Ransomware attacks
Ransomware has evolved beyond simple encryption. Modern “double extortion” attacks exfiltrate sensitive data before encrypting systems, threatening to publish it unless a ransom is paid. Healthcare, education, and government sectors have been heavily targeted, with some ransomware groups demanding tens of millions of dollars.
Notable Data Breaches: A Timeline
| Year | Company | Records Exposed | Primary Cause |
|---|---|---|---|
| 2013 | Adobe | 153 million | SQL injection |
| 2014 | Yahoo | 3 billion | Credential theft |
| 2016 | 164 million | Password cracking | |
| 2017 | Equifax | 147 million | Unpatched vulnerability |
| 2018 | 533 million | Data scraping | |
| 2019 | Capital One | 106 million | Misconfigured cloud storage |
| 2020 | Marriott | 5.2 million | Credential compromise |
| 2021 | T-Mobile | 76.6 million | Server breach |
| 2022 | 5.4 million | API vulnerability | |
| 2023 | MOVEit | 77 million | Zero-day vulnerability |
| 2024 | National Public Data | 2.9 billion | Database breach |
| 2025 | Various healthcare | 100+ million combined | Ransomware attacks |
Lessons from these breaches
Equifax (2017): A known vulnerability in Apache Struts went unpatched for months. When Equifax finally patched it, the breach had already occurred. Lesson: patch management is critical.
Capital One (2019): A misconfigured web application firewall allowed an attacker to access data stored in AWS. Lesson: cloud security requires careful configuration.
T-Mobile (2021): Attackers used stolen credentials to access internal systems. Lesson: strong authentication and access controls are essential.
What Happens After a Breach
A breach is not the endpoint—it is the beginning of a chain of exploitation. Once data is exposed, attackers move through several stages:
Credential stuffing and account takeover
Leaked username/password pairs are automatically tested across hundreds of other websites. Because password reuse is rampant, a single breach cascades into compromises across banking, email, social media, and cloud storage accounts. This is how a breach at one retailer can lead to your email being hijacked weeks later.
Identity theft
When personal data like full names, dates of birth, Social Security numbers, and addresses are exposed, criminals open new credit accounts, file fraudulent tax returns, and apply for loans in victims’ names. The Identity Theft Resource Center reported over 1.4 million identity theft reports in 2024 alone.
Financial fraud
Exposed credit card numbers and banking details lead to unauthorized purchases, wire transfers, and fund draining. Even partial information (name + card number + expiration date) is sufficient for online fraud.
Corporate espionage and ransomware
Exposed corporate credentials enable lateral movement within networks, deployment of ransomware, and theft of intellectual property. Nation-state actors may use breached data for intelligence gathering rather than immediate financial gain.
Sold on dark web markets
Stolen data is packaged and sold in tiers: basic credentials ($1-$10), financial account access ($50-$200), full identity packages ($100-$500+), and corporate network access ($1,000-$10,000+).
How to Check If Your Data Has Been Breached
Using Have I Been Pwned (HIBP)
Have I Been Pwned (haveibeenpwned.com) is the most widely used free tool for checking whether your data has appeared in known breaches. Created by security researcher Troy Hunt, it aggregates data from hundreds of breaches and allows you to search by email address.
How to use HIBP:
- Visit haveibeenpwned.com
- Enter your email address
- Review the list of breaches your email appeared in
- Note the type of data exposed in each breach
Using GeneratePass Breach Checker
Our Breach Checker allows you to check if your email or credentials have appeared in known data breaches. All checks are performed client-side — your data never leaves your browser.
Other breach notification services
- Google’s Password Checkup (built into Chrome): Checks saved passwords against known breaches
- Firefox Monitor: Sends alerts when your email appears in new breaches
- DeHashed: Advanced search tool for leaked credentials
What to do when you find your data in a breach
Finding your data in a breach is alarming but not hopeless. The key is to act quickly and systematically.
What to Do After a Data Breach: Step-by-Step
Step 1: Change compromised passwords immediately
Go to every account that used the breached password and change it. Use a strong, unique password for each account. Generate new passwords with our Password Generator and verify their strength with our Password Strength Checker.
Step 2: Enable two-factor authentication
Enable 2FA on every account that supports it. Use an authenticator app (Google Authenticator, Authy) or a hardware security key. Avoid SMS-based 2FA when possible, as it is vulnerable to SIM-swapping attacks.
Step 3: Check for unauthorized activity
Review your accounts for signs of unauthorized access:
- Check email for password reset confirmations you did not initiate
- Review financial statements for unauthorized transactions
- Check social media for posts or messages you did not send
- Review account settings for changes you did not make
Step 4: Monitor your credit
If financial data or your Social Security number was exposed:
- Place a fraud alert with the three credit bureaus (Equifax, Experian, TransUnion)
- Consider a credit freeze to prevent new accounts from being opened in your name
- Review your credit reports for unauthorized accounts
Step 5: Watch for targeted phishing
After a breach, you are more likely to receive targeted phishing emails. Attackers may use information from the breach to craft convincing messages. Be extra vigilant about any communication that references your personal information.
Step 6: Update security questions
If security questions were exposed, update them on all accounts. Use nonsensical answers stored in your password manager rather than truthful answers that could be found on social media.
Breach Notification Laws
When a breach occurs, organizations have legal obligations to notify affected individuals and authorities. These laws set strict timelines and penalties:
GDPR (European Union)
The General Data Protection Regulation requires organizations to notify the relevant supervisory authority within 72 hours of becoming aware of a breach. If the breach poses a high risk to individuals, those individuals must also be notified “without undue delay.” Non-compliance can result in fines of up to €20 million or 4% of global annual turnover, whichever is higher.
United States — State Breach Laws
The U.S. has no single federal breach notification law. Instead, all 50 states, plus Washington D.C. and U.S. territories, have their own breach notification statutes. Key variations include:
- Notification timelines range from 30 days (Colorado, Ohio) to 60 days (Massachusetts) to “without unreasonable delay” (California, New York)
- Definition of personal information varies by state — some include health data, biometrics, and genetic information
- Attorney General notification is required in most states; some also require notification to credit reporting agencies
HIPAA (U.S. Healthcare)
The Health Insurance Portability and Accountability Act requires covered entities to notify affected individuals within 60 days of discovering a breach affecting protected health information (PHI). Breaches affecting 500+ individuals require notification to the Department of Health and Human Services and prominent media outlets. Penalties range from $100 to $50,000 per violation, with annual maximums of $1.5 million per category.
Other notable frameworks
- PCI DSS: Payment card industry requires immediate notification of cardholder data breaches
- CCPA/CPRA (California): Requires notification and provides consumers with a private right of action for certain breaches ($100-$750 per consumer per incident)
- PIPEDA (Canada): Requires notification “as soon as feasible” to the Privacy Commissioner and affected individuals
How to Protect Yourself
After understanding breaches and their consequences, here are practical steps to reduce your risk:
Use a password manager
A password manager generates and stores unique, high-entropy passwords for every account. If one service is breached, your other accounts remain secure. Recommended options include Bitwarden (open-source, free tier), 1Password, and KeePassXC (offline, local storage).
Enable multi-factor authentication everywhere
Enable 2FA on every account that supports it. Use an authenticator app (Google Authenticator, Authy) or a hardware security key. Avoid SMS-based 2FA when possible—it is vulnerable to SIM-swapping attacks. Hardware security keys (YubiKey, Google Titan) provide the strongest protection.
Monitor for breaches proactively
Set up automatic breach notifications through Have I Been Pwned (HIBP), Firefox Monitor, or your password manager’s built-in monitoring. After any major news of a breach at a service you use, check immediately. You can also use our Breach Checker to verify credentials client-side.
Minimize your digital footprint
Reduce the number of accounts you maintain. Delete old accounts you no longer use. Provide minimal personal information when creating new accounts. The less data a company has about you, the less can be exposed in a breach.
Keep software updated
Enable automatic updates for your operating system, browsers, and applications. Many breaches exploit known vulnerabilities that already have patches available. The Equifax breach (147 million records) occurred because a known Apache Struts vulnerability went unpatched for months.
Use secure DNS and email filtering
DNS filtering (NextDNS, Quad9) blocks connections to known malicious domains. Email filtering services catch phishing attempts before they reach your inbox. Combined with browser-level protections, these create multiple layers of defense.
Freeze your credit
Place a credit freeze with all three major credit bureaus (Equifax, Experian, TransUnion). A credit freeze prevents new accounts from being opened in your name and is free under federal law. This is one of the most effective defenses against identity theft.
Frequently Asked Questions
How do I know which passwords to change after a breach?
Start with the specific account that was breached. Then change any other accounts where you used the same or a similar password. Use our [Breach Checker](/breach-checker/) to identify which of your credentials have appeared in known breaches. Prioritize email, banking, and social media accounts.Is it safe to continue using a service after it has been breached?
In most cases, yes — provided the company has addressed the vulnerability and you have taken protective steps (changing passwords, enabling 2FA). Check the company's breach response: did they notify users promptly? Did they offer remediation? Did they patch the vulnerability? If the company has a history of multiple breaches, consider whether the service is worth the risk.Should I pay for identity theft protection after a breach?
Many breached companies offer free identity theft monitoring to affected users. Take advantage of these offers. For ongoing protection, monitor your credit reports directly through AnnualCreditReport.com (free weekly reports) and consider placing a credit freeze, which is free and provides stronger protection than monitoring alone.Can I remove my data from breach databases?
Once data has been exposed in a breach, it cannot be removed from breach notification databases like HIBP — the data is already in the hands of attackers. However, you can limit the damage by rotating compromised credentials, enabling 2FA on affected accounts, and monitoring for further exposure. Use our [Breach Checker](/breach-checker/) to track whether your credentials surface in new breaches.How often should I check for breaches?
Set up automatic breach notifications through HIBP, Firefox Monitor, or your password manager's built-in monitoring. Additionally, manually check your email and critical accounts every 3-6 months. After any major news of a breach at a service you use, check immediately.References
- Identity Theft Resource Center. “Annual Data Breach Report 2025.” https://www.idtheftcenter.org/
- Have I Been Pwned. “Breaches, Passwords, and Compromised Accounts.” https://haveibeenpwned.com/
- SpyCloud. “2024 Annual Identity Exposure Report.” https://www.spycloud.com/
- NIST. “Guide to Protecting the Confidentiality of Personally Identifiable Information (PII).” SP 800-122. https://csrc.nist.gov/
- Verizon. “2025 Data Breach Investigations Report (DBIR).” https://www.verizon.com/business/resources/reports/dbir/
- Troy Hunt. “Lessons from the Trenches of Data Breaches.” https://www.troyhunt.com/
See Also
- Breach Checker — Check if your credentials appear in known breaches
- How Password Breaches Happen — Attack vectors used to steal credentials
- Password Reuse Risks — Why one breach compromises everything
- Password Managers Explained — How password managers protect your credentials
About the Author
The GeneratePass Editorial Team builds privacy-first security tools that run entirely in your browser. Every tool on GeneratePass processes data locally — nothing is ever sent to a server. Visit generatepass.me to try our free Password Generator, Entropy Calculator, and Breach Checker.
GeneratePass Developers
Developers of GeneratePass, building client-side security tools and educational content focused on local execution, zero-trust patterns, and client-side data sovereignty.
Related Security Tools
Related Publications
Browser Fingerprinting: How Websites Track You Without Cookies
Learn how browser fingerprinting works, what data it collects, and practical steps to resist this advanced tracking technique.
Browser Security Basics: Protecting Yourself Online
Browser security settings, HTTPS verification, extension auditing, and DNS-over-HTTPS — the settings that actually reduce your attack surface.
Online Privacy Checklist: 50 Steps to Protect Your Digital Life
A comprehensive 50-step checklist covering account security, browser settings, social media privacy, email, device, and network protection.