
Key Takeaways
Data Breach
A data breach is an incident where unauthorized individuals gain access to private, protected, or sensitive information held by an organization. This can include names, email addresses, passwords, Social Security numbers, and payment card details. Breaches happen when attackers exploit security vulnerabilities, steal employee credentials, or use malware to infiltrate company systems.
Breaches are distinct from data leaks, which typically involve accidental exposure rather than deliberate unauthorized access. Both can result in sensitive data appearing on dark web marketplaces.
The Moment a Breach Happens
When attackers successfully penetrate a company's systems, the clock starts moving — often before the company itself is aware anything went wrong. The average time for an organization to detect a breach has historically been measured in weeks or months, giving attackers a significant head start.
Once inside, intruders typically extract data in bulk: usernames, hashed or plaintext passwords, email addresses, phone numbers, and in more serious cases, financial account numbers or government-issued ID details. This data is compressed, packaged, and moved off the target's servers, usually to anonymous infrastructure. For unfamiliar terminology, see the Cybersecurity Glossary for plain-English definitions of terms like hashing, malware, and credential stuffing.
277 days
Average time to identify and contain a breach
According to IBM's Cost of a Data Breach Report, the average breach lifecycle has consistently exceeded nine months across multiple report years.
$4.45M
Average cost of a data breach globally
IBM's 2023 Cost of a Data Breach Report placed the global average total cost of a breach at $4.45 million, the highest figure recorded in the report's history at that time.
81%
Of breaches involving stolen or weak credentials
Verizon's Data Breach Investigations Report has repeatedly found that a large majority of hacking-related breaches exploit compromised or reused passwords.
Where Your Data Goes Next
Stolen data doesn't simply vanish into the internet — it enters a well-organized underground economy. Cybercriminals sell data on dark web marketplaces, private forums, and encrypted chat channels. Pricing varies by data type: a full set of identity credentials (name, SSN, date of birth, and address) commands a higher price than a list of email addresses alone.
Buyers use this data in several ways. Credential stuffing attacks use leaked username-and-password combinations to attempt logins across hundreds of sites, exploiting the fact that many people reuse passwords. This is one reason strong passwords alone aren't always sufficient protection — if the password is already known from a prior breach, its complexity becomes irrelevant.
Financial data, such as card numbers or bank account details, may be sold to specialists who create counterfeit cards or initiate fraudulent transfers. Social Security numbers and identity documents enable more serious crimes including tax fraud and account takeover.
The Timeline of Misuse
Not all stolen data is weaponized immediately. Sophisticated attackers deliberately delay using credentials to avoid triggering fraud detection systems or to allow the breach news cycle to fade. Some data sits in marketplaces for months before being purchased.
Broadly, the misuse timeline breaks into three phases:
- Immediate (days to weeks): Financial data, especially payment card numbers, is used quickly because cards are cancelled once a breach is reported. Speed is essential for this category.
- Medium-term (weeks to months): Login credentials are tested in bulk credential-stuffing campaigns. Attackers prioritize high-value targets like email, banking, and cloud storage accounts.
- Long-term (months to years): Full identity records — SSNs, addresses, birthdates — may be held and used to open fraudulent accounts, file false tax returns, or commit medical fraud over an extended period.
Act on Payment Card Exposure Quickly
If a breach exposed your payment card number, contact your bank or card issuer as soon as possible to request a replacement card. Financial institutions can often flag the old number for monitoring or cancel it outright. Acting within the first 48–72 hours significantly limits the window for fraudulent transactions.
What You Can Do After a Breach
Your practical response depends on what type of data was exposed. The notification you receive from the breached company should outline this. As a baseline, change the password for the affected account immediately and update it anywhere else you used the same credentials — password reuse is one of the most exploited vulnerabilities in consumer security.
Placing a free credit freeze with Equifax, Experian, and TransUnion blocks new credit from being opened in your name without your authorization. This is particularly valuable when Social Security numbers or identity documents were exposed. Freezes don't affect your existing accounts or credit score.
Attackers also use breached personal details to craft convincing phishing messages — knowing your name, employer, or recent purchases makes a fraudulent message far more persuasive. Understanding how social engineering tactics work helps you recognize these attempts before they succeed.
Finally, consider reviewing what personal data various apps and services hold on you. Limiting unnecessary data sharing reduces your exposure in future incidents. App permissions are one often-overlooked area where data collection exceeds what most users expect.
US State Breach Notification Laws
All 50 US states have data breach notification laws requiring companies to inform affected residents when personal information is compromised. Federal rules also apply in sectors like healthcare (HIPAA) and finance (GLBA). Notification timelines and required content vary by state. If you haven't received a notice but suspect your data was involved, you can often find breach disclosures on state attorney general websites or through public press releases.
