
Key Takeaways
Data Breach
A data breach occurs when an unauthorized person gains access to private information stored by a company — such as names, passwords, email addresses, or payment details. Once inside a company's systems, attackers can copy, export, or delete that data. The information then leaves the organization's control entirely, often without the company or its customers immediately knowing.
Breaches can result from external hacking, insider threats, or misconfigured servers that inadvertently expose databases to the public internet — the cause shapes both the scope and the likely destination of the stolen data.
Where Does Stolen Data Go First?
When attackers breach a company's systems, the data they extract rarely stays in one place. The most common immediate destination is a dark web marketplace — private, encrypted forums where stolen credentials, financial records, and personal details are packaged and sold in bulk. A single breach can yield millions of records, which are often sorted and priced based on how complete or verified the information is.
Freshly stolen data commands higher prices. A record containing a working email-and-password combination, a linked credit card number, and a billing address is worth considerably more than a name and email alone. Attackers sometimes verify records in bulk before listing them — a process that can involve automated login attempts against popular services.
422M+
People affected by data compromises in a single year
According to the Identity Theft Resource Center's 2022 Annual Data Breach Report, over 422 million individuals were impacted by data compromises — including breaches, exposures, and leaks — in that year alone.
277 days
Average time to identify and contain a breach
IBM's Cost of a Data Breach Report found that, on average, organizations take around 277 days to identify and contain a data breach — meaning stolen data often circulates well before customers are notified.
$10.93B
Reported losses from identity theft and fraud
The FTC's Consumer Sentinel Network has reported that identity theft and related fraud generate billions in consumer losses annually, underscoring the real financial consequences of breached personal data.
Understanding this pipeline matters because it helps explain the timing of fraud. You might receive a breach notification from a company weeks after the actual intrusion, but criminal buyers may have already been testing your credentials in the interim.
How Your Information Gets Used
Once purchased, stolen data fuels a range of downstream crimes. Credential stuffing — where attackers automatically try stolen username-and-password pairs across hundreds of websites — is one of the most common. Because many people reuse passwords, a breach at a small retailer can unlock accounts at a bank or email provider. This is why even a strong password isn't a complete defense if it's reused across services.
Financial data enables direct fraud: unauthorized purchases, new account openings in your name, or draining existing accounts. More sensitive data — Social Security numbers, dates of birth, medical records — powers identity theft, where a criminal constructs a fraudulent identity detailed enough to apply for loans, file false tax returns, or obtain government benefits.
Use a Unique Password for Every Account
The single most effective way to limit the blast radius of a breach is to never reuse passwords across services. A password manager can generate and store strong, unique credentials for every account, so a breach at one company doesn't expose your accounts at others. Most major platforms also offer two-factor authentication — enabling it adds a critical second layer that stolen passwords alone cannot bypass.
Phishing attacks also spike after major breaches. Criminals use the leaked email addresses to send targeted messages that appear to come from the breached company, tricking recipients into handing over additional credentials.
What Companies Are Required to Tell You
In the United States, data breach notification laws exist in all 50 states, though the specifics vary. Generally, companies must inform affected individuals when certain categories of personal information — such as Social Security numbers, financial account numbers, or medical data — are exposed. The required notification window differs by state, ranging from as few as 30 days to 90 days or more after discovery.
Notifications must typically describe what type of data was exposed, when the breach occurred, and what steps the company is taking in response. They often include offers of free credit monitoring. Reading these notices carefully matters: the categories of exposed data directly determine what actions you should prioritize. Understanding what data you share and with whom in the first place can help you gauge your exposure when a breach is announced.
Notification Timing Can Lag the Breach Itself
Companies often don't discover a breach immediately — attackers can remain inside systems undetected for weeks or months. Once discovered, organizations need time to investigate before notifying customers, which means the notification you receive may come well after your data was already taken. This lag is one reason proactive monitoring — rather than waiting for a notification — is a sound baseline habit. See how everyday digital habits create exposure for broader context on where risk actually comes from.
Practical Steps If You're Affected
Your response should be proportional to what type of data was compromised. If only an email and hashed password were exposed, changing that password and enabling two-factor authentication covers most of your risk. If financial details or government-issued ID numbers were involved, the response needs to go further.
- Change affected credentials immediately — and anywhere you've reused that password.
- Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion if financial or identity data was exposed. A freeze is free and prevents new credit accounts from being opened in your name.
- Monitor account statements for unfamiliar charges over the following months.
- Watch for targeted phishing — be skeptical of any follow-up emails referencing the breach, even if they appear official.
For a structured walkthrough of what to do when an account is directly compromised, see this ordered response plan for hacked accounts.
