What is a Data Breach?
Data Breach is a situation where confidential, private, protected or sensitive information is exposed to a person who is not authorized to access it. It can be the result of a deliberate act to steal information from an individual or organization, or it may be the consequence of an accidental event.
Cybercriminals attack for a variety of reasons: financial gain, political activism, social engineering, espionage, and more. Regardless of the motive, a data breach can have devastating consequences on companies, their brands, and their customers.
The most significant data breaches are based on hacking and/or unauthorized access to IT systems. Bad actors exploit authentication and authorization control system vulnerabilities, data on the move where sensitive information is transmitted in the clear via HTTP or other non-secure protocols, theft of unencrypted devices, and more.
Often, the information stolen in a Data Breach includes personal details, such as names, email addresses and phone numbers. It can also include more sensitive information such as healthcare records or credit card information.
If you are a victim of a Data Breach, there are things you can do to protect yourself. Notify the appropriate parties. For example, if health records are involved you should contact the Department of Health and Human Services. If social security numbers are involved, notify the credit reporting agencies (Equifax, Experian and TransUnion). You can also use multifactor authentication and zero trust based security protocols to reduce your risk of being targeted in future attacks such as spear phishing or malware.