What is a data breach?
A data breach is any incident where data someone else was holding about you — a company, a hospital, a government agency — gets accessed, copied, or exposed by someone not authorized to see it. It doesn't have to involve an attacker breaking through a firewall; a database left open on the public internet by mistake is just as much a breach as a targeted hack, and the risk to you is identical either way.
How breaches actually happen
"Hacked" is the word that ends up in headlines, but it covers a much narrower set of causes than most people assume. In practice, breaches trace back to a handful of recurring failures:
- Stolen or reused credentials — an employee's password, obtained through a phishing message or pulled from an unrelated breach via credential stuffing, used to log into a company's own systems.
- Misconfigured cloud storage — a database or storage bucket set to "public" instead of "private," found by anyone who happens to look, no intrusion required.
- Third-party vendor compromise — a breach at a contractor or software supplier that had legitimate access to the primary company's systems or data.
- Insider access — an employee or contractor who copies or exposes data they were legitimately allowed to touch, deliberately or by mistake.
- Unpatched software vulnerabilities — a known, exploitable flaw in server or application software that was never updated.
The National Public Data breach: when the breached company was never yours to choose
Most breach coverage assumes you're a customer of the company that got breached. National Public Data's case is the clearest recent example of the more unsettling version: you can be exposed by a company you never signed up for, never heard of, and never gave permission to hold your data in the first place.
NPD, a Florida-based background-check data broker, was compromised starting in December 2023. A hacker using the handle USDoD listed the stolen database for sale on a criminal forum in April 2024, claiming 2.9 billion records covering an estimated 272 million unique Social Security numbers, spanning US, UK, and Canadian residents — full names, current and past addresses going back decades, dates of birth, and information about relatives, some of whom had been dead for years. NPD didn't publicly confirm the breach until August 2024, roughly eight months after it began, and wasn't legally required to move any faster since the company wasn't covered by the 72-hour notification rules that apply to critical infrastructure. The company filed for Chapter 11 bankruptcy in October 2024, citing potential liability for credit monitoring costs "in the hundreds of millions," and ceased operations that December.
Records like these don't just sit idle — the same personal details (full name, address, date of birth) are the raw material for SIM swapping's social-engineering step, and stolen email/password pairs from breaches like this one are exactly what feeds credential-stuffing attacks against unrelated sites months or years later.
Why notification timing varies so much
| Jurisdiction / rule | Notification deadline |
|---|---|
| EU (GDPR) | 72 hours to the relevant regulator after discovery |
| US federal critical-infrastructure sectors (CIRCIA) | 72 hours to CISA for covered entities only |
| Most US states (general consumer breach laws) | Typically 30–60 days, varies significantly by state |
| Companies outside any of the above (e.g. National Public Data) | No fixed legal deadline — NPD took roughly 8 months |
There's no single global standard, which is why two people affected by two different breaches can have wildly different amounts of warning before their data starts circulating.
What to do if you're notified you were in a breach
- Read what specific data was involved before deciding how to respond — a breached email-only list needs a different response than one including Social Security numbers.
- Freeze your credit with all three bureaus if a Social Security number was involved, regardless of whether you were ever a customer of the breached company.
- Check your email at Have I Been Pwned to see which breaches it's already turned up in, even ones you were never notified about.
- Change the password anywhere you reused it — assume any reused password from a breached site is compromised everywhere it was reused, not just on the breached site itself. Run it through our password strength checker if you're unsure it holds up.
- Enable MFA on the affected account and anywhere else you reused the same login.
Is a data breach always caused by hacking?
No. A breach just means data was accessed or exposed without authorization — the cause is often a misconfigured cloud storage bucket left open to the public internet, a lost or stolen laptop, an employee mistake, or a compromised vendor, none of which require an attacker to "hack" anything in the sense of breaking through active defenses.
How long does a company have to tell me about a breach?
It depends entirely on where you and the company are, since there's no single global rule. The EU's GDPR requires notifying the relevant regulator within 72 hours of discovery. The U.S. has no equivalent federal law — each state sets its own deadline, typically 30 to 60 days, and some sectors (like companies covered by CIRCIA critical-infrastructure rules) have separate requirements entirely. National Public Data took roughly eight months between the breach starting and public disclosure, and wasn't legally required to move faster.
What's the difference between a breach and a leak?
A breach implies someone bypassed or exploited some form of access control to get data that was otherwise protected. A leak (or "exposure") means the data was accessible to anyone who found it — no bypassing required — often because of a misconfigured database or storage bucket left open to the public internet. In practice, the two terms get used almost interchangeably in reporting, and the practical risk to you is the same either way: your data left the custody it was supposed to stay in.
Can I do anything if a data broker breach exposed my SSN and I never used that company?
Yes — the same protective steps apply whether or not you ever created an account. Freeze your credit with all three bureaus (Equifax, Experian, TransUnion), since a frozen credit file blocks new accounts from being opened in your name regardless of who leaked the SSN. This is exactly the situation the National Public Data breach created for millions of people who never signed up for the service in the first place.
Does a breach notification mean my specific data was definitely stolen?
Not necessarily. Companies are often required to notify everyone whose data was potentially accessible, even when they can't confirm exactly which individual records an attacker actually copied. Treat any notification as "assume the worst, verify what you can" — check the specific fields the company says were involved, and act on those, rather than assuming either total exposure or no exposure by default.