| [ Web Proxy ] |
| Viewing: https://brave.com/glossary/data-breach/ | [Back] [Original] |
The unauthorized access or release of sensitive information, often due to a cyber attack or human error. Breaches occur when data stored in one system (often that of a business or government) ends up in unauthorized hands. A data breach can be harmful to both the owners of the database and the people whose data was released.
A data breach can result from physical theft of hardware, or from sophisticated hacking (sometimes even as an “inside job”). The compromised data is usually sensitive—for example corporate intellectual property, government secrets, or customer data like credit card numbers—and used for financial gain. But the data can also be used for social or political purposes.
A data breach can occur when a hacker takes advantage of a weakness in a company’s cybersecurity systems. It may be as straightforward as a stolen laptop that contains unsecured sensitive information or access credentials. Or an employee could accidentally release data to the wrong person, or even intentionally leak data to a journalist or other organization. Phishing and social engineering are also commonly used to steal login credentials that provide access to data.
Personal data—names, social security numbers, credit card numbers, health and banking info, login credentials, and more—can all be used to steal from a person’s accounts, or be sold online. Corporate and government-classified data might be stolen for purposes of whistleblowing or blackmail. Sometimes stolen data is never actually made public, but the threat of doing so is enough to extort ransom payments.
For a company that experiences a breach, costs can include fines, settlements and legal fees,reputation damage, and loss of customers. According to a recent study, the average cost of a breach to a company is around $1.5 million USD. A ransomware attack can cost even more, since it also includes the ransom price.
Financial costs of a breach are large, but the costs of time and emotional stress on an individual whose personal data is compromised can also add up.
To protect data, organizations adopt good cybersecurity practices like limiting who has access to sensitive data, and using enhanced login protocols like multi-factor authentication. They’ll also train employees on social engineering threats and how to secure physical devices like laptops or phones.
Recently, there’s been increased pressure on companies to limit the amount of data they collect and store. This has positive effects with regard to both privacy and security. The less data that’s exposed when a breach occurs, the less damage to all involved.
Some governments require notification when a breach is discovered, with varying rules on how quickly the notification is delivered, levels of fines, and remediation available to individuals. These regulations usually do not apply to encrypted data, since encrypted data is not readable and thus not a risk.
Some of the bigger regulations to come about in recent years include:
If you receive a letter or email that your personal data may have been involved in a breach, the first step is to make sure it’s legitimate, and not a phishing scam. If it’s real, then you should take the suggested actions, and sign up for any free credit monitoring that may be offered. In addition, make sure to do the following:
There’s not much you as an individual can do to protect your data once it’s in someone else’s database—generally, you have to rely on the owner of the data to practice good cybersecurity. However, you can exercise care about where and when to supply your personal data, so it’s less exposed to a data breach in the first place:
Using a browser with strong privacy and security protections, such as the Brave browser, will also limit the risk of your data getting into the wrong hands:
Brave’s easy-to-use browser blocks ads by default, making the Web faster, safer, and less cluttered for people all over the world.
Get Brave| Web Proxy Viewer | New URL | Original Page |