Data Breach
A data breach is an incident where confidential data is accessed, stolen or exposed by an unauthorized party — most often starting with a human mistake.
A data breach is a security incident in which confidential, protected or sensitive information — customer records, credentials, intellectual property, financial data — is accessed, copied, stolen or exposed by someone not authorized to have it. A breach can be the work of an external attacker, a malicious insider, or simple negligence such as a misconfigured cloud bucket; legally, exposure alone can trigger notification duties even if no misuse is ever proven.
How it works
Most breaches follow a recognizable arc: initial access, escalation, and exfiltration. The initial foothold is overwhelmingly human — the Verizon DBIR consistently attributes a majority of breaches to the human element, whether that is a phishing email that harvests credentials, a reused password cracked open at scale by credential stuffing, a persuasive phone call to an employee or help desk, or a mistake like emailing a spreadsheet to the wrong recipient. Once inside, attackers escalate privileges, move laterally toward the data stores that matter, and exfiltrate quietly — often for weeks before detection. Increasingly, exfiltration is paired with ransomware in double-extortion schemes: pay, or the stolen data is published. The stolen records are then traded on the dark web and feed the next round of attacks, giving future callers and phishers accurate personal details to build pretexts with.
How to defend against it
Because breaches are chains, defense means breaking links at every stage: minimize and encrypt the data you hold, enforce least privilege and phishing-resistant MFA, segment networks so one compromised account cannot reach everything, and monitor for the access anomalies that precede exfiltration. Prepare the response before you need it — a rehearsed plan with clear roles, containment steps and regulator notification deadlines dramatically reduces cost, as our incident response guide for social-engineering attacks sets out. And since the first link is usually a person, measure and reduce that exposure deliberately: continuous training, realistic simulations, and an employee-level Human Risk Score that shows where the next breach is most likely to start.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo