Data breach
An incident exposing stored personal data, which is then reused to fuel further fraud.
A data breach is an incident in which information held by a company or service is exposed, stolen or leaked — anything from email addresses and passwords to payment-card and identity details. Breaches happen through hacking, misconfigured systems, insider error or lost devices, and the fallout often lands on customers who did nothing wrong.
Exposed data rarely sits idle: it is traded and reused to fuel phishing, credential stuffing, account takeover and identity theft. You may learn of one from the company itself, from the news, or from a service that checks whether your address has appeared in a leak. Practical steps: change the password on the affected account and anywhere you reused it, switch on two-factor authentication, and stay alert for scam messages that quote real details about you to seem credible — a leak makes convincing impersonation much easier. Watching your bank and card statements, and your credit file, helps catch misuse early. You cannot stop a company being breached, but not reusing passwords limits how far any single leak can spread. Our identity-theft warning signs explains what to watch for next.
Related terms
Phishing
Fraudulent messages that impersonate a trusted brand to steal your passwords, card details or money.
Credential stuffing
Automated attacks that try leaked passwords across many sites, exploiting password reuse.
Account takeover
A criminal seizing control of your email, banking or shopping account and acting as you.
Identity theft
Misuse of your personal details to impersonate you, open credit or commit fraud in your name.