Home › Fraud News › How data breaches actually happen
EXPLAINER · CYBER FRAUD NEWS

How data breaches actually happen

Most breaches arrive through a handful of unremarkable routes. Knowing which ones explains why the standard advice is what it is.

Last reviewed 13/09/2026 · Written and maintained by the cyberhygiene.tools team

In this article

  • Breaches are mostly boring
  • The five common routes in
  • What happens to the data afterwards
  • What a breach notice actually means for you
  • Why the same advice keeps appearing
  • A reasonable personal response

Breaches are mostly boring

The public picture of a data breach involves sophisticated intrusion. The reality is that the overwhelming majority arrive through a small number of unremarkable routes, and understanding which ones explains why the standard advice is what it is.

The five common routes in

1. A stolen or reused password

An employee reuses a password that leaked from an unrelated site years earlier. An automated tool tries the pair against corporate systems and one of them works. No malware, no exploit, no skill required. This is the single most common starting point, and it is why unique passwords and two-factor authentication matter more than any security product.

2. A phished login

A convincing copy of a login page captures a username, a password, and — through real-time relaying — a one-time code. The attacker is inside within the code's 30-second window. Passkeys defeat this because they will not respond to a domain that is not the real one.

3. An unpatched internet-facing system

A remote access service, a firewall, a file transfer appliance or a web application with a known flaw that was fixed months earlier. Automated scanning finds these continuously, at internet scale, without any interest in who owns them.

4. A third party

The breached organisation is often not the one you have a relationship with. Payroll providers, marketing platforms, customer service tools, analytics vendors and file transfer services all hold other companies' data, which makes them efficient targets. This is why you sometimes receive a notice from a company you have never heard of.

5. Misconfiguration

A storage bucket left publicly readable, a database exposed without a password, a backup on an open server. No attack is required at all; the data was simply reachable.

What happens to the data afterwards

Stolen records follow a fairly consistent path. They are first used by whoever took them, then sold to others, then eventually circulated freely as their commercial value decays. Password hashes are cracked in bulk where the original storage was weak — old systems using fast, unsalted algorithms can have most of their passwords recovered quickly, while modern slow hashing with proper salting resists this far better.

Records from different breaches are then combined. An email address from one leak, a home address from another and a date of birth from a third produce a profile far more useful than any single source. This aggregation is why old breaches still matter years later, and why a leak that seemed harmless in isolation can contribute to identity theft long afterwards.

What a breach notice actually means for you

Read what was exposed, because the right response differs.

One warning: emails claiming "your password was found in a breach, click here" are themselves one of the most common phishing hooks. Go to the service directly rather than clicking, and check with an independent breach-lookup service instead.

Why the same advice keeps appearing

Look back at the five routes. Unique passwords defeat route one. Passkeys or an authenticator app blunt route two. Automatic updates close route three. Routes four and five are outside your control entirely — which is exactly why limiting the blast radius matters more than trying to prevent breaches you cannot influence.

That is the whole logic of the standard advice. It is not a checklist for its own sake; each item maps to a specific, commonly used route.

A reasonable personal response

  1. Use a password manager so every account has a different password. Our guide sets out a realistic plan.
  2. Turn on two-factor authentication, starting with your email account.
  3. Check your addresses against known breaches, and act on what you find.
  4. Delete accounts you no longer use rather than abandoning them.
  5. Keep the sensitive documents out of your inbox — most mailboxes are an accidental archive of exactly what an attacker wants.

Frequently asked questions

What is the most common cause of a data breach?

A stolen or reused password. An automated tool tries credential pairs leaked from unrelated sites, and eventually one works. No exploit or technical skill is involved.

Why did I get a breach notice from a company I have never used?

Because many breaches happen at third parties — payroll, marketing, support or file transfer providers — that hold data on behalf of companies you do use.

Does a breach mean my password was definitely exposed?

Not always. Read what the notice says was taken. Passwords are usually stored scrambled, and how recoverable they are depends on how the company stored them. Change it anyway if you reused it.

Why do old breaches still matter?

Records from different leaks are combined into profiles. An address from one and a date of birth from another make future fraud attempts far more convincing, long after the original incident.

What should I do the moment I hear about a breach?

Change that password, and change it anywhere else you used it. Then check the account's security settings for anything added that you did not create.