Skip to main content

Career Education

Summer Sale!

Get any course for £9.99

A data breach in cyber security occurs when information is accessed, disclosed, changed, destroyed, lost or made unavailable without proper authorisation. It may result from a deliberate cyber attack, but breaches can also happen through human error, insecure settings, lost devices or failures by third-party suppliers.

A breach can affect customer records, passwords, payment information, health details, business documents, intellectual property or any other data that should be protected. The consequences depend on the type of information involved, how much was affected and whether criminals can use it to harm individuals or organisations.

Understanding what is a data breach in cybersecurity is important because data breaches do not always look like dramatic hacking incidents. A confidential spreadsheet sent to the wrong recipient or a cloud folder accidentally made public may be just as serious as an external attack.

This guide explains how data breaches happen, the difference between a data breach and a security breach, common data breach examples, the role of cyber crime and the practical steps organisations can take to prevent and respond to incidents.

What Is a Data Breach?

A data breach is a security incident that compromises the confidentiality, integrity or availability of information.

This means that data may have been:

  • Viewed by someone without permission
  • Shared with an unintended recipient
  • Copied or downloaded without authority
  • Changed improperly
  • Deleted accidentally or deliberately
  • Encrypted by ransomware
  • Lost with a physical device
  • Published or exposed online
  • Made unavailable to authorised users

The term is not limited to stolen information. A breach also occurs when data is changed, destroyed or lost in a way that affects the people or organisation relying on it.

For example, if criminals alter supplier bank details in a company’s system, the integrity of the information has been compromised. If ransomware prevents a hospital from accessing records, the availability of the information has been affected.

The three security principles affected by a breach

Data security is commonly based on three principles.

Confidentiality means that information can only be accessed by authorised people and systems.

Integrity means that information remains correct, complete and protected against unauthorised changes.

Availability means that information remains accessible to authorised users when they need it.

One data breach may affect all three. Criminals could copy a database, change records and then encrypt the organisation’s servers.

Personal Data Breaches

A personal data breach specifically involves information relating to an identified or identifiable person.

Personal data can include:

  • Names
  • Home addresses
  • Email addresses
  • Telephone numbers
  • Dates of birth
  • Identification numbers
  • Employee records
  • Online identifiers
  • Customer account details
  • Financial information
  • Location data
  • Photographs
  • Medical or educational records

Some personal information is especially sensitive because exposure could cause greater harm.

This may include information about health, genetics, biometric identification, racial or ethnic origin, religious beliefs, trade-union membership, political opinions or a person’s sexual life or orientation.

Criminal-conviction and safeguarding information can also require particularly careful handling.

A personal data breach may happen accidentally or unlawfully. Criminal intent is not required.

For example, an employee who attaches the wrong customer file to an email may create a personal data breach even though they did not intend to disclose it.

Data Breach, Security Breach and Cyber Attack

These terms are related, but they describe different parts of a security problem.

Data breach

A data breach involves information being accessed, disclosed, altered, destroyed, lost or made unavailable without proper authority.

Security breach

A security breach is a wider failure of protection affecting an account, system, network, device or information.

A criminal who gains unauthorised access to a company network has created a security breach. If they then open or copy confidential files, the incident also becomes a data breach.

Not every security breach involves data. An attacker may compromise a device only to use its computing resources or disrupt a service.

Cyber attack

A cyber attack is a deliberate attempt to gain access, steal information, cause damage or interrupt digital services.

An attack does not need to succeed. A phishing email that the recipient recognises and reports is still an attempted cyber attack.

A breach means the attack, error or security failure has successfully compromised something.

Cyber crime

Cyber crime involves criminal conduct in which computers, networks or digital services are the target or an important tool.

Examples include ransomware, account takeover, online fraud, theft of confidential information and business email compromise.

Not every data breach is cyber crime. Accidental disclosure, lost paperwork and an incorrectly shared file can create breaches without criminal involvement.

What Is Sensitive Information?

Sensitive information is data that could cause significant harm if it were exposed, changed or lost.

The term may include legally protected personal data as well as commercially confidential information.

Examples include:

  • Passwords and authentication codes
  • Bank and card information
  • Passport or identification details
  • Medical records
  • Payroll information
  • Children’s information
  • Safeguarding records
  • Legal documents
  • Confidential business plans
  • Customer lists
  • Intellectual property
  • Security configurations
  • Source code
  • Private communications

Sensitivity depends partly on context.

An employee’s work email address may create limited risk by itself. However, when combined with their password, telephone number, job role and private correspondence, the same record could support account takeover or targeted fraud.

Organisations should therefore consider both individual pieces of data and what criminals could learn by combining them.

Main Types of Data Breach

Data breaches can be classified according to what happened to the information.

Confidentiality breach

A confidentiality breach occurs when information is disclosed or accessed without authorisation.

Examples include:

  • An attacker downloading customer records
  • A confidential email sent to the wrong person
  • An employee viewing files without a business reason
  • A public cloud folder containing private documents
  • A stolen unencrypted laptop

This is the type most people associate with the phrase “data breach”.

Integrity breach

An integrity breach occurs when information is altered without permission or can no longer be trusted.

Examples include:

  • Supplier payment details being changed
  • Customer records being modified
  • Examination results being altered
  • Software code being manipulated
  • Log files being deleted to hide an attack

Integrity breaches can be difficult to identify because the information may still appear normal.

Availability breach

An availability breach occurs when authorised users cannot access the information they need.

Examples include:

  • Ransomware encrypting files
  • An attacker deleting a database
  • A backup failure causing permanent data loss
  • An employee accidentally erasing records
  • A denial-of-service incident interrupting access to an online system

Availability breaches can be particularly serious in healthcare, transport, finance and other services where access to accurate information is time-sensitive.

How Does a Data Breach Happen?

A deliberate breach often develops in stages.

First, the attacker looks for a route into an account, device or service. This may involve phishing, a vulnerable application, stolen login details or an exposed remote-access system.

Once inside, the attacker may attempt to keep access available by creating accounts, changing recovery settings or installing malicious software.

They may then look for greater permissions or move from the first compromised device towards databases, file servers, cloud storage and administrator systems.

Finally, the attacker may copy, alter, delete or encrypt the information.

Some breaches happen much more quickly. A cloud-storage setting can expose thousands of documents immediately, while one incorrectly addressed email can disclose sensitive information within seconds.

Common Causes of Data Breaches

Most breaches arise from a combination of technical weaknesses, human decisions and organisational failures.

1. Phishing and Social Engineering

Phishing is a common starting point for cyber crime and data theft.

A criminal sends a message that appears to come from a trusted organisation or person. The message may ask the recipient to:

  • Enter a password
  • Approve a login request
  • Open an attachment
  • Install software
  • Reveal an authentication code
  • Transfer money
  • Share confidential documents

The attacker may create urgency by claiming that an account will be suspended, an invoice must be paid immediately or a manager needs information quickly.

Modern phishing messages may be well written and personalised. Staff should therefore evaluate the request and context rather than relying only on spelling mistakes as a warning sign.

Employee awareness is useful, but technical controls are also needed. Email filtering, multi-factor authentication, limited permissions and independent verification of payment changes can all reduce risk.

2. Compromised Passwords

Passwords may be stolen through phishing, malware, previous breaches or insecure storage.

Criminals often test stolen passwords against other services because many people reuse the same login details.

The risk is greater where organisations use:

  • Shared accounts
  • Default passwords
  • Weak administrator credentials
  • Accounts without multi-factor authentication
  • Inactive accounts belonging to former workers
  • Passwords recorded in unprotected documents

A compromised email account can be particularly damaging because it may contain private information and password-reset links for other services.

3. Malware and Ransomware

Malware is software created or used to perform harmful actions.

It may:

  • Steal files
  • Record keystrokes
  • Capture login details
  • Monitor activity
  • Provide remote access
  • Damage systems
  • Spread across a network

Ransomware prevents access to data, commonly by encrypting it. Criminal groups may also copy information before encryption and threaten to publish it unless payment is made.

This means one ransomware incident can affect both availability and confidentiality.

Malware may enter through phishing attachments, unsafe downloads, compromised websites, unapproved software or vulnerable internet-facing systems.

4. Unpatched Software and Firmware

Applications, operating systems, network devices and firmware can contain security vulnerabilities.

Manufacturers release updates to correct known weaknesses. When an organisation delays updates or continues using unsupported technology, attackers may exploit vulnerabilities for which fixes already exist.

Internet-facing systems deserve particular attention because criminals can reach them remotely. These may include websites, virtual private networks, firewalls, email services and remote-management tools.

Effective update management begins with knowing which devices and applications the organisation uses.

5. Cloud Misconfiguration

Cloud services can be secure while the information stored in them remains exposed through incorrect customer settings.

Common problems include:

  • Publicly accessible storage
  • Excessive sharing permissions
  • Unprotected administrator accounts
  • Inactive accounts remaining enabled
  • Security logging being turned off
  • Unapproved third-party applications
  • Sensitive files being shared through unrestricted links

Organisations should understand that cloud security normally follows a shared-responsibility model. The provider protects parts of the underlying service, while the customer remains responsible for areas such as accounts, permissions and information sharing.

6. Human Error

Data breaches frequently happen because someone makes a mistake.

Examples include:

  • Sending an email to the wrong recipient
  • Attaching the wrong document
  • Publishing a private file
  • Granting excessive access
  • Uploading information to the wrong folder
  • Losing paperwork or equipment
  • Failing to remove an old account
  • Disposing of storage insecurely

It is not enough to tell people to be more careful. Organisations should design processes so one mistake is less likely to cause widespread harm.

Secure defaults, confirmation prompts, limited access and clear approval procedures can all help.

7. Insider Misuse

An insider is someone with legitimate access to an organisation’s systems or information.

This may include an employee, contractor, volunteer or supplier.

Insider breaches may be accidental, but they can also be deliberate. Someone may copy customer lists, take business information to a new employer or misuse records for personal reasons.

Least privilege, access monitoring and prompt removal of unnecessary accounts reduce the opportunity for misuse.

The organisation should also investigate unusual access proportionately rather than assuming every employee is a threat.

8. Lost or Stolen Devices

Laptops, phones, portable drives and backup media can contain substantial amounts of sensitive information.

The consequences are more serious when:

  • Storage is not encrypted
  • The device lacks a screen lock
  • Accounts remain signed in
  • Files are stored locally
  • Remote wiping is unavailable
  • The loss is reported slowly

Full-disk encryption can prevent someone from reading the stored information even if they remove the drive.

Organisations should also be able to revoke active sessions and assess which services were accessible from the lost device.

9. Third-Party and Supply-Chain Failures

A supplier may process information, host an application or connect to internal systems.

If the supplier is compromised, the attacker may gain access to the customer’s data or distribute malicious software through a trusted service.

Risk increases when organisations do not know:

  • Which suppliers hold sensitive information
  • What access each supplier has
  • How supplier accounts are protected
  • Whether incidents must be reported promptly
  • What happens when the contract ends

Supplier access should be limited to what is necessary and removed when no longer required.

Data Breach Examples

The following data breach examples show how differently incidents can develop.

Example 1: Customer records emailed incorrectly

An employee intends to send a customer spreadsheet to an authorised manager but selects an external contact with a similar name.

The recipient now has access to information they were not meant to receive. The organisation should try to recover the information or obtain confirmation that it has been securely deleted.

Example 2: Stolen cloud password

A worker enters their password into a false login page. The criminal accesses cloud storage and downloads confidential documents.

This is both an account compromise and a confidentiality breach.

Example 3: Ransomware attack

Criminals exploit an unpatched remote-access service, enter the network and encrypt business records.

They also claim to have copied sensitive information. The breach affects availability and may also involve unauthorised disclosure.

Example 4: Lost unencrypted laptop

A staff member leaves a laptop on public transport. It contains employee records and is not encrypted.

The organisation may not know whether anyone opened the files, but it can no longer guarantee that the information remains confidential.

Example 5: Public cloud database

A developer mistakenly configures a database so it can be accessed from the internet without authentication.

Automated scanning tools find it. The breach results from misconfiguration rather than stolen credentials.

Example 6: Malicious employee

An employee with legitimate access downloads a customer list before leaving the organisation.

This is an insider breach. Access restrictions, monitoring and proper exit procedures could reduce the risk.

Example 7: Supplier compromise

A payroll provider suffers a cyber attack that exposes information belonging to several customer organisations.

Although the customers’ own systems were not directly attacked, their employee information has still been compromised.

Example 8: Deleted records

An administrator accidentally deletes important records, and the organisation discovers that its backups cannot be restored.

This is an availability breach even though the information was not stolen.

Consequences of a Data Breach

The impact depends on the type of data involved and what criminals or unintended recipients can do with it.

Harm to individuals

People may experience:

  • Identity fraud
  • Financial theft
  • Account takeover
  • Targeted phishing
  • Exposure of private information
  • Safeguarding concerns
  • Discrimination
  • Reputational harm
  • Emotional distress

An exposed password can create additional risk where the same password is used elsewhere.

Medical, financial or safeguarding information can cause particularly serious harm because individuals may not be able to change it as easily as a password.

Harm to organisations

Organisations may face:

  • Service disruption
  • Lost productivity
  • Incident-investigation costs
  • System-recovery costs
  • Fraudulent payments
  • Customer complaints
  • Legal or contractual disputes
  • Regulatory scrutiny
  • Loss of intellectual property
  • Reputational damage

The technical problem may be corrected quickly, but restoring trust can take considerably longer.

Warning Signs of a Possible Data Breach

Possible indicators include:

  • Login alerts from unknown devices or locations
  • Unexpected password changes
  • New administrator accounts
  • Unexplained access to sensitive files
  • Unusually large downloads
  • New email-forwarding rules
  • Security tools being disabled
  • Unknown software or processes
  • Missing or encrypted files
  • Unplanned public sharing links
  • Unexpected changes to payment details
  • Customers receiving fraudulent messages
  • Confidential records appearing online

One warning sign does not prove that a breach has occurred. Legitimate maintenance, travel or business activity may appear unusual.

The correct response is to investigate promptly and preserve the available evidence.

How to Respond to a Data Breach

A well-prepared incident-response plan helps an organisation act quickly without making the situation worse.

1. Record the initial report

Document when the issue was discovered, who reported it and what was observed.

Create a timeline and update it as new information becomes available.

2. Establish what happened

Identify:

  • The systems involved
  • The affected information
  • How access occurred
  • Whether the activity is continuing
  • How many people may be affected
  • Whether the information was encrypted
  • Whether a supplier is involved
  • Whether essential services are at risk

Separate confirmed facts from assumptions.

3. Contain the breach

Containment may involve:

  • Disabling compromised accounts
  • Revoking active sessions
  • Isolating infected devices
  • Removing public access
  • Blocking malicious connections
  • Correcting permissions
  • Contacting an unintended recipient
  • Remotely locking or wiping a lost device

Containment should begin quickly, but major actions should be coordinated to avoid destroying evidence or interrupting essential services unnecessarily.

4. Preserve evidence

Retain relevant logs, emails, alerts, files and device information.

Record which actions were taken, by whom and at what time.

Serious breaches may require digital-forensics support, law-enforcement involvement or evidence for insurers and regulators.

5. Assess the risk

Consider the nature and sensitivity of the information, the number of people affected and the possible consequences.

Ask:

  • Can the data support fraud or identity theft?
  • Does it involve children or vulnerable people?
  • Is the information already public?
  • Was the information encrypted?
  • Can the recipient be trusted to delete it?
  • Could the disclosure cause financial or emotional harm?
  • Could the data be combined with other information?

Risk should be assessed from the perspective of the affected people, not only the organisation.

6. Remove the cause

Correct the weakness that allowed the breach.

This may require:

  • Applying updates
  • Removing malware
  • Resetting credentials
  • Closing exposed services
  • Correcting cloud settings
  • Removing unauthorised accounts
  • Rebuilding compromised devices
  • Strengthening monitoring

Restoring files without closing the original route into the system may allow the incident to happen again.

7. Recover safely

Restore information from trusted backups and return systems to service in a controlled order.

Check that security controls are working and monitor affected accounts and devices for further suspicious activity.

8. Communicate appropriately

Affected employees, customers, suppliers or other parties may need to be informed.

Communication should explain:

  • What happened
  • Which information was involved
  • What the organisation has done
  • What risks may remain
  • What protective steps people should take
  • Where they can obtain support

Avoid unsupported claims that the incident is fully resolved before the investigation is complete.

Reporting a Personal Data Breach in the UK

Not every data breach must be reported to the Information Commissioner’s Office.

The organisation must assess whether the personal data breach is likely to create a risk to the rights and freedoms of the people affected.

Where the reporting threshold is met, the breach must be reported to the ICO without undue delay and, where feasible, within 72 hours of the organisation becoming aware of it.

The 72-hour period does not necessarily begin when the breach first occurred. It begins when the organisation becomes aware that a personal data breach has happened.

Where all the details are not yet available, the organisation may provide the information in stages rather than delaying the initial report.

If the breach is likely to create a high risk to affected people, they will normally need to be informed without undue delay.

The communication should be clear and practical. People should understand what happened, what information was affected and what they can do to protect themselves.

Organisations should document every personal data breach and their reasoning, including cases where they decide that ICO notification is not required.

Data Breach Prevention

Breach prevention requires technical controls, organisational procedures and informed people.

Minimise the Data Collected

An organisation cannot lose information it does not hold.

Collect only the information needed for a genuine purpose and avoid retaining it indefinitely.

Regularly review records and securely delete information that is no longer required.

Classify Sensitive Information

Classifying information helps employees understand how it should be handled.

A simple classification system might identify information as:

  • Public
  • Internal
  • Confidential
  • Highly restricted

The classification should affect where information can be stored, who can access it and how it can be shared.

Strengthen Authentication

Use unique passwords, password managers or passkeys. Enable multi-factor authentication for email, cloud platforms, remote access and administrative accounts.

Authentication apps, security keys and passkeys generally provide stronger protection than passwords alone.

Apply Least Privilege

Users should receive only the access required for their work.

Administrative access should be restricted and reviewed regularly. Accounts should be updated when someone changes role and closed promptly when they leave.

Keep Systems Updated

Maintain an inventory of hardware, software and cloud services.

Apply security updates promptly, especially to internet-facing systems. Replace unsupported devices or applications that no longer receive fixes.

Encrypt Sensitive Data

Encryption can protect information stored on devices and travelling between systems.

Portable equipment should use full-disk encryption, and recovery keys should be managed securely.

Encryption does not remove every risk, because an authorised but compromised account may still access the information. It should be combined with access controls and monitoring.

Secure Cloud Services

Review public links, guest access, administrator accounts and third-party applications.

Enable logging and alerts for important permission changes. Do not assume the cloud provider controls how employees share data.

Protect Endpoints and Networks

Use firewalls, endpoint protection, secure configuration and network segmentation.

Restrict unauthorised software and removable media. Monitor devices for suspicious processes, account activity and connections.

Maintain Tested Backups

Keep reliable backups separate from the systems being protected.

Test that data can be restored. A backup that exists but cannot be recovered does not provide meaningful resilience.

Train Employees

Training should cover phishing, passwords, sensitive information, payment fraud and incident reporting.

Use realistic examples and short refresher sessions rather than depending only on one annual presentation.

Employees should know how to report a mistake immediately. A constructive reporting culture allows the organisation to contain incidents sooner.

Review Suppliers

Assess suppliers before giving them access to information or systems.

Contracts should address data protection, access control, security responsibilities and breach notification.

Remove supplier access when the relationship ends or the access is no longer needed.

Prepare for Incidents

Maintain an incident-response plan identifying responsibilities, communication routes, technical actions and decision-making authority.

Test the plan through realistic exercises. Include management, technical teams, legal advisers and communications staff where appropriate.

The Cyber Essentials controls—firewalls, secure configuration, security update management, user access control and malware protection—provide a useful baseline for UK organisations.

What Should Individuals Do After a Data Breach?

Someone notified that their information has been breached should follow the advice provided by the affected organisation.

Useful steps may include:

  • Change any exposed or reused passwords.
  • Enable multi-factor authentication.
  • Review recent account activity.
  • Sign out unknown devices or sessions.
  • Monitor bank and card transactions.
  • Be alert to targeted phishing messages.
  • Verify unexpected telephone calls independently.
  • Never share authentication codes.
  • Contact the provider about suspicious activity.
  • Keep copies of breach notifications.

Criminals may use genuine exposed information to make later scams appear credible. Knowing a person’s correct name, address or employer does not prove that a caller or message is legitimate.

Frequently Asked Questions

What is a data breach in cybersecurity?

A data breach occurs when information is accessed, disclosed, changed, destroyed, lost or made unavailable without proper authorisation. It may be deliberate or accidental.

Is a data breach the same as a cyber attack?

No. A cyber attack is a deliberate attempt to compromise technology or information. A data breach is the harmful outcome in which data is actually compromised.

Is every data breach a security breach?

Yes, a data breach is a type of security breach. However, some security breaches affect systems or services without compromising data.

Can a data breach happen accidentally?

Yes. Sending an email to the wrong person, losing an unencrypted device or misconfiguring cloud storage can all cause a breach.

What are common data breach examples?

Examples include stolen email accounts, ransomware, exposed databases, lost laptops, insider data theft, accidental email disclosure and supplier compromise.

What types of sensitive information are most at risk?

Passwords, financial data, identification details, health records, safeguarding information, employee files and confidential business material can create substantial harm when exposed.

Does every personal data breach need to be reported?

No. UK organisations must assess the risk to affected people. Breaches meeting the reporting threshold must be reported to the ICO without undue delay and, where feasible, within 72 hours.

Can antivirus prevent every breach?

No. Antivirus helps detect malware, but it cannot prevent every stolen password, accidental disclosure, cloud misconfiguration or insider incident.

What is the first step after discovering a breach?

Start the incident-response process, record what has been discovered and take safe steps to prevent further exposure while preserving evidence.

How can small businesses prevent data breaches?

Small businesses should prioritise multi-factor authentication, software updates, secure configuration, limited access, backups, employee awareness and an incident-response plan.

Conclusion

A data breach in cyber security happens when information is exposed, accessed, changed, destroyed, lost or made unavailable without proper authority.

It may result from cyber crime, including phishing, malware and account takeover, but breaches can also be caused by mistakes, lost devices, insecure cloud settings and supplier failures.

The seriousness of a breach depends on the sensitivity of the information, the number of people affected and the potential consequences. Passwords, financial records, health information and identification details require particularly careful protection.

When a breach occurs, organisations should contain the incident, preserve evidence, assess the risk, remove the cause and recover safely. UK personal data reporting obligations must be considered immediately rather than after the entire investigation has finished.

Effective breach prevention combines strong authentication, least privilege, security updates, encryption, cloud controls, monitoring, backups, employee training and supplier management.

No organisation can remove every risk. However, collecting less unnecessary data, applying layered protection and practising incident response can greatly reduce both the likelihood and impact of a breach.

Leave a Reply

Your email address will not be published. Required fields are marked *