Skip to main content

What is a data breach?

By Allstate Identity Protection

Data breaches are cyber attacks or security incidents that expose information without authorization. Let’s take a closer look at how data breaches can occur, and how a breach could impact you. Got a breach notification? Read on for resources to guide you.

When a database of information is accessed without authorization, that's a data breach. And they're a growing problem. According to the Identity Theft Resource Center, there were more than 3,150 publicly reported data compromises in 2024, resulting in more than 1.3 billion breach notifications.

But what exactly is a data breach, and how does it happen? There are a few ways a database of information could be wrongfully exposed, and it can happen intentionally or accidentally.

If a company or organization that stores customer data experiences a breach, personal information can wind up exposed—a scenario that's become all too familiar. These days, it seems like no industry is off limits. From banks and hospitals to online retailers and social media platforms, organizations of all kinds may experience data breaches.

Fast Facts

Biggest data breaches of the last decade

Wondering how a data breach might impact you? Here are three real-world examples of large-scale data breaches from the last decade, including the customer information that was exposed:

  • Ticketmaster (2024): Hackers claimed to have accessed data belonging to up to 560 million customers, including names, email addresses, phone numbers, mailing addresses, and partial payment card information.

  • National Public Data (2024): A breach at the background check company National Public Data reportedly exposed billions of records containing highly sensitive personal information, including names, addresses, phone numbers, and Social Security numbers.

  • Equifax in 2017: Hackers attacked the credit bureau’s systems, exposing the personal information of 147 million people. Exposed details included full names, dates of birth, Social Security numbers, physical addresses, and other personal information.

What type of information could be exposed in a data breach?

Here are some examples of personally identifiable information (PII) that could be exposed in a data breach and may be attractive to cybercriminals:

Medical information—such as healthcare records, Medicare numbers, and insurance member IDs—is also highly valuable. Fraudsters can use health data to commit medical identity theft, a scheme that involves obtaining medical services, prescription drugs, or other health care in someone else’s name.

Here’s another thing fraudsters want: financial information. Stolen checking, savings, retirement, or credit card account information can be used by criminals for their own monetary gain. 

How data breaches happens

Let’s take a look at some common ways a data breach may occur. 

Cyberattacks

Here are just a few of the tactics cybercriminals may use to steal data: 

  • Malware: When malware (which is short for “malicious software”) is installed on a device or server, it can collect data and send it back to the cybercriminals who initiated the attack. 

  • Ransomware: One common type of malware is ransomware, which encrypts files and makes them unusable. In a ransomware attack, bad actors typically demand a fee in exchange for decryption.

  • Denial-of-service attack: In this scenario, cybercriminals attempt to crash a network by flooding it with traffic. The goal may be to disrupt operations: once a network is overwhelmed, legitimate users may be unable to access information systems or process requests. This can act as a diversion, or even crash a firewall or security system, making it easier for hackers to pull off a data breach. 

  • SQL injection attack (or SQLi): This type of attack “injects” or inserts malicious SQL code into a website or web application’s database. SQL or Structured Query Language is a programming language commonly used in databases, so attackers sometimes use SQL injection attacks to bypass the site or app's security measures and get access to unauthorized data.

Human error 

Without proper training, an employee may not follow best practices for online safety—which can lead to the unauthorized exposure of information. 

  • Phishing: Keep in mind that phishing messages may include links or attachments that contain malware. Sometimes, hackers target individual employees in order to gain access to a company or organization’s data. 

  • Weak passwords: Similarly, if a hacker’s able to guess or decipher an employee’s credentials, they may be able to access the employer’s systems. Sometimes, cybercriminals use trial and error to guess login information — a tactic known as a brute force attack. That’s one reason why strong passwords are key, for both work and personal accounts. 

Physical attacks 

When files or devices fall into the wrong hands, the information they contain may be at risk. 

  • Stolen or lost computers, phones, or any other files—digital or otherwise—that contain information: If a company device is lost or stolen, hackers may be able to gain access to confidential data or systems. 

One more thing to consider. Imagine you own a company that relies on a third-party vendor—such as a payment processor—and that vendor experiences a data breach involving your company’s information. This is known as a third-party data breach. As organizations increasingly rely on vendors, software providers, and cloud services, a breach at one company can sometimes expose data belonging to many others.

How to know if you’ve been affected by a data breach

According to the National Council of State Legislatures (NCSL), all 50 states have laws that require private businesses—and in most states, governmental entities as well—to notify individuals of security breaches of information involving personally identifiable information.

These notifications, also known as data breach responses, may include more information about what specific data was compromised. 

Some data breaches come to light long after the actual incident occurred—so take note of any notice of a breach that you receive, even if it happened many months ago.

What to do after a data breach

If you receive such communication, it’s important to understand that you’re not necessarily experiencing identity theft. But, data breaches can leave your personally identifiable information exposed, which can make you more vulnerable to fraud in the future. 

If you receive a breach notification:

  • Read the notice carefully to understand what information was exposed.

  • Change affected passwords immediately.

  • Enable multi-factor authentication on impacted accounts.

  • Monitor bank, credit card, and online accounts for suspicious activity.

  • Review your credit reports for unfamiliar accounts or inquiries.

  • Consider placing a fraud alert or freezing your credit if highly sensitive information was exposed.

Got a data breach notification? We’re here to guide you on what to do next.

Share this content to your social channels