How Do Data Breaches Happen? The Main Causes, and What to Do When Your Data Leaks

A data breach is any incident where information that was supposed to be protected (passwords, Social Security numbers, medical records, payment cards) is accessed, copied, or exposed by someone who shouldn't have it. Most people picture an elite hacker breaking through defenses. The incident data tells a duller story: a stolen password, a convincing phishing email, or a database someone left open to the internet by mistake.

The scale is hard to overstate. The Identity Theft Resource Center's 2025 Annual Data Breach Report tracked 3,322 compromises in a single year, a new record, generating roughly 279 million victim notices. And that was a comparatively calm year; 2024's total exceeded 1.3 billion notices, inflated by a handful of mega-breaches. If you have an email address, statistically it has already been through several breaches. You can check which ones at Have I Been Pwned.

Hands typing on a laptop keyboard as red warning triangles with exclamation marks float above the keys.

How data breaches actually happen

Verizon's Data Breach Investigations Report (DBIR), the industry's standard annual autopsy of thousands of real incidents, is consistent about the causes even as the exact rankings shuffle. The 2026 edition found vulnerability exploitation the most common way in for the first time in the report's history, while stolen credentials still appear somewhere in 39% of breaches — more than any other component. The main doors in:

Stolen credentials

Initial access in 13% of breaches in the 2026 DBIR, and involved somewhere in the attack chain in 39%. Attackers rarely guess passwords; they buy them. Passwords leak in one breach, get sold in bulk, then get replayed against every other service ("credential stuffing"). Password reuse turns one company's breach into your personal breach. Infostealer malware feeds the same market: the 2025 edition found that over half of ransomware victims had employee credentials circulating in infostealer logs before the attack.

Phishing and social engineering

16% of breaches start with phishing. One employee enters their login on a fake portal and the attacker walks in the front door. Phishing was also the FBI's most-reported cybercrime in 2025, with 191,561 complaints. The tactics are covered in depth in our guide to types of social engineering attacks.

Unpatched software vulnerabilities

The 2026 DBIR's new number one, kicking off 31% of breaches, up sharply year over year. When a security flaw is disclosed, a race starts between organizations patching and attackers scanning the internet for systems that haven't. Several of the largest breaches of recent years were exactly this, including the MOVEit file-transfer breach that rippled through thousands of downstream organizations: one vulnerability, exploited at scale before patches landed.

Misconfiguration and human error

No attacker required. Cloud storage buckets left publicly readable, databases exposed without passwords, backup files in the wrong place, an email with a spreadsheet sent to the wrong recipient. Error has held steady as one of the DBIR's leading breach patterns for years.

Third-party and supply-chain compromise

Your data is only as safe as the least secure vendor holding a copy. Payroll processors, marketing platforms, debt collectors, and software suppliers all hold customer data, and a breach at any of them exposes you, often at a company you've never heard of and never chose to do business with.

Insiders and physical loss

The long tail: employees who abuse legitimate access, plus the older-fashioned failures like stolen laptops, lost drives, and paper records, which still account for a steady trickle of incidents.

What a breach costs, and who pays

IBM's 2025 Cost of a Data Breach Report puts the global average cost to the breached organization at $4.44 million ($10.22 million in the United States), with breaches taking an average of 241 days to identify and contain. That's roughly eight months during which the stolen data is already circulating.

For individuals, the costs arrive later and less visibly: account takeovers using leaked passwords, targeted phishing that quotes your real data to sound legitimate, SIM-swapping, and identity theft in the form of new credit lines, tax refunds, and medical claims in your name.

Where your data goes after a breach

Breached data doesn't vanish after the headlines. It flows into markets:

  1. Dark-web sale. Fresh credential dumps and "fullz" (full identity packages) are sold, resold, and eventually dumped for free. Data from a decade-old breach still fuels attacks today.
  2. Aggregation. Criminals merge breach data with what's legally public, like voter rolls, property records, and court filings, to build fuller profiles for fraud and social engineering.
  3. Data brokers, the legal end of the pipeline. People-search and data broker sites compile and republish your address history, phone numbers, and relatives, entirely lawfully. In our own catalog of these sites, dozens of differently branded storefronts turn out to resell the same few back-end databases, so one profile of you surfaces in many places at once. When a scammer wants to impersonate you to your bank or your carrier, breach data provides the secrets and broker data provides the biography. Our guide to where data brokers get your information traces that supply chain.

What to do if your data was breached

  1. Find out what leaked. The breach notice tells you the categories: passwords, SSNs, card numbers, medical data. Your response depends on which.
  2. Change the breached password everywhere you used it, and turn on two-factor authentication. If you reuse passwords, assume the attackers' software has already tried them elsewhere.
  3. If financial data leaked, watch statements, request new card numbers, and dispute anything unfamiliar.
  4. If your SSN leaked, freeze your credit at all three bureaus. It's free, fast, and the single most effective anti-identity-theft move available. A fraud alert is the lighter option.
  5. Don't let a settlement's free credit monitoring lull you into doing nothing else. Monitoring tells you about fraud after it happens; a freeze prevents it.
  6. If identity theft actually occurs, use IdentityTheft.gov for an official FTC report and recovery plan.
  7. Reduce what the next breach can expose. You can't patch a company's servers, but you can shrink your footprint: close dormant accounts, use unique email aliases and passwords per service, and remove the personal data that brokers republish about you. Our step-by-step removal guide covers how. The follow-up scams get much harder to aim once the public half of your profile is gone.

What actually protects you

A record 3,322 compromises in one year means the realistic questions are when your data leaks and how much, not whether. The companies holding your data decide how well it's defended. What you decide is how much damage a leak can do. Unique passwords keep one company's breach from spreading to the rest of your accounts, and a credit freeze blocks the most expensive kind of fraud. Clearing your data off broker sites helps in a quieter way: it removes the public profile that the follow-up scams are aimed with.

Get founding-member access when we open the doors.

No spam. One email when Delist My Data opens for your area.