Last price

Data Breach: what it is and what to do

Every time we enter our credentials on a website, make an online purchase or fill in a digital form, we leave behind a trail of personal data. Most of the time, this data is secure. But not always. A data breach can affect anyone: private individuals, companies, hospitals, banks and public authorities. When it happens, the consequences can be long-lasting and difficult to contain.

Understanding what a data breach is, how to recognise it and how to act promptly is not merely a technical matter: it is a fundamental skill in the digital age, both for individual users and for organisations that handle sensitive data.

What is a data breach and what can cause It?

The most precise definition of a data breach is provided by the European General Data Protection Regulation (GDPR): a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. Put more simply, a data breach is any event in which data that should have remained confidential falls into the wrong hands or is made inaccessible to its legitimate owners.

Data breaches can have many causes and are not always the result of a sophisticated cyberattack. External attacks – such as hacker intrusions, malware infections, phishing campaigns or ransomware – are the most common cause, but a significant proportion of breaches are due to internal human error: an email sent to the wrong recipient, a lost company laptop, credentials shared insecurely or incorrectly configured cloud systems. In some cases, the threat originates within the organisation itself, from employees or contractors who intentionally access data they are not authorised to view.

Among the best-known data breaches worldwide, the Yahoo incident of 2013–2014 remains the largest ever recorded: more than 3 billion accounts were compromised, with usernames, email addresses, dates of birth and encrypted passwords stolen and offered for sale on the dark web. In 2021, the data of more than 533 million Facebook users – including telephone numbers, names, email addresses and location data – was published online after being obtained by exploiting an API vulnerability through scraping. In Italy, in 2023, a ransomware attack against the regional healthcare authority in Calabria (ASP Catanzaro) compromised thousands of patient medical records and made systems inaccessible for several days.

Which data is most at risk?

Not all data has the same value to those seeking to obtain it unlawfully. Cybercriminals have specific objectives, and understanding which categories of data are most exposed helps explain why a data breach can have such serious and long-lasting consequences.

The most sought-after – and therefore most at-risk – data includes:

  • Login credentials (username and password): these are the most readily tradable currency on the digital black market. They are used directly to access bank accounts or online services, or sold in bulk on the dark web.
  • Financial data: credit card numbers, bank details and current account information. These enable immediate fraud that can be difficult to trace.
  • Personal details and identity documents: name, tax identification number, date of birth, passport number or identity card details. These are the raw materials for identity theft, which can cause financial and legal harm to the victim for years.
  • Health data: medical records, diagnoses, treatments and genetic data. This information is particularly sensitive because it cannot be changed – you cannot change your medical history as you would a password – and it is valuable for insurance fraud or blackmail.
  • Confidential corporate data: trade secrets, strategic plans, customer and supplier data, and internal communications. A data breach in this area can undermine a company’s competitiveness and expose it to significant legal disputes.
  • Critical infrastructure data: network configurations, industrial control system credentials and plant maps. In sectors such as energy or water, exposure of this information can have consequences that extend well beyond cyber damage, potentially creating risks to people’s physical safety.

 

How to know whether your data has been compromised

One of the most insidious aspects of a data breach is that victims often do not realise immediately that it has occurred. In many cases, the affected company discovers the breach months later, and stolen data may circulate on the dark web for years before anyone uses it. This makes proactive monitoring an essential practice rather than an exceptional activity.

The first warning sign is often a direct notification: companies subject to the GDPR are required to notify the supervisory authority – in Italy, the Italian Data Protection Authority – within 72 hours of becoming aware of a breach and to inform affected users when the breach is likely to result in a high risk to their rights. An email notification from a service you use should therefore be taken seriously, even when the message appears generic.

There are also tools that allow users to check independently whether their credentials have been involved in a known breach. For example, leading browsers – particularly Chrome and Safari – now include automatic warning features that alert users when a saved password has appeared in a known breach.

Indirect signs of a possible compromise include unrecognised logins to your accounts, visible in the history of active sessions; unauthorised charges on payment cards; unsolicited password-reset emails; or messages referring to personal data that you do not remember sharing with the sender. Each of these signs warrants immediate investigation.

 

Signs of a possible data breach and how to respond
Warning sign What it may indicate Recommended action
Notification email from a service Breach confirmed by the company Change the password immediately
Unrecognised account logins Credentials already being used by third parties Revoke active sessions and enable MFA
Unauthorised charges Compromised financial data Block the card and contact the bank
Unsolicited password reset Attempted access by a third party Do not click the link; access the service directly

 

What to do in the event of a breach

Discovering that you have been involved in a data breach can be disorienting. Having a clear action plan –  and acting quickly – often makes the difference between containing the damage and allowing it to persist over time.

The first step is to change the passwords for the affected accounts immediately, starting with the most critical ones: your primary email account, online banking and services containing payment information. If the same password was used for other services – an unfortunately common practice – it must be changed there as well, because criminals systematically use stolen credentials to attempt access to other websites, in an attack known as credential stuffing. New passwords should be unique to each service, at least 12 characters long and made up of a combination of letters, numbers and symbols. A password manager can help you manage them without having to remember them all.

The second step is to enable multi-factor authentication (MFA) wherever it is available. Even if credentials have been stolen, the second factor – a temporary code sent by SMS or generated by an authentication app – prevents the attacker from accessing the account. At the same time, it is advisable to revoke all active sessions on the affected services, forcing a logout from every device, and to check that no email-forwarding rules or profile-data changes have been created without your knowledge.

If financial data has been exposed, contact your bank promptly to block or replace compromised cards and monitor transactions over the following days. In the event of identity theft – where personal details are used to open accounts, incur debt or sign contracts – a report should be filed with the Postal and Communications Police, the Italian authority responsible for cybercrime. Keeping all documentation relating to the breach is essential both for the report and for any subsequent compensation claim.

For companies, the GDPR imposes specific obligations in the event of a data breach: notification to the Data Protection Authority within 72 hours, assessment of the risk to data subjects and, where necessary, direct communication to affected users. Failure to comply with these obligations may result in fines of up to 2% of total worldwide annual turnover or €10 million, whichever is higher.

 

How to prevent a data breach

Preventing a data breach requires an approach that combines technology, processes and organisational culture. There is no single solution: security is built in layers, progressively reducing the attack surface and limiting damage in the event of a partial compromise.

From a technical perspective, data encryption is the most effective measure for rendering stolen information unusable: when data is properly encrypted, even someone who obtains it unlawfully cannot read it without the decryption key. Access control is equally important: applying the principle of least privilege – where each user and system can access only the data strictly necessary for their role – limits the damage if an account is compromised. The adoption of multi-factor authentication across all critical systems and the centralised management of digital identities complete the access-protection framework.

Continuous monitoring of logs and network traffic, using SIEM systems and anomaly-detection solutions, makes it possible to identify suspicious behaviour before it develops into a confirmed breach. In this context, surveillance spyware – malicious software that operates silently on devices and collects data without the user’s knowledge – is one of the most insidious vectors of data exfiltration, and its early detection is an integral part of an effective prevention strategy.

At an organisational level, staff training is often the most underestimated defence. A significant proportion of data breaches originate from human error – clicking phishing links, opening attachments without verification or sharing passwords insecurely – which regular, targeted training can drastically reduce. Alongside training, it is essential to define clear incident-response procedures: knowing exactly whom to contact, what to do and in what order of priority during the first hours after a breach is discovered reduces the overall damage and ensures compliance with regulatory requirements.

For organisations that manage large volumes of data or operate in critical sectors, regularly conducting vulnerability assessments and penetration tests makes it possible to identify weaknesses before they are exploited by real attackers. Likewise, verifying the security of suppliers and partners that process data on the company’s behalf – an often-overlooked aspect – is an integral part of responsible risk management. The case of the US retail chain Target, which suffered a data breach in 2013 that exposed 40 million payment cards, is illustrative: the attackers gained entry through an HVAC contractor with access to the company’s internal network.

In summary, the key measures for reducing the risk of a data breach are:

  • Encryption of sensitive data both in transit and at rest, so that the information remains unusable even in the event of unauthorised access.
  • Multi-factor authentication (MFA) on all critical systems and accounts, as a second line of defence in addition to passwords.
  • Principle of least privilege: each user can access only the data required for their role, limiting the scope of damage in the event of a compromise.
  • Continuous monitoring and SIEM systems to detect anomalies and suspicious behaviour before they develop into a breach.
  • Regular staff training on phishing, secure credential management and incident-response procedures.
  • Regular vulnerability assessments and penetration tests, also extended to suppliers and partners that process corporate data.
  • A documented and tested incident-response plan, enabling rapid action in compliance with GDPR obligations in the event of a breach.

 

In a world where data has become a strategic resource, protecting it is no longer optional: it is a regulatory obligation, a responsibility towards people and a prerequisite for competitiveness. For companies that manage critical infrastructure, where a data breach may have not only digital but also operational and physical consequences, investing in data-breach prevention means protecting not only information, but also service continuity and users’ trust.