What Is a Data Breach?

What is a data breach? It is an incident in which sensitive or personal information is accessed, exposed, acquired, disclosed, copied, transmitted, stolen or used without authorization. The issue remains significant in the United States, with the Identity Theft Resource Center (ITRC) reporting 1,803 data compromises during the first half of 2026 and an estimated 471.2 million victim notices issued during that period.

A data breach can affect individuals, businesses, government organizations and other institutions. The information involved may include names, addresses, Social Security numbers, financial details, passwords, health information and other confidential records.

The latest U.S. data shows that these incidents continue to occur at a high rate. The ITRC’s H1 2026 report found that the second quarter alone accounted for 1,029 compromises, making it the second-highest single-quarter total in the organization’s tracking history.

What Does a Data Breach Mean?

A data breach happens when information reaches someone who is not authorized to access it. The National Institute of Standards and Technology (NIST) describes a breach as a loss of control, compromise, unauthorized disclosure or unauthorized acquisition involving personally identifiable information.

The incident does not necessarily require a hacker to break into a computer system. Unauthorized access can occur through several different circumstances.

For example, information could be stolen by an attacker, exposed through a security weakness, accidentally disclosed, or accessed by an employee who does not have permission to use it for that purpose.

NIST also recognizes situations involving authorized users who access personal information for an unauthorized purpose. That means a breach can involve both external attackers and people inside an organization.

What Information Can Be Exposed in a Data Breach?

The information affected depends on what an organization stores and what an attacker or unauthorized person can access.

Common categories include:

  • Names and contact information
  • Home or mailing addresses
  • Email addresses
  • Telephone numbers
  • Account usernames and passwords
  • Social Security numbers
  • Driver’s license information
  • Bank account information
  • Credit and debit card information
  • Medical or health information
  • Employment records
  • Customer records
  • Other confidential business information

NIST notes that exposed information can include credit card numbers, personal health information, customer data, trade secrets and other sensitive information.

Not every breach exposes every type of information. The level of risk depends heavily on what information was involved.

A stolen email address may create a different level of risk than an exposed Social Security number. Likewise, compromised passwords can create immediate account-security concerns, especially when the same password is reused on multiple websites.

How Do Data Breaches Happen?

Data breaches can occur through many different methods. Cyberattacks are a major source of compromises, but they are not the only cause.

Common causes include:

  • Hacking or unauthorized system access
  • Phishing and stolen credentials
  • Malware
  • Ransomware and other cyberattacks
  • Misconfigured systems
  • Accidental disclosure
  • Lost or stolen devices
  • Insider activity
  • Third-party or supply-chain weaknesses
  • Improper handling of sensitive information

The ITRC reported that cyberattacks remained the primary cause of data breaches involving stolen personal information in the first half of 2025, with 1,348 such incidents recorded.

The organization has also highlighted the growing importance of third-party risk. A company may maintain its own security controls while still depending on vendors that handle customer or employee information.

That means a security problem at one organization can affect people connected to another organization.

Are Data Breaches Always Caused by Hackers?

No. A data breach does not always begin with a criminal hacking into a computer.

The NIST definition covers unauthorized disclosure and unauthorized acquisition, as well as unauthorized access to personally identifiable information.

An organization could accidentally expose information through an improperly secured system. An employee could disclose information to someone who is not authorized to receive it. A device containing sensitive records could also be lost or stolen.

The key issue is unauthorized access, disclosure, acquisition or use of protected information.

What Is the Difference Between a Data Breach and a Data Leak?

The terms are often used together, but they can describe different circumstances.

A data breach generally refers to unauthorized access, acquisition, disclosure or loss of control involving sensitive information.

A data leak commonly describes information becoming exposed outside its intended security boundary. The exposure may result from an attack, a mistake or an improperly secured system.

NIST’s cybersecurity glossary lists data leakage as a synonym related to data breach terminology.

The important point for consumers is not simply the terminology. What matters is whether personal or confidential information became accessible to an unauthorized person and what information was involved.

How Common Are Data Breaches in the United States?

Recent U.S. data shows that data compromises remain widespread.

The ITRC tracked 3,322 data compromises in 2025, which represented a five percent increase from 3,152 in 2024 and established a new annual record in the organization’s tracking.

The situation continued into 2026. During the first six months of the year, the ITRC recorded 1,803 compromises.

The number of victim notices was especially notable. The organization estimated that 471.2 million victim notices were issued during H1 2026. That figure already exceeded the 297.5 million notices reported for all of 2025.

The figures demonstrate why consumers should take breach notifications seriously. A notice does not automatically mean that identity theft has occurred, but it indicates that an organization believes information connected to affected individuals was compromised or potentially compromised.

Which Industries Are Affected by Data Breaches?

Data breaches can affect virtually any sector that stores sensitive information.

The ITRC’s 2025 annual report identified financial services as the most breached industry, followed by healthcare, professional services, manufacturing and education.

These sectors maintain large amounts of valuable information. Financial organizations handle payment and account information. Healthcare organizations maintain sensitive medical records. Professional-services companies can hold information belonging to many clients.

The risk also extends beyond the organization directly serving a consumer.

Third-party providers can store, process or transmit information for businesses. When a vendor is compromised, multiple organizations and their customers can potentially be affected.

Why Is a Data Breach Dangerous?

The consequences depend on the type of information exposed and how criminals use it.

A compromised password may allow someone to attempt unauthorized access to an online account. Exposed financial information may increase the risk of fraud. A stolen Social Security number can create longer-term identity-theft concerns.

There can also be an increase in phishing and scam attempts after information becomes available to criminals.

The ITRC’s 2025 consumer survey found that 88 percent of people who received a data breach notice reported at least one negative consequence. Reported consequences included increased phishing or scam attempts, more spam emails or robocalls, and attempted account takeovers.

This is why a breach notice should not simply be ignored.

What Should You Do After a Data Breach?

The Federal Trade Commission recommends acting quickly after receiving a breach notification.

First, determine what information was exposed. The appropriate response depends on whether the affected information involves a password, Social Security number, financial account or another type of personal information.

If a password was involved, change it immediately. The FTC also recommends changing that password on other accounts where the same or a similar password was used.

Enable multifactor authentication when it is available. This provides an additional security step beyond a password.

If a Social Security number was exposed, consumers can obtain their credit reports and review them for accounts or activity they do not recognize. The FTC also recommends considering a credit freeze or fraud alert in appropriate circumstances.

Consumers should also be cautious about messages that arrive after a breach. Criminals may use stolen information to make phishing attempts appear more convincing.

Do not assume that a message is legitimate simply because it contains your name, email address or other information connected to the breach.

Does a Data Breach Mean Someone Stole Your Identity?

Not necessarily.

A data breach means information was accessed, exposed, acquired or otherwise compromised without proper authorization. It does not automatically prove that every affected person’s information was used for identity theft.

However, exposed information can increase the risk of identity theft, fraud, account takeover and targeted scams.

That is why consumers should pay attention to the specific information identified in their breach notification and follow the recommended protective measures.

What Are Companies Expected to Do After a Data Breach?

Organizations have responsibilities that can vary depending on the type of information involved, the industry and the applicable federal and state laws.

The FTC advises businesses responding to a breach to secure their systems, determine what information was affected, investigate the incident, address vulnerabilities and communicate appropriately with affected individuals.

The FTC also notes that all states, the District of Columbia, Puerto Rico and the U.S. Virgin Islands have enacted laws requiring notification for certain security breaches involving personal information. Specific notification requirements vary by jurisdiction and circumstance.

Certain industries have additional requirements.

For example, the FTC’s Health Breach Notification Rule applies to covered organizations and certain health-related entities. The FTC updated the rule in 2024, including provisions addressing unauthorized disclosures of certain health information.

Financial institutions covered by the FTC’s Safeguards Rule also face specific federal notification requirements for certain security breaches. Since May 13, 2024, covered financial institutions must notify the FTC as soon as possible and no later than 30 days after discovering certain breaches involving the information of at least 500 consumers.

Why Current Data Breach Numbers Matter

The latest statistics show that data compromises are not a rare cybersecurity event.

In 2025, the ITRC recorded 3,322 compromises. In just the first half of 2026, it recorded 1,803. The organization said that if the 2026 pace continued, the year could reach approximately 3,600 compromises.

The ITRC also reported a major increase in victim notices during the first half of 2026. More than 471 million notices were issued, surpassing the full-year figure reported for 2025.

Those numbers do not mean that 471 million unique people were affected. Victim-notice totals can include multiple notices connected to different compromises and do not necessarily represent unique individuals.

Still, the figures show the scale of personal-information exposure being tracked in the United States.

The Bottom Line on Data Breaches

A data breach is an unauthorized loss of control, access, acquisition or disclosure involving sensitive or personal information. It can result from hacking, stolen credentials, accidental exposure, insider activity, vendor weaknesses and other security failures.

The latest U.S. figures show that the problem remains substantial in 2026. The ITRC’s H1 2026 report recorded 1,803 compromises and an estimated 471.2 million victim notices during the first six months of the year.

For consumers, the most important step is to understand what information was affected and respond accordingly. Changing exposed passwords, enabling multifactor authentication, monitoring financial activity and considering a credit freeze or fraud alert when appropriate can help reduce the potential impact.

Understanding what a data breach means is the first step toward recognizing the risks and taking action when your information is exposed.

Is Starbucks Open on...

If you're wondering is Starbucks open on Labor Day,...

Does FedEx Deliver on...

If you are waiting for a package or planning...

Cognizant Data Breach: Latest...

The Cognizant data breach remains an important cybersecurity story...

Biftx Expands Cryptocurrency Trading...

Cryptocurrency trading is gaining another platform development story as...

Mathspace Data Breach: More...

The Mathspace data breach has affected 1,079,819 people in...

Manchester Airport Data Breach:...

The Manchester Airport data breach has become a major...