Every year, billions of records - emails, passwords, personal details - spill out of companies and onto the internet. Each spill is a data breach, and the odds that some of your data is in one are high. The good news: while you can't stop an organisation from being breached, you can dramatically limit what a breach costs you. This guide explains what a data breach is, how they happen, what gets exposed, and how to protect yourself.
What a data breach is
A data breach is an incident where confidential or sensitive data is accessed, copied, exposed or stolen by someone unauthorized. It might be a hacked customer database, a misconfigured cloud server left open, an insider leaking records, or a lost device full of files.
Breaches are common, and the stolen data doesn't just sit there - it fuels fraud, phishing and account takeover, often years later.
How they happen
- Hacking & malware - exploiting software flaws or stolen credentials.
- Phishing - tricking staff into granting access.
- Misconfiguration - a cloud database or storage bucket left publicly accessible.
- Insider threats - employees leaking or stealing data.
- Physical loss - stolen or lost laptops and drives.
Many big breaches combine these. The common thread: organisations hold huge amounts of your data, and any weak point can expose it.
What gets exposed
Depending on what the organisation stored: emails and usernames, passwords (sometimes weakly hashed or plaintext), names, phone numbers, addresses, dates of birth - and in worse cases payment cards, government IDs or health records.
Even "just" an email-and-password pair is dangerous: attackers replay it on other sites (credential stuffing). The more complete the leaked profile, the more it enables identity theft.
Credential stuffing: why one breach becomes many
The reason a single leak is so dangerous is credential stuffing. Attackers take the email-and-password pairs from one breach and automatically try them against hundreds of other sites - banks, email, shopping, social. Because so many people reuse passwords, a small percentage of those attempts succeed, and one old leak quietly unlocks accounts that were never breached themselves. It's cheap, automated, and runs at massive scale.
This is why "I'll change it on that one site" isn't enough: the leaked pair is now in lists traded and replayed for years. A unique password per site is the single change that breaks the cascade - a leak from one service then unlocks nothing else.
How to check whether you've been breached
You can find out, for free:
- Have I Been Pwned (haveibeenpwned.com) lets you enter an email and see which known breaches include it, and offers alerts for future leaks.
- Your password manager likely has built-in breach monitoring (often called a security dashboard or watchtower) that flags reused, weak, or leaked passwords across all your logins.
- Browser checks - Chrome, Firefox and Safari now warn when a saved password appears in a known breach.
Run the check, then rotate anything flagged - starting with email and banking, the accounts that unlock everything else.
What to do if you're affected
- Change the password on the breached account and anywhere you reused it - unique strong passwords (a password manager makes this easy).
- Turn on 2FA, ideally phishing-resistant.
- Watch for phishing that references the breach; be sceptical of urgent "security" messages.
- If payment or identity data leaked, monitor statements and consider fraud alerts.
- Treat the leaked password as permanently burned - never reuse it.
How to limit the damage in advance
You can't stop a company being breached, but you can contain the fallout:
- Unique password per site - one leak never unlocks another.
- 2FA everywhere it's offered.
- Share less - the less an organisation holds, the less can leak.
- End-to-end encrypted storage for files you control: even if the provider is breached, attackers get only unreadable ciphertext.
Related guides
To dig deeper, see what a digital footprint is.
Files the provider can't leak → pCloud + Crypto
Swiss jurisdiction · Client-side (zero-knowledge) encryption with the Crypto add-on · Lifetime plans
For the encryption that makes a provider breach harmless, see end-to-end encryption and our best encrypted cloud storage guide; for how providers hold your data in the first place, what is cloud storage.
The bottom line
A data breach is the unauthorized exposure of confidential data - and given how much of your information organisations hold, some of it will likely leak eventually. You can't prevent their breaches, but you can make them harmless to you: unique passwords, 2FA, sharing less, and end-to-end encryption turn most breaches from a personal disaster into a non-event. Assume your data can leak, and arrange your security so it doesn't matter when it does.
Editorial guide based on how data breaches occur (hacking, phishing, misconfiguration, insider, physical loss) and standard personal protections (unique passwords, 2FA, data minimisation, E2EE). The commercial link carries the rel="sponsored nofollow" attribute; an affiliate commission may apply at no extra cost to you.
Frequently asked questions
- What is a data breach?
- A data breach is an incident where confidential, protected or sensitive data is accessed, copied, exposed or stolen by someone unauthorized to do so. That can be a company's customer database hacked by criminals, a misconfigured cloud server left open to the internet, an employee leaking records, or a lost laptop full of files. The exposed data often includes emails, passwords, personal details, payment information or health records. Breaches are common - billions of records leak each year - and the stolen data fuels further attacks like fraud, phishing and account takeover.
- How do data breaches happen?
- Several ways. Hacking and malware that exploit software vulnerabilities or stolen credentials; phishing that tricks employees into giving access; misconfiguration, like a cloud database or storage bucket left publicly accessible; insider threats from staff who leak or steal data; and physical loss or theft of devices. Many large breaches combine these - a phishing email leads to stolen credentials, which lead to access to a poorly segmented database. The common thread is that organisations hold huge amounts of your data, and any weak point can expose it.
- What information gets exposed in a data breach?
- It depends on what the breached organisation stored, but commonly: email addresses and usernames, passwords (sometimes weakly hashed or even plaintext), names, phone numbers, home addresses, dates of birth, and in worse cases payment card data, government IDs, or health records. Even 'just' an email-and-password pair is dangerous, because attackers replay it on other sites (credential stuffing). The more complete the profile leaked, the more it enables identity theft and targeted fraud. Assume any data you give a service could one day appear in a breach.
- What should I do if my data is breached?
- Act fast. Change the password on the breached account and anywhere you reused it, using unique strong passwords (a password manager makes this easy). Turn on two-factor authentication, ideally a phishing-resistant method. Watch for phishing that references the breach, and be sceptical of urgent 'security' messages. If payment or identity data leaked, monitor financial statements and consider fraud alerts. Check whether your accounts appear in known breaches, and treat the leaked password as permanently burned - never use it again.
- How can I limit the damage of a data breach?
- You can't stop a company from being breached, but you can contain what it costs you. Use a unique password per site so one leak never unlocks another. Turn on 2FA everywhere it's offered. Share less data - the less an organisation holds about you, the less can leak. For files you control, use end-to-end (zero-knowledge) encrypted storage, so even if the provider is breached, attackers get only unreadable ciphertext. Minimisation plus unique passwords plus 2FA turns most breaches from a disaster into a non-event for you.
Get encrypted cloud storage → pCloud
Swiss-based · client-side Crypto add-on · lifetime plans



