A data breach is a situation in which our personal information falls into the wrong hands. Not because we’ve done anything wrong, but because someone else has made a mistake.
The most important thing to remember:
A data breach is very often NOT the user’s fault.
We can be careful, avoid clicking on suspicious links and use strong passwords, yet our data may still be ‘leaked’ because it was stored by a company that had access to it. A data breach can occur in several ways:
- the company where we have an account (an online shop, a clinic, a bank, a website) has weak security,
- someone hacks into the company’s server and steals customer data,
- a company employee makes a mistake (e.g. sends data to the wrong person),
- a company employee deliberately takes data and sells it on.
In such situations, the user has no control over the matter. The data was already in the system and a third party has gained access to it.
What data is most commonly leaked?
The following are very often disclosed during data breaches:
- full name,
- home address,
- telephone number,
- email address,
- PESEL number,
- account passwords (sometimes in encrypted form),
- medical or insurance details.
Sometimes it’s just a few pieces of information, but even these can be enough for a fraudster to:
- impersonate us,
- call ‘from the bank’ or ‘from the clinic’,
- try to extract further details,
- try to take out a loan in our name.