Data Breach

A data breach is an incident where information is accessed, taken or exposed without authorization. For identity work the consequential kind is a breach of personal data — because unlike a stolen password, a date of birth or a national ID number cannot be changed once it circulates.

Definition Unauthorized access to, or disclosure of, protected information
Common causes Credential compromise, phishing, unpatched systems, misconfiguration, insider access, third-party compromise
Most damaging class Personal identifying data, because it cannot be reset
Typical exposed data Names, dates of birth, national ID numbers, addresses, security answers
Where it goes Dark web marketplaces, combined into fullz packages
Notification duties GDPR requires notice to a supervisory authority within 72 hours; U.S. rules vary by state and sector
Downstream use Account takeover, new-account fraud, synthetic identity construction
Shelf life Indefinite — the data does not expire
Structural consequence Knowledge-based authentication no longer works

How it works

The causes are unglamorous and consistent. Compromised credentials — often reused, often phished. Unpatched systems with known vulnerabilities. Cloud storage left publicly readable. Insiders with more access than their role requires. And increasingly a third party: a vendor, a processor, a supplier with a connection into the environment, which is why an organization’s breach exposure is not confined to its own systems.

What matters afterwards is the type of data. A breached password is a bounded problem — reset it and the exposure ends. A breached date of birth, national ID number, mother’s maiden name or former address is unbounded, because none of it can be reissued. The victim cannot make their date of birth private again.

That permanence is what turns individual breaches into a cumulative condition. Data from separate incidents gets correlated and assembled into fullz — complete identity packages combining fragments from many sources into something more useful than any single breach produced.

Notification duties differ sharply by jurisdiction. GDPR requires notifying a supervisory authority within 72 hours of becoming aware, and affected individuals where risk is high. The U.S. has no single federal standard, so obligations vary by state and by sector, which is why disclosure timing is often driven by the strictest applicable rule.

Why it matters for identity verification

Breaches are the reason a whole generation of identity controls stopped working, and the mechanism is worth being precise about.

Knowledge-based authentication assumed personal data was private. Breach data made that false at scale. A fraudster reading answers from a purchased file answers more consistently than a genuine customer recalling a decade-old address — so the control does not weaken gracefully, it inverts. KBA now performs better for attackers than for the people it protects.

The same logic undermines any check resting on knowledge. Security questions, address matching, and data-only verification all assume secrecy that no longer exists for a large share of the population.

What breaches cannot produce is a person. No package contains a live face matching a document portrait, and no volume of leaked data manufactures a genuine government credential. That asymmetry is the entire argument for document and biometric verification — it asks for something the market cannot sell. Authenticating a document and matching it to a live person is the control breach data does not defeat, and Microblink’s stolen identity detection is built on that premise.

Breached credentials vs breached identity data

  Credentials Personal identity data
Example Username and password Date of birth, national ID number, address history
Can be changed Yes — reset it No
Exposure window Until reset Indefinite
Primary downstream use Account takeover, credential stuffing New-account fraud, synthetic identities
Victim awareness Often prompted to reset Frequently never notified in a useful form
Effective countermeasure Rotation, MFA, passkeys Document and biometric verification

What breach response can’t do

It cannot un-leak the data. Notification, credit monitoring and identity-theft insurance manage consequences. None returns the information to private, and none expires it.

It cannot predict when the data will be used. Breached identity data surfaces in fraud years later, often after monitoring offers have lapsed. The gap between breach and exploitation is a deliberate tactic.

Credit monitoring does not cover synthetic use. Where a breached national ID number is combined with a fabricated name to build a synthetic identity, the activity attaches to a file the victim does not recognize and monitoring does not surface it.

It cannot restore controls that depended on secrecy. Once personal data circulates, knowledge-based verification is not repairable by better questions. The premise is gone, and the answer is a different kind of control.

Frequently asked questions

What is the difference between a data breach and a data leak?

A breach generally implies unauthorized access by someone who should not have had it. A leak often describes exposure through error — a misconfigured database, an unsecured bucket. The consequences for the affected people are usually identical.

How long does breached personal data remain useful to fraudsters?

Indefinitely for anything that cannot be changed. Passwords and card numbers decay quickly; dates of birth, national ID numbers and address histories do not, which is why breach data resurfaces in fraud years after the incident.

Why does a data breach make knowledge-based authentication unusable?

Because KBA assumes only the real person knows the answers, and breach data puts those answers in a file the fraudster is reading from. The control fails asymmetrically — attackers answer more accurately than genuine customers do.

What can businesses do about breach data they did not lose?

Stop treating knowledge of personal data as proof of identity. Document authentication paired with a biometric check asks for something no breach supplies — a genuine credential held by the matching live person.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data