What Is a Data Breach, and What Actually Gets Leaked?
TL;DR: A data breach is when a company's stored information gets accessed without authorization — but "breach" covers a huge range, from a leaked email list to a full financial database. Here's what the term actually means and doesn't mean.
👉 See if your data's already leaked — free 30-second check →
The basic definition
A data breach happens when information a company was storing — about you, as a customer or user — is accessed, copied, or exposed by someone not authorized to have it. That's the whole definition. It says nothing about scale, cause, or severity, which is exactly why the word gets used for wildly different situations.
How breaches typically happen
- External hacking — someone exploits a security vulnerability to get into a company's systems directly.
- Misconfigured storage — a database or cloud storage bucket left publicly accessible by mistake, no hacking required, just an open door nobody closed.
- Insider access — an employee or contractor with legitimate access misuses or leaks it, sometimes for money.
- Third-party vendor compromise — a company you never directly interacted with (an analytics provider, a payment processor) gets breached, and your data goes with it because it had access as a vendor.
What "gets leaked" actually varies enormously
This is the part most people skip past. Not every breach exposes the same categories of data:
- Contact data — name, email, phone number. Common, low-to-moderate severity on its own.
- Account credentials — passwords, sometimes hashed (scrambled, harder to reverse) and sometimes not. Severity depends heavily on whether it's hashed properly.
- Behavioral data — purchase history, app usage, browsing activity tied to your account.
- Financial data — card numbers, bank details, UPI IDs. High severity, usually requires immediate action.
- Government ID data — Aadhaar, PAN, passport numbers. Highest severity, longest-lasting consequences since these identifiers are hard to change.
A single incident often exposes a mix — which is why breach notifications matter: they should tell you which specific categories were involved in that particular event, not just that "a breach happened."
Why breach size gets reported the way it does
Headlines usually lead with the number of records affected — "500 million users" — because it's the easiest number to report. But record count says nothing about severity. A breach of 500 million email addresses is a very different event from a breach of 50,000 full financial profiles, even though the second number sounds smaller and less newsworthy.
What happens to the data after a breach
It rarely stays in one place. Breached datasets typically get posted on hacking forums or dark web marketplaces, sometimes sold, sometimes shared for free to build reputation within those communities. From there, it gets copied, repackaged, and combined with other breach data over time — which is why a breach from years ago can still be circulating and causing spam or phishing attempts long after the original incident is forgotten.
India's regulatory response
Under CERT-In directions, certain organizations are required to report specified categories of cybersecurity incidents, including breaches, within a defined timeframe. The DPDP Act adds obligations around notifying affected individuals and the Data Protection Board in the event of a "personal data breach," reinforcing that companies can't simply stay silent when this happens.
What this means for you practically
When you hear a company you use was breached, the useful next step is finding out specifically what data category was involved — not just reacting to the headline. If you can't get clarity from the company's notification, checking your own exposure directly across sources gives you a more concrete answer. This is what Scan My Shadow does — checking your phone number and email across 1,500+ sources so you know what's actually out there rather than reacting to a scary-sounding headline alone.
FAQs
Is every data breach reported publicly?
No — many go undisclosed for a long time, or are never disclosed at all if the affected company doesn't detect it or isn't legally required to report it in that jurisdiction.
Does a breach mean my specific account was definitely accessed?
Not always — some breaches expose an entire database regardless of individual account activity, while others are more targeted. Checking your specific email or phone number against the breach is the only way to know for sure.
Can a company be held liable for a breach in India?
Under the DPDP Act, data fiduciaries can face significant penalties for failing to implement reasonable security safeguards or for delayed breach notification, though enforcement is still developing.
Curious what's already out there about you? Scan My Shadow checks your phone number and email across 1,500+ sources and sends you a clear report — no guesswork, just facts. Start your scan.
- Results within about 5 minutes
- Clear, plain-English report
- Delivered straight to your inbox
- No login or passwords required
- Scan data deleted after report is generated