Skip to content

Data breach

In plain terms

A company where you had an account had its customer files stolen, and you're in them. You didn't do anything wrong, and you can't get the exposure undone.

Definition

A data breach is the disclosure, whether accidental or through an intrusion, of data an organization holds about its customers, users, or employees. This fiche takes the point of view of the person affected: what does it mean to be caught in a breach, and what can you usefully do about it.

How it works

The origin lies with the organization — an intrusion, a misconfiguration, a compromised vendor, a misused internal access — not with you: no personal precaution would have kept your address out of a file entrusted to a third party. What concerns you starts afterward. The extracted data circulates, gets cross-referenced with other breaches, and feeds specific uses. An email address paired with a password gets tried against other services. A phone number paired with a name and address makes a message that reuses those details credible. A purchase history makes a fake delivery message credible. This is why a breach often shows up as a rise in well-informed solicitations, months after the fact — and why the delay is nothing to be reassured by: a database doesn't expire.

Warning signs

  • Notification from the organization informing you that your data was affected
  • Messages or calls that reuse accurate information about you: name, address, a recent purchase
  • Reported login attempts on accounts that reuse the same password
  • A sharp rise in spam emails and sales calls targeting the same address
  • A password-reset request you didn't trigger

How to verify

Take the notification from the organization seriously, but reach your account on your own rather than through the link in the message — a real breach is often followed by fake messages imitating it, and that's a moment when people click. Check recent activity and connected devices on the affected accounts. Ask the organization exactly which data was affected: the right response isn't the same for email addresses as it is for identity documents.

What to do

Change the password of the affected service, and above all every other one where you reused it — that's the only action that addresses the main consequence. Turn on two-factor authentication wherever it's available. Expect well-informed messages in the months that follow, and treat every incoming solicitation with the same rule as elsewhere: never reply through the channel it arrived on.

If it already happened

You have rights you can assert against the organization — to be told which data was affected, to request access to it, to request its erasure — and a right of recourse with the CNIL if it doesn't respond. If the breach includes identity documents or banking details, the risk changes in nature: watch your statements, notify your bank, and read the identity theft fiche. Keep the notification you received, it documents the date and origin. Report the incident to the relevant authority. If someone tries to blackmail you by citing this data, the fiche on extortion after a data breach covers that specific case.

Frequently asked questions

Can I get my data taken down once it has leaked?
You can ask the organization that held it to erase it, and that's useful going forward. On copies already circulating, no one can — that's the reality to accept, because it redirects effort to where it's effective: changing what can be changed, starting with passwords.
The breach happened two years ago — am I still affected?
Yes. A database doesn't go out of date: your name, address, and date of birth haven't changed, and a password never renewed is still valid. Old files keep circulating and get cross-referenced with newer ones.
How do I know if I'm affected without a notification?
You won't always know, since not every breach is known or notified. Rather than trying to compile a list, adopt the stance that holds in both cases: one unique password per service and two-factor authentication on the accounts that matter. That makes the question far less decisive.

Official sources

This article is part of the Data and digital identity family. Last updated: 2026-09-03.