Skip to main content
Back to the wiki
Privacy & Compliance

What Is a Data Breach?

Last updated on August 3, 2026

A data breach is an incident in which protected data (personal information, credentials, financial records, trade secrets) is accessed, disclosed, or exfiltrated without authorization. The cause varies: external attackers exploiting a vulnerability, an employee mistake exposing a database to the public internet, a stolen device, or a third-party vendor compromised down the supply chain. What unifies the category legally is exposure rather than intent: GDPR's definition covers accidental as well as malicious incidents, because the harm to the people whose data is exposed does not depend on why it happened.

The obligations a breach triggers

For organizations handling EU personal data, GDPR imposes hard deadlines the moment a breach is confirmed: notification to the relevant supervisory authority within 72 hours where the breach poses a risk to individuals, and direct notification to affected people when the risk is high. Fines for inadequate security or delayed disclosure have run into the hundreds of millions of euros for major incidents. The data controller vs. processor distinction shapes who carries which obligation: a breach at a processor still triggers the controller's duty to notify, which is why data processing agreements typically mandate that processors report incidents to controllers immediately rather than on their own timeline.

Where breached data ends up

A breach is rarely the end of the story: it is usually the beginning of a longer one, playing out on the dark web and in the credential-stuffing economy it feeds. Login credentials get compiled into combo lists tested automatically against every login page reachable, exploiting how widely passwords are reused across services. Personal records feed identity theft and combine with other sources into fullz. Payment data feeds card-not-present fraud. The lag between breach and exploitation can run from hours to years, which is why a company's own breach history keeps mattering long after the headline fades: every subsequent login attempt against its site may be testing credentials the breach handed out.

Reducing breach risk and its aftershocks

Data minimization shrinks what a breach can expose in the first place: data never collected cannot leak. Encryption at rest and in transit, strict access controls, and prompt patching close the paths breaches typically travel. But because breaches elsewhere routinely become attacks here (a company's own systems can be perfectly secure and still face waves of credential-stuffing traffic sourced from someone else's breach), login and account-recovery endpoints need defenses that assume compromised credentials will arrive. Human verification such as CaptchaFox at those endpoints blocks the automated testing that turns a breach elsewhere into an account takeover here, which is the practical reality every company inherits from an industry-wide problem it did not cause.

About CaptchaFox

CaptchaFox is a GDPR-compliant solution based in Germany that protects websites and applications from automated abuse, such as bots and spam. Its distinctive, multi-layered approach utilises risk signals and cryptographic challenges to facilitate a robust verification process. CaptchaFox enables customers to be onboarded in a matter of minutes, requires no ongoing management and provides enterprises with long-lasting protection.

To learn more about CaptchaFox, talk to us or start integrating our solution with a free trial.

Related terms

What Is a Data Controller vs. a Data Processor?

Under the GDPR, the controller decides why and how personal data is processed while the processor acts on its instructions, a split that assigns liability.

Read more
What Is a Web Cookie?

A web cookie is a small piece of data a website stores in the browser to remember state, the mechanism behind sessions, preferences, and tracking.

Read more
What Is Data Minimization?

Data minimization is the GDPR principle that personal data must be limited to what a stated purpose actually requires: collect less, keep it shorter.

Read more
What Is Data Residency?

Data residency is the question of where data is physically stored and processed, and which country's laws and authorities can reach it as a result.

Read more

Fight bots and protect your users' data.

Don't give fraudsters and spammers a chance and protect your website with CaptchaFox today.

CaptchaFox protecting websites on desktop and mobile devices