What Is a Security Breach?
What Is a Security Breach?
A security breach is an incident where security measures are bypassed or defeated, allowing unauthorized access to systems, networks, or data. It is a broad term covering any breach of security defenses, of which a data breach (where data specifically is accessed or stolen) is one important type. This article explains what a security breach is, how breaches happen, and what to do, in plain terms.
What a Security Breach Is
A security breach, in plain terms:
A breach of security defenses: A security breach occurs when an attacker, or unauthorized party, bypasses or defeats security measures, gaining unauthorized access to systems, networks, accounts, or data.
Broad term: "Security breach" broadly covers any incident where security is compromised — from unauthorized system access to account takeover to data theft.
Related to data breach: A data breach (where data specifically is accessed, stolen, or exposed) is a type of security breach. A security breach can lead to a data breach, but also includes other compromises.
How Security Breaches Happen
Breaches occur through various means:
Exploiting vulnerabilities: Attackers exploit unpatched software vulnerabilities or weaknesses to gain access.
Stolen or weak credentials: Using stolen, weak, or reused credentials to access systems and accounts (often from prior breaches, via credential stuffing).
Phishing and social engineering: Tricking people into revealing credentials or access.
Malware: Using malware to gain access to systems and data.
Misconfigurations and weaknesses: Exploiting misconfigured systems or security weaknesses.
Insider threats: Misuse of access by insiders.
Types of Security Breaches
Breaches take various forms:
System/network intrusion: Unauthorized access to systems or networks.
Account compromise: Unauthorized access to accounts (an account-level security breach).
Data breach: Access to or theft of data (a data-focused security breach).
Malware infection: Compromise of systems by malware.
Each represents security being defeated in some way.
What a Security Breach Means for You
Breaches can affect you directly or indirectly:
Organizational breaches: If an organization holding your data has a security breach, your data may be exposed, with risks of fraud, identity theft, and misuse.
Your own account/device breaches: If your own account or device is breached (a personal security breach), the attacker may access your information and accounts.
Risk of misuse: Exposed credentials and data can be used for fraud, phishing, credential stuffing, and other misuse.
What to Do About Security Breaches
Your response depends on the type:
For breaches of your accounts/devices: Regain control, change passwords, enable 2FA, remove the attacker's access, and secure affected systems (see recovering a compromised account, and responding to a hacked device).
For organizational breaches affecting you: Change affected passwords (and anywhere reused), enable 2FA, and monitor for misuse.
Use breach notification tools: Learn if your information appears in known breaches.
Reduce future risk: Use strong, unique passwords, 2FA, updated software, and good security habits to reduce your risk of breaches.
How to Reduce Your Risk
Prevention reduces breach risk:
Strong, unique passwords and 2FA: Prevent credential-based breaches of your accounts.
Keep software updated: Patch the vulnerabilities breaches exploit.
Beware phishing: Avoid the social engineering behind many breaches.
Prevent malware: Avoid the malware that causes breaches.
Limit your exposure: Reduce the data and accounts that could be exposed.
Frequently Asked Questions
What is a security breach?
A security breach is an incident where security measures are bypassed or defeated, allowing unauthorized access to systems, networks, accounts, or data. It is a broad term covering any breach of security defenses — from unauthorized system access to account takeover to data theft. Security breaches happen through exploiting vulnerabilities, using stolen or weak credentials, phishing and social engineering, malware, misconfigurations, and insider threats. A data breach (where data specifically is accessed or stolen) is one important type of security breach. In short, a security breach is any incident where security is compromised and unauthorized access is gained.
What is the difference between a security breach and a data breach?
A security breach is the broader term — any incident where security measures are bypassed or defeated, allowing unauthorized access to systems, networks, accounts, or data. A data breach is a specific type of security breach where data in particular is accessed, stolen, or exposed. So all data breaches are security breaches, but not all security breaches are data breaches — a security breach could involve unauthorized system access or account takeover without (or before) data being stolen. A security breach can lead to a data breach. In practice, the terms are related, with data breach focusing specifically on the exposure of data.
What should I do if there's a security breach affecting me?
It depends on the type. If your own account or device is breached, regain control, change your passwords, enable 2FA, remove the attacker's access (sign out sessions, fix settings), and secure affected systems. If an organization holding your data has a breach affecting you, change affected passwords (and anywhere you reused them), enable 2FA on affected and important accounts, and monitor for fraud and misuse. Use breach notification tools to learn if your information appears in known breaches. To reduce future risk, use strong, unique passwords and 2FA, keep software updated, beware phishing, prevent malware, and limit your exposure.
Conclusion
A security breach is an incident where security measures are bypassed or defeated, allowing unauthorized access to systems, networks, accounts, or data — a broad term covering any breach of security defenses, of which a data breach (where data specifically is accessed or stolen) is one important type. Security breaches happen through exploiting vulnerabilities, using stolen or weak credentials, phishing and social engineering, malware, misconfigurations, and insider threats, and take forms like system intrusion, account compromise, data breaches, and malware infection. A breach can affect you through organizations holding your data (exposing your data) or through your own accounts or devices being breached, with risks of fraud, identity theft, and misuse. Respond based on the type: for breaches of your own accounts or devices, regain control and secure them; for organizational breaches, change affected passwords, enable 2FA, and monitor for misuse; and use breach notification tools. Reduce your risk with strong, unique passwords and 2FA, updated software, phishing awareness, malware prevention, and limited exposure. Understanding what a security breach is — and how it relates to data breaches — helps you respond appropriately and reduce your risk.