Data breach.
In plain English
A data breach happens when a company, agency, or vendor loses control of the personal records it holds and an outsider copies or views them. The stolen material can include names, addresses, Social Security numbers, account numbers, or login credentials. Breaches often start with a stolen employee password, an unpatched server, or a compromised supplier. The data is usually sold or traded long before anyone notices, which is why the harm can arrive months after the incident itself.
01Why it matters
You can freeze your credit files for free at each of the three nationwide credit bureaus, which blocks new accounts opened in your name, and a breach is a failure by the company holding the data, not by the person whose data was taken.
02The math, step by step
A retailer is breached and 2 million records leak. If a scammer opens even one account per 1,000 records, that is 2,000 fraudulent accounts from a single incident, spread across people who may never shop there again.
Illustrative example. The amounts here are hypothetical, chosen to show how the math works, not real quoted rates or figures.
03What this is NOT
A breach is the exposure. Identity theft is what someone does with the exposed data. Most breached records are never used against a specific person, and identity theft happens all the time without any breach at all, for example from a stolen wallet.
04Receipts
Every figure on this page is sourced to a primary document. Tap to open the original.
Plain-English answers from our glossary. Receipts included. Never advice.
Educational tool. Answers come only from ClearMoneySchool's published glossary and are not advice. Why we never give advice