Data Breach
A data breach is a security incident in which someone who is not authorized gains access to, exposes, or acquires confidential or personal information. In a payment context, this can involve cardholder data or other sensitive information being viewed, taken, or disclosed without permission. Responding to a breach typically involves steps such as notifying law enforcement and affected parties, depending on applicable laws and rules.
A data breach is a security incident resulting in the unauthorized access, exposure, disclosure, acquisition, or loss of confidential, private, protected, or sensitive information, compromising its confidentiality, integrity, or security. In payment security, the exposed data may include cardholder data (such as PAN, cardholder name, expiration date, and service code) and, if improperly retained, sensitive authentication data (such as full track data, CAV2/CVC2/CVV2/CID, or PIN blocks), the latter of which must not be stored after authorization even in encrypted form. Whether a specific event constitutes a reportable breach, and the required response and notification obligations, depend on the nature of the data involved and on applicable legal, regulatory, and card brand or network requirements, which vary by jurisdiction and change over time. The scope, containment, and forensic response for a suspected compromise are governed by incident response processes and by card brand rules rather than by any single fixed procedure.
Why it matters
A data breach in a payment environment can expose cardholder data such as the PAN, cardholder name, expiration date, and service code, and in cases of improper retention, sensitive authentication data such as full track data, CAV2/CVC2/CVV2/CID, or PIN blocks. Because sensitive authentication data must not be stored after authorization even in encrypted form, its presence in a breached environment often indicates a control failure that increases both the harm to affected parties and the exposure of the entity involved. The consequences of a breach extend beyond the technical loss of data to include obligations toward affected individuals, law enforcement, and card brands or networks.
Breaches matter because they compromise the confidentiality, integrity, or security of the information involved, and the response requirements are not uniform. Whether a specific event is a reportable breach, and what notification steps are required, depends on the nature of the data and on applicable legal, regulatory, and card brand or network rules that vary by jurisdiction and change over time. This variability means organizations cannot rely on a single fixed checklist; they must map the specific data exposed to the specific obligations that apply to them.
Because of these dependencies, timely and disciplined response is important. Guidance such as the FTC's recommends notifying law enforcement promptly, and reducing delay can help limit downstream harm such as identity theft. The actual scope of impact, however, depends on facts specific to each incident, and precise figures on cost or affected records vary by source, period, and methodology.
Who it's relevant to
Inside Data Breach
Common questions
Answers to the questions practitioners most commonly ask about Data Breach.