Attack outcomes
Data breach
A data breach is an incident in which personal, financial or confidential information is accessed, copied or disclosed by someone not authorized to see it. Breaches can start with an identity failure, such as a stolen password, a missing second factor or excess access, and many trigger legal duties to notify the people affected.
How it works
An attacker gets in, often with valid credentials, finds where sensitive data is stored and copies it out. The organization may learn of it from its own monitoring, from a ransom note or from data appearing for sale. Breach notification laws then usually require it to tell affected people and regulators what was taken.
A real example
In May 2024 Senate testimony, UnitedHealth Group's CEO said criminals used compromised credentials to access a Change Healthcare Citrix remote-access portal that did not have multi-factor authentication, then moved laterally and exfiltrated data.
Source: Testimony of Andrew Witty, Chief Executive Officer, UnitedHealth Group, before the Senate Finance Committee — US Senate Committee on Finance, 2024-05-01
How to stop it
Require MFA on every externally reachable login, limit each identity's access to the data it needs, and monitor for large or unusual data transfers.
Related terms
Threat actors that use it
- Lazarus Group
Profile with government sources
Sources
- Testimony of Andrew Witty, Chief Executive Officer, UnitedHealth Group, before the Senate Finance Committee — US Senate Committee on Finance, 2024-05-01
Last reviewed Oct 2, 2026