Technology

Data breaches stay hidden for 194 days on average — then the fraud starts

Susan Hill

Most data breaches reach individuals through a familiar envelope: a company letter, a cautious apology, and an offer of twelve months of free credit monitoring. What the letter does not describe is everything that happened before it was sent. Between the moment an attacker first enters a network and the moment you learn your information was involved, an average of 194 days passes. Understanding what occurs in those months and why they stay invisible is more useful than the monitoring service.

A data breach is any security incident in which protected information is accessed, copied, or extracted without authorization. This covers customer records, financial data, medical files, government identifiers, and employee information. The legal frameworks that govern them add another layer: under the European General Data Protection Regulation, organizations must notify authorities within 72 hours of becoming aware of a breach. The operative phrase is becoming aware and the gap between when a breach begins and when a company becomes aware of it is exactly where most of the damage accumulates.

Attackers find their way inside through a small number of reliable methods. In 2024, vulnerability exploitation targeting security flaws in software, particularly in the VPNs, firewalls, and remote access tools that organizations use as secure entry points accounted for 33 percent of breaches. Stolen or compromised credentials were responsible for 16 percent, and phishing emails for 14 percent. The MOVEit breach, which affected more than 62 million people across hundreds of organizations in a single campaign, illustrates how a single undisclosed vulnerability in widely trusted file-transfer software can be weaponized before the vendor has any knowledge of it. Supply chain attacks of this kind exploit the trust organizations place in third-party tools; once the software is compromised, every organization using it becomes a potential target simultaneously.

Getting inside a network is the beginning, not the objective. Once an attacker has initial access, the work of moving through the network begins: harvesting additional credentials, escalating privileges, and identifying the systems that hold the most valuable data. This phase, called lateral movement, takes time and is designed to stay invisible. The Change Healthcare breach, which ultimately affected an estimated 100 million Americans and cost more than 2.4 billion dollars in direct response costs, began with a single compromised credential for a remote access portal that lacked multi-factor authentication. Authentication gaps at the access layer, a missing second factor or an unpatched login interface, consistently prove more consequential than sophisticated technical exploits.

The 194-day detection average reflects a fundamental asymmetry: attackers work at their own pace inside a network they already control, while defenders search for signals the attacker is actively hiding. When organizations detect breaches through their own monitoring, the median dwell time drops sharply to 16 days, suggesting that internal detection capabilities, when they exist and function correctly, catch intrusions far earlier. Companies using real-time threat intelligence identified intrusions 28 days faster on average. After detection, containing a breach takes an additional 64 days on average, for a total lifecycle from intrusion to containment of around 258 days.

Before detection occurs, exfiltration has almost always already happened. Stolen data follows predictable routes through criminal markets. High-value records including Social Security numbers, medical identifiers, and financial account details are sold in bulk and resold to specialist buyers. The National Public Data breach compromised an estimated 2.9 billion records including Social Security numbers for individuals in the United States, United Kingdom, and Canada, with the dataset offered for sale at 3.5 million dollars before the company made a public statement. Automated tools now accelerate both the exploitation and monetization stages, meaning the window between a successful breach and the first criminal use of extracted data can be far shorter than the window between the breach and your notification.

The downstream effects of a breach are not immediate or uniform. Identity fraud losses in 2025 reached 27.3 billion dollars, but most fraudulent accounts opened with stolen identities appear months or years after the breach, when criminals judge the moment advantageous. Medical identity theft carries its own particular timeline: fraudulent insurance claims filed under a stolen identity can corrupt the medical history of the legitimate holder, affect future coverage, and take years to identify and correct. Awareness of how this pipeline works is among the most effective individual defenses available, not because awareness prevents breaches, but because early recognition of suspicious activity dramatically reduces eventual harm.

No security investment eliminates breach risk entirely. The organizations that suffered the largest and most consequential breaches in recent years were not negligent. They were operating complex systems at scale, and attackers found the gaps that inevitably exist in complex systems at scale. What security spending changes is detection speed and the scope of access an attacker can accumulate before being found. Breaches discovered within 200 days cost organizations an average of 1.39 million dollars less than those that remained undetected longer. The realistic goal is not imperviousness but responsiveness.

If you receive a data breach notification, three steps matter more than the credit monitoring offer. First, freeze your credit with the major bureaus: this prevents new accounts from being opened in your name, and unfreezing is straightforward when you need to apply for credit. Second, check the free tool Have I Been Pwned to see whether your email address appears in known breach datasets. Third, change any password shared between the breached service and other accounts, since credential stuffing relies on reused passwords. The GDPR notification you may receive from a European company represents the 72-hour window from when the organization became aware, not from when the breach began. The most useful detail in any notification letter is the specific type of data involved: knowing whether your medical records, financial credentials, or government identifiers were exposed determines how urgently to act.

Tags: , , , , ,

Discussion

There are 0 comments.