Does Anybody Care About Data Breaches?

Data breaches are now a routine part of life, but people affected still have almost no way to get a remedy. Lucy Purdon asks what real consequences for companies could look like.

Does Anybody Care About Data Breaches?
Photo by Rafael Garcin / Unsplash

By Lucy Purdon, also published in her newsletter The Prompt by Courage Everywhere

Many years ago at The Glass Room art exhibition in London, I leafed through thick white books, similar to old school telephone directories, containing every password stolen in a 2012 hack that exposed LinkedIn’s entire database. Artist Aram Bartholl alphabetized, printed and bound the list of 4.6 million passwords into 8 volumes to tell a story about data, inviting visitors to pick up the books and search for their own password. (Yes, mine was in there.)

4.6 million passwords seems a quaint number now due to the scale of today’s data breaches. It’s likely you yourself have recently received a message about a cybersecurity incident that has exposed your personal details held in a company’s system, and I’ll bet that wasn’t the first time- 4.4 million online accounts were reportedly exposed in the first 3 months of 2026 in the UK alone. For most people a data breach involves an email, telephone number or financial information like credit card details. Do you feel the consequences of such a breach are kind of left hanging, often downplayed and unclear? Do you feel confident the company in question has given you the information you need, beyond “soz, change your password”?

As Jamie Bartlett wrote in the excellent Substack post, “What actually happens to your stolen data?” your data goes on a “five stage, globe trotting, magical mystery tour”. He also wrote about how scams are becoming more sophisticated with the help of AI; those “phishing” scams are getting more convincing- and it all starts with a stolen email.

It gets worse of course. I have written before about the data breach from consumer genetic testing company 23andMe, resulting in the theft of millions of customer profiles including date of birth and ancestry information. Hackers advertised the data for sale and boasted it included around 1 million people of Ashkenazi Jewish descent, 100,000 of Chinese descent and “the wealthiest people living in the U.S and Western Europe”. Changing a password doesn’t touch the sides when your actual DNA is stolen.

In May this year, a cyberattack on the World Food Programme exposed the personal data of 600,000 Palestinian households in Gaza, including their names, ID numbers, and location. The weaponization of this information could prove deadly.

The UK’s National Cyber Security Centre describes data breaches as “a fact of modern life”. I don’t believe that means we accept the organizational carelessness, lack of security investment or the greed of collecting as much data as possible that so often leads to data breaches. Data breaches matter, they don’t seem to be taken seriously enough and we are often left in the dark with no meaningful remedy.

What actually is a data breach?

Organizations that collect and hold your personal data are bound by data protection law (where it exists) to keep it safe and secure. A data breach under the EU GDPR describes a situation where an organization has failed to keep it safe, leading to the destruction, loss, alteration, or - most relevant here- the unauthorized access to or disclosure of personal data.

Data breaches are increasingly the result of a cyber attack, but human error plays a major part. Just last month, the UK’s Metropolitan Police accidentally disclosed the emails of 140 people accusing the late owner of Harrods of sexual abuse by cc’ing them in an email update, rather than bcc’ing.

Under the EU (and UK) GDPR, organizations have the obligation to notify both the regulator and affected people of the breach, and provide remedy.

Tracking company responses

Ranking Digital Rights (RDR) evaluates the policies and practices of 26 of the world’s largest digital and telecommunications companies on how they uphold commitments to respect human rights such as freedom of expression and privacy, publishing an index of the findings. Since 2017, the index has included an indicator on company responses to data breaches as part of their methodology.

The indicator assesses three issues in line with data protection legislation: whether companies commit to notifying relevant authorities, whether they explain the process they will follow to notify people (data subjects) affected by a data breach, and whether they explain the steps they may take to address the impact of said breach.

Leandro Ucciferri, Deputy Director of RDR, has charted how the introduction of the GDPR in 2018 slowly made a difference to transparency around data breaches, but there are still major gaps in protections:

“In the 2017 RDR Index, only 3 of the 22 companies evaluated published some information about their policies to address data breaches (the companies were Telefónica, AT&T, and Vodafone). But we didn't see a notable improvement until 2019 [after the GDPR was adopted], when 10 of the 24 companies we evaluated published policies on this issue (five were digital platforms and five were telcos).

Fast forward to the latest assessments we published (2025 Big Tech Edition and 2026 Telco Giants Edition), 19 of the 26 companies we evaluated disclose some information about their data breach policies, but still none of them reached the full score for the three concrete questions in this indicator.

Notably, giants like Google, Amazon, and TikTok, do not publish explicit policies and commitments to notify authorities and users, nor explain the processes they may take to mitigate the harms caused by a breach.”

Remedy is so often the weakest point of rights-based legislation and the gaps are glaring when it comes to data protection. Compensation is a grey area as harm connected to a specific data breach is difficult to prove, even when the breaches are so egregious and the impacts potentially infinite. Leandro points out that accessing remedy under GDPR is a high bar, with a data subject needing to demonstrate in court that a damage existed, there was infringement of GDPR and the direct causality of the damage suffered and the GDPR violation.

This relies on individuals knowing what has happened to their data in order to exercise their rights, which is impossible when it comes to engaging with increasingly opaque systems and so little disclosure or transparency from companies.

Fine!

Failing to secure data can lead to headline-grabbing fines for companies, but usually only when financial details are involved, which appears to be assessed as the most tangible harm. In 2020, British Airways was fined £20 million by the Information Commissioner's Office (ICO), the UK’s data protection regulator, after users were directed to a fraudulent site where hackers harvested data of 400,000 customers including credit card information. Capita Pensions was fined £14 million by the ICO (negotiated down from £45 million mind you) for a hack that exposed 6.6 million people’s financial information.

But harm is not just financial and damage may not be immediate. Data hangs around.

How this plays out IRL: my Substack experience

If you have a Substack account you may, like me, have received an email from Substack CEO Chris Best on February 5th describing, in the most casual terms, that Substack was hacked and the email and phone number connected with your Substack account was “shared without your permission”.

“This sucks,” says Chris. It’s OK though!, “Importantly, credit card numbers, passwords, and financial information were not accessed.”

I have since been inundated with spam emails, including one claiming to be from the ShinyHunters criminal group, the notorious hackers behind some of the biggest data breaches of the past 5 years. Their email directly references the Substack data breach as the source of obtaining my information and tries to extort me by claiming they have videos of me watching pornography and “pleasuring myself” and will release these videos unless I pay $2000 in Bitcoin.

It’s not really ShinyHunters of course and this kind of “sextortion” scam is increasingly common.

Nonetheless, is Substack warning their users about the direct correlation between the breach and these attempted extortion attempts from a scary criminal gang, perhaps pointing to or supporting the work of fact checking groups exposing the scam?

No.

In response to my email complaint to Substack that my data has not been handled properly I am told that there is “no evidence that malware was installed via Substack”- the answer to a question I was not asking and a clear deflection.

Not satisfied with this response, I complained to the ICO, as is my right when there is a concern that an organization has not handled personal information properly. I am given a case number and informed I will receive a response within… 40 weeks!

Actually 6 weeks later, I received the decision that the ICO will not take the complaint further as Substack “has handled the matter in line with its data protection obligations by informing you of the data breach.”

So…that’s it. Notify those who bear the brunt and shift the onus onto the user to change passwords, monitor emails for phishing attempts and scams and put up with the torrent of spam emails, never being sure where our data is and what it is being used for, the next scam or trick around the corner.

Hardly reassuring.

A game of consequences, anyone?

I would opine that organizations often collect way more data than they need, because it’s valuable, so there is more data to breach. Databases are often poorly secured; procedures for dealing with data breaches are shockingly lax (the Substack breach reportedly went undetected for 4 months); companies often take ages to disclose and there are very few consequences (the recent ICO investigation into ACRO, a company that handles criminal records, is a jaw-dropping insight into abysmal cybersecurity failings). Leandro from RDR sums it up,

“My main concern at the moment is whether we've reached a point of apathy. Sure, some companies are receiving fines after being investigated by data protection authorities, but that's simply another cost of conducting business. And at the same time, the people affected may feel powerless, since they keep receiving news about new ways in which their data was exposed, likely multiple times in a given year. Even looking at the situation in a handful of European countries (Spain, France, Germany, the Netherlands, and Ireland), there were a combined total of more than 64000 data breach notifications to the national data protection authorities in 2025. The scale of this issue doesn't seem to be slowing down at all.”

As AI demands more data to train models and agentic AI requires more access to our personal data, what can we expect in the future?

“When it comes to the current conversation involving “AI” systems, as long as companies’ business models rely on extracting as much data as possible, we can expect them to face security incidents that end up exposing personal information.”

In the face of this we need stronger protections not less but intense lobbying from tech companies is steering our rights-based legislation in the wrong direction. The EU Digital Omnibus, an initiative to “streamline” EU digital legislation is perceived by many civil society actors as a potential dilution of safeguards established by the GDPR, the ePrivacy Directive, and the AI Act.

We need to bring ideas to the table on what we expect remedy to look like - not just fines but actual consequences and repercussions for companies to mitigate any potential harms, like being a victim of identity theft, targeted with scams, or worse. How about a company fined for a major breach also cannot collect any consumer data for a month? Companies must track the data breached and provide you with weekly updates about where it is and who has it? Then there might be more of an incentive to protect the data we often have no choice but to hand over.

Class action lawsuits may start to bite; over in Kenya, subscribers of the telecommunications company Safaricom won thousands of dollars in compensation over a large scale data-breach where the High Court found Safaricom failed to secure data and breached the constitutional right to privacy.

Let me know your experiences of data breaches, and your ideas about how companies should provide remedy!


Support the Internet Exchange

If you find our emails useful, consider becoming a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling.

Not ready for a long-term commitment? You can always leave us a tip.

Become A Paid Subscriber

HRPC.io is Back Online

The website for the Human Rights Protocol Considerations (HRPC) research group at the Internet Research Task Force is back online, and features a short documentary about how the technical design of the internet relates to human rights. The HRPC studies how internet standards and protocols enable, strengthen, or threaten human rights, especially freedom of expression and assembly. IX's Mallory Knodel chairs the group, and the site is a good place to start for anyone who wants to learn more and get involved with this work.

🚨
Stop press! Do you enjoy our links? Links are now available to paid subscribers only. Become a paid subscriber today.