4 Major Data Breaches of 2023 and What Small Businesses Can Learn

Written by

in

By J. Mesa

March 2023 was a rough month for cybersecurity. A financial company, a pharmacy services provider, a phone carrier, and a school district all disclosed breaches within weeks of each other. I covered them in our April 2023 Cyber Bytes.

The details differ. The lessons repeat, and they apply to a business of any size.

What happened at Latitude Financial?

Latitude Financial, an Australian consumer lender, disclosed a breach that reached about 14 million customer records. The stolen data included driver’s license numbers, passport numbers, and financial statements.

The lesson: keep less data. Many of the records belonged to past customers and applicants. Data you no longer need is risk with no benefit.

  • Set a retention period for each type of record
  • Delete or destroy records when the period ends
  • Collect ID documents only when the law requires it

What happened at PharMerica?

PharMerica, a large US pharmacy services provider, suffered a ransomware attack. The attackers took personal information on nearly 6 million people, including names, addresses, Social Security numbers, and health data.

The lesson: ransomware is also data theft. Attackers steal first and encrypt second. Healthcare organizations of every size, including small clinics, hold the kind of data they want.

  • Patch systems, and start with those that face the internet
  • Keep an offline backup and test it
  • Encrypt sensitive records
  • Limit each account to the data its user needs

What happened at T-Mobile?

T-Mobile started 2023 by disclosing a breach that affected about 37 million customer accounts. In the spring it disclosed a second, smaller incident that affected 836 customers and exposed account PINs and personal details.

The lesson: one fix is not the end. A company that has been breached once stays a target. Security needs steady attention, with regular reviews and monitoring.

  • Review access and security settings on a schedule
  • Monitor for unusual activity on customer accounts
  • Treat every incident as a reason to look for related gaps

What happened at Minneapolis Public Schools?

A cyberattack disrupted the district’s computer systems for days. The attackers later published student and employee data online.

The lesson: attackers go where defenses are thin. Schools, local governments, and nonprofits hold sensitive records and run on tight budgets. The same is true of many small businesses.

  • Know what sensitive data you hold and where
  • Have a response plan before you need one
  • Decide in advance how you will communicate with the people affected

Were small businesses hit too?

Yes. Small business breaches seldom make national news, and reports from the same period describe many of them. Most involved phishing or ransomware, and they exposed financial data, customer information, and internal documents.

A small company faces the same attackers with fewer resources. It also has one advantage: fewer systems and fewer people make the basics easier to get right.

What do these breaches have in common?

  • Valuable data in one place. Each victim held large volumes of personal information.
  • A gap in the basics. Access controls, patching, and monitoring matter more than advanced tools.
  • Costs beyond the attack. Notification, legal work, and lost trust followed each one.

How do breaches like these affect me as a customer?

If your data was in one of these breaches:

  1. Read the notice the company sent and accept any free credit monitoring.
  2. Place a free credit freeze with Equifax, Experian, and TransUnion.
  3. Change your password and PIN on the affected account, and anywhere you reused them.
  4. Watch for phishing that mentions the breach. Criminals use stolen details to look legitimate.

What should a small business do now?

  1. Invest in employee training. Teach staff to recognize and avoid phishing.
  2. Use strong passwords and multi-factor authentication. Make it harder for attackers to log in.
  3. Back up your data on a schedule. Have a tested plan to restore it after an attack.
  4. Reduce what you store. Delete records you no longer need.
  5. Consider outside help. A security firm can find gaps you don’t see.

How much does a breach cost a small business?

The bill has several parts: recovery work, legal advice, notification, lost sales during downtime, and customers who leave. Businesses that hold regulated data can also face fines. For many small companies, the downtime alone threatens the business.

Does cyber insurance help?

It can. A policy can pay for forensic investigation, legal help, notification, and business interruption. Insurers expect controls such as multi-factor authentication and backups, and they ask about them on the application. Insurance works alongside good security. It does not replace it.

How do I prepare before a breach happens?

  • Write a one-page incident response plan with names and phone numbers
  • Keep a printed copy
  • Know your notification duties under state law and any industry rules
  • Run a short tabletop exercise once a year: walk through a pretend breach and see where the plan falls short

How can I tell if a breach notice is real?

Scammers send fake breach notices to steal more information. A real notice does not ask you to click a link and enter your password or Social Security number. If you receive one, go to the company’s website by typing its address yourself, or call a number you already have, and confirm the notice there.

Which industries do attackers target most?

Any industry that holds personal or financial data draws attention. Healthcare, finance, education, retail, and professional services such as law and accounting appear in breach reports year after year. Attackers follow two things: data they can sell and organizations that can’t afford downtime. If your business fits either description, plan as though you are on the list.

How long do I have to notify people after a breach?

It depends on the law that applies. US state laws set their own deadlines, and many call for notice without unreasonable delay. Rules for health and financial data add their own timelines. Learn your deadlines now, and keep your attorney’s number in your response plan.

Your next step

Organizations must keep adapting their defenses to protect their money, their reputation, and the people who trust them. If you want to know how your business would hold up, Cerberus Cybersecurity can help with training, policy, and risk assessments. Visit our contact page to get in touch.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *