5 Common Data Breach Scenarios And How to Avoid Them

29th August 2025

When you hear the words ‘data breach’, you might think of an expert team of hackers using cutting-edge technology or advanced social engineering techniques to gain access to personal data. However, breaches rarely occur solely due to hackers. More often, they come down to small mistakes, weak processes, or gaps in staff awareness. In fact, according to the Information Commissioner’s Office (ICO), the majority of UK data breaches reported in recent years were the result of human error.

Here are five common data breach scenarios and the steps your organisation can take to prevent them.

Emails Sent to the Wrong Recipient

Unsurprisingly, sending emails to the wrong recipients due to human error is at the top of our list. Often, members of staff will use the autocomplete function for speed, the result of which is to send sensitive information to the wrong “John”. This has been one of the most frequently reported incidents to the ICO. Sending an email to multiple recipients without using the ‘BCC’ function is also high on the ICO’s list and can expose personal data to potentially hundreds of people.

In 2017, the Independent Inquiry into Child Sexual Abuse accidentally disclosed the email addresses of possible abuse victims by failing to use blind copy (BCC). Sensitive information about abuse survivors was exposed to all recipients. This was a breach of the Security Principle under the old Data Protection Act, and the ICO fined them £200,000; however, the fine could now be in the millions. Source: BBC News 

You can avoid this by training team members to always double-check all email recipients before sending an email, especially when personal or sensitive data is attached. Always use the BCC function to protect the anonymity of all recipients when emailing multiple people, or send emails separately or use a mail-merge function if you are concerned about security. When sharing highly sensitive information within an organisation, consider using a document portal instead of email to avoid this scenario entirely. When training staff, use real examples and practical exercises to raise awareness of how easily emails can be mis-sent.

Lost or Stolen Devices

A laptop left on a train, a mobile phone or a briefcase stolen from a car, or a missing hard drive are all easy routes to a data breach. These devices could contain unencrypted files with client data, sensitive data and other personal information that could be accessed by whoever finds the device.

Glasgow City Council was fined £150,000 for the loss of two unencrypted laptops, as one of these contained the personal data of more than 20,000 people. Following an investigation by the ICO, it was discovered that a further 74 unencrypted laptops were also missing, 6 of which were known to be stolen. Source: BBC News

You can avoid this scenario by ensuring that all data stored on company laptops and mobile phones is encrypted,  and the devices themselves are protected with multifactor authentication when logging in. You can also enable mobile defence management systems (MDM), which will allow remote wiping, so if a device does go missing, all data can be removed from it remotely. When training staff, remind them that all laptops and computers should be locked if left unattended, even in the office. 

Weak Passwords and Phishing Attacks

Employees may use the same password across multiple accounts, so if one password is leaked, this grants access to multiple accounts or systems, potentially exposing personal data. A phishing email could trick an employee into handing over their passwords, leading to unauthorised access. 

In 2020, EasyJet announced that hackers had accessed the email addresses and travel details of around 9 million customers, with 2,200 also having credit card details stolen. The breach reportedly began with a phishing attack exploiting weak account protections. Source: BBC News

Prevent this from happening in your organisation by requiring long, unique passwords that are different for each system or account. A password manager can securely hold multiple passwords so that employees don’t have to remember them all. Multi-factor authentication (MFA) can add an extra layer of protection, requiring employees to verify their login using an authenticator or using a code sent to their email address or phone. When training employees, run a phishing simulation to test their awareness and provide feedback on existing security measures in a safe and controlled way. 

Unauthorised Access by Former Staff

If a former employee’s account is not deactivated upon their exit from the organisation, they could use their existing login information to access client files and other personal data months after their departure. They could use this to poach customers or even act maliciously to damage the reputation of their former employers.

Following a disciplinary hearing and a personal grudge against the company, a Morrisons employee copied and leaked payroll data of nearly 100,000 staff to a public website. He still had access to the data after leaving his role, and the incident led to the first data leak class action case in the UK, brought against Morrisons by the affected employees, and a lengthy court battle over liability. The Supreme Court eventually found that Morrisons was not vicariously liable for the data leak, although they could have avoided this scenario entirely by revoking the former employee’s access to their systems. Source: The Guardian

When an employee leaves an organisation, HR and IT must work together to immediately remove all system access on the employee’s last day. Perform regular audits to review user accounts at least quarterly to ensure there are no old accounts that could be used by former employees. Where possible, use SSO (single sign-on), as cloud-based systems are particularly vulnerable, as all former employees would need to gain access to company data through an internet browser. When providing data protection training, emphasise to managers the importance of notifying the IT department when any staff member leaves the organisation.

Data Left Unsecured

Unsecured data can easily lead to a serious data breach. Sensitive paper files left on a desk, or a database set to “public” by mistake, may end up being accessed by unauthorised parties.

Earlier in 2025, a member of the public found piles of papers scattered in the street that appeared to include sensitive military information, including soldiers’ ranks, emails, shift patterns and weapon issue details. Many of the documents were marked “official – sensitive”, which denotes that the information contained could lead to a “threat to life” if compromised. An investigation into this incident is currently underway at the time of writing (August 2025).  Source: BBC News

Implement a paperless workplace to prevent the loss or improper disposal of personal data through paperwork. If printed documents must be used, ensure that they are shredded using a cross-cut shredder before being thrown away. Carry out regular technical audits of databases and cloud storage to ensure they are secure and cannot be accessed by unauthorised users. Use case studies in staff workshops to show how simple oversights can lead to major reputational damage.

Regular training using practical examples can help staff understand not only what to do to prevent data breaches, but also why it matters. Regularly review your data protection policies to ensure they are practical and reflect how your organisation actually works. Test and improve policies by running internal audits, regular refresher training, and phishing simulations to keep all systems and processes resilient. Avoiding a data breach doesn’t mean buying the most expensive software – it’s about building a culture of awareness, responsibility and accountability at your organisation.

And just one final thought, a data breach not only refers to physical records, but verbal disclosure of personal or confidential information could also be a breach. Employees need to ensure that the person to whom data is being disclosed is authorised and that an accidental breach cannot occur, for example, holding a confidential conversation in a public space.

If you’d like some support strengthening your data protection practices, from staff training to internal audits and policy reviews, we are here to help. Get in touch with Griffin House Consultancy today to discuss how we can reduce your organisation’s risk of a data breach.

 

Author: Mike Martin LLM

Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details