Cover: $500 median loss that data breach victims reported; 32% said the breach cost them nothing
|

Data Breaches: What the Evidence Shows

Key takeaways · 10 min read

  • About a quarter of US adults recalled a breach notice in a single year; most people have been in several breaches.
  • Most victims report little or no loss, but just under 6% reported costs of $10,000 or more.
  • Breach victims are more likely to suffer identity crime, though proving that a specific breach caused it is hard.
  • Notification laws have a modest or uncertain effect, and the letters are often hard to act on.

The letter usually arrives weeks or months after the event. A company you may barely remember dealing with regrets to inform you that an unauthorised party may have accessed some of your information. It offers a year of free credit monitoring, a phone number and an apology. Then, for most people, nothing seems to happen.

Data breaches have become so common that they barely make the news unless the numbers are enormous. In 2024, a ransomware attack on Change Healthcare, a US company that processes medical claims, exposed the health and personal information of about 190 million people. In 2017, the Equifax breach exposed the Social Security numbers of about 147 million Americans. Most adults in rich countries have been in several breaches, often without knowing it.

What does it actually mean for the person whose data leaked? This article looks at the research on how often breach victims suffer fraud, how much it costs them, whether breach notification laws reduce harm, and which of the protective steps offered in those letters make a real difference.

How many people are affected

The most detailed survey of breach victims comes from the RAND Corporation. In 2015, Lillian Ablon, Paul Heaton, Diana Lavery and Sasha Romanosky surveyed 2,038 US adults from a nationally representative panel. Twenty-six percent recalled receiving a breach notification in the previous 12 months, which the authors estimated at 64 million adults. More than half of those had received two or more. Forty-four percent had received a notice at some point in their lives.

Many people are affected without being told. In 2021, Peter Mayer and colleagues used the database of the Have I Been Pwned service to show 413 participants the breaches that had exposed their own email addresses. Seventy-three percent had been in at least one breach, with an average of 5.36. Participants had not known about 74% of the breaches they were shown. Many blamed their own habits, and only 14% correctly identified the cause as the breached organisations or the attackers.

How common breach notices are

Nationally representative survey of 2,038 US adults, 2015.

26%recalled a breach notice in the past 12 months, about 64 million adults
62%accepted free credit monitoring when it was offered

Ablon L, Heaton P, Lavery DC, Romanosky S, Consumer Attitudes Toward Data Breach Notifications and Loss of Personal Information, RAND Corporation, 2016.

A pointillist illustration: a server room corridor with tall black racks and rows of small green and blue lights, one rack door open with an amber glow inside.
A server room. Most breaches expose data held by companies people rarely think about.

What it costs the people affected

Most breach victims report little or no loss. In the RAND survey, 32% of those who had received a notice said the breach had cost them nothing. For those who put a value on it, including the time and inconvenience, the median was $500.

The type of data matters. The median rose to $1,000 when health information or a Social Security number was involved, and to $864 for other financial details. Just under 6% said the breach had cost them $10,000 or more, which the authors estimated at about 6 million US adults. That pattern, with most people losing little and a minority losing a great deal, is typical of fraud.

Reported cost of a data breach

Median value that victims put on the loss and inconvenience, by type of data exposed.

Data exposedMedian cost
All breaches, among those reporting a loss$500
Other financial information$864
Health information$1,000
Social Security number$1,000

Ablon L et al, RAND Corporation, 2016. 32% reported no loss at all; just under 6% reported $10,000 or more.

Money is not the whole story. Cassandra Cross and Thomas Holt surveyed 552 Australian breach victims and reported in 2025 that breaches were also linked to emotional distress, health effects and strain on relationships, especially when the data lost was sensitive and when victims had to spend a long time repairing the damage. Health records and identity numbers are especially troublesome because they cannot be changed the way a card number can.

The Change Healthcare case

The 2024 attack on Change Healthcare shows how far one breach can reach. The company, part of UnitedHealth Group, handles billions of medical claims a year, so almost nobody affected had ever heard of it. In February 2024, a ransomware group got in through a remote-access portal that, the company’s chief executive later told the US Congress, was not protected by multifactor authentication. Pharmacies and hospitals across the country struggled to process payments for weeks, and UnitedHealth said it paid a ransom of $22 million.

The stolen data included names, addresses, insurance details, diagnoses and treatments, and for some people Social Security numbers. It became the largest health data breach ever reported to the US Department of Health and Human Services. For the people affected, it combines the two kinds of data that are hardest to replace: medical history and identity numbers.

Does a breach lead to identity theft?

The link between a specific breach and a later fraud is hard to prove. Stolen data is often sold, combined with other leaks and used months or years later. Most people who suffer identity theft never find out where the thief got their details.

Surveys can show an association. The Australian Institute of Criminology, in a 2022 report by Anthony Morgan and Isabella Voce, found that 9.3% of Australian computer users had been notified of a data breach in the previous 12 months. Nearly a third of them, 28.0%, had also been a victim of identity crime in the same period. Those notified of a breach were 34% more likely than other respondents to have been victims of identity crime, and also more likely to have suffered online scams and ransomware.

A pointillist illustration: an opened envelope on a doormat with a folded letter half out of it, a small amber stamp in the corner.
A breach notice on the doormat. Most arrive weeks or months after the event.

That is an association, not proof that the breach caused the crime. People who are online more, shop more and hold more accounts are more likely both to be in breaches and to be targeted by fraudsters. But it fits what investigators see: breached data is raw material. Email addresses and passwords fuel account takeovers, and names, addresses and dates of birth make phishing messages and phone scams far more convincing.

For scale, the US Bureau of Justice Statistics estimates that about 9% of US residents aged 16 or older, roughly 24 million people, experienced some form of identity theft in 2021. The most common kind by far was misuse of an existing credit card or bank account, which a card replacement usually fixes. Opening new accounts in someone else’s name, the kind of fraud that breach letters warn about most, is much less common.

Breach notices and identity crime in Australia

National survey of computer users, previous 12 months.

9.3%of respondents were notified of a data breach
28.0%of those notified were also victims of identity crime

Morgan A, Voce I, Data breaches and cybercrime victimisation, Australian Institute of Criminology, 2022. Notified respondents were 34% more likely to be identity crime victims.

Do breach notification laws help?

Every US state now requires organisations to tell people when their personal information has been exposed, and the European Union’s General Data Protection Regulation requires notice to regulators within 72 hours and to individuals when the risk to them is high. The idea is that notice lets people protect themselves and shames companies into better security.

The best-known study found a modest benefit. Sasha Romanosky, Rahul Telang and Alessandro Acquisti used Federal Trade Commission complaint data from 2002 to 2009 and estimated, in the Journal of Policy Analysis and Management in 2011, that adopting a disclosure law reduced identity theft caused by data breaches by 6.1% on average.

A later analysis was less encouraging. Brad Greenwood and Paul Vaaler, presenting at the Academy of Management in 2022, examined state laws enacted from 2003 to 2018 and found no significant change in the number or size of breaches after a law was passed, and no significant long-term change in identity theft and fraud. This was a conference paper rather than a full peer-reviewed article, so it is weaker evidence, but it matches the RAND finding that only 11% of people stopped dealing with a company after it was breached. If customers do not leave, the shaming effect is limited.

Research on breach notification

What the studies measured and found.

StudyDataFinding
Romanosky and colleagues, 2011US identity theft complaints, 2002–2009Laws cut breach-related identity theft 6.1%
Greenwood and Vaaler, 2022State laws, 2003–2018No significant change (conference paper)
Zou and colleagues, 2019161 notification lettersLong, hard to read, risks downplayed
Ablon and colleagues, 20162,038 US adults11% stopped dealing with the company

Romanosky S, Telang R, Acquisti A, J Policy Anal Manage, 2011; Greenwood BN, Vaaler PM, Academy of Management Proceedings, 2022; Zou Y et al, CHI, 2019; Ablon L et al, RAND, 2016.

Why the letters do not work better

Part of the problem is the letters themselves. In 2019, Yixin Zou and colleagues at the University of Michigan analysed 161 breach notifications. They found that the letters were long and required advanced reading skills, that many companies downplayed or obscured the chance that the reader had been affected, and that possible actions were buried in paragraphs with little guidance on which mattered most. The title of their paper quoted a phrase they saw repeatedly: you ‘might’ be affected.

Even people who read the letters often do nothing. After the 2017 Equifax breach, Zou and colleagues interviewed consumers and found that few knew whether they had been affected and fewer took action. The reasons were cost and effort, optimism that it would happen to someone else, and a tendency to wait until harm actually appeared. In the Mayer study, many participants intended to act, but a follow-up showed that most did not.

The picture is not entirely bleak. When a 2012 breach at the South Carolina Department of Revenue exposed millions of tax records, Vyacheslav Mikhed and Michael Vogan at the Federal Reserve Bank of Philadelphia found that a remarkably large share of people who were directly affected signed up for fraud protection immediately. People responded to clear evidence of their own exposure, not to general news about breaches.

How much people know about their own breaches

413 people shown the breaches that had exposed their own email addresses.

73%had been in at least one breach, 5.36 on average
74%of those breaches were unknown to them

Mayer P, Zou Y, Schaub F, Aviv AJ, USENIX Security Symposium, 2021; Mayer P et al, ACM Transactions on Computer-Human Interaction, 2023.

A pointillist illustration: a kitchen table at night with a laptop, a paper bank statement and a pen, a small amber reading lamp lighting the page.
Checking a statement. The most common fraud after a breach uses an account you already have.

What actually protects you

Because most harm comes from a few types of data, it helps to match the response to what was lost. If a password was exposed, change it everywhere you used it, and turn on the strongest sign-in method available. Reused passwords are what turn one breach into many account takeovers. If a card number was exposed, ask for a new card and watch the statements.

If an identity number, such as a US Social Security number, was exposed, a credit freeze is the strongest single step, and it is free by law in the United States. It stops new credit being opened in your name, although, as we explained in our article on credit freezes, it does nothing about misuse of the accounts you already have. Free credit monitoring, which the RAND survey found 62% of people accept, tells you after the event rather than preventing it.

Finally, expect better-targeted scams. After a breach, messages and calls that quote your real name, address, bank or recent purchase are more likely. The breach gives criminals the details that make a lie believable. Treat any unexpected request for a code, a password or a payment as a reason to hang up and call back on a number you already know.

Questions people ask

What should I do after a data breach?

Change any exposed password and wherever you reused it, turn on strong sign-in, watch your statements, and freeze your credit if an identity number was exposed.

Will a data breach lead to identity theft?

For most people, no measurable loss follows. But breach victims are more likely to suffer identity crime; one Australian survey found them 34% more likely.

How much does a data breach cost victims?

In a RAND survey, 32% reported no loss and the median among the rest was $500. Just under 6% reported $10,000 or more.

Is free credit monitoring worth it?

It can alert you to new accounts, but it does not prevent them. A credit freeze blocks new credit and is free in the US.

Do breach notification laws reduce harm?

One study found a 6.1% drop in breach-related identity theft. A later analysis found no significant long-term effect.

The short version

  • About a quarter of US adults recalled a breach notice in a single year; most people have been in several breaches.
  • Most victims report little or no loss, but just under 6% reported costs of $10,000 or more.
  • Breach victims are more likely to suffer identity crime, though proving that a specific breach caused it is hard.
  • Notification laws have a modest or uncertain effect, and the letters are often hard to act on.
  • Changing reused passwords and freezing credit do more than monitoring after the event.

This article summarises published research on data breaches and their effects on individuals. It is not legal or financial advice. If you think you are a victim of identity theft, contact your bank and report it to the relevant authority in your country.

Further reading. Ablon and colleagues, Consumer Attitudes Toward Data Breach Notifications and Loss of Personal Information, RAND, 2016, is free to read. Zou and colleagues, ‘You “Might” Be Affected’, CHI 2019, looks closely at the letters themselves.

Three books
  • Breached!, Daniel J. Solove and Woodrow Hartzog (2022). Two law professors on why data security law keeps failing and how it could protect people better.
  • Means of Control, Byron Tau (2024). A journalist on how personal data from phones and apps flows to brokers and governments.
  • Privacy Is Power, Carissa Véliz (2020). A philosopher on why personal data matters and what individuals can do about it.

Sources

  1. Ablon L, Heaton P, Lavery DC, Romanosky S. Consumer Attitudes Toward Data Breach Notifications and Loss of Personal Information. RAND Corporation, 2016. doi:10.7249/RR1187.
  2. Mayer P, Zou Y, Schaub F, Aviv AJ. ‘Now I’m a bit angry:’ individuals’ awareness, perception, and responses to data breaches that affected them. 30th USENIX Security Symposium, 2021.
  3. Mayer P, Zou Y, Lowens BM, and colleagues. Awareness, intention, (in)action: individuals’ reactions to data breaches. ACM Transactions on Computer-Human Interaction, 2023;30(5):1–53. doi:10.1145/3589958.
  4. Morgan A, Voce I. Data Breaches and Cybercrime Victimisation. Statistical Bulletin 37, Australian Institute of Criminology, 2022. doi:10.52922/sb78832.
  5. Cross C, Holt TJ. Beyond fraud and identity theft: assessing the impact of data breaches on individual victims. Journal of Crime and Justice, 2025. doi:10.1080/0735648X.2025.2535007.
  6. Romanosky S, Telang R, Acquisti A. Do data breach disclosure laws reduce identity theft? Journal of Policy Analysis and Management, 2011;30(2):256–286. doi:10.1002/pam.20567.
  7. Greenwood BN, Vaaler PM. Do US state breach notification laws reduce firm data breaches? Academy of Management Proceedings, 2022;2022(1):11493 (conference abstract). doi:10.5465/AMBPP.2022.11493abstract.
  8. Zou Y, Danino S, Sun K, Schaub F. You ‘might’ be affected: an empirical analysis of readability and usability issues in data breach notifications. Proceedings of the 2019 CHI Conference on Human Factors in Computing Systems, 1–14. doi:10.1145/3290605.3300424.
  9. Zou Y, Mhaidli AH, McCall A, Schaub F. ‘I’ve got nothing to lose’: consumers’ risk perceptions and protective actions after the Equifax data breach. Fourteenth Symposium on Usable Privacy and Security (SOUPS), 2018.
  10. Mikhed V, Vogan M. Out of sight, out of mind: consumer reaction to news on data breaches and identity theft. Federal Reserve Bank of Philadelphia Working Paper 15-42, 2015. doi:10.21799/frbp.wp.2015.42.
  11. Harrell E, Thompson A. Victims of Identity Theft, 2021. US Bureau of Justice Statistics, 2023.
  12. US Department of Health and Human Services, Office for Civil Rights. Breach portal and Change Healthcare cybersecurity incident updates, 2024–2025.

Similar Posts