A
data breach generally describes unauthorized access to data.
Data exposure often describes information made available where it should not be, such as a misconfigured storage location. Public reports may use these words differently. Neither label tells you, by itself, which of your records were involved or whether anyone used them.
A useful example
A company reports that names and email addresses were accessible, but passwords were not. Your response is different from a notice saying password hashes or payment details were taken. Even with only an email address exposed, convincing follow-up phishing can arrive.
Three questions to ask
Which data about you was affected? During what period? What has the provider reset, revoked or advised? Use its official notice and update your response as the investigation changes. The
FTC's breach-response guide organizes actions by exposed information. Our
breach checklist turns the notice into steps.
Practical distinction
An incident date and a discovery date are not necessarily the same. Look for the period when the data was accessible and when the provider actually contained it.