Data Breach Shows No Signs of Slowing Down

Despite growing investments in cybersecurity and stricter regulations, data breaches have surged across nearly every sector from 2022 through 2025. What’s most alarming? The fact that even high-profile attacks from previous years haven’t slowed the pace or severity of breaches in the years that followed.

For small and medium-sized businesses (SMBs), the key lesson is this: your size doesn’t make you invisible, and complacency is no longer an option.

In this article, we’ll examine some of the most impactful breaches from 2022 to 2025, the tactics behind them, and what SMBs can do now to mitigate the risk of becoming the next headline.


1. A Timeline of Escalation: Major Breaches from 2022–2025

2022: Alarming Patterns Begin to Surface

  • LastPass: One of the most shocking breaches involved a company that sells password management solutions. Attackers accessed customer vault backups containing encrypted and unencrypted data. The breach exposed just how vulnerable even cybersecurity vendors can be — and how sensitive personal data was left insufficiently protected.
  • Medibank (Australia): Hackers accessed sensitive health records of millions, including data on treatments, procedures, and diagnoses. The incident sparked intense global conversation on data ethics and breach disclosure standards.

2023: Supply Chains and Critical Infrastructure Targeted

  • MoveIt File Transfer Software: A zero-day exploit in a widely used secure file transfer tool allowed ransomware groups (notably CL0P) to breach over 600 organizations, including U.S. government agencies, healthcare providers, and financial institutions. The scale and impact made it one of the most far-reaching cyberattacks of the decade.
  • 23andMe: The genetic testing company suffered a breach where attackers used credential-stuffing to access millions of user profiles. The stolen data — which included ethnic ancestry and health markers — was later posted online and offered for sale, raising deep concerns about how personal genetics data is handled and stored.

These breaches set the stage for what became an even more aggressive and sophisticated set of attacks in 2024 and 2025.


2. Breaches Are Bigger, Bolder, and More Frequent

2024–2025 has seen a continuation — and escalation — of the threat landscape:

  • UnitedHealth Group’s Change Healthcare (Feb 2024): ALPHV/BlackCat ransomware group stole data and disrupted operations across thousands of pharmacies nationwide. A ransom of $22 million was reportedly paid.
  • Snowflake Data Breach (May–June 2024): Threat actors leveraged stolen credentials and exploited weak authentication to access sensitive data from over 165 Snowflake customers, including Ticketmaster and Santander Bank.
  • AT&T Data Leak (March 2024): Personal data from 73 million current and former customers — including SSNs and passcodes — appeared on the dark web, years after the data was likely first stolen.

Each incident underscores the uncomfortable truth: even if you’re not directly targeted, your partners, vendors, or tools might be — with consequences for your business.


3. How Attackers Are Getting In: Common Tactics

Across all these incidents, three key patterns emerge:

  • Stolen Credentials: Many breaches started with login credentials obtained via phishing, brute force, or third-party leaks.
  • Lack of Multi-Factor Authentication (MFA): Several compromised systems either lacked MFA entirely or used weak implementations.
  • Third-Party Exploits: As seen in the Snowflake and MoveIt breaches, attackers often enter through trusted vendors or SaaS tools.

For SMBs, these represent actionable gaps to address with urgency.


4. The Fallout: What Breaches Cost

The consequences of a breach extend far beyond immediate operational disruption:

  • Legal Exposure: The AT&T and 23andMe incidents triggered class-action lawsuits.
  • Reputational Damage: Customers affected by data breaches often lose trust — and may take their business elsewhere.
  • Regulatory Pressure: GDPR, HIPAA, FTC actions, and state-level laws like California’s CCPA are increasingly being enforced.

And while large companies may survive the hit, many SMBs don’t. The cost of remediation, lost revenue, and legal compliance can be catastrophic.


5. Insurance and Compliance: New Standards

As breaches grow in frequency and severity, insurers and regulators are demanding more:

  • Cyber Insurance: Policies now require stronger controls like endpoint protection, regular risk assessments, and proof of MFA deployment.
  • Vendor Due Diligence: If a vendor handles your customer data, regulators expect you to validate their security posture.
  • Incident Response Planning: Authorities increasingly expect that companies have detailed breach response plans and disclosure procedures.

Compliance is no longer just a checkbox — it’s a shield.


6. What SMBs Can Do: 6 Actionable Steps

1. Implement MFA Across All Systems

Especially for email, cloud apps, admin portals, and financial systems.

2. Reduce Your Data Footprint

Retain only the customer data you truly need — and encrypt what you store.

3. Audit Third-Party Vendors

Ask about their security controls, breach history, and data handling policies.

4. Train Employees Regularly

Human error remains the top cause of breaches. Invest in phishing simulations and security awareness programs.

5. Segment and Monitor Your Network

Limit lateral movement and install intrusion detection tools where feasible.

6. Prepare an Incident Response Plan

Make sure everyone on your team knows what to do in the first 48 hours of a suspected breach.


7. Final Thought: Complacency Is the Real Threat

From LastPass to UnitedHealth, the evidence is clear: cybersecurity threats are intensifying and evolving. The fact that global enterprises with vast resources have fallen victim should not cause despair — but it should inspire urgency.

For SMBs, being smaller means you must be smarter. You may not be able to stop every attack, but you can harden your defenses, limit damage, and prepare for what’s next.

Because in today’s environment, it’s not a matter of if a breach happens — it’s a matter of when, and how well you’re prepared to respond.