The number of large IT data leaks has been increasing steadily for years and we have seen significant leaks even in the last few months. In April 2021, LinkedIn experienced a data leak which stole over 500 million users’ sensitive information, including email addresses, mobile phone numbers, workplace information, full names, account IDs, gender details and more. Facebook experienced a data leak that included the personal information of over 533 million users. Clubhouse also experienced a leak of users’ public information through a legitimate Application Programming Interface (API), exposing 1.3 million user records.
If your organization is a small-to-medium-sized business (SMB), don’t be misled because you only hear about attacks on global companies. SMBs are attacked, and attacked frequently. Private user data leaks is one big way your business systems can be breached.

Consequences when private users leak data
Many individuals have Facebook and LinkedIn accounts. If a user’s public information is leaked, it can have consequences for both the user and for the user’s employer.
Consequences to the private user
Information leaked from a social media outlet can be used to personalize a cyberattack (often through phishing) on specific users. The personal touch of these emails – using a name and a real reference – can be very convincing and easily trick a user. After the data leak from Facebook, there was an increase in spam SMS on published mobile numbers, which announced alleged parcel deliveries, but were aimed at stealing credit card data.
Stolen credit card data can be very profitable for cybercriminals. This data is often traded in underground forums. If a user’s passwords are stolen during an attack, the circle of attack can increase. With the password, attackers can log into an account and can send convincing spam messages to the user’s circle of friends to find new potential victims. User profiles are also misused to distribute malware or to stimulate other accounts with followers.
Consequences to your business
Criminal access to a private user’s account can create a number of problems for their employer. Unfortunately, many users still use the same password for different services. If one of these services suffers a data incident, the attacker can test the combination of user name and password on other services as well. This shotgun method is called credential stuffing. Attackers can often gain access to the company’s VPN, the Microsoft 365 environment, file sharing platforms, or other company resources. If the business email account falls into the wrong hands, the attacker can even reset passwords and gain intel from email archives.
With the shift towards remote work, personal life has become entwined with business life. Business laptops may be used for private surfing. Thus, malware infestation through a private social media network leads directly to a compromised business device. The next time the user logs into the company VPN, the malicious code can slip past the firewall into the company network.
If the private account of an employee is hacked, it can give the attacker the keys to the company. An attacker now has the needed data for CEO fraud phishing or business email compromise (BEC), where the attacker impersonates an executive or management person that works at the user’s company to steal money or more data.
Safe handling of passwords and authentication are essential. Strong and unique passwords are just the beginning. Multi-factor authentication (MFA), user entity behavior analytics (UEBA) or Zero Trust access can also minimize the consequences of stolen passwords. Since these are private employee accounts not under the control of the company, user education is an important part of the security campaign.
5 Tips to increase data resilience and protection for SMBs
To better protect sensitive or personal data from an attack, every SMB should follow these five tips:
- Use strong passwords. Every user should use strong and different passwords for every service, change these passwords frequently, and your business should use a password manager as a company-wide tool.
- Back up. Every SMB should follow the 3-2-1 backup rule, which stipulates that you keep your data in three places, across two media, with one backup stored offsite, such as in the cloud.
- Deploy a security solution. Every SMB must invest in a security solution that incorporates the newest technologies.
- Encrypt data. All data should be encrypted in transit and at rest, using enterprise-grade encryption.
- Patch software quickly. Patches should be applied as soon as possible after their release dates since many of these patches are developed to stop new threats. If you are using unsupported applications (e.g., no patches available), you should consider upgrading to a supported version to minimize the risk of an attack. Unpatched software is a prime opportunity for cybercriminals.
