Insights Article: The Identity Risk Series – The Hidden Data Breach

For Business Owners, CIOs & CISOs [5-minute read]
The Hidden Data Breach
They Were Inside for 4 Years. How Long Have They Been Inside Yours?
“A data breach is not a moment. It is a slow, silent catastrophe, one that typically begins with a single compromised account and ends with your customers’ most sensitive data for sale on the dark web, long after you ever knew anyone was there.”
In 2014, attackers quietly slipped into the Starwood Hotel reservation system using stolen credentials. They installed tools to capture passwords, move laterally, and stay hidden. Then they waited. And watched. And collected data: passport numbers, credit card details, travel records, and personal information on hundreds of millions of guests.
Nobody knew.
Marriott acquired Starwood in 2016 and inherited the breach along with the brand. The attackers were still inside. Still collecting. It was not until September 2018, four years after the initial compromise, that an internal security tool finally flagged something suspicious. By then, the records of up to 383 million guests had been compromised: passport numbers, credit card details, home addresses, and decades of travel history.
Four years. One set of stolen credentials. The guest data of a population larger than the United States.
The average organization takes 241 days to detect and contain a data breach.
That is eight months of an attacker moving freely through your systems, reading your files, copying your data, and mapping your infrastructure, while your security team sees nothing out of the ordinary. Take a free risk assessment to uncover data breach vulnerabilities before attackers do.
The Scope of What Is at Stake
A data breach is categorically different from any other business crisis. There is no product recall, no service outage, no operational failure that compares. The damage is permanent to your customers, to your reputation, and to your organization’s financial position. You cannot un-expose a passport number. You cannot un-sell a database of health records. Once that data is out, it is out forever.
$10.22M
Average total cost of a data breach for U.S. companies in 2025, an all-time record high, per IBM
$4.88M
Global average cost of a data breach in 2024, a 10% jump from the prior year, the largest single-year increase since the pandemic.
#1
Stolen or compromised credentials are the single most common initial attack vector in data breaches worldwide
241 days
Average time to identify and contain a breach, meaning attackers have months of undetected access before anyone responds
And those figures reflect only the costs organizations can measure: forensics, legal fees, notification, regulatory fines, and credit monitoring. They do not capture the customers who quietly close their accounts, the enterprise contracts that are not renewed, or the reputational damage that takes years to surface in the numbers.
One Account. Everything Exposed.
The pattern in nearly every major data breach is the same. Attackers do not bulldoze through your defenses. They find one account — a forgotten vendor login, an unrotated service credential, a remote access portal missing a single security control — and they walk in. From there, it is a matter of time and patience.
“Attackers are not looking for a vulnerability in your firewall. They are looking for an account with enough access to make the breach worth their while.”
Privileged accounts, those with access to databases, file transfer systems, cloud storage, identity platforms, or administrative infrastructure, are the prize. The greater the access, the greater the volume of data an attacker can reach. And the greater the volume of data, the greater the leverage: to sell on criminal markets, use in targeted fraud, or weaponize in regulatory complaints against your organization.
This is not a worst-case scenario. It is the documented reality of the most significant data breaches in recent history, across every industry, every organization size, every geography.
What the Breaches Tell Us
The Attacker Is Already Inside. You Just Don’t Know It Yet.
Read that again: 241 days. That is the average time between an attacker’s initial access and an organization’s detection and containment of the breach. For eight months, they can read your files, map your systems, identify sensitive data, and determine what it is worth on the criminal market.
The Marriott breach remained undetected for four years. Target took three weeks to confirm its breach, despite security alerts from the start. The Snowflake attacks relied on credentials that, in some cases, had been stolen years earlier.
The uncomfortable truth is that detecting a breach, even quickly, is not a strategy. By the time you know an attacker was inside, the data is often already gone. The only effective defense is preventing attackers from reaching high-value data in the first place by tightly controlling privileged access, eliminating unnecessary standing privileges, and monitoring for suspicious activity in real time.
When organizations honestly assess their privileged access environment, they often find former employees whose accounts remain active, vendors whose access was never revoked, service accounts with unexplained administrator rights, and credentials that have not been rotated in years.
These are the open doors. And they are exactly where sophisticated attackers begin.
Do You Know Your Blast Radius?
One vendor account, one unprotected portal or one unmonitored credential can expose millions of records. Our Ransomware & Data Breach Gap Analysis identifies the privileged access exposures most likely to result in a breach, and quantifies the risk your organization is carrying right now. Most organizations are surprised by what they find.
