Why Breach Count Tells Only Half the Story
22 June 2026BREACHAWARE HQ
A total of 10 breach events were found and analysed resulting in 2,472,370 exposed accounts containing a total of 33 different data types of personal datum. The breaches found publicly and freely available included Capifrance, Chrysler, University of Nottingham, BCD Travel and BinDawood Holding. Sign in to view the full
library of breach events which includes, where available, reference articles relating to
each breach.
Categories of Personal Data Discovered
Sociodemographic, Academic, Contact, Finance, National Identifiers, Commerce, Audio and Visual, Career, Unstructured, Geolocation, Digital Behaviour, Technology.
The signal this week
The ten breach events analysed this week contained 2,472,370 exposed accounts and 33 distinct types of personal data. A count of ten events may appear straightforward, but event count alone says little about the complexity of the underlying exposure. The selected breaches span property, automotive, higher education, corporate travel and retail, sectors with very different relationships, operating models and data requirements.For a defensive team, the work created by an exposure is influenced by the types of data involved, the people and services represented, and whether those relationships remain active. A single event containing several connected identifiers may require more investigation than multiple events containing only limited or historical records.
What the selected breaches tell us
The selected breaches represent organisations operating through a mixture of physical locations, digital services and distributed networks:- Capifrance is a French network of independent real-estate advisers.
- Chrysler is an automotive brand within the Stellantis group.
- The University of Nottingham is a higher-education institution with campuses in the UK, China and Malaysia.
- BCD Travel provides corporate travel, meeting, event and travel-consulting services.
- BinDawood Holding is a Saudi retail group operating supermarkets, hypermarkets, express stores and online retail services.
The BreachAware team has recorded and reviewed the provenance of this material. The descriptions shared here are intentionally limited, providing useful context without publishing source locations, detailed contents or information that could encourage misuse.
The variety of organisations is significant because each maintains different relationships. These may include customers, students, employees, travellers, advisers, suppliers and business partners. The summary does not establish which of these groups appeared in each event, but it illustrates why exposure cannot be understood from the organisation’s industry label alone.
[Capifrance describes its model as a nationwide network of independent real-estate advisers](https://www.capifrance.fr/fr). [Stellantis lists Chrysler within its portfolio of automotive brands](https://www.stellantis.com/en/brands/chrysler). [The University of Nottingham operates campuses in the UK, China and Malaysia](https://www.nottingham.ac.uk/about/campuses/campuses.aspx). [BCD Travel provides corporate travel and related services](https://www.bcdtravel.com/). [BinDawood Holding describes retail and retail technology as central to its operations](https://www.bindawoodholding.com/about/).
Why complexity matters more than the event count
The 33 distinct data types found across ten events show that a relatively short breach list can still create a broad classification and response challenge. Different categories of information require different questions. Authentication data may require credential resets or session revocation. Contact information may affect phishing and impersonation risk. Employment, education, travel or customer information may require a review of identity-verification and support processes.The relationship between fields can also matter. A record containing several related identifiers may be easier to match to an active person or business account than an isolated data point. This does not mean the information has been combined or misused; it means defenders should assess records in context rather than counting fields independently.
The selected organisations also illustrate the importance of ownership. A recognisable brand may operate through subsidiaries, advisers, campuses, regional entities, retail channels or service partners. When exposed information is discovered, security teams need to determine which legal entity, platform and business relationship it concerns before an effective response can begin.
A similar issue applies to time. A person may have been a student, traveller, customer or employee years earlier but still have information retained within an organisation’s systems. Conversely, a current relationship does not automatically mean the exposed record is current. Discovery date, record age and relationship status should therefore be treated as separate facts.
Three defensive checks
1.Classify the information before prioritising the event. Separate authentication, contact, financial, employment, education, travel and other relevant data categories. Response priority should reflect what the information could enable, not simply the number of records.2.
Identify the entity and relationship involved. Establish whether an exposure relates to a parent company, subsidiary, regional operation, adviser network, campus, supplier or digital platform. Record who owns the investigation and who can make response decisions.3.
Check whether the identity is still active. Determine whether the affected person remains a customer, employee, student, contractor or account holder. Where the relationship has ended, confirm that access has been removed and that retained information still has a legitimate business purpose.Perspective
The selected examples do not demonstrate that property, automotive, education, travel or retail organisations are being targeted more heavily than other sectors. They are not a representative sample from which to calculate an industry trend.The account total should not automatically be interpreted as 2,472,370 unique or currently active people. The material may include duplicate, historical or overlapping records. Similarly, the 33 data types describe the variety found across all ten events and were not necessarily present in every event or account.
The useful conclusion is that breach volume and response complexity are different measures. Event and account totals describe scale, while data types, organisational structures and relationship status help determine what a business may need to do.
BreachAware does not publish source locations, complete breach inventories or unnecessary operational details that could facilitate misuse.