• tiramichu@lemm.ee
    ·
    5 months ago

    IBM defines "Data Breach" as:

    any security incident in which unauthorized parties gain access to sensitive data or confidential information, including personal data (Social Security numbers, bank account numbers, healthcare data) or corporate data (customer data records, intellectual property, financial information).

    Despite the fact the attackers used real passwords to log in they are still an 'unauthorized party' because they are not the intended party.

    It's also legally the case that using a password to access data you know you are not supposed to access still counts as 'hacking'

    • MrCookieRespect@reddthat.com
      ·
      5 months ago

      Well, the authorisation is the password, so from their side it was in fact not a breach because they just got a normal login with the correct authorisation(password).