Põhisisu algus

Expert warns: a data leak may affect you even if you have never been a customer of the company

29.06.2026

When a well-known foreign company falls victim to a cyberattack, it is usually followed by direct notifications and sometimes also media coverage. Many people assume that if they are not customers of the company that suffered the data breach, then the incident does not concern them. In reality, that may not be the case at all. According to Elisa’s Head of Information Security, Mai Kraft, public discussion often overlooks the fact that data breaches frequently affect far more people than just the company’s own customer base, which is why such news should be followed carefully. People tend to think that if they have never dealt with that company, then their data is not at risk either. In reality, data often moves through the systems of many partners — meaning that even if someone originally became a user on one platform, some companies may, where there is a genuine operational need, share that data with others as well. Many companies — though not all — use dozens of different systems, software platforms, and subcontractors in their work. Logistics companies, accounting service providers, customer management software developers, or marketing platforms often also process customer data. If one of them becomes the victim of an attack, the data of people who have never directly interacted with that company may also be leaked. At the same time, it is important to note that these partners are often genuinely necessary for providing the service, and data only moves when there is a real need for it. A good example is a case from a few years ago involving a genetic testing company, which resulted in the leak of the health data of nearly 10,000 patients. At the same time, most of those patients had never interacted with that company themselves — their data had reached it through a doctor, a laboratory, or another healthcare service provider. Altogether, the incident affected patients from 42 healthcare institutions. This means that although customers of companies involved in major data breaches usually receive a notification and are able to respond, that only shows part of the real picture. In today’s highly connected digital environment, every major data breach means that many other people may potentially also be at risk. This is a classic supply chain risk — if a central link somewhere runs into trouble, those problems may indirectly spread to other partners as well. Your data travels further than you think Online shopping is also a good example. When a customer makes a purchase, their name, address, and contact details often move simultaneously through several systems: the payment platform, warehouse management, courier service, and sometimes also a marketing platform. Yes, partners are usually listed in the company’s privacy terms. In practice, however, this is often just a formality, because few people read those documents in detail. Most companies that respect themselves and follow the rules — including most large Estonian companies — act reasonably, but this may not always be the case, for example, with smaller online stores. This means that the online store itself does not necessarily need to be the victim of an attack for data to leak. It is enough if a problem occurs in one of its partners’ systems. In that case, the potential leak point is not one company, but an entire network of service providers. That is why it is worth getting used to the idea that data protection risks do not end where the customer’s direct relationship with a company ends. If the media reports a data breach at a company whose name you have never heard before, that does not necessarily mean the incident has nothing to do with you. The company name may mean nothing to you — but the breach may still affect you The European Union’s General Data Protection Regulation, or GDPR, obliges companies to notify the data protection authority. If the breach poses a significant risk to people, the affected individuals must also be informed. If a data breach takes place in a third-party company, the proper process is that the service provider informs its clients — meaning the companies — who in turn inform their own customers. Ideally, this means that a person will always find out if their data has been leaked. In practice, however, it may not be so simple, because although larger local companies that follow the rules generally comply with requirements, the same may not be true, for example, in the case of a PDF generation tool from India or a Korean image editing app that requires account creation. In many cases, people also do not know how to look for information proactively. If a breach occurs at a company with which a person has had no direct contact, they may not feel affected. A company may also not always know exactly whose data is involved — especially if the data entered the system through partners or subcontractors and the company only holds partial fragments of information. That is why every major data breach deserves attention, even if the company name seems completely unfamiliar. Even a seemingly distant data breach may in fact involve your data. That is exactly why, whenever a major breach is reported, it is worth taking a moment to check whether it might affect you in some way — for example, by reviewing your account security settings or checking whether your email address has appeared in a breach. FACT BOX: What to do if you suspect your data may have been leaked Check the HaveIBeenPwned website to see whether your email address appears in any known data breach. It is worth doing this even without a specific reason. Change your password immediately, even if the company has not yet notified you. Do not wait for an official letter. If you use the same password in several places, change it everywhere. Attackers automatically test passwords from leaked databases on other platforms. Enable two-factor authentication wherever possible — especially for email and banking services. Today, this is one of the most effective protective measures, and it is free and accessible to everyone. If the company sends a notification, check whether it contains specific information — which data was leaked, what the company itself has already done, and what is expected from you.
Seotud märksõnad