A breach notice usually arrives as a short letter or email, and the longer investigation report behind it can be dense. Knowing how to read a data breach report helps you move past the reassuring language and work out what actually happened to your information. A good report covers attack vectors, dwell time, and containment strategies. Each of these tells you something different about your personal risk.
This guide walks through those pieces, uses MOVEit and Change Healthcare as reference points, and ends with steps you can take once your name appears on a notification list.
What a Breach Investigation Report Actually Discloses
A breach investigation report is the organization's (or its investigators') account of how an intrusion happened and what it touched. The core elements are:
- Attack vector: how the intruder got in, such as stolen credentials, a software flaw, or a compromised third party.
- Dwell time: how long the attacker had access before being detected and removed.
- Scope of data: which systems and which categories of information were reached.
- Containment and remediation: what the organization did to shut the attacker out and prevent a repeat.
Not every report includes all four, and notification letters often include far less. When something is missing, treat the gap as information. A letter that says "some personal information" without naming the data types leaves you to assume the broader category until the organization says otherwise.
Dwell Time and Attack Vector: What They Mean for Your Exposure
The attack vector tells you how the breach could have reached you. If the entry point was a vendor or a shared tool, you may have been notified by a company you never dealt with directly. That is common enough that it is worth checking who the notice actually comes from and why they held your data.
Dwell time is the number that changes how you should think about risk. A short window suggests the attacker had less opportunity to browse, copy, and stage data. A long window means more time to move through systems and collect more. Two questions help here:
- Does the report give a start and end date for the access? If it only gives a discovery date, you do not know how long your data was exposed.
- Does the exposed data match the period when you were a customer, patient, or student? Your records may fall inside the window even if you left the organization years ago.
Speed on the attacker's side matters too. Google's Threat Intelligence Group reported in May 2026 that AI is now powering zero-day exploits, which is one reason defenders emphasize fast detection and short dwell times. The faster an intruder can be spotted and removed, the less data is likely to leave.
Lessons From MOVEit and Change Healthcare
MOVEit and Change Healthcare are frequently cited when people discuss how breaches are investigated and disclosed, and they illustrate a few patterns useful to any reader. We are not restating every detail of those incidents here, only the habits of reading that they encourage.
Look past the brand on the letter. In large incidents, the organization that notifies you may be one link in a chain of vendors and service providers. If a notice mentions a third party you do not recognize, that is a signal the breach sat upstream from the company you trusted with your data.
Expect updates. Investigations in major incidents tend to evolve. An early statement about what was accessed may be revised as analysts review more logs. Keep the original notice and any follow-ups so you can compare them, and watch for a revised count or a newly listed data category.
Match data types to real-world harm. Health information, financial details, and government identifiers carry different risks than an email address. Medical data can be used for fraud that is slow to surface, while identifiers can support account takeover. The report's list of data types is the best guide to which protections to prioritize.
What to Do After You're Named in a Breach
A notification is not proof that you will be harmed, but it is a reason to act. Stolen data is not always used immediately. It can be held, traded, or used later for extortion, as seen in the ShinyHunters campaign targeting Canvas school portals, where an initial data theft escalated into ransom pressure. That pattern is a reminder that the risk window can stretch well beyond the date of the notice.
Use the report details to set your response:
- Passwords exposed or possibly exposed: change them and any reused ones, and turn on multi-factor authentication.
- Identifiers or financial data involved: consider a credit freeze and review statements regularly.
- Medical or insurance information involved: review explanation-of-benefits statements for services you did not receive.
- Contact details involved: expect phishing that references the breach, and verify messages through official channels rather than links in the message.
What This Means For You
The practical value of a breach report is that it turns a vague worry into specific tasks. Attack vector tells you whose systems failed, dwell time tells you how much opportunity the attacker had, and the data list tells you which protections matter most. If a report leaves those answers out, ask the organization directly and keep a record of the response.
Key Takeaways
- When you receive a notice, find the data types, the access dates, and the entry point before anything else.
- Treat missing details as questions to ask, not as reassurance.
- Save every notice and update in case figures or scope change.
- Match your response to the data exposed: credentials, identifiers, financial, or medical.
- Stay alert for later misuse, including phishing and extortion attempts.
Knowing how to read a data breach report will not undo a breach, but it lets you judge your own exposure and respond early. Check whether your information appears in your notice, lock down the accounts it affects, and keep watching for follow-on scams.




