A person often discovers a problem long after the incident that caused it. The delay is not accidental, and it follows from how stolen data is handled after a breach.

Detection takes time on its own

Many intrusions are discovered by an outside party rather than by the company affected, which means the data was already circulating before anyone knew.

Investigation follows, and determining precisely what was accessed can take weeks because it requires reconstructing activity from logs that were not written for that purpose.

Notification comes after that work, so the gap between the intrusion and the public statement is often considerable even when the company acts responsibly.

Stolen data moves through intermediaries

Whoever obtains a database frequently is not the person who will use it. The data is sold, traded and repackaged, and each step takes time.

Fresh credentials are more valuable, so the first buyers use them quickly against high-value targets. What remains circulates more widely and more cheaply.

By the time a set of credentials reaches broad automated use, it may have passed through several hands over many months.

Passwords must be cracked before use

Well-protected passwords are stored using functions designed to be slow, so recovering the original text requires substantial computation per account.

Attackers therefore work through a stolen file in order of likely value, cracking simple passwords first and leaving strong ones for later or never.

A strong unique password may survive indefinitely, while a common one from the same file is usable within hours of the theft.

The damage lands on other accounts

The breached service is often not where the harm occurs. Automated systems try the stolen combination across many popular sites, looking for reuse.

Success on an email account is the most damaging, because password resets for everything else flow through it.

This is the mechanism that makes password reuse expensive. One weak point converts a single company's incident into a problem across a person's whole set of accounts.

What shortens the exposure

Unique passwords contain a breach to the service that suffered it, which is the single largest reduction in exposure available.

A second factor blocks reuse even where a password is recovered, and breach notification services alert a user before the credentials reach broad circulation.

None of these prevent a company being breached. They shorten the window during which someone else's incident remains a live problem for you.