BSN 4.26.2021

Normalizing Breaches

BSN 4.26.2021

In August of 2019, Facebook was the victim of a data breach that compromised information from 533 million people from 106 different countries.  Why is this in the news now?  Because the breach was addressed in a recent email from Facebook management, and that email was accidentally sent to a Belgium-based news outlet and, in that email, they don’t seem too concerned.

The information that was stolen included phone numbers, Facebook IDs, full names, birthdates, location information, biographical information, and even some email addresses.  But Facebook feels that this didn’t need to be relayed to users, and they don’t plan on changing their minds about it.  In fact, the email indicates that they are looking to normalize this type of incident.

It was part of a feature that no longer exists, they fixed the issue, and users couldn’t fix it themselves anyway.  With doubt around whether or not users would even be successfully notified, they didn’t feel that there was a way to ensure the situation was remedied any further.  As they seem to see it, they had already addressed it on their end, and there was nothing that could really be done by the general public.  Seems like a “hey, what can you do, it’s going to happen” kind of response and they said as much in a blog post.

Yes, data breaches are so common now, we’ve no longer become phased when a large breach hits the headlines.  That in itself is a problem, but when we stop reporting on it altogether, that makes it even worse.  Are we admitting defeat? Or are we just saying that we’re ok living with it?  Neither answer should be acceptable, and businesses should not be able to say that it is ok to be a part of their problem because it is just a “normal occurrence”.

How did Facebook react when the email was discovered?  They confirmed it was genuine and told the BBC: “We understand people’s concerns, which is why we continue to strengthen our systems to make scraping from Facebook without our permission more difficult and go after the people behind it.” The spokesperson later added that LinkedIn and Clubhouse had also faced “data scraping” issues.

Look, it’s not just us, everyone has this problem.

But that doesn’t mean it is ok!  We need to continually work together to ensure that our personal and professional information is protected through safe cybersecurity practices.  It isn’t something that we see as negotiable, especially when the statistics show how likely a small business is to not survive a data breach.

Yes, data breaches are being normalized, but that doesn’t mean that we need to accept that as the new normal.

badge w light burst white (1)
Exclusively for Our MSP Partners

Now Available: Gen AI Certification From BSN

Lead Strategic AI Conversations with Confidence

Breach Secure Now’s Generative AI Certification helps MSPs simplify the AI conversation, enabling clients to unlock the value of gen AI for their business, build trust, and drive growth – positioning you as a leader in the AI space.

More on blogs

Training That Sells: How Certifications Drive Revenue in 2026

Cybersecurity training is evolving beyond compliance. Today, MSPs can offer certifications in cybersecurity, AI awareness, and productivity tools that provide real professional value for end-users.

March Madness is Here and So is Our Full-Court Press in Cybersecurity

March Madness is all about preparation, strategy, and execution — and the same is true for cybersecurity in the age of AI. As threats accelerate,

When AI Hallucinates: What ‘The Pitt’ Reveals About Cybersecurity and the Power of Human Oversight 

AI-assisted tools promise efficiency in healthcare, but AI hallucinations can quietly introduce clinical and cybersecurity risk. As highlighted in The Pitt, human proof-checking and governance
Take the First Step

Experience Training That Makes a Difference

during the demo you’ll:

Take the First Step

Experience Training That Makes a Difference

During the demo you’ll: