What People and Organizations Can Do After a Database Exposure
Jeremiah Fowler, Security Researcher and EU Training Consultant at Black Hills Information Security, details the risks surrounding an exposed Brazilian health database. He explains how people and organizations can respond to it and similar incidents.
People can change passwords, but they cannot replace their fingerprints or faces. What can someone realistically do after biometric information is exposed?
Unlike a password, biometric data is permanent. Once fingerprints, facial images, or other biometric identifiers are exposed, they cannot simply be changed or reissued. Individuals should monitor their accounts for suspicious activity, enable multi-factor authentication that does not rely solely on biometrics, remain vigilant for identity fraud, and be cautious of unsolicited requests for personal information.
While these steps cannot undo the exposure, they can reduce the likelihood that stolen personal information will be combined with biometric data in broader identity fraud or social engineering attacks.
You contacted multiple agencies but received no response. What does that silence mean for people awaiting confirmation, guidance, or notification?
A lack of response should not be interpreted as confirmation that no risk exists. It often means investigations, internal reviews, or legal processes are still underway. However, in my experience, no reply is usually not a good sign.
Often I will get a reply like "we care deeply about privacy and security" followed by steps they will take. This is the right approach, while silence leaves open questions.
Breach notices often arrive after exposed data may already have circulated. What information should notices provide to help people reduce future victimization? What should they ask organizations collecting their data?
In my opinion, a breach notice should clearly explain:
- What type of information was exposed?
- How long the data may have been accessible?
- Whether there is evidence of unauthorized access?
- What specific actions affected individuals should take?
Organizations should also explain:
- Why the information was collected?
- How long it was intended to be retained?
- Whether sensitive data such as biometric identifiers or identity documents were encrypted?
- Whether that information remains necessary for ongoing business operations?
Transparency helps individuals to better understand their level of risk rather than relying on vague or generic notifications.
Organizations may have governance policies without consistently enforcing them. How should they determine who needs access, how long records should remain, and when sensitive data must be deleted?
Data governance should follow the principle of least privilege, meaning employees and systems should only have access to the information required for their specific responsibilities.
Organizations and even governments should:
- Establish documented retention schedules based on legal, regulatory, and operational requirements
- Regularly review whether sensitive records are still needed
- Securely delete or anonymize data once those requirements have been satisfied.
Periodic audits and automated lifecycle management can help ensure that governance policies are consistently enforced instead of existing only on paper.
The database held identity documents, addresses, fingerprints, and health compliance records without password protection. In your experience, which overlooked responsibilities most often allow such exposures?
Many data exposures are not caused by sophisticated cyberattacks but by basic security mistakes and human error. The most common issues I encounter include
- Cloud storage or databases that are deployed without authentication
- Overly permissive access controls
- Inadequate asset inventories
- Forgotten development or backup environments
- Poor security monitoring
- The absence of regular security audits
Organizations also frequently retain sensitive information far longer than necessary, increasing the potential impact if those records are exposed.
Security is not only about deploying technical controls—it also requires continuous governance, accountability, and verification that those controls remain effective over time.




