What People and Organizations Can Do After a Database Exposure 

Published
Written by:
Vishwa Pandagle
Vishwa Pandagle
Cybersecurity Staff Editor

Jeremiah Fowler, Security Researcher and EU Training Consultant at Black Hills Information Security, details the risks surrounding an exposed Brazilian health database. He explains how people and organizations can respond to it and similar incidents. 

People can change passwords, but they cannot replace their fingerprints or faces. What can someone realistically do after biometric information is exposed?

Unlike a password, biometric data is permanent. Once fingerprints, facial images, or other biometric identifiers are exposed, they cannot simply be changed or reissued. Individuals should monitor their accounts for suspicious activity, enable multi-factor authentication that does not rely solely on biometrics, remain vigilant for identity fraud, and be cautious of unsolicited requests for personal information. 

While these steps cannot undo the exposure, they can reduce the likelihood that stolen personal information will be combined with biometric data in broader identity fraud or social engineering attacks.

You contacted multiple agencies but received no response. What does that silence mean for people awaiting confirmation, guidance, or notification?

A lack of response should not be interpreted as confirmation that no risk exists. It often means investigations, internal reviews, or legal processes are still underway. However, in my experience, no reply is usually not a good sign. 

Often I will get a reply like "we care deeply about privacy and security" followed by steps they will take. This is the right approach, while silence leaves open questions. 

Breach notices often arrive after exposed data may already have circulated. What information should notices provide to help people reduce future victimization? What should they ask organizations collecting their data?

In my opinion, a breach notice should clearly explain: 

Organizations should also explain:

Transparency helps individuals to better understand their level of risk rather than relying on vague or generic notifications.

Organizations may have governance policies without consistently enforcing them. How should they determine who needs access, how long records should remain, and when sensitive data must be deleted?

Data governance should follow the principle of least privilege, meaning employees and systems should only have access to the information required for their specific responsibilities

Organizations and even governments should:

Periodic audits and automated lifecycle management can help ensure that governance policies are consistently enforced instead of existing only on paper.

The database held identity documents, addresses, fingerprints, and health compliance records without password protection. In your experience, which overlooked responsibilities most often allow such exposures?

Many data exposures are not caused by sophisticated cyberattacks but by basic security mistakes and human error. The most common issues I encounter include 

Organizations also frequently retain sensitive information far longer than necessary, increasing the potential impact if those records are exposed. 

Security is not only about deploying technical controls—it also requires continuous governance, accountability, and verification that those controls remain effective over time.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: