The risk of hoarding customer data
# The risk of hoarding customer data
12.9 million.
That is the number of user accounts exposed in the Carhartt breach. For a company that sells heavy-duty workwear, holding onto nearly 13 million sets of credentials and personal details isn't an asset; it's a liability with a massive surface area. It’s unusual because most people think of "big data" as a perk for the marketing department. In reality, every single record you keep is just another line item on a future settlement check.
When you see numbers like this—or the 8.7 million customers affected by the breach at three UK airports—it’s easy to dismiss it as an "enterprise problem." You probably don't have 12 million users. You might have five thousand. You might have five hundred. But the logic remains identical whether you're a global brand or a local plumbing supply shop with ten employees and no dedicated security person.
If you are storing customer data on a local server or in an unmanaged cloud bucket, you are playing a game where the house always wins. There were 382 stories about data breaches this week alone. The odds aren't in your favor.
The irony is that while companies treat these databases like gold, criminals price them like scrap metal. Look at the Love Electric breach: someone put 877,000 driver records up for sale for $600. That’s less than a dollar per thousand records. The "value" of the data only exists to the person who stole it and knows how to use it for phishing; for the company that lost it, the value is negative.
The cost difference here is staggering. An enterprise like Carhartt or a major airport operator has a retainer with a forensic firm that costs more than most small businesses make in a year. They pay people to tell them exactly how they got hit and then spend millions on legal counsel to manage the fallout. A ten-person shop doesn't have a "incident response budget." For a small firm, a breach of this scale usually means closing the doors or spending every cent of profit for the next two years on lawyers.
Some will argue that you need this data for CRM, loyalty programs, or "better customer insights." They’ll say it's essential for growth.
That is a mistake. Most small shops don't need to be their own database administrators. If you are keeping PII (personally identifiable information) on your own hardware, you're taking on the risk of a global corporation without any of the budget to defend it. Move that data to a reputable third-party provider who spends their entire existence securing that specific type of data. It’s cheaper to pay a monthly SaaS fee than to pay for a forensic audit after your server is wiped.
The second-order effect here is where it gets ugly. When 12.9 million people are leaked from a workwear brand, the attackers don't just sell the list; they use it to build profiles. They know these victims are likely contractors, tradespeople, or laborers. These aren't people sitting behind corporate firewalls with a security team breathing down their necks. They’re using personal emails and mobile phones. This leads to a wave of highly targeted phishing campaigns that look like legitimate invoices or shipping updates for gear they actually buy. The breach at the company becomes a weapon against the customer in a way that is very hard to stop once it starts.
We saw this play out years ago with the various hotel chain breaches, where "loyalty member" lists were used to trick people into giving up credit card details via fake "account verification" emails. The parallel here is the specificity of the target. Attackers aren't casting a wide net; they're using these leaked lists to pretend they already know who you are and what you wear to work.
Stop collecting data you don't actually use. If you haven't looked at a customer's address in three years, delete it. If your "loyalty list" is just a spreadsheet on a shared drive, move it or kill it.
Check how many old spreadsheets containing customer emails and phone numbers are sitting in your shared folders this week. Delete the ones you don't need.
◼
Sources
The reporting this analysis was built from. Follow the originals before acting on anything here.
- Carhartt data breach exposed information from 12.9 million user accounts - TechRadar Google News Security
- ShinyHunters claims McKesson data breach exposing 284 million patients - CyberInsider Google News Security
- UK airport operator confirms data breach affecting 8.7 million customers - SC Media UK Google News Security
- PaperCut Issues Emergency Patches Amid Active Exploitation Risks - India News Network Google News Security
- Hackers Steal Data of 8.7 Million Customers in Cyberattack on Three UK Airports - CyberSecurityNews Google News Security
- McKesson discloses breach after ShinyHunters claims patient data theft BleepingComputer
- Cl0p Ransomware Hits Shell, GE, Philips via PTC Bug [2026] - tech-insider.org Google News Security
- TheHatman Azure Breach: 3.6M Records, 9 Firms Hit [2026] - tech-insider.org Google News Security