Article

You Were Already in the File

ON DATA, IDENTITY, AND THE RECORD

A data breach is treated as a wall failing. It is closer to a publication, and the exposure it publishes was the standing condition long before anyone broke in.

Jason Newell

The letter comes on ordinary paper. It says your information may have been exposed, and it offers you a year of credit monitoring, and it uses the word unfortunately. You read it at the kitchen table with a cup going cold, and what you feel is duller than fear. You already knew. You have had this letter before, from a different company, about a different file, and you will have it again.

I build the machinery underneath those letters. The stores where the data rests, the pipes that carry it, the identifiers that let one record recognize another as the same person. I have spent years making information legible to other information. So when the letter lands at my own table, I cannot hold it at arm's length. I laid some of the trail it is about.

We talk about a breach as a break-in. A wall was up, it failed, and now the wrong people are inside. The picture is comforting because it makes exposure an event, a thing with a before and an after. Something went wrong on a Tuesday, and on some better Tuesday it would have gone right.

Look at the breaches themselves and the picture comes apart.

Part I. The break-in that wasn't one

In March 2024, AT&T confirmed that data on more than seventy million current and former customers was sitting where anyone could reach it. Names, addresses, dates of birth, Social Security numbers. Much of it dated to 2019 or earlier. By the seller's account it had been out there for years before the company would say the words out loud. That is a long time for a wall to have been down, if a wall was ever the right picture. The exposure had held quietly, and the disclosure only gave it a date.

A few months before that, the personal records of about three and a half million Oregonians, most of the adults in the state, left through the DMV. Except the DMV's own systems were never broken into. The data went out through a file-transfer tool called MOVEit, a piece of plumbing the department had run since 2015 to move files between partners. The records were already assembled, already in motion, already shaped into transferable files, when a flaw in the pipe was found and used. No wall failed. A door that had always been slightly open was walked through.

This is the ordinary condition of a connected life. The data is already gathered, already joined, already legible, resting in stores you agreed to and moving through pipes you never saw. A breach does not create the exposure. It publishes it.

Figure 1. The break-in model treats exposure as an event. The standing-condition model treats it as a publication of what was already assembled.

Part II. The surface area

Ask what is actually collectable about a person moving through an ordinary day, and the honest answer runs longer than anyone wants it to.

The trail runs in layers. At the top are the identifiers that name your machine and your connection: the addresses, the device model, the operating system, the screen you are reading this on. Below that is the behavioral exhaust, the record of what you did: the searches, the browsing, the places your phone went, the apps you opened, the rhythm of your own typing. Below that sits the sensor layer your phone carries without being asked: the microphone, the camera, the accelerometer that knows your gait, the radios that log every network you pass. Then the content itself, the messages and contacts and calendar and files. And at the bottom, smallest and heaviest, the credentials and the money.

Figure 2. What is collectable about a person runs in layers, from the identifiers that name a device to the credentials that name a bank account.

Almost none of this is stolen in the dramatic sense. Most of it is given, in exchange for a service, under a policy no one reads, through a checkbox everyone clicks. I have written those checkboxes. Some of it is taken with no exchange at all, by parties the person never meets and could not name. Either way it accumulates, and accumulation is the point.

Part III. Where the trail pools

A scattered trail is a nuisance. The danger begins when the pieces find each other.

The path is well worn. Data is collected from many sources, most of them consented to one at a time. Brokers aggregate it, joining fields until a scatter of records becomes a single profile with a name on it. A breach or a leak empties one of those stores. On a market the pieces meet, and the profile that was spread across forty companies is now one file for sale. At the end of the path a stranger has enough to be you at a bank or a pharmacy.

Figure 3. A single leaked field is trivia. The danger is the path that joins it to the others.

A single leaked field is trivia. Joined to the others it becomes a key. The Social Security number is the worst of it, because unlike a password it is not a secret you can rotate. It is a fact about you. Once it is out, it stays out, and the AT&T records show what that means in practice: information from 2019 doing its damage in 2024, and available to do more in the years after.

Part IV. What the defenders actually do

There is real work on the other side of this, and it deserves an honest accounting rather than a brochure.

Machine learning earns its place here. A model watching a stream of logins can flag the one that does not fit, the sign-in from a new country at an odd hour, the transfer that does not match a lifetime of transfers, faster and more tirelessly than any human review. Device-reputation services like Iovation weigh whether the machine asking for access has behaved like a fraud before. Certification bodies do quieter work: LegitScript sorts the legitimate online pharmacy from the storefront that only looks like one, and UpGuard and its kind map an organization's exposed surface so someone can close a door before it is found. In healthcare, HIPAA sets a floor under all of it, a legal obligation to guard the record that does not depend on anyone's goodwill.

None of this closes the gap. It keeps the gap narrow, and narrow is what maintenance buys you. A model that catches the anomalous login is standing guard at a door that should never have been reachable. Certification tells you which pharmacy is real and does nothing about the prescription record already resting in three vendors' files. The defenses are upkeep on a structure that keeps settling. Useful, necessary, and never finished.

What the letter confirms

The letter is still on the table. The monitoring it offers is free for a year, and when the year ends the thing it was monitoring will still be there, because it was there before the letter came and the letter changed nothing. Freeze your credit. Rotate the passwords. Do all of it, because the small walls are worth keeping up. Underneath them the trail stays where it was, assembled and joined and legible, waiting in a store you agreed to for the next flaw in the next pipe.

You were already in the file. The breach only told you which one.

Agentic AIART-AGT-031

Related

Related field notes

Keep reading

More field notes

This piece is part of the MAX Research Collective library. Browse the rest, or connect on LinkedIn.