The Breaches You Can't Control, and the Data You Can
July 2026 brought another wave of breach notices, from Chick-fil-A loyalty accounts to nearly 7 million insurance customers. You can't stop companies from getting hacked. You can control how much they're holding when it happens.

If it feels like the breach notifications never stop, that is because they do not. The last two weeks of July 2026 alone brought Chick-fil-A telling customers their loyalty accounts were raided, a Health-ISAC warning that the extortion crew ShinyHunters is actively hitting healthcare organizations, and IBM's annual report putting the global average cost of a breach at $4.99 million. The Chicago Tribune ran a column on July 29 with the headline "Data breaches becoming uncomfortably common." Uncomfortably common is a polite way of saying constant.
There is a natural reaction to all of this, which is to feel like none of it is your problem to solve. And honestly, most of it isn't. But not all of it.
What actually happened in July
Two incidents are worth looking at closely, because they illustrate two very different failure modes.
Chick-fil-A. In notification letters filed with state attorneys general, the company said it detected attacks against its website and app between June 17 and June 19. Attackers used automated tools and credentials "obtained from a third-party source" to break into Chick-fil-A One loyalty accounts. Per a filing with Maine's attorney general reported by BleepingComputer, 13,322 people were affected. What came out: names, email addresses, membership numbers, account credit balances, mobile pay numbers, and the last four digits of payment cards, plus birth dates, phone numbers, and addresses where customers had stored them.That is a credential stuffing attack. The passwords came from somewhere else. Chick-fil-A was not hacked so much as unlocked with keys the attackers already had, which is what happens in a world where the same password gets reused across a dozen services.
AssuranceAmerica. Different story, bigger number. The auto and renters insurer disclosed a breach affecting 6,998,886 people. Attackers targeted an employee on March 16, got into the company's IT environment, and copied data files. The stolen documents contained names, contact information, policy and account details, driver and vehicle information, claims information, and driver's license numbers. The company detected it on March 17. It finished reviewing which files were affected on June 15. Notification letters went out in July.Read that timeline again. Three and a half months between "we found it" and "you found out." That is not a scandal, it is the normal pace of forensic review on a large file set. But it means your driver's license number can be in circulation for a full quarter before anyone tells you.
The part you genuinely cannot control
You cannot audit your insurer's endpoint detection. You cannot make a fast food chain rate-limit its login endpoint. IBM's 2026 Cost of a Data Breach Report found that one in four malicious breaches were AI-enabled, a 56% increase over the prior year, and that only 37% of breached organizations encrypt sensitive data both at rest and in transit. The attack side is getting cheaper and faster. The defense side is uneven and mostly invisible to you as a customer.
So the honest framing is this: whether a company holding your data gets breached is not up to you. It's a question of when, not if, and the answer depends on their security budget, their vendors, and their luck.
The part you actually do control
Here's the thing the breach coverage tends to skip. A breach can only expose what the company was holding.
The AssuranceAmerica attackers got driver's license numbers because driver's license numbers were sitting in those files. The Chick-fil-A attackers got birth dates and home addresses only for the accounts where customers had stored them. Every field in a breach disclosure traces back to a moment when someone handed that field over and the company kept it.
That moment is your lever.
Think about how many documents you've emailed in the last two years. A pay stub to a landlord. A bank statement to a mortgage broker. A driver's license photo to a gig platform, a car rental desk, a coworking space, a crypto exchange. Each of those was probably sent in full, because that is what you were asked for and attaching the whole file is easier than editing it.
Every one of those files is now somebody else's liability. It lives in an inbox, a CRM, a shared drive, a vendor's cloud bucket. It is protected by security practices you will never see and cannot evaluate. And when that company shows up in a headline eighteen months from now, whatever was in the file you sent is what gets exposed.
Minimization is the individual's version of security
Companies have a term for this: data minimization. Collect only what you need, keep it only as long as you need it. It is written into GDPR and into most serious internal privacy policies, and it is the single most effective control there is, because data you never collected cannot leak.
The individual version is exactly the same principle pointed in the other direction. Send only what the recipient needs to make their decision.
A landlord verifying income needs your name, your employer, the pay period, and the amount. They do not need your Social Security number or your direct deposit account number, both of which sit on a standard pay stub. A lender verifying reserves needs your ending balance and your deposit pattern, not every line item on the bank statement and not your full account number. A platform verifying you are a real adult human needs your face, name, and expiration date on an ID. It does not need your license number and full home address, which is precisely the combination that got exposed at AssuranceAmerica.
The asymmetry here is what makes it worth doing. Redacting a document takes about a minute. The exposure it prevents is permanent, because you cannot rotate a Social Security number or a date of birth the way you rotate a password. When one of those leaks, it is out for good.
What to actually do
Change your passwords when you get a notice, obviously. Use unique ones so credential stuffing has nothing to stuff. Freeze your credit if identifiers were involved. That's the standard advice and it's correct.
But add one more habit. Before you attach a document to an email or a portal upload, ask what decision the recipient is making, and black out everything that has nothing to do with that decision. Then send the redacted version. Most recipients never notice, and the ones who do usually just say thanks.
You cannot stop the next breach. You can make sure that when it happens, the company in the headline was holding a lot less of you than it could have been.
---
Related: Redact any document online · Redact a bank statement · Redact a pay stub · Redact an ID
Ready to try it? Redact a document in your browser → nothing uploads, nothing stored, free to try. For unlimited redactions, check out our plans & pricing.Ready to Protect Your Privacy?
RedactID lets you redact sensitive information from documents without uploading them — everything is processed on your device.