← All insights

Your Employee Data Is Someone Else's Attack Plan

Stolen HR records don't get used on the people they describe. They get used to write a convincing email to your controller. Here's what that means for a company your size, and who should own it.

A vendor newsletter landed in my inbox this week about two government data breaches. It was a sales piece, so I did what I'd recommend anyone do with a security email that wants your credit card: I ignored the pitch and went looking for what actually happened.

What I found is worth your attention, but not for the reason the newsletter wanted. The story isn't that federal agencies got hacked. It's what the stolen material is good for, and the fact that your company is sitting on the same kind of material, spread across more systems than anyone there can name.

What actually happened

The Pentagon. On 16 July 2026, the Defense Manpower Data Center discovered a vulnerability in a file-sharing system that let unauthorized users read files on a server holding unencrypted personal data. The notification letters, dated 18 September, say access ran from October 2025 until the day it was found: roughly nine months undetected. A Department of War official has put the number at about 2.76 million living people and 294,000 deceased. Exposed fields included Social Security numbers alongside names, dates of birth, contact information, sex, race and military occupational specialty.

The FBI. In late September, the extortion group ShinyHunters claimed it had taken data on current, former and prospective FBI personnel from the bureau's recruiting systems. The public application portals went offline on 22 September. The FBI told its own staff that names, addresses, job titles and Social Security numbers were exposed, classified it a "major" cybersecurity incident and notified Congress on 25 September. Here's the part to be careful about: there is no confirmed number of people affected. The attackers claim terabytes; the Justice Department has said it hasn't yet identified the full scope. The intrusion method, a claimed unpatched flaw in a widely used HR platform, is also the attackers' account rather than a confirmed finding. The FBI has said publicly it doesn't yet know whether the breach started in a third party or in its own enterprise.

I'm being pedantic about what's confirmed because that distinction matters later. When something like this happens to you, the gap between "what we know" and "what's being said" is the thing you'll be managing.

The lesson isn't that the government got hacked

Strip the agencies out and look at the shape of it:

  • A personnel system, not a classified one, holding identity records for millions of people.
  • A file-sharing component with a flaw nobody noticed.
  • Data sitting unencrypted because, at some point, that was the convenient choice.
  • Nine months between the first unauthorized access and anyone realizing.
  • An unresolved question about whether the problem started inside or at a vendor.

Every one of those is a thing I've found inside normal mid-sized companies. Not because owners are negligent, but because nobody had the job of looking. These two organizations have budgets and dedicated security staff. If a nine-month gap can open there, the honest question for a $15M distributor or a multi-location practice is not whether it could happen, but who would notice.

What stolen HR data is actually for

This is the part the credit-monitoring pitch gets wrong. Identity records are rarely used against the person they describe. They're raw material for attacks on organizations, and the supply has never been richer.

Convincing phishing and business email compromise. A generic "your invoice is attached" email gets deleted. An email that uses a real name, a real job title, a real reporting line and a real project reference gets opened. Breached personnel data turns spam into something that reads like it came from inside. The FBI's 2025 Internet Crime Report logged more than a million complaints and roughly $20.9 billion in reported losses, with business email compromise accounting for more than $3 billion of it. That category is almost entirely about convincing someone to move money or data.

Impersonation that now sounds and looks right. This is what changed in the last two years. The same report included, for the first time, a dedicated section on artificial intelligence: over 22,000 complaints with an AI connection and nearly $900 million in losses, involving voice clones, synthetic video and forged documents. A Gartner survey of security leaders, published in September, found 41% had seen a social-engineering incident involving an audio deepfake in the prior twelve months. The best-documented corporate case remains the engineering firm Arup, where a finance employee in Hong Kong joined a video call with people who looked and sounded like colleagues, and approved roughly $25 million in transfers. Every other participant was generated.

The old advice was "if the email seems off, call them." It assumed a phone call was proof. It isn't anymore.

Account takeover. Dates of birth, addresses and Social Security numbers are what help desks and password-reset flows use to decide you're you. Enough of that in an attacker's hands turns your own account recovery process into the way in.

Vendor and supply-chain compromise. Your payroll provider, your benefits broker, your bookkeeper, your IT contractor. They hold your employee and customer data too, and a breach at any of them is a breach of yours in every way that matters to the people on the list. Notice that the FBI couldn't initially say whether the problem was theirs or a third party's. Most companies can't answer that question on a good day.

The question is no longer "could someone fake an email from me." They can. The question is whether your company has a process that survives it.

You hold the same records

Run the inventory in your head. HR files with Social Security numbers and dates of birth. Payroll, in a cloud platform. Benefits, in another. Customer records in the CRM. Payment details with the processor. Vendor banking details in the accounting system. Resumes from applicants you never hired, sitting in an inbox. Identity documents someone emailed during onboarding, still in that thread.

Now the harder question: how many separate SaaS tools is that spread across, and who at your company could list them all? In my experience the answer is "more than anyone thinks" and "nobody." That's the real exposure. Not one dramatic vulnerability, but a sprawl of systems, each added for a good reason, none of them owned end to end.

It's the same pattern I see when a company outgrows its tech stack. This is the same disease showing a different symptom. When nobody owns the whole picture, security isn't weak in one place. It's unmeasured everywhere.

This needs an owner, not a product

You cannot buy your way out of this. There's no tool that knows which of your vendors can read customer records, or that your former bookkeeper still has a login, or that your controller has never been told what to do when the CEO's voice asks for a wire.

What this environment requires is a technology leader who understands current threats and owns the entire surface: who has access to what, where sensitive data actually lives, what your vendors can see, and how the company would notice and respond. That's a judgment job, and it sits across the line that usually separates "IT" from "the platform," which is exactly why it so often belongs to nobody. I get into that split in CIO vs CTO, and into whether you're at the stage that needs this in When Is the Right Time to Hire a CTO?.

I'll admit to a bias here. I got my first IT job because a company caught me inside their servers and decided to hire me to secure them instead. I've spent my career since on the other side of that, and the pattern hasn't changed: the gap is almost never exotic. It's a thing nobody was assigned to look at.

What a good one does in the first 90 days

Concretely, this is the work. None of it is glamorous and all of it is doable.

  1. Inventory every system. Every SaaS tool, every login, every place company data lives, including the ones a department bought on a credit card. You cannot protect what isn't on the list.
  2. Map the sensitive data. For employee records, customer records, payment details and identity documents: which system is the system of record, who can read it, and is it encrypted at rest? Where the answer is a shrug, you've found the priority.
  3. Audit access and kill the orphans. Former employees, former contractors, former agencies, shared logins, service accounts nobody claims. This exercise always finds something.
  4. Turn on phishing-resistant MFA everywhere, starting with email, finance systems and anything holding personal data. Email first, because email is how the money moves.
  5. Write the money rule and the identity rule. No payment or banking-detail change happens on the strength of an email, a call or a video. Ever. It doesn't matter who it appears to come from. Verification goes through a known channel the requester didn't choose. Then tell your staff they will never be punished for slowing a request down. That cultural permission is doing more work than any software you could buy.
  6. Review the vendors that hold your data. What do they have, what are their breach-notification terms, and who at your company is responsible for each relationship?
  7. Decide how you'd find out and what you'd do. Logging and alerting on the systems that matter, a named person to call, and a one-page plan for the first 48 hours. The nine-month detection gap is the scariest number in either of these breaches.
  8. Rehearse it once. A one-hour tabletop with your leadership team beats a binder nobody opens.

A useful test of the money rule: ask your controller what they would do if you called them from an unfamiliar number, sounding stressed, asking them to push a payment through before end of day. If the answer depends on recognizing your voice, you don't have a control. You have a habit.

Questions to ask this week

You don't need to be technical to find out where you stand. Ask whoever runs your technology:

  • How many SaaS applications do we pay for, and can I see the list?
  • Where do employee Social Security numbers and dates of birth live, and who can read them?
  • If someone logged into our email from another country tonight, how would we know?
  • Who still has access that shouldn't? When did we last check?
  • Which vendors hold our employee or customer data, and what are they required to tell us if they're breached?
  • What is our rule for verifying a request to move money or change bank details?
  • If we had a breach on Friday afternoon, who do I call, and what are the first three things we do?

If those answers come back quickly and consistently, you're in better shape than most. If they come back as "I'd have to look into that," that's your finding. It's the same finding whether your company is 20 people or 200.

Where to start

Don't start with a purchase, and don't start with fear. Start with the inventory, because almost every question above is answerable once you have one, and none of them are before.

If you want a fast read on whether this is a few fixes or a structural problem, the Outgrown-your-tech scorecard takes about three minutes and covers access, data and ownership among other things. And if the honest answer is that nobody owns this today, that's not unusual at this stage. It's the gap a fractional CTO most often fills, and it's a lot cheaper to close before you need it than after.

The organizations in the news these past few weeks had security teams. What they apparently didn't have was someone who noticed for nine months. Your company's version of that question is worth asking before someone else answers it for you.

Not sure what level of tech leadership you need?

Tell me where the business is and where it's headed. I'll tell you honestly whether you need a fractional CTO, a full-time hire, or neither yet.

Start a conversation → Take the free scorecard