A large retail chain sent breach notices on May 1 after unauthorised access to franchisee document systems. The group responsible claimed over 600,000 records taken from a corporate management platform and released a 9.4 gigabyte archive.
The target describes where sensitive data tends to be forgotten. It isn't the sales system or the payment system: it's the administrative repository, holding contracts, personal documents and financial information for hundreds of small business owners.
That kind of system usually has looser controls because it doesn't halt operations when it fails. Security is prioritised by what interrupts revenue, and a document repository interrupts nothing.
The content, however, doesn't follow that hierarchy. A partner's identity document and a signed contract are worth more to a scammer than the sales history the main system guards zealously.
The review that solves much of this fits in a morning: list where documents with personal data live, remove access for people who left, delete what's past retention, and define who owns that system.
