Welcome to the first Post-Breach Briefing, our quarterly note for security, risk, legal and public-sector leaders on the stage that incident response does not close: what happens to data after it has been copied.
The incident ends. The data carries on.
Most breach reporting follows the attack: how attackers got in, how long systems were down and when operations recovered. For the organisation, and for the people in the records, a second timeline starts when the data leaves. Copied records do not expire when the attacker is removed. They can be sold, published, used for extortion or used to make scams more convincing, months after recovery is declared.
Three incidents from 2025 show the pattern.
1. Co-op (UK): every member record copied
In July 2025, Co-op's chief executive confirmed that all 6.5 million members had their data stolen in the April attack. Names, addresses and contact information were taken; Co-op said no financial or transaction data was involved. Systems were brought back, but the copied records remain outside Co-op's control. Source: BBC News
2. Qantas (Australia): published three months later
Customer data stolen via a third-party platform in early July 2025 was released by a criminal group in October, after a ransom deadline passed. Qantas said about 5.7 million people were affected and obtained a court injunction to stop people in Australia from accessing, viewing or releasing the data. The value of the stolen copy lasted well beyond the original incident. Sources: The Record, The Guardian
3. Kido nurseries (UK): relying on the attacker's word
In September 2025, criminals posted profiles of children taken from the Kido nursery chain and threatened further releases unless a ransom was paid. After public outcry they took the posts down and claimed to have deleted the private details and pictures of around 8,000 children. Nobody outside the group can confirm that deletion. Source: BBC News
What the three have in common
In each case, prevention and response did their jobs to some degree: attacks were contained, systems recovered and regulators were notified. What none of those steps could change was how the copied data could be used afterwards. Organisations were left with injunctions, notifications, customer warnings and attackers' promises.
That is the gap boards, regulators and insurers increasingly ask about. Not only "how did they get in?" but "what could be done with what they took, and what can you show?"
Where PastWipe fits
PastWipe™ is post-breach data control for enterprise and government. It attaches policy to selected high-value data and re-checks identity, device, purpose and the current security state each time protected data is used. Uses outside approved conditions are denied, restricted or degraded, and every decision is recorded as evidence for audit, investigation, legal and insurance review.
PastWipe works alongside your existing IAM, EDR, DLP, SIEM and incident response, and coverage is agreed for each deployment. US patent pending.
Scope an evaluation
Pick one data class and one workflow where a stolen copy would cause real harm. We will agree the conditions, signals and success criteria with you before anything is deployed. Nothing is deployed and no data is shared until the scope is agreed in writing.
All insights and news · Get the quarterly Post-Breach Briefing
