A service you use just got breached. Here is your response, step by step
This week's news that a widely used AI platform was breached, with reports of a follow-on extortion demand, is a reminder of a risk every business now carries: you can do everything right and still be exposed because a service you depend on was compromised. The damage usually comes not from the breach itself but from the business doing nothing in response.
Why someone else's breach becomes your problem
Your business runs on other people's software — email, storage, hosting, payments, design tools, AI services. Each one holds some of your data or credentials. When one is breached, attackers get whatever it held: your login there, and by extension any other account where you reused that password, plus whatever business data lived in it.
The recent AI-platform incident is a specific case, but breaches of SaaS providers are routine. The response is the same regardless of which vendor it is.
The response checklist
- Confirm it is real. Check the vendor's official status page or security bulletin, not a screenshot on social media. Breach rumours spread faster than facts. Attackers also send fake "you were breached, reset here" phishing that piggybacks on real news — go to the site directly, never through an emailed link.
- Change your password on that service. Immediately, and to something unique.
- Change it anywhere you reused it. This is the step that actually limits damage. If you cannot remember where you reused it, that is exactly why a password manager matters.
- Revoke sessions and API keys. A password change does not always kick out an active session or disable an API token. Do those separately.
- Turn on MFA if it was not already. A stolen password is far less useful to an attacker when a second factor is required.
- Check what data was exposed. Customer records, client files, payment details? If personal data of others was involved, you may have notification obligations — take advice.
- Watch for targeted phishing. After a breach, attackers use the leaked data to send convincing, personalised messages. Warn your team to be extra sceptical for a few weeks.
The extortion angle, specifically
When a breach is followed by a ransom or extortion demand, the pressure is on the breached vendor, not usually on you. But two things matter for your business:
- Do not pay anyone who contacts you claiming to hold your data. Verify independently through the vendor. Extortion news attracts copycats who email customers pretending to be the attackers.
- Assume exposed data stays exposed. Even when a vendor pays, treat compromised data as permanently out. Rotate anything sensitive it contained — credentials, keys, tokens.
What to have ready before it happens
You cannot stop a vendor being breached, but preparation turns it from a scramble into a checklist:
| Preparation | Why it helps on the day |
|---|---|
| Unique passwords via a manager | One breach cannot cascade into ten accounts |
| MFA on important accounts | A leaked password alone is not enough to get in |
| A list of which vendors hold what data | You know immediately what is at risk |
| Tested backups | You can recover if data is destroyed, per our backup guide |
| An incident contact page | Nobody researches calmly mid-incident |
| Least-privilege access | A breached integration can reach less |
The uncomfortable part: vendor choice is a security decision
Every SaaS tool you add is another company whose security failures become yours. That is not a reason to avoid tools, but it is a reason to be deliberate:
- Favour vendors with a visible security posture and a real status page.
- Do not scatter sensitive data across a dozen half-used services — the software audit reduces your exposure surface as a side effect of cutting cost.
- For AI tools specifically, mind what you paste in; the classification in our AI policy guide exists partly for this.
The summary
Breaches of the services you rely on are now a normal operating hazard, not a rare event. You cannot prevent them, but you decide how much they cost you. Unique passwords, MFA, knowing which vendor holds what, and tested backups turn a vendor breach from a crisis into an afternoon of resets. The businesses that get hurt are the ones that reused one password everywhere and found out the hard way.
No company paid for placement in this article. Verify current prices and terms with each provider before buying.