Breach notifications follow a recognisable template built under legal advice and time pressure. Reading one properly means attending to the tense of the verbs, the scope of the nouns, and the questions the letter answers instead of the ones you asked. A guide to the standard phrases and what each one leaves open.
The document is not lying to you
It was drafted at speed, under legal review, while the investigation was still running, by people having the worst week of their professional lives.
Its caution is usually honest caution. A sentence that seems evasive is often a sentence somebody could not responsibly make stronger at the time it had to be sent.
Reading it well means understanding the constraints it was written under. Assuming bad faith produces worse readings than assuming good faith and attending to the grammar.
Phrases and what they leave open
"We have no evidence that X was accessed." A statement about the evidence, not about the access. Its strength depends entirely on how much logging existed and how far back it reached. Where instrumentation was thin, this sentence is nearly empty — and the letter will not tell you which case you are in.
"Passwords were encrypted." Usually means hashed, which is a different operation. The useful questions are which function and whether it was chosen to be slow. A modern password-hashing function buys you weeks; a fast general-purpose digest buys you very little.
"A limited number of accounts." Limited relative to what is never stated.
"We detected unusual activity on [date]." The date of detection. Not the date of entry.
"The incident has been contained." The access has stopped. Nothing has been said about what left while it was open.
"We have engaged a leading forensic firm." True, correct, standard, and not information about you.
The number nobody volunteers
Dwell time: the interval between entry and detection.
It matters more than the count of affected records, because it bounds what somebody had the opportunity to reach. A thousand records over four hours and a thousand over eleven months are different events wearing the same headline.
Its absence is rarely sinister. It is absent because it is either unknown — which is itself informative about the logging — or known and unflattering. Both readings are worth having, and the letter permits neither to be confirmed.
Why the letter is vague about scope
Early estimates revise upward. They almost always do, as investigators find systems nobody had mapped.
An organisation that publishes a figure and corrects it upward twice is treated far more harshly than one that stayed general throughout, even when the first was being more open.
So the incentive produces vagueness without requiring anybody to intend it. Worth knowing before reading imprecision as evasion — the process rewards imprecision on its own.
The advice section was written before the incident
Every notification ends with a block of guidance: change your password, monitor your accounts, remain vigilant.
That block is boilerplate. It was drafted in advance, it is identical across incidents involving entirely different categories of data, and it is calibrated to be safe to send rather than to be useful to you.
Which means the letter's two halves have different evidentiary value. The specific paragraphs — what was taken, when, from where — are worth close reading. The closing advice is a template, and what you should actually do depends on which categories of data were in it, a question the letter answers only in outline and which deserves its own treatment.
One thing does follow directly from the document, though: expect approaches that reference it. They will be the most convincing you ever receive, because they are true, timely and specific, and because you are now expecting to be contacted. Reach the organisation through a number you found yourself, never one supplied to you.
What a good notification contains
When entry occurred, alongside when it was detected.
Which fields were exposed, named, rather than a category like contact information.
Which hashing function protected the credentials, stated plainly enough to be looked up.
What has been changed since, in terms specific enough to be wrong about.
And a route to a person who can answer a question that the template did not anticipate.
Each of those costs something to publish. That cost is what makes their presence meaningful.
Close
The letter is evidence about the incident and evidence about the organisation, and the second reading is usually the more durable of the two.
One tells you what happened to your data. The other tells you what to expect the next time, which is the question you were really asking.
