Breach Please

Breach Please Team

Cybersecurity has a nonsense problem. Vendors overpromise, headlines overhype, and half the "experts" in your feed have never actually responded to an incident at 3 a.m. Breach Please is the antidote — cybersecurity news, analysis, and unfiltered commentary from two people who have actually done the work: breaking into networks, defending them, and cleaning up after the breaches everyone else only tweets about. Every episode, Jake Williams and Jess Hebenstreit break down the stories that matter, call out the nonsense that doesn't, and translate the never-ending chaos into something you can actually use — whether you're in the SOC, the boardroom, or somewhere pretending to understand both. No fear-mongering. No vendor scripts. No "synergizing our threat posture." Just two seasoned practitioners, the news that matters, and the takes your CISO wishes they could say out loud. Breach? Please. Pull up a chair.

  1. 6 days ago

    S0E23. The LA County Museum of Art breach that took a year to unravel

    LACMA’s year-long breach disclosure delay and what it says about incident responseJess Hebenstreit and Jake Williams break down a Los Angeles County Museum of Art data security incident that raises big questions about breach timelines, notification delays, and response ownership. They focus on what the disclosure says, what it leaves unsaid, and why the cleanup process may have taken far longer than it should have. In this episode, they examine the gap between initial detection, timeline validation, data review, and eventual notification. They also unpack why the kind of data exposed suggests employee and benefits records, and why that matters for both legal exposure and response logistics. Key topicsThe breach timeline looks unusually longJess and Jake note that LACMA says it detected suspicious activity on July 11, 2025, but did not publish the disclosure until August 24, 2026.They question how it took weeks to confirm the intrusion window and then months more to complete the data review. The delay in scoping the incident raises red flagsJake points out that the investigation later narrowed the third party’s access to July 7 through July 11.They discuss how incident teams can get stuck chasing false leads in logs, but still say this timeline feels slow. Data review appears to have dragged onThe disclosure says the initial data review results arrived in late February 2026.Jess and Jake interpret that as a sign of weak data governance, poor vendor management, or both. The affected data suggests employee and benefits recordsThe potentially exposed data includes full names, dates of birth, Social Security numbers, government ID numbers, financial account numbers, payment card data, health insurance information, and limited medical details.Jess argues that this pattern looks like employee data, possibly tied to a self-funded health plan. Notification logistics seem inconsistentJake questions why the organization spent months trying to obtain “accurate contact information” before notifying impacted people.He notes that breach notification rules generally do not wait for perfect contact data before state reporting obligations begin. A class action lawsuit seems likelyJess says she expects litigation, and Jake agrees.They also suggest state attorney general investigations are likely. The response may have suffered from leadership turnoverJess thinks a change in leadership or responsibility may have disrupted the response.Jake agrees that handoffs, missing context, or people being removed mid-incident can create major problems. They believe outsourcing the data review was the right move, but too lateJake explains why identifying impacted records is harder than it sounds, especially with inconsistent name formats, spellings, and duplicate records.Both agree this kind of work should be handled by a firm that does breach review every day. Cyber insurance and breach counsel likely shaped the responseThey debate whether the organization had cyber insurance and how that would have affected the handling of the case.Jake explains that cyber claims usually involve upfront costs and reimbursement later, which can slow response work. The human cost of a broken incident responseJess closes by saying she feels bad for the responders who had to deal with the mess.Jake advises responders to keep notes, assume they may be deposed later, and remember that the organization will not protect them in enforcement actions. Timestamps00:00 - Breach Please intro and the show’s no-nonsense mission 01:33 - LACMA data security incident enters the conversation 01:50 - Why the disclosure timeline is so hard to believe 03:18 - What the timeline says about detection and scoping 06:01 - Late February 2026 data review results 07:57 - Why “accurate contact information” is a weak explanation 08:52 - Why a lawsuit and state investigations seem likely 09:27 - The exposed data and why it looks like employee records 10:54 - A Reddit post suggesting notifications were already going out 12:12 - Possible leadership change during the response 13:37 - When even counsel decides the incident is too messy 15:31 - Whether cyber insurance was involved at all 17:04 - How cyber claims actually get paid 18:38 - Procurement problems or failed in-house review? 20:21 - Why identifying impacted people is much harder than it sounds 22:36 - Why outsourcing the review was probably necessary 23:35 - Why state reporting obligations still matter even if mailing is slow 24:04 - Sympathy for the responders caught in the middle 25:02 - Why responders should document everything now 25:57 - Final reminder: organizations do not protect employees in enforcement actions 26:11 - Outro and closing sign-off

About

Cybersecurity has a nonsense problem. Vendors overpromise, headlines overhype, and half the "experts" in your feed have never actually responded to an incident at 3 a.m. Breach Please is the antidote — cybersecurity news, analysis, and unfiltered commentary from two people who have actually done the work: breaking into networks, defending them, and cleaning up after the breaches everyone else only tweets about. Every episode, Jake Williams and Jess Hebenstreit break down the stories that matter, call out the nonsense that doesn't, and translate the never-ending chaos into something you can actually use — whether you're in the SOC, the boardroom, or somewhere pretending to understand both. No fear-mongering. No vendor scripts. No "synergizing our threat posture." Just two seasoned practitioners, the news that matters, and the takes your CISO wishes they could say out loud. Breach? Please. Pull up a chair.