Breach Please

Breach Please Team

Cybersecurity has a nonsense problem. Vendors overpromise, headlines overhype, and half the "experts" in your feed have never actually responded to an incident at 3 a.m. Breach Please is the antidote — cybersecurity news, analysis, and unfiltered commentary from two people who have actually done the work: breaking into networks, defending them, and cleaning up after the breaches everyone else only tweets about. Every episode, Jake Williams and Jess Hebenstreit break down the stories that matter, call out the nonsense that doesn't, and translate the never-ending chaos into something you can actually use — whether you're in the SOC, the boardroom, or somewhere pretending to understand both. No fear-mongering. No vendor scripts. No "synergizing our threat posture." Just two seasoned practitioners, the news that matters, and the takes your CISO wishes they could say out loud. Breach? Please. Pull up a chair.

  1. 16h ago

    S0E23. The LA County Museum of Art breach that took a year to unravel

    LACMA’s year-long breach disclosure delay and what it says about incident responseJess Hebenstreit and Jake Williams break down a Los Angeles County Museum of Art data security incident that raises big questions about breach timelines, notification delays, and response ownership. They focus on what the disclosure says, what it leaves unsaid, and why the cleanup process may have taken far longer than it should have. In this episode, they examine the gap between initial detection, timeline validation, data review, and eventual notification. They also unpack why the kind of data exposed suggests employee and benefits records, and why that matters for both legal exposure and response logistics. Key topicsThe breach timeline looks unusually longJess and Jake note that LACMA says it detected suspicious activity on July 11, 2025, but did not publish the disclosure until August 24, 2026.They question how it took weeks to confirm the intrusion window and then months more to complete the data review. The delay in scoping the incident raises red flagsJake points out that the investigation later narrowed the third party’s access to July 7 through July 11.They discuss how incident teams can get stuck chasing false leads in logs, but still say this timeline feels slow. Data review appears to have dragged onThe disclosure says the initial data review results arrived in late February 2026.Jess and Jake interpret that as a sign of weak data governance, poor vendor management, or both. The affected data suggests employee and benefits recordsThe potentially exposed data includes full names, dates of birth, Social Security numbers, government ID numbers, financial account numbers, payment card data, health insurance information, and limited medical details.Jess argues that this pattern looks like employee data, possibly tied to a self-funded health plan. Notification logistics seem inconsistentJake questions why the organization spent months trying to obtain “accurate contact information” before notifying impacted people.He notes that breach notification rules generally do not wait for perfect contact data before state reporting obligations begin. A class action lawsuit seems likelyJess says she expects litigation, and Jake agrees.They also suggest state attorney general investigations are likely. The response may have suffered from leadership turnoverJess thinks a change in leadership or responsibility may have disrupted the response.Jake agrees that handoffs, missing context, or people being removed mid-incident can create major problems. They believe outsourcing the data review was the right move, but too lateJake explains why identifying impacted records is harder than it sounds, especially with inconsistent name formats, spellings, and duplicate records.Both agree this kind of work should be handled by a firm that does breach review every day. Cyber insurance and breach counsel likely shaped the responseThey debate whether the organization had cyber insurance and how that would have affected the handling of the case.Jake explains that cyber claims usually involve upfront costs and reimbursement later, which can slow response work. The human cost of a broken incident responseJess closes by saying she feels bad for the responders who had to deal with the mess.Jake advises responders to keep notes, assume they may be deposed later, and remember that the organization will not protect them in enforcement actions. Timestamps00:00 - Breach Please intro and the show’s no-nonsense mission 01:33 - LACMA data security incident enters the conversation 01:50 - Why the disclosure timeline is so hard to believe 03:18 - What the timeline says about detection and scoping 06:01 - Late February 2026 data review results 07:57 - Why “accurate contact information” is a weak explanation 08:52 - Why a lawsuit and state investigations seem likely 09:27 - The exposed data and why it looks like employee records 10:54 - A Reddit post suggesting notifications were already going out 12:12 - Possible leadership change during the response 13:37 - When even counsel decides the incident is too messy 15:31 - Whether cyber insurance was involved at all 17:04 - How cyber claims actually get paid 18:38 - Procurement problems or failed in-house review? 20:21 - Why identifying impacted people is much harder than it sounds 22:36 - Why outsourcing the review was probably necessary 23:35 - Why state reporting obligations still matter even if mailing is slow 24:04 - Sympathy for the responders caught in the middle 25:02 - Why responders should document everything now 25:57 - Final reminder: organizations do not protect employees in enforcement actions 26:11 - Outro and closing sign-off

  2. Aug 20

    S0E17: Amazon vs Perplexity Reveals the First Big AI Agent Liability Test

    AI agents are about to test the limits of who gets blamed when they act on your behalf. A new Ninth Circuit ruling in the Amazon vs. Perplexity fight could reshape how enterprises think about autonomous tools, non-human identities, and legal exposure - and the takeaway is more unsettling than most vendors will admit. Jake Williams and Jess Hebenstreit break down what happened when Amazon pushed back against Perplexity’s AI browser, why the CFAA and California’s CDFAA matter here, and how the court’s reasoning could shift responsibility from the agent publisher to the organization that deploys it. They also dig into what this means for legal teams, risk registers, and why every AI agent needs its own identity instead of borrowing a human user’s. You’ll also hear how this ruling fits into the bigger enterprise governance problem: who owns AI risk, who should be accountable when an agent crosses a line, and why security teams can’t be expected to carry every line-of-business risk themselves. Jake and Jess make the case for splitting cybersecurity risk from business risk, naming a real owner, and making legal counsel aware before your agent does something expensive. Then the conversation pivots to another cautionary tale: a 3M expert witness who allegedly used ChatGPT to generate a report aimed at proving the company was 0% at fault in a gas detector explosion case. That story opens up a bigger discussion about leading prompts, hallucinated conclusions, discoverability, and why AI-generated work product can become evidence against you. Perfect for security leaders, legal teams, incident responders, and anyone deploying AI agents in the enterprise.

About

Cybersecurity has a nonsense problem. Vendors overpromise, headlines overhype, and half the "experts" in your feed have never actually responded to an incident at 3 a.m. Breach Please is the antidote — cybersecurity news, analysis, and unfiltered commentary from two people who have actually done the work: breaking into networks, defending them, and cleaning up after the breaches everyone else only tweets about. Every episode, Jake Williams and Jess Hebenstreit break down the stories that matter, call out the nonsense that doesn't, and translate the never-ending chaos into something you can actually use — whether you're in the SOC, the boardroom, or somewhere pretending to understand both. No fear-mongering. No vendor scripts. No "synergizing our threat posture." Just two seasoned practitioners, the news that matters, and the takes your CISO wishes they could say out loud. Breach? Please. Pull up a chair.