cybersecurity
laptop screen with money being sucked into the screen

Breach-Driven Bankruptcies: When a Cyberattack Ends the Business

David Stells
Senior Security and Delivery Executive

For years, data breaches were treated as costly but manageable events—nuisances that prompted press releases, customer apologies, and perhaps a fine or two. But that era is over. Today, a single breach can destroy a business entirely. Cybersecurity failures are no longer isolated IT problems; they’re existential events. We now live in a world where breach-driven bankruptcies are not rare—they’re multiplying.

What makes a breach fatal?

What makes a breach fatal rather than merely disruptive? It’s rarely the technical damage alone. Rather, it’s the convergence of the breach with underlying weaknesses: fragile financials, poor vendor oversight, a lack of resilience planning, and reputational fragility. The cyberattack is often just the spark—what follows is a systemic collapse.

Consider the cautionary case of Code Spaces, a DevOps platform that suffered a full compromise of its AWS environment in 2014. An attacker took control of the company’s admin console and deleted everything—source code, backups, configurations—when a ransom wasn’t paid. Within two days, Code Spaces was gone. It didn’t fail gradually. It evaporated.

Other collapses played out more slowly, but no less terminally. Travelex, the international currency exchange firm, was hit by ransomware in late 2019. Its systems went offline for weeks, and the timing couldn’t have been worse. As the COVID-19 pandemic erupted, international travel—and Travelex’s core business—ground to a halt. The cyberattack didn’t cause the pandemic, but it prevented Travelex from weathering it. The company filed for administration in 2020 and laid off over 1,300 employees.

Then there is AMCA—the American Medical Collection Agency. The firm handled billing data for major healthcare labs like Quest Diagnostics and LabCorp. When AMCA’s systems were breached in 2019, the personal and financial data of more than 25 million patients was exposed. Lawsuits, regulatory investigations, and client terminations followed. Within months, AMCA filed for bankruptcy. It wasn’t just the loss of data that did them in—it was the erosion of trust from both clients and regulators.

The most prominent recent example is 23andMe. In 2023, the genetic testing company suffered a credential-stuffing attack that exposed sensitive ancestry and genetic profiles for millions of users. While the immediate cause was user password reuse, the public—and regulators—perceived a deeper failure. How could a company that trades in immutable, intensely personal biometric data not foresee this threat? The breach was followed by lawsuits, plummeting investor confidence, and regulatory scrutiny. By early 2025, 23andMe filed for Chapter 11 protection. The reputational damage proved irreversible.

These examples have something in common. The breach was the catalyst, but the collapse occurred because the companies lacked the systems—technical, financial, operational, and reputational—to absorb the blow.

Worse still is when the damage spreads beyond the breached company. In 2024, Change Healthcare, a subsidiary of UnitedHealth Group and one of the largest healthcare payment processors in the United States, fell victim to ransomware. The breach paralyzed core systems used to process billing, prescriptions, and insurance claims for thousands of clinics and hospitals. According to the American Medical Association, 80% of physician practices reported lost revenue as a direct result. Small and rural clinics were hit the hardest, with many reducing hours, laying off staff, or shutting down altogether. Some were forced to sell to larger hospital systems just to survive.

This is what we now call the “spider effect”—when a breach in one organization ripples outward, destabilizing dozens or even thousands of others. In the case of Change Healthcare, the economic impact of the breach was national in scope. And while UnitedHealth eventually provided billions in emergency financial assistance, many providers later reported being pressured to repay those funds even while operations remained offline. In an already strained healthcare system, the breach caused lasting structural damage.

These events expose a critical truth: cyber risk is no longer confined to the breached entity. It’s systemic. In our interconnected infrastructure—where one company’s backend powers thousands of others—the failure of one node can compromise the whole web.

Legal and regulatory environments have also shifted. Regulators in both the U.S. and Europe now view data protection as a matter of public interest. General Data Protection Regulation (GDPR) enforcement can result in fines of up to 4% of global revenue. U.S. state laws like the California Consumer Privacy Act (CCPA) are becoming stricter and more actively enforced. Lawsuits increasingly follow large breaches—often before investigations are complete—and companies are now held to ethical as well as legal standards. Firms like 23andMe didn’t just face legal challenges—they faced moral outrage from a public that felt betrayed.

So, what can be done? The companies that failed offer painful lessons. Cybersecurity cannot remain the sole responsibility of IT departments. Boards and executives must internalize that cybersecurity is strategic—tied directly to enterprise risk, valuation, and brand survival. Planning for resilience is just as important as preventing attacks. Backups must be tested. Breach drills must be cross-functional. Third-party vendors must be vetted continuously, not just during onboarding. And perhaps most importantly, companies that handle sensitive or biometric data must lead with ethical transparency. Consent buried in fine print is not a viable defense.

In the current climate, breach survival is no longer guaranteed. Companies must ask themselves a blunt but essential question: If we suffered a breach tomorrow, would we survive it?

If the answer is uncertain, then maybe cybersecurity needs re-prioritizing in your organization.