Beyond the immediate headache for consumers impacted by a data breach, new Virginia Tech research has found they can also trigger years of financial repercussions such as mortgage refinancing and home improvement loan denials. Using data from the 2012 South Carolina Department of Revenue breach, Tony Vance, professor of business information technology in the Pamplin College of Business, discovered a 22 percent increase in loan denials following the incident by comparing border counties in South Carolina with neighboring counties in Georgia and North Carolina.
“The impact of data breaches is notoriously difficult to quantify because of the sensitivity of data, including Social Security numbers,” Vance said. “What differentiates this study is that we were able to use a rare natural experiment because every taxpayer in South Carolina was impacted by this breach. By comparing South Carolina counties with neighboring counties in Georgia and North Carolina, we showed a direct effect between the breach and subsequent financial harm.”
To ensure the data was not skewed by residents moving into new homes from out of the area, the researchers only analyzed data from existing residents who were applying to either refinance their mortgage or apply for home improvement loans. This allowed them to localize the impact of the breach and create a clear comparison between denials in South Carolina and adjacent states.
The findings show that the financial consequences of a data breach can persist for years for consumers, but companies involved may recover much more quickly.
“One of the frustrating things is that after a data breach, a company’s stock usually takes a hit, but it recovers within about 30 days,” Vance said. “So, it’s clear that these companies are not bearing the long-term costs. This suggests a market failure.”
Companies may also go for weeks to months without being aware of the breach, and when they do find out, they often do not discover it themselves. This means that consumers may not be notified until months later. According to Vance, companies commonly learn from law enforcement or their internet service providers, and the longer the breach goes undetected, the more at-risk consumer data becomes.
Beyond the immediate cybersecurity implications, the study adds to a growing body of research examining how technology failures create broader economic consequences for consumers, businesses, and markets.
Consumers cannot stop corporate data leaks from occurring. However, Vance said there are proactive ways consumers can protect their data from long-term damage:
- Place a credit freeze by calling credit bureaus to block attempts to open new lines of credit.
- Use a password manager to create and store unique login information for various sites.
- Sign up for notification services that inform consumers of a data breach that often notify a victim before the official company breach notifications are sent.
- Change passwords for the breached company’s website immediately to help prevent further damage.
Vance’s research provides rare evidence of consumer financial harm caused by a data breach. By demonstrating the real-world cost of corporate leaks, the study highlights the importance of proactive cybersecurity measures for consumers and the long-term impacts that can occur.
The research was published in MIS Quarterly and coauthored by Min-Seok Pang from the University of Wisconsin-Madison. It also received the 2026 AOM CTO Division Best Published Paper Award from MIS Quarterly.
Original study: doi.org/10.25300/MISQ/2024/18787
