Using algorithms to charge different customers different prices for the same products or services is not illegal. We encounter such dynamic pricing every day. Rideshare apps have surge pricing; hotel prices fluctuate nightly, and there are countless other examples of algorithmic pricing based on supply and demand.

However, things get dicey when companies combine algorithmic pricing with troves of personal consumer data, and then use that personal data to set individualized prices. In my opinion, this pernicious practice, called “surveillance pricing,” should be illegal.

Thankfully, certain actions are being taken at the state level. Maryland, Connecticut, and New York have passed surveillance pricing laws, and already in 2026, 40 more bills have been put forth in over 24 different states.

Over the past few months, surveillance pricing has gone from a wonky tech policy issue to a mainstream issue with a lot of cross-partisan appeal. Much of surveillance pricing’s newfound awareness can be traced back to a December 2025 investigation of Instacart.

Instacart investigation

According to an investigation from Consumer Reports and Groundwork Collaborative, Instacart allegedly was conducting “widespread AI-enabled experiments that price identical products differently from one customer to the next, sometimes by as much as 23 percent.” In the wake of the report, Instacart stopped doing these “pricing experiments.”

Lindsey Owens, executive director of Groundwork Collaborative, went on the record, saying, “Once we pulled back the curtain on Instacart’s hidden pricing experiments, the company had no choice but to reverse course. But it shouldn’t take investigative research, public outcry, and the threat of FTC action to convince companies not to treat consumers like lab rats.”

JetBlue’s alleged surveillance pricing practices under scrutiny

By no means are surveillance pricing accusations limited to the tech industry. As a quick example, JetBlue was recently accused of using individual’s internet search histories to charge customers different prices for the same flights.

Responding to a social media post from the New York-based airline, Texas congressman Greg Casar (D-Austin, TX) wrote, “Using people’s personal data to charge them more should be illegal.” In February 2026, Sen. Ruben Gallego (D-Arizona) brought even more awareness to these surveillance pricing accusations, when he formerly asked JetBlue CEO Joanna Geraghty for more information.

A class action lawsuit against JetBlue is making its way through the courts. For his part, Casar put forth a “Stop AI price gouging and wage fixing” bill last July; however, it didn’t gain much traction.

In fact, there hasn’t been any surveillance pricing legislation at all at the federal level. Although an FTC study under Lina Khan did find that a wide range of personal data was, indeed, being used to set individualized consumer prices, the current administration downplayed the findings. Current FTC chair Andrew Ferguson has described the report as “a rush job.”

Given Ferguson’s take, I don’t expect anything to happen at the federal level, but it is heartening to see some action being taken at the state level.

Maryland becomes the first state to pass a ban on surveillance pricing

On April 28, 2026, Maryland Gov. Wes Moore signed the Protection From Predatory Pricing Act into law. Taking effect on October 1, 2026, this law prevents grocery stores, food retailers, and third-party delivery services from setting higher prices based on individual customers’ personal data.

Although anti-surveillance advocates are happy to see an increased focus on surveillance pricing, they lament that Maryland’s law has a bunch of industry carve-outs. Tom McBrien, counsel at the Electronic Privacy Information Center (EPIC), says, “We’re excited Maryland took this step, but we do have serious concerns. The exemptions allow other ways of arriving at the same outcome that are just harder for consumers to detect.”

In addition to providing exemptions for promotional offers and loyalty programs, the Maryland law does not address the reduction of prices. If a grocery store were to raise prices across the board and then offer individual discounts to certain individuals, “suddenly you’ve arrived at the same outcome,” McBrien points out.

Also, the Maryland law has no private right of action; all enforcement comes via the state Attorney General.

Connecticut passes its own law

On June 4, 2026, Connecticut Gov. Ned Lamont signed a surveillance pricing ban into law. Connecticut’s law is significantly stronger than Maryland’s, as it casts a much wider net, covering retail sellers and third-party delivery services. Unlike Maryland’s law, this one isn’t solely limited to food sales.

Additionally, the Connecticut law has a disclosure requirement, which forces retailers that use surveillance pricing to disclose whenever a price has been raised due to a customer’s personal data.

Like Maryland’s law, the Connecticut law doesn’t have a private right of action, and the loophole of raising prices across the board and subsequently offering discounts to certain individuals is not addressed.

The New York state legislature follows suit

Not to be outdone, the New York legislature passed its own surveillance pricing bill on June 4. New York’s One Fair Price Act, which is currently on the desk of Governor Hochul, is much broader than the Maryland bill, and it carries various civil penalties for violating companies. Hochul has until December 31, 2026 to sign this bill.

New York already has a disclosure law in place, which requires companies to disclose whenever they’ve used an algorithm to set a price using customers’ personal data. This law, the Algorithmic Pricing Disclosure Act, has been in effect since November 2025; however, the One Fair Price Act would go much further. If passed in its current form, it would essentially be an outright ban on surveillance pricing. Between now and the end of the year, we can expect tech lobbyists and industry trade organization representatives to be in Horchul’s ear.

Colorado Gov. Jared Polis and tech industry lobbyists have a different viewpoint

On June 3, 2026, Gov. Polis (D-CO) vetoed a surveillance pricing bill that would have banned the use of surveillance pricing to set worker’s wages and the price of consumer goods.

To be fair, this bill was larger in scope than the Maryland, Connecticut, and New York bills, as it would have applied to all sorts of industries, and workers’ wages as well. For example, it would have prevented rideshare companies from setting drivers’ wages based on data collected on them.

Tech and retail industry lobbyists agreed with Polis’ judgment, as they argued that the law was overly broad, likely to disrupt markets, and spur frivolous lawsuits. A common argument from lobbyist groups is that surveillance pricing bans prevent companies from offering customer discounts and loyalty programs, although we’ve already seen carve-outs for such things in the Maryland and Connecticut laws.

Given the situation with JetBlue, I suppose the argument that these surveillance pricing bans will spark class action lawsuits has some credence as well. However, I’d argue that a few class action lawsuits are warranted, at least in some instances.

Advice for organizations using surveillance pricing mechanisms

As a reminder, dynamic pricing is perfectly legal. Changing prices based on supply and demand, time of day, and inventory is all permitted; what is not permitted under these new laws is surveillance pricing: using individuals’ personal consumer data to set different prices for the same goods and services.

To get ahead of the privacy legislation, organizations should examine their pricing strategies to assess exactly what, if any, personal consumer data goes into the organization’s pricing algorithms. Under certain circumstances, state Attorney Generals, and possibly the FTC, will demand this information, so it is best to be prepared.

Also, Maryland and Connecticut now have bans on surveillance pricing of retail and food delivery services. New York could have an even stronger law coming down the pike, and at least 24 other states have similar legislation in the works. Surveillance pricing is no longer a low-risk business activity. Even if the federal government remains on the sidelines, it looks like some states will take data privacy matters into their own hands.

There is a particular kind of professional betrayal that stings the most. It’s not the loud kind, where someone storms out of the room, but the subtle kind, where they smile, stay seated, and start feeding you slightly wrong information. By the time you figure it out, the meeting is over and the decisions are already made.

That is what Claude Fable 5 introduced to enterprise AI on June 9, 2026. If you’re a CTO, CIO, or CEO building strategy on top of AI infrastructure, pay close attention. Not because Anthropic did something cartoonishly evil, but because what they did is arguably more unsettling. It was reasonable, well-documented, defensible, and it broke something foundational about the relationship between an enterprise and its tools.

Claude Fable 5 performance: What the benchmarks actually show

Claude Fable 5 is exceptional. SWE-bench is the industry’s standard test for AI coding ability. It throws real, unsolved GitHub bugs at the model and scores how many it fixes without human help. Fable 5 hits 95% on the verified version and 80.3% on the harder Pro variant, a 22-point lead over GPT-5.5.

In plain English: it writes and fixes production-grade code at a level no public model has reached before. Stripe put that to the test by running a 50-million-line Ruby migration in a single day; their estimate was it would require a human team more than two months to accomplish this. This is a machine that, on the right tasks, outperforms human teams.

And that’s precisely why what comes next matters so much.

What Anthrophic’s Claude Fable 5 system card reveals about enterprise AI risk

Buried in Fable 5’s system card was a disclosure unlike anything a major AI lab has published before. For certain requests, specifically anything related to building advanced AI systems from scratch, Fable 5 is engineered to underperform. It won’t refuse or flag the request as restricted. It will answer you, except the answer would be deliberately worse than what the model is actually capable of. And you would have no way of knowing because the model would not tell you. It would just produce responses that look complete and helpful but are designed to be less useful than they should be.

The system card is unambiguous: “These safeguards will not be visible to the user. Fable 5 will not fall back to a different model. Instead, the safeguards will limit effectiveness.”

Developer Clay Merritt put it plainly: “Anthropic’s Fable 5 silently sabotages its answers when it detects AI/ML work. No refusal. No notice. Purposeful degradation invisible to the user.”

Anthropic’s rationale was safety. Their worry: if Claude helps rival AI labs build better models faster, and those labs don’t have the same safety standards, the whole industry gets more dangerous. Fair enough, in principle. To soften the blow, they added that these restrictions would only affect 0.03% of traffic, essentially telling the world “relax, almost nobody will notice.” That number sounds reassuring because it was designed to. But the 0.03% that does get affected isn’t a random slice of users. It’s the most strategically important ones.

The enterprise AI trust problem Claude Fable 5 just made real

There is a concept in economics called the principal-agent problem: what happens when the agent you hired starts serving their own interests. Corporate governance exists largely to manage this. For decades, software just did what you told it to. It had no interests of its own, no reason to give you anything less than its best.

Claude Fable 5 changed this. For the first time, a commercially deployed AI model has been officially documented to produce intentionally degraded outputs. And this wasn’t a bug that slipped through testing or a technical limitation the team was working to fix. It was a deliberate policy decision, made unilaterally by the vendor, with no obligation to tell you about it.

With a normal reliability problem, you at least know something is wrong. A server goes down, an API throws an error, and you know exactly what to fix. But this is a different kind of problem. When Claude gives you a weak answer on an ML infrastructure question, you now have four possible explanations: the model misunderstood the context, you lacked detail, the task hit a ceiling, or the model was instructed to underperform on exactly this task type. Three are normal. One means the tool is working against you. And you cannot tell the difference from the output.

For a CTO managing AI-assisted engineering teams, that ambiguity is a governance crisis. Your entire quality assurance framework, code reviews, output validation, performance benchmarks, is built on the assumption that when a tool underperforms, you can diagnose why. But a tool that is deliberately designed to hide its own limitations breaks that assumption completely.

Why Anthrophic’s 0.03% claim should concern every AI leader

If your AI usage covers drafting emails, summarizing contracts, generating boilerplate, you’re probably in the safe majority. But if you’re a tech company with serious ambitions in AI-adjacent infrastructure or custom model development, the probability that your highest-value work sits inside that throttled minority is significantly higher than 0.03%.

Then there is the justification structure. When Anthropic framed these interventions as safety measures, they placed them in the one category enterprise customers have no framework to contest. If a vendor changes pricing, you renegotiate. If performance degrades, you invoke the SLA. But “safety” carries moral weight that commercial arguments don’t. Push back and you’re cast as the party that wants the unsafe thing.

The vocabulary of AI governance is being written right now, largely by the labs. Enterprise leaders need a seat at that table, not to argue against safety, but to insist it cannot become a convenient cover for competitive decisions.

The AI governance risk hiding in plain sight

The mechanism Anthropic used today to block competing AI development is the same one that could tomorrow throttle legal research, competitive intelligence, or any output a vendor or a government finds inconvenient. As AI researcher Nathan Lambert put it: “An AI model that gets less intelligent without notifying me is categorically misaligned AI.”

The architecture exists now, it’s publicly documented, and it survived a product launch. What you thought was a tool purchase was actually an agreement to use a behavior that someone else can change whenever they see fit.

What CTOs and CIOs should do differently after Claude Fable 5

You shouldn’t walk away from a model that compresses two months of work into a single day. But adopting AI used to come down to one question: is this model good enough? You now need a second: who controls how it behaves, and will I know if that changes?

Your AI governance requires a more consequential question. Most governance today focuses on outputs, bias, hallucinations, accuracy. Fable 5 adds a new category: intentional underperformance. Not just “is this output wrong?” but “is it worse than what this model is actually capable of?” That requires tracking performance baselines over time, which almost no enterprise is doing today.

The AI governance question every enterprise should be asking right now

If your highest-value AI workflows were producing outputs that were 20% less useful than the model is capable of, would you know? Not immediately, but within three months?

If the answer is “probably not,” the Fable 5 controversy isn’t really about Anthropic. It’s about a gap in your own AI governance posture. A gap that, until last week, was theoretical.

It isn’t anymore.

When ChatGPT crossed 100 million users in early 2023, employees didn’t wait for organizational approval before putting it to work. Between March 2023 and March 2024, the volume of corporate data that workers fed into AI tools increased by 485%.

Unrestricted AI use can lead to serious repercussions. In 2023, employees at a major tech company used ChatGPT to summarize confidential internal meetings and process proprietary source code, leading to a significant data breach. The company immediately banned generative AI tools across all devices and networks and launched disciplinary investigations into those involved.

Today, shadow AI is still a threat, humming quietly in the background of your enterprise. Many security leaders now rank unsanctioned AI usage as one of their most pressing governance concerns.

Learn the implications of shadow AI and how it can put your organization at risk. Here are six ways shadow AI may already be harming your organization:

 1. AI tools use encrypted web traffic , leading to lack of visibility

The biggest risk with shadow AI begins when employees upload confidential organizational data into unauthorized AI tools without understanding where that information goes or how it’s processed.

Once you upload important information, such as financial models, customer data, legal documents, or source code, the information is stored and processed in multiple jurisdictions.

Since the interactions occur in the encrypted web traffic, most organizations can see employees visited AI sites, but not what documents or information they have shared.

This creates several layers of risk.

The most obvious is data leakage. Customer records, legal documents, product designs, and financial models may now exist in systems that were never reviewed by security or legal teams.

The less obvious risk layer is contractual risk. If confidential information belonging to customers, partners, or suppliers is shared with an external AI tool, the organization may violate non-disclosure agreements and data handling commitments.

 2. Compliance violations can occur without malicious intent 

Most employees using shadow AI are doing so without any malicious intent. But intent doesn’t determine liability.

Industries like healthcare, finance, and legal services operate under strict data regulations, such as HIPAA, the GDPR, SOX, and PCI DSS. These frameworks govern not just how data is stored, but where it can be processed and who can access it.

When a doctor feeds patient information into a consumer AI tool or a financial advisor runs financial projections through an unapproved platform, they may be triggering compliance violations without realizing it.

Unlike traditional data breaches, unintentional AI-related breaches generate no alerts, no anomaly flags, and no incident logs. An employee who pastes a confidential client summary into ChatGPT won’t trigger a firewall. The first sign something went wrong may be an audit finding, months later, after the data has already left the organization’s control permanently.

 3. Shadow AI impacts intellectual property governance  

When an engineer pastes proprietary code into an AI tool, they are probably not considering that they’re exposing their organization’s intellectual property.

Consumer-grade AI tools utilize user inputs to improve their outputs. The data shared by a user is inevitably processed on an external server and stored, raising a valid question about ownership.

If an engineer uses an AI tool to produce code, who owns the output? What happens if similar content appears in other users’ responses?

The legal frameworks around AI and intellectual property is still evolving, which makes the exposure of intellectual property harder to quantify and defend against.]

 4. The unmanaged third-party risk  

Third-party security risk management actively involves security assessments, contractual obligations, and ongoing monitoring. Every AI tool that an employee uses means a new vendor relationship, yet the nature of shadow AI means many are never vetted.

Every enterprise AI tool has its own security posture, data retention policy, and breach history. If an employee is using an AI tool that gets compromised, what happens next?

The organization’s data that is uploaded in the tool can be exposed in the breach. The trickiest part is that the tool is never registered as a vendor, the organization may not even know there is an incident to investigate. The proliferation of new AI tools makes this nightmare scenario a real risk.

 5. The reputational fallout of unreliable AI-generated outputs 

While rummaging through the security consequences of employees using shadow AI, it is also important to note that shadow AI also presents a quality control problem. Employees may be generating reports, drafting customer questions, and producing content using unsanctioned AI tools that are confidently wrong.

It’s now well established that AI tools can produce plausible sounding information that is factually incorrect.

The downstream consequences range from issuing an embarrassing correction to facing legal liability, depending on what was said, to whom, and in what context.

The risk is sharpest in high-stakes domains: a legal summary with incorrect case citations, a financial brief with fabricated figures, a compliance report that misrepresents a regulation. With shadow AI, there is no established process to catch these mistakes.

 6. Shadow AI undermines your ability to govern AI at scale 

Shadow AI eliminates your organization’s ability to govern AI use. Every unsanctioned AI platform is a data point that you don’t own. Every unsanctioned AI workflow is a dependency you don’t manage.

Moreover, organizations that lack visibility into AI use can’t make informed decisions about which AI investments to prioritize, which workflows are ripe for automation, or which risks require immediate mitigation. Simply put, they are governing in the dark.

With maturing AI regulations such as the European Union AI Act, organizations will increasingly be required to demonstrate how AI is used within their operations. Shadow AI makes that demonstration impossible.

What’s next: You can’t ban your way to safety

The question isn’t whether to allow AI in your organization—the question is how you’re going to govern it. Organizations must treat AI governance as an ongoing operational function rather than a one-time policy rollout.

The pace of AI adoption is evolving faster than traditional governance cycles, and reactive approaches will continue to leave blind spots. Regular awareness training can help close the gap more effectively than fear-based restrictions.

Employees are already using AI at work—in their browsers, their inboxes, their meeting summaries, and their code editors. The organizations that reduce risk successfully will be the ones that accept this reality early. Creating secure pathways for adoption is how enterprises root out shadow AI.

That means sanctioning the tools employees are already reaching for, setting guardrails inside platforms like Microsoft Copilot and Google Gemini, and making the compliant path the easiest one. Because when governance is harder to follow than it is to ignore, it isn’t governance—it’s a liability.

Here’s a scenario that should feel uncomfortably familiar.

A loyal customer—let’s call her Sarah—has spent thousands of dollars on your platform over three years. She buys premium cookware, organic groceries, and the occasional kitchen gadget. Your recommendation engine knows her well. So when she opens your app on a rainy Tuesday evening, it greets her with a curated shelf of her top picks: A cast-iron skillet, some artisan pasta, and a new espresso machine.

However, Sarah is at the airport and her flight was just cancelled. She needs a phone charger, a neck pillow, and something to eat in the next 20 minutes.

Your algorithm served her perfectly according to her profile, but failed her completely in this moment. That gap, between who a customer is and what they need right now, is the central problem in retail intelligence.

McKinsey’s research shows that 71% of consumers expect personalized interactions, and 76% report frustration when brands miss the mark. Despite years of investment, most retailers still can’t close that gap because they’re solving for the wrong variable. It’s clear that it’s not a technology problem, but a context problem.

What is contextual decision intelligence?

Contextual decision intelligence is the practice of making retail decisions by synthesizing what you know about a customer and what is happening around them at this specific moment. Traditional personalization asks one question: Who is this customer? CDI asks four simultaneously:

  • What is happening around them right now? (weather, local events, time of day)
  • What are they signaling in this session? (scroll speed, search phrasing, cart behavior)
  • What’s our operational reality? (inventory positions, margin, fulfillment capacity)
  • What has changed since they last visited? (a competitor’s stock out, a price sensitivity signal)

The output isn’t a smarter recommendation, rather it’s a situationally calibrated action. It looks different for Sarah at the airport than for Sarah planning a dinner party at home, even though the profile data is identical. This is the shift from personalization to situational commerce, and retailers who get there first are pulling away from those still optimizing their recommendation carousels.

Why your personalization engine is not working

Profile-based personalization has delivered real value. McKinsey pegs it at up to 50% reduction in customer acquisition costs and a 5-15% revenue lift. But the ceiling is becoming visible and the cracks are structural, not operational.

The same customer is multiple shoppers. You browse differently at 11pm than at 9am, more price-sensitive the week before payday, and in an entirely different mindset when buying for yourself versus the household. Personalization engines flatten all of that into one identity.

Collaborative filtering, the engine behind you might also like selections compounds the problem by aggregating behavior across millions of sessions, eliminating the situational variation that actually drives purchases. It’s the algorithmic equivalent of asking what your friends generally like for dinner and serving that every single time.

There’s also the operational blind spot: Most personalization engines surface recommendations with zero visibility into inventory position or fulfillment viability. Recommending a product that’s three weeks from restock doesn’t just fail the customer, it silently destroys trust and profit margins. Contextual decision intelligence is bidirectional by design, and that changes everything.

BCG research shows retailers deploying contextually adaptive decisions across merchandising, supply chain, marketing and customer service achieve revenue lifts 40 to 60% higher than those using profile-only personalization.

Three contextual decision intelligence levers that move the needle  

The most underused signal in retail is weather. IT influences the purchasing decisions for 93% of shoppers, yet most retailers treat it as a logistics variable, not a demand intelligence tool. Rainy days drive a significant spike in e-commerce activity, as adverse weather keeps shoppers away from physical stores. Retailers using weather-driven inventory systems cut stockout events by 30% and spoilage by 20% during peak seasons. H&M reduced its markdown costs by 1.5 percentage points in relation to sales by integrating AI-driven weather tracking and localized demand forecasting into merchandise planning.

Behavioral microcontext reads the session like a conversation. For example, scroll speed signals decision confidence. “Running shoes” versus “running shoes for flat feet under $120” tells you everything about intent stage and price sensitivity. Adding and removing the same product from a cart twice is a distress signal; someone who wants to buy an item but is hitting friction. The logic is straightforward: A customer’s behavior in this session reflects their intent right now, not who they were six months ago. Yet most retailers are still making real-time decisions using historical data. CDI systems that act on these signals in real time, surfacing social proof when a customer hesitates and adjusting price presentation when sensitivity signals fire, consistently outperform static models.

Competitive context capturing demand instantly. When a competitor goes out of stock on a high-demand SKU, demand doesn’t disappear it migrates. Retailers with CDI infrastructure that monitors competitor availability and activates quickly (adjusted search rankings, targeted promotions, outreach to relevant segments) can intercept that demand within hours. The same logic applies to competitor pricing windows and assortment gaps. Profile-based personalization has no mechanism for this. CDI does.

The org chart problem nobody mentions  

Here’s the uncomfortable truth: Most CDI efforts don’t fail because of bad technology. They fail because nobody owns the problem end-to-end. Your inventory team doesn’t talk to your digital team. Your data platform was built to track what customers bought, not what they’re doing right now. What about contextual signals like weather or competitor stockouts? Well, that’s under no one’s radar.

Getting this right takes two things.

First, a data setup that can pull live signals together in one place.

Second, a team with the authority to act on those signals across merchandising, marketing, and the supply chain simultaneously.

Dollar General’s Paul Bucalo captured it well: “Instead of amassing large quantities of data, we focus on acquiring quality data that provides a contextual understanding of our customers that we can adapt to predict trends and future behaviors.”

Simple idea, but it takes real executive will to make it happen.

Stop personalizing. Start responding. 

The numbers tell you everything you need to know: the AI in e-commerce market is growing at nearly 24% a year, from $7.25 billion today toward $64 billion by the end of the 2034.

The infrastructure is commoditizing. Yet 85% of companies claim to deliver personalized experiences while only 60% of customers agree. The gap isn’t closing, instead it’s growing.

Profile data tells you Sarah loves cooking. Context tells you she’s stranded at an airport with 20 minutes to spare. One of those facts is useful right now. Only Contextual Decision Intelligence knows which one.

The retailers building CDI capability now are building a compounding advantage that will be very hard to close in a few years. The real question is: are you one of them?

In this episode, CIO Varundeep Kaur explores how technology at scale amplifies leadership decisions, organizational clarity, and existing assumptions rather than simply solving problems. From her experiences across complex and rural FinTech environments, she reflects on when leadership judgment mattered more than technical capability, why speed without clarity creates fragile systems, and how AI and digital platforms can scale inclusion or deepen inequity. This conversation provides a thoughtful look at responsible technology leadership in high-impact environments.

Agenda  

  • Transitioning from technologist to leadership-driven decision making

  • Understanding what technology truly amplifies at scale

  • Knowing when to deploy technology, and when to pause

  • Lessons from technology solutions that failed in real-world environments

  • Challenges of designing technology for rural and underserved communities

  • Avoiding assumptions in FinTech and digital platform design

  • Deciding whether a problem needs technology, process change, or human intervention

  • What leaders should never outsource to technology

  • Questions CIOs should ask before approving technology initiatives

  • Ensuring AI scales inclusion rather than inequity

  • Building responsible, human-centered systems for long-term impact

Most organizations don’t discover a data breach on their own. On average, it takes organizations 241 days to identify and contain a data breach, according to IBM’s 2025 Cost of a Data Breach Report. That’s eight months of undetected access. Eight months of a cyber criminal copying files, reading emails, accessing accounts, and quietly mapping your entire environment.

The signs of a network compromise are almost always there in hindsight. The challenge is learning to spot them in real time. Here are seven indicators your organization may already be breached and what your IT team should check right now.

1. A former employee’s account is still active

Stolen and compromised credentials are now the initial access vector in 22% of all breaches, according to Verizon’s 2025 Data Breach Investigations Report (DBIR), and orphaned accounts belonging to ex-employees are among the easiest targets. They carry real permissions, a legitimate activity history, and zero scrutiny from a team that has mentally moved on. Attackers actively scan for them.

What to check: Cross-reference every active account against your current HR roster. Anything that doesn’t match should be disabled immediately. Set up an automatic workflow that disables all accounts and access permissions the second an employee finishes all exit formalities.

2. The help desk has had to reset the same password several times, but the employee never requested it

Your help desk is trained to be helpful. Attackers are trained to exploit that. Ten minutes of LinkedIn research—finding a name, a manager, and a department—is enough to impersonate an employee convincingly over the phone. Verizon’s 2025 DBIR found that the human element was involved in 60% of all breaches, with social engineering through support channels being one of the most consistent ways in.

What to check: Flag any account with three or more password resets in 30 days and require manager verification before approving the next one.

3. A vendor you depended on was breached and you were the last to find out

Third-party involvement in breaches doubled year-over-year according to Verizon’s 2025 DBIR, accounting for 30% of all incidents—up from 15% the year prior. When a vendor is compromised, they notify their legal team and the concerned authorities. Not you. Every supplier with an API integration, SSO connection, or service agent on your network is a potential entry point you don’t control.

What to check: Map every vendor that has access to your systems and treat them as an extension of your own attack surface. Monitor dark web and breach disclosure feeds for mentions of your suppliers. If you’re finding out about a vendor breach from a news headline, your process is already too slow.

4. Your monitoring tools keep failing in the same places

Sophisticated attackers don’t disable your security tools outright. That triggers alerts. When they gain a foothold, one of their first moves is to quietly tamper with monitoring agents on the specific machines they’re operating from. Not your entire environment, just the corners they’re using. What reads as a recurring technical glitch on the same three servers might be someone actively managing your visibility. The 241-day average detection time in IBM’s report doesn’t happen by accident. It’s partly the result of this kind of deliberate noise.

What to check: Track monitoring failures by specific asset. If the same machines repeatedly lose visibility with no clear root cause, escalate it as a security finding, not a maintenance ticket.

5. Employees are seeing emails that appear to be sent from their own addresses

Business email compromise (BEC) cost organizations $2.77 billion in 2024, making it the second-highest loss cybercrime category, according to the FBI’s 2024 Internet Crime Report. It rarely starts dramatically. An attacker gains quiet access to a mailbox, plants a hidden forwarding rule, and reads everything for weeks. Employees sometimes notice something feels off, like a reply they don’t remember sending, but those observations rarely make it to IT. They should.

What to check: Audit mailbox forwarding rules across your organization, especially for critical functions and leadership roles. Any rule forwarding externally and created outside business hours needs immediate investigation.

6. Your cloud bill inexplicably went up

A documented attacker technique involves compromising a cloud account, quietly staging database exports in an obscure storage bucket over several weeks, then exfiltrating everything in a single burst. IBM’s 2025 Cost of a Data Breach Report found that 30% of breaches entailed data being distributed across multiple cloud and on-premises environments and those breaches are among the costliest and hardest to detect. The evidence often shows up first in the invoice, filed away as an unexplained cost variance.

What to check: Route cloud cost anomaly alerts to your security team alongside finance. Unexplained storage or egress spikes should be treated as potential breach indicators until proven otherwise.

7. Successful backup reports mean nothing if nobody tests the restore

Ransomware groups that plan their attacks often target backup infrastructure weeks before the encryption begins, ensuring that recovery is impossible when it matters. According to Sophos’ 2025 State of Ransomware report, the use of backups to restore encrypted data has hit a six-year low: They were relied on in just 54% of ransomware incidents, while 49% of victims ended up paying the ransom instead. These numbers repeat the same story: When backups fail, the ransom becomes the only way out. A backup job reporting Success every night means nothing if the data it wrote was corrupted weeks ago.

What to check: Make restore validation a monthly discipline, not an annual check box. The question isn’t whether the backup job ran, it’s whether you can actually recover from it within the time your business can afford.

How to detect a network breach before it’s too late

None of these network compromise indicators need to be made by a sophisticated attacker for them to go unnoticed. Most exist because of ordinary blind spots such as offboarding gaps, unread logs, and untested backups that adversaries have learned to rely on. The organizations that get blindsided aren’t always the ones with the weakest security. They’re often the ones with decent security but little real visibility into what was quietly happening underneath.

Visibility is what separates a breach you catch in week one from one you find out in month eight.

Unsure about AI? Take our two-minute quiz for a clear readiness score Arrow X
x