The Breach Brief  ·  Story Week UAE-005

What happens when
one CRM export walks out the door?

Dana is a Senior Account Manager at a company in Dubai.
In her final two weeks, she exported the CRM to write a better handover.
Thirty-four days later, a customer asked how a stranger got their private number.

Dubai, UAE 17 – 21 Aug 2026 UAE PDPL 5-day story

This week’s story

Day 1  ·  Monday 17 Aug
The Last Two Weeks

Dana, a Senior Account Manager in Dubai, was leaving on good terms after four years. Wanting to leave a thorough handover, she exported the whole CRM to her personal laptop to write notes in the evenings.

No rule stopped her. No training covered it. The system offered the button, so she used it.

She didn’t think of it as taking anything. That was the mistake.

Day 2  ·  Tuesday 18 Aug
What the Export Copied

Being allowed to see the data every day isn’t the same as being allowed to carry a copy out. Two clicks turned 2,847 customer records — names, private mobiles, account notes, deal values — into one file in a personal inbox.

Outside the CRM, every control fell away. It was just a file now. Nobody inside Northbridge knew it was there.

Day 3  ·  Wednesday 19 Aug
The Silence

Thirty-four days. No alert, no flag. Her exit was clean — accounts reassigned, laptop wiped, access revoked.

But a copy had already left. On the tenth day, her personal inbox was opened by someone using a password she’d reused, sitting in a public breach dump. The attachment was still there.

Day 4  ·  Thursday 20 Aug
The Phone Call

A client of years called, unsettled. A message had reached him on the private mobile only Northbridge had, quoting his real renewal and contract value.

None of it had come from the company. It had come from the export. The breach was reported that afternoon — 34 days too late to have caught it.

Day 5  ·  Friday 21 Aug
The Verdict
Live now

The timeline was reconstructed in full. Export emailed to a personal account at 9:15 PM on 3 July. Last day and access revoked on 11 July. Personal inbox accessed by an unauthorised party on 13 July, using a password reused from an unrelated breach. First client contacted on the private number in early August. The call that surfaced it reaching the account team at 11:20 AM on 6 August. The breach reported at 3:45 PM the same day.

Thirty-four days between the moment the data left and the moment anyone inside knew to start the clock.

This is what the investigation found. Not as background. As verdict.

No one owned the alarm.
A breach has to be raised the moment it happens — not whenever a customer eventually calls in, confused. The data left on 3 July. The company became aware on 6 August. In between, a resignation had been processed as an HR event: notice, handover, goodbye, access off, file closed. No one was assigned to ask whether a data breach had walked out with the leaver.
No one owned the data.
There was no named person responsible for what customer data could leave the building, or in whose hands. Nobody whose job it was to notice that the entire customer master could be turned into a single file and carried out — or to decide that it shouldn’t be. So the question never got asked, and the habit was never governed.
Nothing guarded the door.
The CRM allowed a bulk export of every record with no limit, no approval step, and no log that anyone read. Nothing stopped that file leaving for a personal inbox. Access was revoked when Dana left — but revoking access to the system does nothing about the copy that already left it.

In the UAE, data protection rules now apply, and the consequences for a breach are no longer hypothetical.

The investigators’ conclusion was the same one that appeared in the reports before it: the person who exported the file was not the problem. The absence of any system around that moment was.

Dana did everything a conscientious professional does. She stayed late to leave a better handover than she’d been given. She used a button the system offered her. She never sold a contact, never misused a record, never intended a thing.

That was the problem — because nothing around her was built to make any of it safe, and nobody had ever told her it wasn’t.

The 3-step protocol the investigators recommended:

1. Make offboarding a data event, not just an HR one. The moment someone gives notice, review and log what they’ve exported, downloaded and emailed — before access is switched off — with a named person who owns that check. A goodbye card is not a data control.

2. Put a limit and an approval on export. No one should be able to turn the whole customer master into a CSV in two clicks with nobody the wiser. Cap bulk exports, require approval for large ones, and keep a log someone actually reads — so an export is a decision, not a reflex.

3. Train the people who live in the CRM. Not a policy handout. Training built around what sales, account management and marketing staff actually do every day — exports, handovers, working from home, “my” client relationships — and the one line UAE data protection law turns on: being allowed to see customer data is not being allowed to take it home.

Dana still works in sales. She knows what to do now. Does your team?

If your organisation needs to close this gap — the training exists, built for exactly this.
training.cybernym.io/login/?tab=demo

Cybernym.io — Cyber Instincts. Built, Not Taught.

Get each instalment
in your inbox

New chapter every day, Mon–Fri. Three minutes to read.
Built for sales, revenue, and compliance teams across the UAE.

No spam. Unsubscribe any time. Your data is handled under UAE PDPL.

You're in — Day 2 arrives tomorrow

Watch your inbox.
Dana’s story continues tomorrow — and it gets worse before it gets better.