Sensitive data leaks aren't usually a dramatic breach — they're a support ticket with a customer's card number in it, forwarded to a logging tool that keeps it forever.
Logs, error trackers, webhooks and third-party APIs routinely receive raw personal data as a side effect of normal application traffic — nobody intended it, but it happens by default unless something actively strips it out first.