what someone could do is provide a patch to a commonly used software library that allows a nefarious actor to do nefarious things... purely for educational purposes
It's an idea that dates way back. https://www.industrialcybersecurity...foundation-for-software-supply-chain-attacks/
The three billion records from the past ~30 years leaked had duplicate social security numbers. For example, my identity monitoring services showed six different leaked records with my social security number.