What to Do After a Data Breach Notification, Step by Step

Got a data breach notice? Learn how to verify it, read what was exposed, lock down accounts, protect your cards and credit, and spot follow-up scams.

What to Do After a Data Breach Notification, Step by Step

A data breach notification means a company that stores your information lost control of some of it. It does not mean someone has taken over your accounts, drained your bank balance, or stolen your identity. In most breaches, your data ends up in a large stolen database that criminals buy, sell, and work through slowly. That gap between the theft and the damage is your window, and it is usually wide enough to shut most of the doors that matter.

The notice itself is the most useful document you will get, and most people skim it. Somewhere in the letter or email is a sentence that begins with something like "the information involved may have included." That list decides everything. An exposed email address calls for different steps than an exposed password, and an exposed Social Security number calls for different steps than either.

This guide walks through the response in order: confirm the notice is real, read what was taken, lock down the affected account, then handle payment data, identity data, and the scams that follow.

Make sure the notification is real

Fake breach notifications are a scam category of their own. Criminals know a security scare makes people click, so they send emails dressed up as breach notices, complete with a "secure your account now" button that leads to a fake login page. Before you act on anything, verify the breach through a channel the message did not choose for you.

  • Do not click links in the notification itself. Type the company's web address into your browser or open its official app.
  • Search the company's name together with "data breach." A real incident shows up in news coverage and in a statement on the company's own site.
  • Real notices explain what happened, what data was involved, and what help the company is offering. They never ask you to confirm your Social Security number, card number, or password to "verify your identity." Any notice that asks for those things is a phishing attempt.

Read exactly what was exposed

Once you know the breach is real, find the section of the notice that lists the data types involved, and let that list set your priorities.

  • Email address or phone number: expect more spam and more convincing phishing. Annoying, but not urgent on its own.
  • Password: urgent. Even if the company says passwords were "hashed" or "encrypted," treat yours as exposed. Weak hashing gets cracked, and you cannot know which kind the company used.
  • Credit or debit card number: urgent but contained. Card fraud is the easiest breach damage to undo, because the bank absorbs the charges and issues a new card.
  • Bank account and routing numbers: serious. These can be used for fraudulent withdrawals and fake checks, and they are harder to replace than a card.
  • Social Security number, driver's license, or passport number: the highest tier. These enable new-account fraud and tax fraud, and you cannot simply request new ones the way you request a new card.
  • Home address and date of birth: low risk alone, but they make every other stolen item more usable, because they answer the identity questions banks and phone carriers ask.

Lock down the breached account first

Whatever else was taken, start with your account at the company that was breached.

  • Change the password to something long, random, and used nowhere else. If that same password protects any other account, change those too, starting with your email account, since password resets for everything else flow through it. A password manager such as Bitwarden or 1Password makes unique passwords practical instead of painful.
  • Turn on two-factor authentication if the account offers it. An authenticator app is stronger than codes sent by text.
  • Sign out of all other sessions. Most account security pages have an option like "log out of all devices," which ends any session an attacker may already have.
  • Check the account settings for changes you did not make: a new recovery email or phone number, mail forwarding rules, unfamiliar linked devices, or a changed shipping address.

If you find evidence that someone has already been inside, such as sent messages you did not write or orders you did not place, follow our guide on what to do if your account is hacked, which covers full recovery step by step.

If card or bank details were exposed

Call the number printed on the back of your card, not any number from the notification, tell the bank the card appeared in a breach, and ask for a replacement. Banks handle this routinely and usually ship a new card within days. While you wait:

  • Turn on transaction alerts in your banking app so every charge triggers a notification. You catch problems the same day instead of at the end of the statement cycle.
  • Review recent statements for small charges you do not recognize. Thieves often test a stolen card with a purchase of a few dollars before trying larger ones.
  • If bank account and routing numbers were exposed, ask your bank whether it recommends closing the account and opening a new one, and watch withdrawals closely in the meantime.
  • When the new card arrives, update subscriptions and autopay arrangements tied to the old number so bills do not bounce.

If your Social Security number was exposed

A stolen Social Security number is mostly used to open new accounts in your name, so the defense is to make new accounts impossible to open.

  • Freeze your credit at all three credit bureaus: Equifax, Experian, and TransUnion. A freeze is free, takes a few minutes per bureau online, and blocks lenders from pulling your file, which stops most new-account fraud cold. You can lift it temporarily whenever you apply for credit yourself.
  • If a freeze feels like too much, a fraud alert is the lighter option. It asks lenders to verify your identity before opening anything, lasts a year, and only needs to be placed with one bureau, which must notify the other two. The freeze is stronger, and we recommend it.
  • Pull your credit reports at AnnualCreditReport.com, the official free source, and look for accounts or hard inquiries you do not recognize.
  • Consider an Identity Protection PIN from the IRS, which prevents anyone else from filing a tax return under your number.

If you find accounts that are not yours, report the theft at IdentityTheft.gov, which generates a recovery plan and the official reports you need to dispute them. For the longer program of monitoring and cleanup, see our guide to preventing and recovering from identity theft.

Expect sharper scams for a while

Stolen data gets packaged and resold, so the fallout from a breach arrives in waves rather than all at once. In the weeks after a notification, expect phishing that mentions the breach by name: fake compensation offers, fake settlement claims, and calls from people claiming to be the breached company's security team. These messages can be unusually convincing, because the caller really does know your name, your address, or the last four digits of your card. Knowing those details proves nothing except that the person has read the same stolen database.

The rule that protects you is simple: never act on inbound contact. If a message or caller claims to be from the breached company, your bank, or a government agency, hang up or close the message, then reach the organization through its official website or app. A real problem will still be there. It also helps to know your overall exposure, since older leaks feed the same scam lists. Run your address through our free email breach checker, or check Have I Been Pwned, to see which past breaches already include your information.

Should you take the free credit monitoring?

Most breach notices offer a year or two of free credit monitoring or identity protection. Accept it, with two things clear in your mind.

  • Monitoring detects problems rather than preventing them. It tells you after someone opens an account in your name. A credit freeze stops the account from being opened at all. Do both, in that order: freeze first, then enroll.
  • Enroll only through the exact web address printed in the official notice, typed by hand into your browser. Scammers stand up lookalike enrollment sites after major breaches to harvest the very identity details you are trying to protect. A legitimate enrollment may ask for your Social Security number so it can monitor it, which is normal through the official address and a red flag anywhere else.

Your first hour, in order

You do not need to do everything today. These steps prevent the most damage in the least time.

  • Verify the breach on the company's own website, without clicking anything in the message.
  • Find the list of exposed data types in the notice and let it set your priorities.
  • Change the password on the breached account, and everywhere that password was reused, starting with your email account.
  • Turn on two-factor authentication for the breached account and for your email.
  • If card details were exposed, call the number on the back of the card and request a replacement.
  • If your Social Security number was exposed, freeze your credit at Equifax, Experian, and TransUnion.
  • Set a reminder to recheck your statements and credit reports in a month, once the stolen data has had time to circulate.