A breach notice arrives and the instinct is either to panic or to ignore it. Neither is useful. The right response depends entirely on one question: what did they get?
First, confirm the notice is real
Fake breach notifications are a standard phishing template, because they manufacture urgency and a plausible reason to ask for your credentials. Before acting on any message:
- Do not click the links in it. Type the company's address yourself, or use the app.
- Check the company's newsroom or security page for an official statement.
- Be suspicious of any "verify your identity to secure your account" flow you arrived at by email or text.
Legitimate notices tell you what happened, what data categories were involved, and what the company is doing. They do not ask you to reply with personal details.
Match your response to the data
Email address alone
Low urgency. Expect more phishing and spam aimed at you, often referencing the company by name so it feels legitimate. Slow down on any message that arrives unprompted and asks you to log in or pay.
Password
Change it on the breached service, and — more importantly — everywhere you reused it or used a close variation. Attackers automate credential stuffing: they take one leaked pair and try it against hundreds of sites within hours.
This is the moment to start using a password manager if you have not. You cannot manually remember unique passwords for a few hundred accounts, and that is the whole reason reuse persists. While you are there, turn on two-factor authentication on email, banking and anything holding payment details — see how to secure your online accounts for the complete checklist.
Payment card number
Contact your bank or card issuer and ask for a replacement number. Federal protections limit your liability for unauthorized credit card charges, and debit card protections are strongest when you report quickly, so speed matters more with debit.
Then review recent statements line by line. Fraudsters often run a small test charge before attempting anything large.
Social Security number, date of birth, driver's license
This is the tier that enables new-account fraud, and it calls for the strongest response:
- Freeze your credit at Equifax, Experian and TransUnion. It is free, reversible, and it is the step that actually blocks a new account from being opened in your name.
- Request an IRS Identity Protection PIN so a fraudulent tax return filed in your name is rejected.
- Check your Social Security earnings record for wages you do not recognize.
- Consider the free monitoring the breached company offers. It is detection rather than prevention, but the enrollment window often expires, so decide before it does.
If a driver's license number was exposed, check with your state's motor vehicle agency about flagging the record.
Health or insurance information
Watch for explanation-of-benefits statements listing care you did not receive, and request a copy of your medical records from providers where fraud may have occurred. Medical identity theft is slower to surface and harder to unwind, so read those statements rather than filing them.
Then set up early warning
Detection is the second half of the job. Turn on transaction alerts at every bank and card account. Stagger free credit report pulls at AnnualCreditReport.com across the three bureaus so you are looking at a fresh file every few months. If your information may already be circulating, our guide on what to do if your personal information is on the dark web covers what monitoring services can and cannot see.
Watch for the follow-up scam
After a large breach, a second wave targets the victims. Callers claim to be the breached company's fraud department, your bank, or a government agency, and they already know real details about you — which is why they sound credible.
The rule that defeats nearly all of it: hang up and call back on a number you find yourself, from the back of your card or the company's official site. No legitimate fraud department will object. Anyone who insists on staying on the line, or asks for gift cards, wire transfers or crypto, is running a scam. Report it at ReportFraud.ftc.gov.
If fraud has already started
Go to IdentityTheft.gov for a personalized recovery plan and an official Identity Theft Report. Dispute fraudulent accounts in writing with both the company and the credit bureaus, and keep a dated log of every contact.
For the broader set of preventive habits, see how to protect yourself from identity theft.
Frequently asked questions
How do I know if a breach notice is legitimate?
Do not click links in the message. Check the company's own website or newsroom for an official statement, and navigate there yourself rather than through the email or text you received.
Should I change my password if only my email address was exposed?
Not necessarily, though you should expect more targeted phishing referencing the breached company. If your password was also part of the exposure, change it immediately, and everywhere you reused it.
Is a credit freeze necessary after every data breach?
It depends on what was exposed. A freeze is most important when a Social Security number, date of birth or driver's license number was involved, since those enable new-account fraud. For a password-only breach, changing the password is the priority.
Can I sue a company after a data breach?
That is a legal question outside what we can advise on; consult an attorney. Some breaches result in class-action settlements you can join, and affected companies often notify eligible consumers directly.
How long should I watch for fraud after a breach?
There is no fixed end date. Continue checking statements and credit reports periodically for months afterward, since stolen data can be used well after the original breach, and old breach data resurfaces in new dumps.