Received a data breach notice? Match your response to the exposed data.

A breach notice tells you information may have been exposed; it does not by itself prove that someone has misused it. Verify the notice independently, identify the affected information, and take the narrowest effective action first.

A verified breach notice beside exposed data tiles and a shield showing prioritized response steps
  1. Verify the notice independently

    Search for the organization's official breach page or contact it through a known website, app, statement, or card. A real incident can attract copycat phishing, so avoid signing in, downloading an attachment, or giving personal information through the notice itself. Save a copy after verification.

  2. Write down exactly what was exposed

    Separate account credentials, payment-card details, bank-account information, Social Security numbers, driver's-license details, medical information, and contact information. Also note whether the organization says the data was encrypted, whether a password was included, and which dates or accounts are affected. Different data supports different actions; a generic “change everything” response can miss the real risk.[1]

  3. If a password was exposed, replace every reused copy

    Change the affected password from the official site or app. If you reused it, replace it anywhere else it appears, starting with email, financial accounts, and your password manager. Use a long, random, unique password and enable multifactor authentication; CISA recommends a password manager to generate and store unique credentials.[2][3]

  4. If card or bank details were exposed, contact the provider

    Use the number on the card, statement, or provider's official site. Ask whether the card or account number should be replaced, review recent activity, and turn on transaction alerts if available. Keep checking statements because a replacement card does not resolve transactions that already occurred. Update legitimate automatic payments only after a replacement is confirmed.

  5. If a Social Security number was exposed, protect new-account credit

    Review reports through AnnualCreditReport.com, the federally authorized source for reports from Equifax, Experian, and TransUnion.[4] Consider a free credit freeze at each bureau; the FTC says a freeze does not affect your credit score and makes it harder for someone to open a new credit account in your name. A fraud alert is a different option that asks creditors to verify your identity.[5] An IRS Identity Protection PIN can help prevent someone from using your SSN or ITIN on a federal tax return.[6]

  6. Use offered monitoring with realistic expectations

    Confirm an offer on the breached organization's official site before enrolling. Check what it watches, how long it lasts, what information enrollment requires, and whether renewal becomes paid. Monitoring can alert you to some changes; it cannot undo an exposure, block every form of misuse, or replace direct account and credit controls.

  7. Escalate when you find misuse

    Contact the affected provider through a verified channel, preserve notices and case numbers, and dispute unauthorized activity through the provider's process. Use IdentityTheft.gov to report identity theft and create a personalized recovery plan. A breach notice without misuse is worth documenting; confirmed misuse requires recovery steps tied to the affected account or record.[1]

Educational information only. This is not legal, financial, tax, or credit advice. Rights, provider procedures, and breach facts vary; follow current instructions from the relevant organization and government agency through verified channels.

Exposure-to-action map

Use the notice's specific data list rather than assuming every response applies.

Email address or phone number
Expect targeted phishing and verify future requests independently; these details alone do not require a credit freeze.
Password or security answers
Replace the affected secret and every reused copy; review recovery methods and active sessions.
Payment card or bank information
Contact the financial provider, review activity, and ask whether account details should be replaced.
Social Security number
Review all three credit reports and consider freezes or a fraud alert; evaluate an IRS IP PIN.

Sources and image note

Primary US consumer and cybersecurity resources used for this guide.

  1. Federal Trade Commission — What To Do After a Data Breach
  2. Cybersecurity and Infrastructure Security Agency — Use Strong Passwords
  3. Cybersecurity and Infrastructure Security Agency — Turn On MFA
  4. AnnualCreditReport.com — federally authorized credit-report source
  5. Federal Trade Commission — Credit Freezes and Fraud Alerts
  6. Internal Revenue Service — Identity Protection Tips

The 1600 × 900 SVG hero is an original vector illustration created for this article. It contains no stock photography, external fonts, scripts, tracking, or embedded third-party assets.