Verify the notice independently
Search for the organization's official breach page or contact it through a known website, app, statement, or card. A real incident can attract copycat phishing, so avoid signing in, downloading an attachment, or giving personal information through the notice itself. Save a copy after verification.
Write down exactly what was exposed
Separate account credentials, payment-card details, bank-account information, Social Security numbers, driver's-license details, medical information, and contact information. Also note whether the organization says the data was encrypted, whether a password was included, and which dates or accounts are affected. Different data supports different actions; a generic “change everything” response can miss the real risk.[1]
If a password was exposed, replace every reused copy
Change the affected password from the official site or app. If you reused it, replace it anywhere else it appears, starting with email, financial accounts, and your password manager. Use a long, random, unique password and enable multifactor authentication; CISA recommends a password manager to generate and store unique credentials.[2][3]
If card or bank details were exposed, contact the provider
Use the number on the card, statement, or provider's official site. Ask whether the card or account number should be replaced, review recent activity, and turn on transaction alerts if available. Keep checking statements because a replacement card does not resolve transactions that already occurred. Update legitimate automatic payments only after a replacement is confirmed.
If a Social Security number was exposed, protect new-account credit
Review reports through AnnualCreditReport.com, the federally authorized source for reports from Equifax, Experian, and TransUnion.[4] Consider a free credit freeze at each bureau; the FTC says a freeze does not affect your credit score and makes it harder for someone to open a new credit account in your name. A fraud alert is a different option that asks creditors to verify your identity.[5] An IRS Identity Protection PIN can help prevent someone from using your SSN or ITIN on a federal tax return.[6]
Use offered monitoring with realistic expectations
Confirm an offer on the breached organization's official site before enrolling. Check what it watches, how long it lasts, what information enrollment requires, and whether renewal becomes paid. Monitoring can alert you to some changes; it cannot undo an exposure, block every form of misuse, or replace direct account and credit controls.
Escalate when you find misuse
Contact the affected provider through a verified channel, preserve notices and case numbers, and dispute unauthorized activity through the provider's process. Use IdentityTheft.gov to report identity theft and create a personalized recovery plan. A breach notice without misuse is worth documenting; confirmed misuse requires recovery steps tied to the affected account or record.[1]
Educational information only. This is not legal, financial, tax, or credit advice. Rights, provider procedures, and breach facts vary; follow current instructions from the relevant organization and government agency through verified channels.