">

What to do first after a breach notice

A breach notice means information may have been exposed. It doesn't prove that someone has used your identity, but you shouldn't wait for an unfamiliar charge or account before taking basic precautions.

Read the notice for three details: what data was involved, when the incident or notification occurred, and whether the company is offering monitoring. Then secure the accounts connected to that information.

Save the notice and check that it's genuine

Keep a copy of the letter or message. Record:

Use contact details from the notice or the company's official website. Don't give a password, one-time code, or payment information to someone who contacts you unexpectedly about the breach.

An unfamiliar account, charge, debt, or credit inquiry can be a warning sign. USAGov's identity theft guidance lists these and other signs to watch for.

Match the response to the data exposed

The next step depends on whether the breach involved a login, Social Security number, payment account, or medical information. USAGov notes that exposed information can include names, addresses, credit or Social Security numbers, bank account numbers, and medical insurance account numbers.

Information exposed Make this your first move Keep an eye on
Email address or login credentials Change the password for the affected account and anywhere you reused it. Turn on multifactor authentication. Password-reset messages, unfamiliar logins, and changes to your recovery email or phone
Social Security number or other identity information Consider a credit freeze or fraud alert, then review your credit reports. New accounts, credit inquiries, collection notices, or mail for accounts you didn't open
Credit card or bank account information Contact the card issuer or bank through its official app, website, or the number on your card. Statements, transfers, withdrawals, and payment alerts
Medical insurance or provider information Contact the insurer or provider and ask which protective steps apply. Unfamiliar bills, claims, explanation-of-benefits notices, or account changes

The categories can overlap. Follow the company's instructions, but don't assume that its free service or suggested remedy secures every account affected by the breach.

Credit freeze or fraud alert?

Both tools are free, but they address new-credit risk differently. The Federal Trade Commission's credit freeze and fraud alert guidance explains how to use them.

Tool What it does When it may fit What it won't do
Credit freeze Restricts access to your credit file, which can make it harder to open new credit in your name. Your Social Security number or other information used in credit applications was exposed, or you want a stronger barrier against new-account fraud. It doesn't protect an existing bank, card, or payment account.
Fraud alert Asks businesses that check your credit report to take additional steps to verify the applicant's identity. You suspect someone may be trying to use your information and want lenders to receive a warning. It doesn't undo the breach or recover money already taken.

Place a credit freeze

A freeze is free and stays in place until you tell the credit bureaus to remove it. Use the FTC's instructions to contact Equifax, Experian, and TransUnion, and complete each bureau's identity-verification process.

Save any confirmation numbers, passwords, or PINs. If you apply for credit later, you'll generally need to lift the freeze temporarily or arrange access for the lender.

Place a fraud alert

The FTC says you can contact one of the three credit bureaus to place a fraud alert and follow that bureau's instructions. Ask how long the alert will remain active and how renewal works.

For some extended or renewed alerts, you may need to submit an FTC identity theft report or police report. A fraud alert can make sense when you suspect attempted identity theft. A freeze is the more direct barrier when the exposed information could be used to open new credit.

Secure accounts and watch for misuse

Work through the affected accounts rather than relying on one general fix:

  1. Change reused passwords. Start with the breached service, your email account, and every account that used the same password. Give each important account a different password.
  2. Turn on multifactor authentication. Use an authenticator app, security key, or another option offered by the service. Store backup codes securely.
  3. Contact financial institutions promptly. Use a trusted number or the official app, not a link in an unexpected message. Ask about replacing a card, securing the account, and disputing unfamiliar activity.
  4. Review statements and alerts. Check bank, card, and payment accounts for charges, transfers, withdrawals, or profile changes you don't recognize.
  5. Check your credit reports. Look for unfamiliar accounts, inquiries, collection activity, or other changes. An account in your name that you don't recognize could be a sign of identity theft.
  6. Protect your recovery channels. Watch your email and phone accounts for password resets or changes to recovery details. Someone who controls those channels may be able to take over other accounts.

Keep a record of calls, dates, confirmation numbers, disputed transactions, and correspondence. It can save time if several companies become involved.

If you find identity theft

A data breach and identity theft aren't the same thing. A breach means information may have been exposed. Identity theft happens when someone uses personal or financial information without permission.

If you find an unfamiliar account, charge, debt, or other misuse:

  1. Contact the business or financial institution involved. Ask it to secure the account, stop further activity, and explain its dispute or recovery process.
  2. Report the identity theft to the FTC. The FTC's guidance on what to do after a data breach directs consumers to IdentityTheft.gov for steps tailored to their situation.
  3. Create an identity theft report when appropriate. The FTC says this report can help show businesses that someone stole your identity and make it easier to correct resulting problems. Its identity theft recovery guidance explains the reporting process.
  4. Dispute unfamiliar credit activity. Contact the lender or company connected to the account and follow the relevant credit bureau's instructions.
  5. Keep supporting evidence. Save statements, emails, letters, screenshots, and police or FTC report details, along with the names of people you contacted.

Call a bank or card issuer as soon as you notice unauthorized activity. Deadlines and procedures can depend on the type of account and transaction, so ask the institution what information it needs.

A breach notice isn't a security fix

The notice itself isn't:

Free credit monitoring offered after a breach is separate from a credit freeze. Check the offer's enrollment deadline, duration, and scope. Monitoring can help you spot certain changes, but it doesn't replace password changes, account reviews, or a decision about credit protection.

Breach notification deadlines vary by state

U.S. breach-notification requirements depend on the state, the type of information, and the organization involved. A company's deadline to notify consumers isn't your deadline to protect your accounts.

For example, the Texas Attorney General says that an organization affecting 250 or more Texans must report the breach to the Texas Attorney General as soon as practicable and no later than 30 days after discovering it. Texas also requires notice to affected consumers. That's a Texas example, not a nationwide deadline.

For questions about a delayed or unclear notice, check your state's attorney general or consumer-protection agency. This is general U.S. consumer information, not legal advice.

Questions that come up

Does a data breach automatically mean identity theft?

No. A breach means information may have been accessed or exposed. Identity theft requires someone to use personal or financial information without permission. Keep monitoring even if you haven't seen fraud.

Should I freeze my credit after every breach?

Not necessarily. A freeze is especially worth considering when the exposed information could be used to apply for credit, such as a Social Security number. If only an email address was exposed, changing the password and turning on multifactor authentication may be the more immediate response.

Do I need to contact all three credit bureaus?

For a credit freeze, follow the FTC's instructions to contact Equifax, Experian, and TransUnion. For a fraud alert, the FTC says you can start with one bureau and follow its instructions.

Can a credit freeze stop unauthorized bank or card transactions?

No. A freeze targets new-credit applications. It doesn't replace monitoring existing accounts or contacting your bank or card issuer about unfamiliar transactions.

Should I file an identity theft report just because I received a breach notice?

A breach notice alone doesn't establish that identity theft occurred. Use the FTC's breach-response guidance to assess the situation. If you find an unfamiliar account, charge, debt, or other misuse, report it and begin the recovery steps.

If you have the notice open now, write down the exposed data and any monitoring deadline, then change the affected password and any reused password. Contact the relevant bank, card issuer, insurer, or provider if financial or medical information was involved.