Start here: verify the breach, then act on the data exposed

If the notice is genuine, don't wait for evidence of misuse. First make sure it really came from the company. An unexpected email isn't a safe place to start: open the company's known website or app yourself, or use a phone number printed on a bill, payment card, or earlier statement. If you can't verify the message, treat it as possible phishing.

Save the notice and write down:

A breach notice doesn't automatically mean that someone opened an account in your name. It also may not identify every affected record in the first notice. Keep checking for updates through a verified company channel.

The right first move depends on the data. A password calls for account security, payment details call for a bank or card-issuer call, and identity information that could be used for credit applications may justify a credit freeze.

What to do in the first day

Secure the affected login

If a login was involved, change its password through the company's official website or app. Change every other account where you reused that password. Use separate passwords for important accounts, especially email, banking, payment, and password-manager accounts.

Turn on multifactor authentication when it's available. Sign out of other sessions, remove unfamiliar devices, and check the account's recovery email address and phone number. Secure your primary email early because it can be used to reset other accounts.

An unexpected password-reset message isn't an instruction to follow. Don't approve it. Go directly to the account instead of using the message's link.

Put the bank or card issuer on notice

If a card number, debit-card details, bank-account information, or other payment credentials were exposed, contact the issuer or bank through a trusted number. Ask whether the card or account should be replaced and how to report unauthorized activity.

Review recent statements now and future statements as they arrive. Look for unfamiliar charges, withdrawals, transfers, or changes to account details. Report suspicious activity promptly; don't wait for the breached company to finish its investigation. Dispute procedures and deadlines vary by payment method, so ask the institution which evidence and forms it needs.

A merchant's promise to investigate a breach doesn't replace your responsibility to notify your bank or card issuer.

Decide whether a credit freeze fits

If the exposed information includes a Social Security number, driver's-license details, or other information that could be used to apply for credit, consider a security freeze with Equifax, Experian, and TransUnion. You generally place the freeze separately with each bureau.

A freeze is intended to keep prospective creditors from accessing your credit file. It won't change a stolen password, close an existing account, or stop every form of identity fraud. Experian's guidance on freezing your credit reports explains the process and identity-verification steps.

Credit monitoring does something different. It may alert you to certain changes, but it isn't a substitute for securing a login or reporting unauthorized transactions. Before enrolling in a service offered after the breach, check its coverage, length, enrollment deadline, and cancellation terms.

Match the response to the exposed information

Information involved Best next step What this step does not address
Username or password Change it, change reused versions, sign out other sessions, and enable multifactor authentication Another account where you still use the old password
Email address or phone number Expect targeted phishing and verify messages through official channels Proof that someone accessed the account
Credit-card number Contact the issuer, ask about replacement, and watch statements Security of the breached online login
Debit-card or bank-account information Contact the bank's fraud department and monitor withdrawals and transfers Activity in an existing bank account that a credit freeze generally won't stop
Social Security number or driver's-license information Consider a freeze with all three credit bureaus and review credit activity Account takeover, tax fraud, or misuse outside the credit system
Medical or insurance information Contact the provider or insurer and watch for unfamiliar claims or account changes Misuse that credit monitoring doesn't reveal

One exposed category may call for more than one action. If a notice says only "personal information," ask the company which categories were tied to your account. Don't send a full Social Security number, password, or one-time code by email unless you've confirmed a secure, official process.

Read the notice for specific answers

The Federal Trade Commission's breach-response guidance for businesses tells companies to mobilize a response team, use appropriate forensic and legal help, and clearly describe what they know about the compromise. Although that guidance is written for businesses, its emphasis on clear information gives consumers a useful standard.

Look for answers to these questions:

A vague notice isn't a reason to ignore the incident. Contact the company's verified security, privacy, or support channel and ask for clarification in writing.

Questions to send the company

Keep the questions short:

  1. Was my specific account or record included?
  2. Which data fields were exposed or accessed?
  3. Were passwords, security questions, tokens, or recovery details involved?
  4. Has the company reset credentials and invalidated active sessions?
  5. What should I do about payment or identity information?
  6. What assistance is available, when does enrollment end, and how will further updates be delivered?
  7. Where should I report suspected misuse connected to the incident?

Don't provide extra personal information just because someone claims to be investigating the breach.

Avoid follow-up scams

A breach gives criminals details they can use to make a message sound believable. A caller or sender may claim to represent the company, your bank, a credit bureau, or a government agency.

Take these precautions:

A legitimate breach-support message may direct you to an enrollment page. Verify that page independently before entering personal information.

Keep evidence of the incident

Create a folder for the breach. Keep:

Save suspicious messages before changing or deleting them if you may need them for a fraud investigation. Don't put passwords or full account numbers in your notes.

U.S. deadlines: separate company duties from your next steps

Data-breach duties vary by state, the type of information exposed, and the organizations involved. A deadline in an online article may apply to the company or a regulator rather than to you.

The GDPR 72-hour rule isn't a general U.S. consumer deadline

Where the General Data Protection Regulation applies, an organization may need to notify a data-protection authority within 72 hours of becoming aware of a qualifying personal-data breach. The UK Information Commissioner's Office guidance on the first 72 hours describes the assessment and recordkeeping process.

That 72-hour period is a regulatory reporting rule. It isn't a universal deadline for a U.S. consumer to freeze credit, contact a bank, or file a complaint.

California's CCPA cure notice is a separate issue

The California Attorney General's CCPA information describes a procedure for certain CCPA claims. Before suing in those circumstances, a consumer must give the business written notice identifying the CCPA sections allegedly violated and allow the business an opportunity to respond within 30 days that it has cured the violation and will not repeat it.

That is a pre-suit cure procedure, not a general 30-day breach-notification deadline. It also doesn't tell you when to secure your accounts.

California consumers considering a legal claim should verify that the CCPA applies to the business, the information, and the conduct at issue. State law and the facts of the incident matter. For substantial loss or a specific potential claim, consider advice from a qualified attorney or an appropriate state consumer-protection office.

When the company doesn't respond

Escalate according to the harm:

A complaint to a company or regulator may not recover money automatically. Keep your evidence, ask what documents are required, and get a case number or expected response date when possible.

Quick breach-response checklist

Do now

Keep watching

Escalate when needed

Common questions

Should I wait for a breach letter before changing my password?

No. If you can verify that a breach affected the account, change the password immediately. If the message itself is suspicious, confirm the incident through the company's known website or app first.

Does a data-breach notice mean someone stole my identity?

No. It means the company believes information was accessed, acquired, disclosed, or otherwise exposed without authorization. Misuse may never occur. The risk depends on what information was involved and how it was protected.

Should I freeze my credit after every breach?

Not necessarily. A freeze is most relevant when the exposed information could be used to apply for credit, such as a Social Security number or certain identification details. For a password-only incident, account security is the more immediate priority. Ask the company what data was involved if the notice isn't specific.

Is credit monitoring enough?

No. Monitoring may alert you to certain changes, while a freeze, password reset, bank notification, or account-recovery step addresses a different risk. Choose the measure that matches the exposed information.

Does the CCPA 30-day period mean a company has 30 days to notify me?

No. The California CCPA cure-notice procedure concerns certain consumer claims and gives a business an opportunity to respond before suit. It isn't a general breach-notification deadline.

What is the most useful next step if I see fraud?

Contact the financial institution or account provider through a trusted channel immediately, report the activity, and request a case number. Save statements, messages, and confirmations rather than relying on the breached company's investigation alone.