Start here: verify the breach, then act on the data exposed
If the notice is genuine, don't wait for evidence of misuse. First make sure it really came from the company. An unexpected email isn't a safe place to start: open the company's known website or app yourself, or use a phone number printed on a bill, payment card, or earlier statement. If you can't verify the message, treat it as possible phishing.
Save the notice and write down:
- When you received it
- The company name and incident or reference number
- The incident dates, if provided
- The specific information involved
- The company's recommended steps
- Any enrollment deadline for credit monitoring or identity-theft assistance
- The contact details used to reach the company
A breach notice doesn't automatically mean that someone opened an account in your name. It also may not identify every affected record in the first notice. Keep checking for updates through a verified company channel.
The right first move depends on the data. A password calls for account security, payment details call for a bank or card-issuer call, and identity information that could be used for credit applications may justify a credit freeze.
What to do in the first day
Secure the affected login
If a login was involved, change its password through the company's official website or app. Change every other account where you reused that password. Use separate passwords for important accounts, especially email, banking, payment, and password-manager accounts.
Turn on multifactor authentication when it's available. Sign out of other sessions, remove unfamiliar devices, and check the account's recovery email address and phone number. Secure your primary email early because it can be used to reset other accounts.
An unexpected password-reset message isn't an instruction to follow. Don't approve it. Go directly to the account instead of using the message's link.
Put the bank or card issuer on notice
If a card number, debit-card details, bank-account information, or other payment credentials were exposed, contact the issuer or bank through a trusted number. Ask whether the card or account should be replaced and how to report unauthorized activity.
Review recent statements now and future statements as they arrive. Look for unfamiliar charges, withdrawals, transfers, or changes to account details. Report suspicious activity promptly; don't wait for the breached company to finish its investigation. Dispute procedures and deadlines vary by payment method, so ask the institution which evidence and forms it needs.
A merchant's promise to investigate a breach doesn't replace your responsibility to notify your bank or card issuer.
Decide whether a credit freeze fits
If the exposed information includes a Social Security number, driver's-license details, or other information that could be used to apply for credit, consider a security freeze with Equifax, Experian, and TransUnion. You generally place the freeze separately with each bureau.
A freeze is intended to keep prospective creditors from accessing your credit file. It won't change a stolen password, close an existing account, or stop every form of identity fraud. Experian's guidance on freezing your credit reports explains the process and identity-verification steps.
Credit monitoring does something different. It may alert you to certain changes, but it isn't a substitute for securing a login or reporting unauthorized transactions. Before enrolling in a service offered after the breach, check its coverage, length, enrollment deadline, and cancellation terms.
Match the response to the exposed information
| Information involved | Best next step | What this step does not address |
|---|---|---|
| Username or password | Change it, change reused versions, sign out other sessions, and enable multifactor authentication | Another account where you still use the old password |
| Email address or phone number | Expect targeted phishing and verify messages through official channels | Proof that someone accessed the account |
| Credit-card number | Contact the issuer, ask about replacement, and watch statements | Security of the breached online login |
| Debit-card or bank-account information | Contact the bank's fraud department and monitor withdrawals and transfers | Activity in an existing bank account that a credit freeze generally won't stop |
| Social Security number or driver's-license information | Consider a freeze with all three credit bureaus and review credit activity | Account takeover, tax fraud, or misuse outside the credit system |
| Medical or insurance information | Contact the provider or insurer and watch for unfamiliar claims or account changes | Misuse that credit monitoring doesn't reveal |
One exposed category may call for more than one action. If a notice says only "personal information," ask the company which categories were tied to your account. Don't send a full Social Security number, password, or one-time code by email unless you've confirmed a secure, official process.
Read the notice for specific answers
The Federal Trade Commission's breach-response guidance for businesses tells companies to mobilize a response team, use appropriate forensic and legal help, and clearly describe what they know about the compromise. Although that guidance is written for businesses, its emphasis on clear information gives consumers a useful standard.
Look for answers to these questions:
- What happened: unauthorized access, lost equipment, a stolen file, ransomware, or another event?
- When did the incident happen, and when did the company discover it?
- Which of your information was involved?
- Was the information encrypted, and were the encryption keys also exposed?
- Did the company reset passwords, revoke sessions, or take other containment steps?
- What does the company want you to do?
- Is monitoring or identity-theft assistance available, and when does enrollment end?
- Who can answer questions, and how will later updates arrive?
A vague notice isn't a reason to ignore the incident. Contact the company's verified security, privacy, or support channel and ask for clarification in writing.
Questions to send the company
Keep the questions short:
- Was my specific account or record included?
- Which data fields were exposed or accessed?
- Were passwords, security questions, tokens, or recovery details involved?
- Has the company reset credentials and invalidated active sessions?
- What should I do about payment or identity information?
- What assistance is available, when does enrollment end, and how will further updates be delivered?
- Where should I report suspected misuse connected to the incident?
Don't provide extra personal information just because someone claims to be investigating the breach.
Avoid follow-up scams
A breach gives criminals details they can use to make a message sound believable. A caller or sender may claim to represent the company, your bank, a credit bureau, or a government agency.
Take these precautions:
- Type the company or bank's address into your browser instead of following an email link.
- Call the number on your card or statement, not a number supplied by an unsolicited caller.
- Never give a password, PIN, security answer, or one-time authentication code to someone who contacted you unexpectedly.
- Don't install remote-access software because a caller says your account is at risk.
- Be suspicious of an upfront fee to "recover" money or secure your identity.
- Check the sender's address, but don't rely on that check alone because addresses can be spoofed.
A legitimate breach-support message may direct you to an enrollment page. Verify that page independently before entering personal information.
Keep evidence of the incident
Create a folder for the breach. Keep:
- The original notice, letters, and later updates
- Screenshots of account alerts or suspicious messages
- Bank and card statements showing disputed activity
- Dates, times, and names from calls with the company or financial institution
- Case numbers, dispute forms, and confirmation emails
- A list of accounts where you changed passwords or enabled multifactor authentication
Save suspicious messages before changing or deleting them if you may need them for a fraud investigation. Don't put passwords or full account numbers in your notes.
U.S. deadlines: separate company duties from your next steps
Data-breach duties vary by state, the type of information exposed, and the organizations involved. A deadline in an online article may apply to the company or a regulator rather than to you.
The GDPR 72-hour rule isn't a general U.S. consumer deadline
Where the General Data Protection Regulation applies, an organization may need to notify a data-protection authority within 72 hours of becoming aware of a qualifying personal-data breach. The UK Information Commissioner's Office guidance on the first 72 hours describes the assessment and recordkeeping process.
That 72-hour period is a regulatory reporting rule. It isn't a universal deadline for a U.S. consumer to freeze credit, contact a bank, or file a complaint.
California's CCPA cure notice is a separate issue
The California Attorney General's CCPA information describes a procedure for certain CCPA claims. Before suing in those circumstances, a consumer must give the business written notice identifying the CCPA sections allegedly violated and allow the business an opportunity to respond within 30 days that it has cured the violation and will not repeat it.
That is a pre-suit cure procedure, not a general 30-day breach-notification deadline. It also doesn't tell you when to secure your accounts.
California consumers considering a legal claim should verify that the CCPA applies to the business, the information, and the conduct at issue. State law and the facts of the incident matter. For substantial loss or a specific potential claim, consider advice from a qualified attorney or an appropriate state consumer-protection office.
When the company doesn't respond
Escalate according to the harm:
- Unauthorized card or bank activity: Contact the issuer or bank's fraud department and follow its dispute process.
- Account takeover: Use the provider's official recovery process, secure your email, and revoke unfamiliar sessions.
- Identity information exposed: Place a credit freeze and review credit activity.
- Privacy questions: Contact the company's privacy office or security contact in writing.
- State-law concerns: Check your state's attorney general or privacy regulator for the applicable complaint route.
- California CCPA questions: Use the California Attorney General's CCPA information to identify the rights and procedures that may apply.
A complaint to a company or regulator may not recover money automatically. Keep your evidence, ask what documents are required, and get a case number or expected response date when possible.
Quick breach-response checklist
Do now
- Verify the notice independently.
- Save the notice and incident details.
- Change the affected password and every reused version.
- Secure your email and turn on multifactor authentication.
- Contact your bank or card issuer if financial information was involved.
- Consider freezing all three credit reports if identity information was exposed.
Keep watching
- Review bank and card statements.
- Watch for credit inquiries, unfamiliar accounts, password-reset notices, and phishing messages.
- Check verified company updates.
- Record every report, dispute, and conversation.
Escalate when needed
- Report unauthorized transactions promptly.
- Ask the company for written clarification if the notice is vague.
- Use the relevant state or privacy complaint route if the company doesn't address your concern.
- Seek qualified advice if you have financial loss, identity theft, or a specific legal claim.
Common questions
Should I wait for a breach letter before changing my password?
No. If you can verify that a breach affected the account, change the password immediately. If the message itself is suspicious, confirm the incident through the company's known website or app first.
Does a data-breach notice mean someone stole my identity?
No. It means the company believes information was accessed, acquired, disclosed, or otherwise exposed without authorization. Misuse may never occur. The risk depends on what information was involved and how it was protected.
Should I freeze my credit after every breach?
Not necessarily. A freeze is most relevant when the exposed information could be used to apply for credit, such as a Social Security number or certain identification details. For a password-only incident, account security is the more immediate priority. Ask the company what data was involved if the notice isn't specific.
Is credit monitoring enough?
No. Monitoring may alert you to certain changes, while a freeze, password reset, bank notification, or account-recovery step addresses a different risk. Choose the measure that matches the exposed information.
Does the CCPA 30-day period mean a company has 30 days to notify me?
No. The California CCPA cure-notice procedure concerns certain consumer claims and gives a business an opportunity to respond before suit. It isn't a general breach-notification deadline.
What is the most useful next step if I see fraud?
Contact the financial institution or account provider through a trusted channel immediately, report the activity, and request a case number. Save statements, messages, and confirmations rather than relying on the breached company's investigation alone.