If you received a U.S. data breach notice, take these steps in order:
- Verify the notice through a trusted company channel.
- Change any exposed or reused passwords and turn on multi-factor authentication.
- Contact your bank or card issuer immediately if payment information or unauthorized activity is involved.
- Save the notice, dates, account records, and proof of loss.
- Decide whether you need a government complaint, a bank dispute, a company reimbursement request, or a settlement claim.
The Federal Trade Commission accepts reports about fraud and bad business practices through ReportFraud.gov. An FTC report is not a private lawsuit and does not automatically produce compensation. Your bank's dispute process, state law, a company program, or a settlement notice may control whether you can recover money.
This is general information for U.S. consumers, not legal advice.
A breach notice, complaint, and compensation claim are different
These processes can relate to the same incident, but they serve different purposes:
| Process | Main purpose | What to expect |
|---|---|---|
| Breach notice | Tells you what a company says happened and what it recommends | It isn't necessarily an admission of wrongdoing or a payment offer |
| Government complaint | Creates a record for a regulator or law-enforcement agency | It may help identify an investigation or pattern, but it usually doesn't produce an individual refund |
| Compensation claim | Seeks reimbursement from a company, insurer, settlement fund, or court | Eligibility, proof, and deadlines depend on the particular claim |
There is no single U.S. complaint form or nationwide notification deadline for every breach. State notification laws, industry-specific rules, company policies, the type of information exposed, and the facts of the incident can all matter. A notice by itself also doesn't establish legal liability or guarantee a payment.
What to do after receiving a breach notice
1. Verify and preserve the notice
Save the email, letter, and envelope. Take screenshots of any online notice, including the date and contact details. A scammer can copy a real breach notice, so don't click an unexpected link or call an unverified number.
Instead, type the company's website address yourself or use a phone number from an account statement or earlier trusted communication. Record:
- The date you received the notice
- The incident date or discovery date, if provided
- The types of information involved
- Whether your account was affected individually or as part of a larger group
- The company's password-reset, monitoring, or reimbursement offer
- Any settlement or claim deadline
Don't assume every customer had the same information exposed. Names, email addresses, passwords, Social Security numbers, medical details, and payment data create different risks.
2. Reduce the immediate risk
If a password or security question may have been exposed, change it on the affected service and anywhere else you reused it. Use a new password and turn on multi-factor authentication.
If a Social Security number or other identity information was exposed, consider placing a credit freeze or fraud alert with each nationwide credit bureau. Review your credit reports and watch for unfamiliar accounts.
If payment information was involved, contact the bank or card issuer through an official number. Ask whether the account or card should be replaced, and report suspicious transactions immediately. These actions are separate from filing a complaint. Waiting for a regulator to respond won't protect an account today.
3. Build an evidence file
Keep a simple timeline showing the date, action, and result. Include:
- The company's notice and follow-up messages
- Password resets, account-lockout messages, and recovery requests
- Bank or card statements showing unauthorized activity
- Credit-monitoring or fraud-alert records
- Police or identity-theft reports, if applicable
- Fees, replacement costs, and other documented out-of-pocket losses
- Your messages to the company and its replies
- The report number for any government complaint
Redact full Social Security numbers, passwords, complete payment-card numbers, and security answers before sharing documents. A complaint needs useful facts, not a new copy of the sensitive data.
4. Ask the company for specific information
Use the privacy, security, or breach-response contact listed in the notice. Ask questions the company can reasonably answer:
- What information connected to your account was exposed?
- When did the company discover the incident, and what period did it cover?
- Has the company secured the affected system?
- What monitoring, replacement, or other remediation is available?
- Is there a reimbursement process, settlement administrator, or claim deadline?
- Where should you send documented losses or questions?
A company may not share a complete forensic report while its investigation is continuing. Keep the request focused on your account, the risk to you, and the remedy you need.
How to file a data breach complaint with the FTC
Use the FTC's ReportFraud.gov complaint process when the breach or the company's response raises a concern about fraud, identity theft, deceptive communications, or a bad business practice. Describe what the business did, when it happened, what information was involved, and what harm followed.
Include:
- The company's legal or public name and website
- The date you received the breach notice
- The incident dates stated in the notice
- The types of information involved
- Any misleading statement or failure to provide promised protection
- Actual financial harm, unauthorized transactions, or identity-theft activity
- The steps you took and the response you received
Separate confirmed facts from suspicion. For example, identify what the notice says, what you observed in your account, and what you believe may have happened. Don't guess at information the notice does not provide.
The FTC's filing guidance says you'll receive a report number and tips about what to do next. Save the number. The report won't function as a private lawsuit, force a company to pay you, or guarantee a personal investigation update. The FTC may use reports to identify patterns and decide whether broader enforcement is appropriate.
You don't have to wait for an agency response before contacting your bank, freezing your credit, or asking the company for remediation.
When another complaint or recovery route makes more sense
Choose the next step based on the harm, not just the existence of a breach.
| Problem | First step | What that step does not replace |
|---|---|---|
| Unauthorized card or bank transaction | Contact the card issuer or bank immediately | An FTC report or state complaint |
| New account or other identity theft | Contact the creditor, credit bureaus, and appropriate law enforcement | A claim for compensation |
| Suspected deceptive notice or bad security practice | File an FTC report and, when appropriate, a complaint with your state attorney general or another relevant state office | A private lawsuit or settlement claim |
| A settlement or reimbursement notice | Use the administrator and follow the notice exactly | A general complaint form |
| No confirmed loss but exposed credentials | Reset passwords, enable multi-factor authentication, and monitor accounts | A decision about whether the company's conduct violated the law |
State complaint procedures differ. A state attorney general may accept a consumer complaint, refer it to another agency, or take no individual action. Filing with a state office doesn't automatically create a right to damages.
These processes can run at the same time. For example, you can contact your bank about an unauthorized transaction while reporting suspected deceptive conduct to the FTC. A government complaint generally won't replace the bank's dispute process or a settlement claim.
A practical letter to the company
Send a short, factual request through the company's verified contact channel. You can adapt this wording:
Subject: Data breach notice dated [date] - request for details and remediation
I received your notice dated [date] concerning the incident involving my [account or service]. The notice states that [list the information identified in the notice] may have been exposed.
Please confirm what information connected to my account was involved, what protective steps are available, and whether there is a process for submitting documented losses. I experienced [briefly describe the confirmed loss or account problem] on [date].
Please respond in writing and identify any claim or enrollment deadline that applies. I have retained the notice and supporting records.
Sincerely,
[Name]
[Safe contact information]
Don't threaten criminal charges, inflate the amount of a loss, or send sensitive information the company didn't request. If you submit a document, remove unnecessary account numbers and other private details.
How compensation claims work
Exposure alone doesn't guarantee a payment in the United States. Possible recovery routes include:
- A company reimbursement or identity-protection program
- An official class-action or settlement claim
- Reimbursement for an unauthorized transaction through the bank or card issuer
- A private legal claim based on the facts and applicable state or federal law
A settlement notice usually states who qualifies, what expenses are covered, what evidence is required, and when the claim must be submitted. It may also require you to release certain claims. Read that language before accepting a payment, coupon, or other benefit.
For a direct request to the company, identify the specific loss, attach redacted records, and ask for a defined remedy. Financial statements, invoices, replacement-cost receipts, and correspondence are more useful than a general statement that the breach caused inconvenience. Time spent or emotional distress isn't automatically reimbursed; whether those losses matter depends on the governing law and the facts.
Be cautious of anyone asking for an upfront fee to release "breach compensation." Verify a settlement administrator through the original company notice or an independently located court or government record, not just a link in an unexpected email.
Deadlines and what happens after you file
Act promptly, but identify which deadline applies to which process:
- Account and payment protection: Contact the bank, card issuer, or creditor as soon as you see a problem. Its dispute procedures may have separate notice requirements.
- FTC or state complaint: File while the facts and records are fresh. A regulator's complaint process doesn't generally guarantee a personal response or payment.
- Settlement claim: The deadline in the official notice controls. Late claims may be rejected.
- Private legal claim: Court filing deadlines vary by state, claim type, and facts. An agency complaint generally doesn't automatically extend that deadline.
After submitting a complaint, keep the confirmation number and update your timeline. The company may send additional notices, a regulator may request information, and the bank may investigate a transaction separately.
What the CafePress FTC action shows
The FTC's action against CafePress illustrates why notices and dates matter. The FTC alleged that a hacker exploited security failures in February 2019 and accessed millions of email addresses and passwords, unencrypted names and addresses, security questions and answers, more than 180,000 Social Security numbers, and other payment information. The agency also alleged that affected customers weren't notified until September 2019.
The action was announced years after the alleged incident. That doesn't mean every delayed notice violates the law, and an enforcement action doesn't automatically pay every affected consumer. It does show why you should preserve the original notice, record the timeline, and separate a regulatory complaint from a personal compensation claim.
Frequently asked questions
Can I file an FTC report if I haven't lost money?
Yes, if you have a credible concern about fraud, identity theft, a deceptive statement, or a bad business practice. Describe what you know and label anything uncertain as a suspicion. A report can help identify a pattern, but it doesn't guarantee compensation.
Does a breach notice mean the company admitted legal fault?
No. A notice generally communicates the company's current understanding of an incident and its obligations or policy. It isn't automatically a legal admission, and it doesn't settle whether the company acted unlawfully.
Does exposed personal information automatically qualify me for a payout?
No. Payment may depend on actual harm, the information involved, causation, applicable law, or the terms of a settlement or company program. Check the official notice instead of relying on advertised averages.
Should I complain to the FTC before contacting the company?
You can report suspected misconduct without waiting for a company reply. Contacting the company is still useful when you need account-specific information, a password reset, a replacement card, monitoring enrollment, or reimbursement instructions.
Does the GDPR 72-hour rule apply to U.S. consumers?
No. This is a U.S.-focused process. The GDPR's 72-hour rule concerns certain organizations notifying a data protection authority; it isn't a universal U.S. consumer deadline for filing a complaint.
Do I need a lawyer?
You don't need a lawyer to secure your accounts or submit an FTC report. Consider advice from a licensed attorney or consumer legal-aid service if you have substantial documented losses, receive a settlement release, face a disputed claim deadline, or are considering court action.
If you're handling a notice now, verify it through a trusted channel, contact any affected bank or card issuer, and write down the exact data and dates involved before filing a complaint or compensation claim.