A business data breach: what should you do first?
If a company says your personal information was exposed, take action before the investigation is over. Verify the notice through a trusted channel, secure affected accounts, contact your bank or card issuer if financial data may be involved, and keep the notice and later updates.
The right response depends on the data. An exposed email address mainly increases phishing and account-takeover risk. A Social Security number may justify a credit freeze. A company's deadline for sending notice isn't a deadline for you to protect yourself.
What to do in the first day
Check that the notice is genuine
Scammers sometimes use a real breach as a reason to send fake messages. Don't click the link or call the number in an unexpected email or text. Instead:
- Type the company's known website into your browser.
- Sign in through the usual app or website.
- Use a phone number from a statement, payment card, or earlier account record.
- Ask the company to confirm the notice and provide an incident reference number.
Keep the original notice, envelope, email headers, attachments, and instructions. The wording may help you work out what information was involved and when the company learned of the incident.
Lock down exposed or reused passwords
Change the affected password from a trusted device. If you used it on other sites, change those passwords too. Start with your email account if it can be used to reset other accounts.
Use a different password for each account and turn on multifactor authentication. Then review active sessions, recovery email addresses, phone numbers, and security questions. Sign out of devices you don't recognize.
A representative should not need your password or a one-time authentication code. Don't give either to a caller who contacts you after the breach.
Call the bank or card issuer when money information is involved
Use the number on your card or statement, not a number in the breach message. Ask the issuer whether you should:
- Replace the card
- Close the account or change its number
- Add transaction alerts
- Review recent and pending transactions
- Dispute an unauthorized transaction
If bank-account details may have been exposed, contact the bank promptly and ask what account-protection or replacement steps it recommends. Report suspicious transactions as soon as you see them. Credit cards, debit cards, and bank accounts can have different dispute procedures and deadlines, so ask the institution what applies to your situation. The breach notice itself does not replace a dispute.
Decide whether a credit freeze or fraud alert fits
These tools address new-credit identity theft, not every kind of fraud.
- A credit freeze restricts access to your credit file, subject to permitted exceptions. You generally have to place or manage it separately with each nationwide credit reporting agency.
- A fraud alert tells prospective creditors to take additional steps to verify your identity. It does not block access to your file in the same way.
A freeze may be worth considering if the notice lists your Social Security number, date of birth, or identity-document information. It won't stop someone from taking over an existing account or using an already-issued payment card.
Equifax's guidance on freezes and fraud alerts explains the distinction and the need to handle a freeze with each nationwide credit reporting agency.
Deal with other exposed identity information
If you see signs that someone is using your information, follow the IdentityTheft.gov data-breach recovery steps. The FTC's consumer guidance on what to do after a data breach can help you identify the next step.
Contact the issuing agency if a driver's license, passport, or other government ID was exposed. If medical information was involved, watch health-plan statements and explanations of benefits for treatment you didn't receive.
Match the response to the information exposed
| Information possibly exposed | Main risk | Practical response |
|---|---|---|
| Email address or phone number | Phishing, impersonation, and account-recovery attacks | Be wary of convincing follow-up messages and use trusted contact methods |
| Username and password | Account takeover and password reuse | Change the password everywhere it was reused and enable multifactor authentication |
| Payment-card information | Unauthorized purchases | Contact the issuer, turn on alerts, and review transactions |
| Bank-account details | Unauthorized withdrawals or transfers | Contact the bank promptly and ask about account protection or replacement |
| Social Security number or date of birth | New-account identity theft | Consider a credit freeze or fraud alert and watch credit activity |
| Medical information | Medical identity theft and privacy exposure | Contact the provider or health plan and review medical statements |
| Driver's license or passport details | Document misuse and impersonation | Contact the issuing agency about replacement or protective steps |
A notice may say that information was "potentially" involved. That doesn't show that anyone has used it, but it also isn't a reason to ignore the warning. Follow the notice's instructions and choose precautions that fit the data category.
What should a breach notice tell you?
The FTC's data breach response guide for businesses says organizations should mobilize a response team and clearly describe what they know about a compromise.
A consumer notice may be updated as the investigation continues, but it should help answer these questions:
- What types of information were involved?
- Which accounts, customers, or time period were affected?
- Were passwords or security questions exposed?
- When did the incident occur, and when was it discovered?
- What has the company done to contain it?
- Is credit monitoring or identity-restoration help available?
- How long does any offered service last, and how do you enroll?
- Where can you ask follow-up questions?
If the notice is vague, contact the company's privacy, security, or incident-response channel. Ask specific questions and record the answers, including the name of the person you speak with and the case number. Don't treat a lack of detail as proof that your information was safe; the investigation may still be developing.
Which U.S. breach law applies?
There isn't one general federal rule that gives every U.S. consumer the same notice, deadline, refund, or monitoring service. The applicable state law, type of information, and industry can change the answer.
State breach-notification laws differ in what they define as personal information, when notice is required, and how the notice must be delivered. The law that applies may depend on where the affected consumer lives and on the business involved.
Health information has a separate federal framework. If a HIPAA-covered provider, health plan, clearinghouse, or business associate has a qualifying breach of unsecured protected health information, individual notice is generally required without unreasonable delay and no later than 60 calendar days after discovery. The HHS breach-reporting information describes the organization's reporting duties.
That 60-day limit is the company's obligation, not a reason for you to wait before changing passwords or calling your financial institution. Likewise, receiving a breach notice doesn't by itself guarantee a payment.
Is free credit monitoring enough?
Credit monitoring can alert you to some changes, but it won't secure your accounts or catch every form of misuse. It may not show:
- A takeover of an existing email, shopping, or banking account
- Unauthorized use of an already-issued payment card
- Medical identity theft
- Fraud that hasn't reached a monitored credit file
- Phishing attempts that use details from the breach
If the company offers monitoring, verify the enrollment process through a known company website or phone number. Check the enrollment deadline, service duration, information the provider collects, and whether identity-restoration assistance is included. Save the confirmation.
Even after enrolling, review bank and card statements, account alerts, and credit activity. Monitoring should supplement those checks, not replace them.
Can you get money after a data breach?
Not automatically. Any recovery may depend on the company's offer, your documented losses, the law that applies, or a settlement or court decision.
If you have lost money or paid costs because of the incident:
- Ask the company whether it has a reimbursement or claims process.
- Keep receipts for replacement cards, document fees, professional assistance, and other direct costs.
- Record unauthorized transactions, dates, calls, case numbers, and the time you spent resolving the problem.
- Report financial fraud to the bank, card issuer, or payment provider first.
- Read settlement or reimbursement notices carefully and use only their official contact details.
Don't pay an upfront fee just to submit a breach claim. If the loss is substantial or the notice refers to a pending legal settlement, consider speaking with a licensed attorney in your state.
Expect scams after a breach
A caller or message may use accurate details about the incident and still be fraudulent. Stop and verify independently if someone:
- Pressures you to act immediately
- Requests a password, PIN, or authentication code
- Tells you to move money to a "safe" account
- Sends a link to a credit-monitoring site with a slightly misspelled domain
- Requests remote access to your computer
- Demands payment to restore an account
End the conversation and contact the company through a website or number you already trust. A legitimate breach administrator can explain the program without asking for your existing login credentials.
Where to take an unresolved problem
Choose the escalation route based on the harm:
- Account access or exposed information: Contact the business's privacy or security team and keep the incident number.
- Unauthorized card or bank activity: Contact the issuer or bank immediately and follow its dispute process.
- Identity theft: Use IdentityTheft.gov and follow its recovery plan.
- A company that won't answer: Contact your state attorney general's consumer-protection office. Complaint procedures and available remedies vary.
- Health information: Ask the provider or health plan whether the incident is being handled under HIPAA and how to obtain more information. The HHS breach-reporting page explains the organization's reporting framework.
A regulator complaint can create a record, but it may not restore account access or recover money as quickly as the bank or company can. Handle urgent financial and account problems first.
Keep a breach-response file
Put the following in one folder:
- The breach notice and later updates
- Screenshots of suspicious messages or transactions
- Names, dates, and case numbers from calls
- Bank or card dispute confirmations
- Password-reset and multifactor-authentication confirmations
- Credit-freeze or fraud-alert confirmations
- Monitoring-service enrollment details
- Receipts and other proof of financial loss
Having the record in one place makes follow-up easier if the company changes its instructions or sends another notice.
Common questions
Does a breach notice mean my identity has already been stolen?
No. It means the company believes unauthorized access, acquisition, or disclosure may have occurred. Take precautions based on the information involved and watch for signs of misuse.
Should I freeze my credit after an email-only breach?
Not necessarily. An email-only exposure mainly creates phishing and account-takeover risks. A freeze is more directly relevant when Social Security, date-of-birth, or similar credit-application information was exposed. You can still choose a freeze if the notice is unclear or you want additional protection.
Do I need to change a password if the notice says passwords weren't exposed?
Change it if you reused it elsewhere, the account shows suspicious activity, or the company recommends a reset. If it was unique and the company confirms credentials weren't involved, focus on multifactor authentication and account monitoring.
How long should I monitor my accounts?
Follow the company's instructions, but don't stop checking simply because a free monitoring period ends. Keep bank and card alerts active, review activity regularly, and report anything you don't recognize promptly.