If you've received a data breach notice, don't use its links or phone numbers until you've confirmed that the message is genuine. Then identify the information involved and respond to that specific risk: change exposed passwords, contact financial institutions about account details, or freeze your credit if sensitive identity information was compromised.
A notice means your information was exposed or may have been exposed. It doesn't necessarily mean someone has used it. Even so, prompt action matters when the affected data includes a Social Security number, financial details, login credentials, or security-question answers.
The steps below are for U.S. consumers and are practical information, not legal advice.
Start with these four steps
- Verify the notice independently. Open the company's trusted app, type its website address yourself, or call a number printed on your card or statement.
- Find out exactly what was exposed. An email address creates a different risk from a reused password, bank account number, or Social Security number.
- Secure the affected account. Change compromised passwords, review recovery settings, and remove devices or connected apps you don't recognize.
- Watch for misuse. Check financial statements and credit reports. If fraud has already occurred, contact the company where it happened and use IdentityTheft.gov to build a recovery plan.
Save the original notice, including its date, sender, envelope, and any reference number. You may need it if fraud appears later.
Confirm that the breach notice is real
Real breaches often attract follow-up phishing attempts. A scammer may copy the affected company's branding and claim that you need to confirm your password, pay for protection, or provide a one-time authentication code.
Before responding:
- Look for a notice inside your existing online account.
- Visit the company's website without following the message's link.
- Contact the company through a number on its official website, your card, or a recent statement.
- Don't give an unexpected caller your password or verification code.
- Don't pay someone who claims payment is required to secure your account or remove exposed information.
A useful notice should identify the types of information involved, describe the incident, and explain any protection being offered. If it doesn't, contact the company through a verified channel.
Match the response to the information exposed
There isn't one remedy for every breach. Use the notice to identify the data at risk, then work through the relevant row below.
| Information involved | Practical response |
|---|---|
| Username and password | Change the password on the affected account and everywhere else you reused it. Secure your email account first if it uses the same password. |
| Email address or phone number | Expect phishing messages and unexpected password-reset attempts. Review the related account's password, recovery details, and sign-in history. |
| Social Security number or other sensitive identity data | Consider freezing your credit with Equifax, Experian, and TransUnion. Review your credit reports for unfamiliar accounts. |
| Debit card, bank account, or routing information | Call the bank or credit union through an official number. Ask whether the account or card should be restricted, replaced, or closed. |
| Credit card number | Contact the issuer, report charges you don't recognize, and ask whether it will replace the card. |
| Medical or insurance information | Check for claims or accounts you don't recognize and contact the provider's or insurer's fraud department if something is wrong. |
Login information deserves particular attention. If you reused a breached password, accounts outside the original incident may also be vulnerable.
Lock down login accounts
Start with email when its password was exposed or reused. Someone with access to your inbox may be able to reset passwords for other services.
Work in this order:
- Change the affected password.
- Replace that password on every other account where you used it.
- Give each important account a unique password. A password manager can generate and store them.
- Turn on two-factor or multifactor authentication where available.
- Review recent sign-ins, recovery email addresses, phone numbers, and connected apps.
- Sign out unfamiliar devices and revoke access you don't recognize.
If you're locked out, use the company's official account-recovery page. Don't trust a recovery link sent in an unexpected email or text, even if the message refers to a real breach.
Credit freeze or fraud alert?
These tools aren't interchangeable, and neither one secures a compromised bank account or password.
Credit freeze
A credit freeze restricts access to your credit report, making it harder for someone to open a new credit account in your name. It's free and stays in place until you lift or remove it.
For broad coverage, request a separate freeze from each of the three major credit bureaus:
- Equifax
- Experian
- TransUnion
A freeze won't stop transactions on an existing bank or credit-card account. It also won't change passwords or close accounts, so continue with the other breach-response steps.
According to USAGov's credit-freeze instructions, a bureau generally must place a freeze within one business day after an online or phone request, or within three business days after a request by mail. An online or phone request to lift a freeze generally must be completed within one hour. Check the bureau's current identity-verification instructions before applying.
Fraud alert
A fraud alert tells businesses to take additional steps to verify your identity before issuing new credit. An initial fraud alert lasts one year and may be renewed. Unlike a freeze, you only need to contact one of the three bureaus; that bureau notifies the other two.
The FTC's credit-freeze and fraud-alert guidance provides current instructions for both options.
A practical way to choose:
- Consider a freeze if a Social Security number or other information used to apply for credit was exposed.
- Consider a fraud alert if you want an added identity-verification signal without restricting access to your reports.
- Don't treat free credit monitoring as a substitute for a freeze. Monitoring may alert you to activity, but a freeze restricts access to the report used for many new-credit applications.
Review money accounts and credit reports
Check bank, debit-card, credit-card, and payment-app activity for transactions you don't recognize. Look at statements from before and after the reported incident; misuse may not appear on the date of the breach.
When you find something suspicious:
- Contact the financial institution or payment service through an official channel.
- Identify each transaction you dispute.
- Ask whether the affected account or card needs to be restricted, replaced, or closed.
- Ask what documents are required and how to submit them.
- Record the date, department, representative's name, case number, and promised follow-up.
- Keep checking statements after a replacement card or account is issued.
The payment method matters. Debit and electronic bank transfers, credit-card charges, wire transfers, and peer-to-peer payments can have different reporting and recovery procedures. Don't assume the billing-dispute process for a credit card applies to another payment type.
Review your credit reports as well. An account you don't recognize can be a sign of identity theft. The FTC's credit-freeze and fraud-alert page links to the official free credit-report resource and explains what to look for.
If someone has already used your information
Exposure alone isn't proof of identity theft. Misuse includes opening an account, making a purchase, taking over an existing account, or committing another fraud with your information.
Start with the business where the fraud occurred. The FTC's identity-theft recovery guidance recommends contacting its fraud department, explaining that your identity was misused, and asking it to close or freeze the affected account.
Next, use IdentityTheft.gov's data breach guidance to create an FTC recovery plan. Save the resulting report and your correspondence with each company.
If bank or card details were exposed but no transaction has appeared, you can still contact the institution. Ask what protections are available and how it wants unauthorized activity reported. Don't wait for a monitoring service to handle an affected financial account for you.
Questions to ask the breached company
A vague notice may not give you enough information to choose the right response. Ask focused questions instead of settling for a general statement that an investigation is continuing:
- Which categories of my information were involved?
- Was the information accessed or acquired, or was it only stored in an affected system?
- What dates does the incident cover?
- Has the company identified any misuse?
- What has been done to secure my account?
- Is credit monitoring or identity-restoration help available?
- How can I enroll without using a link from the notice?
- Where should I report fraud that appears later?
The company may not know whether a particular person viewed or used your record. An uncertain answer isn't proof that misuse occurred, but it isn't proof of safety either. Ask what the investigation has established and what remains unknown.
The FTC's business breach-response guidance tells companies to describe clearly what they know about a compromise. That is a useful standard when deciding whether a notice contains enough detail to act on.
Keep a breach file
Put the records in one physical or digital folder:
- The notice, envelope, or original electronic message
- Dates when you changed passwords or enabled multifactor authentication
- Freeze or fraud-alert confirmations
- Bank and card-issuer call notes
- Dispute forms and account-closure confirmations
- Replacement-card notices
- Relevant credit-report pages
- Identity-theft reports and company follow-up messages
Don't put passwords or one-time authentication codes in this file. Its purpose is to preserve evidence, dates, case numbers, and contact history.
Mistakes that leave gaps
- Changing a reused password only on the breached website
- Assuming credit monitoring prevents new accounts from being opened
- Freezing credit but leaving compromised passwords unchanged
- Waiting for a fraudulent charge before contacting a bank about exposed account details
- Calling a number from a message that hasn't been verified
- Giving an unsolicited caller a password or authentication code
- Assuming that exposure of an email address automatically means the credit file was compromised
- Using a credit-card dispute process for a different payment rail without checking the applicable procedure
Common questions
Must I freeze my credit after every breach?
No. Base the decision on the information involved. A freeze is particularly relevant when a Social Security number or other data used for new-credit applications was exposed. If the incident involved a password, the immediate job is to secure the affected accounts and any other account where that password was reused.
Does a breach notice mean my identity was stolen?
Not by itself. The notice means information was exposed or may have been exposed. Identity theft occurs when someone uses that information without permission, such as to open an account, take over an account, or make a purchase.
How long will a credit freeze remain?
It stays in place until you ask the bureau to lift or remove it. You can lift it temporarily when a legitimate creditor needs access and restore it afterward.
Is there one deadline for responding to a breach?
No single schedule covers every breach, account, or payment method. A company notice may include enrollment dates for offered services, while banks and payment providers have their own procedures for unauthorized activity. Secure accounts and report suspicious transactions promptly rather than waiting for every detail of the breach investigation.
What should I do if fraud appears months later?
Contact the business or financial institution where it occurred, secure the affected account, and document the case. Then update or create your recovery plan through IdentityTheft.gov. Keep the original breach notice because it may help establish the timeline.
Start now with the notice itself: verify the sender through an independent channel, mark the exact data involved, and complete the matching account, bank, or credit-protection steps.