A breach notice does not automatically mean someone has accessed your money or identity. It means you need to verify the message, then protect the accounts and data that were exposed. Don't start with the link in the notice. The right response depends on what was taken. A password leak usually calls for account lockdown. A Social Security number exposure calls for credit and identity safeguards. Stolen payment data means contacting your bank or card issuer right away.

The notice alone also doesn't prove misuse. The steps below are for U.S. consumers and focus on what you can control, not tracking the attacker.

Verify the notice first

Save the email, text, or letter, but don't use its links as your starting point. Type the company's address into your browser, open the app you normally use, or call a number from a bank statement, card, or prior account message. An unexpected breach alert, password-reset notice, or suspicious-login warning can itself be phishing.

CISA warns that phishing messages can use login problems, password resets, or suspicious-activity alerts to trick people into revealing credentials.

The official notice should tell you:

If the notice stays vague, ask what categories of data were involved. Don't give an unsolicited caller your password, one-time code, or full Social Security number because they claim to be helping.

Match the response to what was exposed

Information exposed Priority action What this step does not solve
Email address and password Change the password on the affected service and anywhere you reused it. Secure your email first. It doesn't remove the old password from breach databases.
Security questions or recovery details Replace answers and review recovery email addresses, phone numbers, and trusted devices. It won't necessarily protect an account where an intruder still has an active session.
Social Security number, date of birth, or driver's license details Consider a credit freeze with all three nationwide bureaus and add a fraud alert. A freeze doesn't stop takeovers of existing accounts or tax-related identity theft.
Credit or debit card details Contact the card issuer or bank, ask about replacement, and review recent transactions. A credit freeze won't reverse an unauthorized charge.
Medical or insurance information Contact the provider or insurer and review statements and explanation-of-benefits notices. Credit monitoring may not reveal medical identity theft.

Secure accounts in the right order

Start with your email account. It often holds password resets for banking, shopping, social media, and phone service. From there, move to the breached account, any account that reused the same or similar password, financial accounts, and your mobile-phone account.

For each important account:

  1. Create a long, unique password. A password manager can generate and store different passwords for every service.
  2. Sign out of other sessions and remove unfamiliar devices.
  3. Check the recovery email address, phone number, forwarding rules, and authorized third-party apps.
  4. Turn on multi-factor authentication.
  5. Review recent login activity and alert settings.

Where supported, passkeys or hardware security keys offer stronger protection against fake login pages. An authentication app also helps, but no method makes an account immune to scams. Don't approve an unexpected sign-in prompt, and never read a one-time code to someone who contacted you.

If you're locked out, use the company's official account-recovery page. Avoid recovery links or phone numbers supplied in a suspicious email or text.

Choose between a credit freeze and a fraud alert

A credit freeze limits access to your credit report and can make it harder for someone to open new credit in your name. You generally place one separately with Equifax, Experian, and TransUnion. Experian's credit-freeze page says you can manage an Experian freeze with a free Experian account.

A freeze won't:

A fraud alert tells businesses to take extra steps to verify your identity before extending credit. You can request one from a bureau, and Experian says that the other two major bureaus are notified. A fraud alert may be easier if you plan to apply for credit soon, while a freeze creates a stronger barrier against new-credit applications.

If your Social Security number or similar identity data was exposed, consider a freeze even if nothing suspicious has appeared yet. If only an email address was exposed, password protection and phishing awareness usually come first.

Monitor credit reports and dispute errors

Check credit reports for unfamiliar accounts, hard inquiries, addresses, collection accounts, or balance changes. Also review bank and card statements, even if no alert arrived.

If you find something wrong, dispute it with every credit bureau showing the information and with the business that supplied it. The FTC's guidance on disputing credit-report errors explains the basic process.

Include:

Keep copies of everything: submission confirmations, letters, dates, and case numbers. Send only what the dispute requires, and follow each company's current submission instructions.

A dispute is for inaccurate or incomplete information. It isn't a way to remove a legitimate account just because it hurts your score. If the information is accurate, use the account's normal resolution process instead.

Contact the correct provider for payment fraud

Don't wait for a credit report to reveal a problem before reporting an unauthorized transaction.

Credit-report disputes and payment disputes are separate processes. Reporting an account to a bureau won't fix a fraudulent debit, card, or ACH transaction, and replacing a card won't correct a fraudulent account listed on your credit report.

Take extra steps if your Social Security number was exposed

A Social Security number can remain useful to an identity thief long after a password change. Beyond a credit freeze or fraud alert:

For online crime, extortion, or account compromise, you can submit information to the FBI's Internet Crime Complaint Center. That report doesn't replace notifying your bank, card issuer, or the company involved.

Use monitoring offers carefully

A breached company may offer free credit monitoring or identity monitoring. Activate it only through a verified company page or a notice you confirmed independently. Monitoring can alert you to certain changes, but it doesn't prevent every misuse and isn't the same as a credit freeze.

You shouldn't need to pay a third party just to place or manage a credit freeze. Be cautious if someone asks for a card number to "activate" protection, demands immediate payment, or asks you to install remote-access software.

Keep a simple record of:

A practical breach-response timeline

Today

Over the next few days

Going forward

Common questions

Do I need to freeze my credit after every breach?

No. A freeze matters most when exposed data could be used to apply for credit, such as a Social Security number or date of birth. If only an email address was exposed, secure the account and watch for phishing first. You can still choose a freeze if you want the extra protection.

Does changing my password undo the breach?

No. It protects the account going forward, but it doesn't erase information that may already have been copied. Change reused passwords elsewhere and review active sessions and recovery settings.

What if my credit score changes after a breach?

The breach alone doesn't explain a score change. Check your reports for new accounts, inquiries, missed-payment reporting, or other errors. Dispute inaccurate information through the process described by the FTC.

Is credit monitoring enough?

No. Monitoring may alert you after a change appears. It doesn't block all account takeovers or unauthorized payments. Use account security, payment-provider alerts, credit protections, and regular review together.

If you're unsure where to begin, verify the notice, secure your email, change every reused password, then match the next step to the data exposed.