A breach notice does not automatically mean someone has accessed your money or identity. It means you need to verify the message, then protect the accounts and data that were exposed. Don't start with the link in the notice. The right response depends on what was taken. A password leak usually calls for account lockdown. A Social Security number exposure calls for credit and identity safeguards. Stolen payment data means contacting your bank or card issuer right away.
The notice alone also doesn't prove misuse. The steps below are for U.S. consumers and focus on what you can control, not tracking the attacker.
Verify the notice first
Save the email, text, or letter, but don't use its links as your starting point. Type the company's address into your browser, open the app you normally use, or call a number from a bank statement, card, or prior account message. An unexpected breach alert, password-reset notice, or suspicious-login warning can itself be phishing.
CISA warns that phishing messages can use login problems, password resets, or suspicious-activity alerts to trick people into revealing credentials.
The official notice should tell you:
- When the incident happened or the period involved
- What data was exposed, such as email address, password, Social Security number, date of birth, driver's license details, or payment numbers
- Whether the company reset credentials or wants you to act
- Whether free credit monitoring or identity protection is included
- A verified way to ask questions
If the notice stays vague, ask what categories of data were involved. Don't give an unsolicited caller your password, one-time code, or full Social Security number because they claim to be helping.
Match the response to what was exposed
| Information exposed | Priority action | What this step does not solve |
|---|---|---|
| Email address and password | Change the password on the affected service and anywhere you reused it. Secure your email first. | It doesn't remove the old password from breach databases. |
| Security questions or recovery details | Replace answers and review recovery email addresses, phone numbers, and trusted devices. | It won't necessarily protect an account where an intruder still has an active session. |
| Social Security number, date of birth, or driver's license details | Consider a credit freeze with all three nationwide bureaus and add a fraud alert. | A freeze doesn't stop takeovers of existing accounts or tax-related identity theft. |
| Credit or debit card details | Contact the card issuer or bank, ask about replacement, and review recent transactions. | A credit freeze won't reverse an unauthorized charge. |
| Medical or insurance information | Contact the provider or insurer and review statements and explanation-of-benefits notices. | Credit monitoring may not reveal medical identity theft. |
Secure accounts in the right order
Start with your email account. It often holds password resets for banking, shopping, social media, and phone service. From there, move to the breached account, any account that reused the same or similar password, financial accounts, and your mobile-phone account.
For each important account:
- Create a long, unique password. A password manager can generate and store different passwords for every service.
- Sign out of other sessions and remove unfamiliar devices.
- Check the recovery email address, phone number, forwarding rules, and authorized third-party apps.
- Turn on multi-factor authentication.
- Review recent login activity and alert settings.
Where supported, passkeys or hardware security keys offer stronger protection against fake login pages. An authentication app also helps, but no method makes an account immune to scams. Don't approve an unexpected sign-in prompt, and never read a one-time code to someone who contacted you.
If you're locked out, use the company's official account-recovery page. Avoid recovery links or phone numbers supplied in a suspicious email or text.
Choose between a credit freeze and a fraud alert
A credit freeze limits access to your credit report and can make it harder for someone to open new credit in your name. You generally place one separately with Equifax, Experian, and TransUnion. Experian's credit-freeze page says you can manage an Experian freeze with a free Experian account.
A freeze won't:
- Stop unauthorized withdrawals or card transactions
- Protect an account that is already open
- Remove information from a credit report
- Prevent every form of identity theft
A fraud alert tells businesses to take extra steps to verify your identity before extending credit. You can request one from a bureau, and Experian says that the other two major bureaus are notified. A fraud alert may be easier if you plan to apply for credit soon, while a freeze creates a stronger barrier against new-credit applications.
If your Social Security number or similar identity data was exposed, consider a freeze even if nothing suspicious has appeared yet. If only an email address was exposed, password protection and phishing awareness usually come first.
Monitor credit reports and dispute errors
Check credit reports for unfamiliar accounts, hard inquiries, addresses, collection accounts, or balance changes. Also review bank and card statements, even if no alert arrived.
If you find something wrong, dispute it with every credit bureau showing the information and with the business that supplied it. The FTC's guidance on disputing credit-report errors explains the basic process.
Include:
- A clear description of the error
- A copy of the relevant report page with the item marked
- Documents that support your position
- Proof of identity or address if requested
- The breach notice, account records, or an identity-theft report when relevant
Keep copies of everything: submission confirmations, letters, dates, and case numbers. Send only what the dispute requires, and follow each company's current submission instructions.
A dispute is for inaccurate or incomplete information. It isn't a way to remove a legitimate account just because it hurts your score. If the information is accurate, use the account's normal resolution process instead.
Contact the correct provider for payment fraud
Don't wait for a credit report to reveal a problem before reporting an unauthorized transaction.
- Credit card: Call the issuer using the number on the card or statement. Ask whether the account number should be replaced and how to submit a billing dispute.
- Debit card or checking account: Contact the bank immediately. Ask about replacing the card, securing the account, and reviewing electronic funds transfers or ACH transactions.
- Prepaid card or payment app: Report the transaction through the provider's official support channel and preserve the transaction ID.
- Wire transfer: Contact the sending bank and the receiving institution as soon as possible. Recovery isn't guaranteed, but delay reduces your options.
Credit-report disputes and payment disputes are separate processes. Reporting an account to a bureau won't fix a fraudulent debit, card, or ACH transaction, and replacing a card won't correct a fraudulent account listed on your credit report.
Take extra steps if your Social Security number was exposed
A Social Security number can remain useful to an identity thief long after a password change. Beyond a credit freeze or fraud alert:
- Review your Social Security activity through your my Social Security account.
- Consider requesting an IRS Identity Protection PIN.
- Watch for unfamiliar tax notices, employer records, benefit claims, or credit applications.
- Contact the relevant agency through its official website if you see suspicious activity.
For online crime, extortion, or account compromise, you can submit information to the FBI's Internet Crime Complaint Center. That report doesn't replace notifying your bank, card issuer, or the company involved.
Use monitoring offers carefully
A breached company may offer free credit monitoring or identity monitoring. Activate it only through a verified company page or a notice you confirmed independently. Monitoring can alert you to certain changes, but it doesn't prevent every misuse and isn't the same as a credit freeze.
You shouldn't need to pay a third party just to place or manage a credit freeze. Be cautious if someone asks for a card number to "activate" protection, demands immediate payment, or asks you to install remote-access software.
Keep a simple record of:
- The breach notice and the date you received it
- Password changes and account-recovery actions
- Freeze or fraud-alert confirmations
- Bank and card case numbers
- Credit-report disputes and supporting documents
- Suspicious calls, emails, texts, or transactions
A practical breach-response timeline
Today
- Verify the notice through the company's official website or a trusted phone number.
- Change the affected password and every reused password.
- Secure your email and turn on multi-factor authentication.
- Call the card issuer or bank if payment information may be involved.
Over the next few days
- Review credit reports and account statements.
- Place a freeze or fraud alert if sensitive identity information was exposed.
- Dispute unfamiliar credit-report entries.
- Activate legitimate free monitoring and request an IRS Identity Protection PIN if appropriate.
Going forward
- Use unique passwords stored in a password manager.
- Review financial statements and account alerts regularly.
- Treat unexpected password-reset and suspicious-login messages as potential phishing.
- Keep breach records until all disputes and account issues are resolved.
Common questions
Do I need to freeze my credit after every breach?
No. A freeze matters most when exposed data could be used to apply for credit, such as a Social Security number or date of birth. If only an email address was exposed, secure the account and watch for phishing first. You can still choose a freeze if you want the extra protection.
Does changing my password undo the breach?
No. It protects the account going forward, but it doesn't erase information that may already have been copied. Change reused passwords elsewhere and review active sessions and recovery settings.
What if my credit score changes after a breach?
The breach alone doesn't explain a score change. Check your reports for new accounts, inquiries, missed-payment reporting, or other errors. Dispute inaccurate information through the process described by the FTC.
Is credit monitoring enough?
No. Monitoring may alert you after a change appears. It doesn't block all account takeovers or unauthorized payments. Use account security, payment-provider alerts, credit protections, and regular review together.
If you're unsure where to begin, verify the notice, secure your email, change every reused password, then match the next step to the data exposed.