If a company says your information was exposed, you don't need every detail before reporting it. Save the notice, protect the accounts that may be at risk, then send the complaint to the body that matches the problem:

A complaint can prompt review, corrective action, or penalties. It usually won't put money in your pocket automatically.

What a complaint does, and what it doesn't

A breach notice is what the company sends you. A complaint is your report to a regulator or enforcement agency. They aren't the same thing.

State and federal rules usually put the investigation and notice duties on the business. A state's business-notification deadline is normally not the deadline for your own complaint. Deadlines and thresholds depend on the state and industry.

Regulators can investigate, demand changes, or pursue penalties. They generally don't become your lawyer, refund every expense, or decide a private damages claim. If money moved, contact the bank, card issuer, or payment provider separately.

Before you file

Take these steps soon after you get a credible notice.

  1. Verify the message. Don't click links in an unexpected email. Go to the company's site by typing the address or using a trusted bookmark, then confirm the incident through official support or privacy channels.
  2. Keep the original notice. Save the email, letter, text, and attachment. Write down the company name, notice date, suspected incident date, and the categories of information involved.
  3. Fix reused passwords. Change any exposed password everywhere it was reused, starting with email and financial accounts. Add multifactor authentication and sign out of sessions you don't recognize.
  4. Think about a credit freeze. Freeze your file separately with Equifax, Experian, and TransUnion. A fraud alert can start with one bureau, which must tell the other two. The FTC's credit freeze and fraud alert guidance explains the difference.
  5. Respond to actual misuse. If someone opened an account, used your identity, or made an unauthorized charge, report it to the business involved right away. You can also create an identity theft report at IdentityTheft.gov. A credit freeze won't stop every takeover of an existing account.

Don't email a full Social Security number, password, authentication code, or complete account number in a public complaint or ordinary message. Use the last four digits or a redacted copy unless the official form specifically requires more.

U.S. complaint routes

FTC for fraud or deceptive conduct

Use the FTC when a company may have made false security promises, handled your data in a deceptive way, or failed to address fraud connected to a breach. The FTC isn't a general breach-notification court, and a report doesn't guarantee an investigation.

  1. Go to ReportFraud.ftc.gov.
  2. Pick the closest category. If no label fits perfectly, describe the exposure in your own words.
  3. Name the company and service, say when you learned about the incident, and repeat what the company told you.
  4. List the information involved and any fraud, fees, or account problems that followed.
  5. Upload redacted evidence if the portal allows it, then save the confirmation.

If you already have identity theft, use the FTC identity theft reporting process too. Keep the reports consistent and don't stretch facts you can't verify.

State attorney general

Your state attorney general may take complaints about late notices, misleading notices, weak privacy practices, or a company's refusal to address a consumer problem.

Use your state's official website and look for a consumer complaint form. A business breach-reporting page may not be the right place for an individual. The Texas Attorney General's data breach reporting page, for example, separates reports filed by affected businesses from complaints filed by individuals.

When you complete the form:

State rules may depend on where you live, where the company operates, how many residents are affected, and the type of data involved. Colorado guidance says businesses must notify no later than 30 days after determining that a security breach occurred, and larger breaches affecting 500 or more Colorado residents must also be reported to the state AG. Texas requires certain businesses affecting at least 250 Texans to report to the AG no later than 30 days after discovery. Those are business duties, not a universal deadline for your personal complaint.

California CCPA and CPRA concerns

California residents have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. The California Attorney General's CCPA information covers access, deletion, and opt-out rights.

A privacy-rights request isn't the same as a breach complaint. Asking a business to provide or delete information doesn't by itself prove that it used reasonable security or violated breach rules.

California's private right of action is limited. It generally involves certain categories of personal information in a security incident and an alleged failure to maintain reasonable security. Before suing, the California AG describes a written notice and a 30-day response or cure step. Don't assume every breach supports a private lawsuit. Check the current statute and talk to a California-licensed lawyer before court action.

HIPAA complaint to HHS OCR

Use the HHS Office for Civil Rights when the organization is a HIPAA-covered health plan, health care provider, health care clearinghouse, or business associate. HIPAA doesn't cover every health app, employer, tech company, or wellness service.

A hospital breach notice doesn't automatically prove a HIPAA violation. OCR may need facts about unauthorized access, disclosure, safeguards, or the organization's response.

  1. Use the HHS OCR complaint portal.
  2. Identify the organization and its location.
  3. Say when you learned about the conduct and what information or privacy right was involved.
  4. Explain who may have accessed or disclosed the information, if known.
  5. Attach a redacted notice, messages, records, or other evidence.
  6. File promptly. HIPAA complaints generally must be filed within 180 days after you knew or should have known about the issue, though OCR can extend that period for good cause.

You can also contact the organization's privacy officer through a safe address. Don't send detailed medical information to a shared family email account or an unsecured channel. An OCR complaint is an enforcement request, not a direct claim for personal damages.

If the breach hasn't been confirmed

A rumor, dark-web post, or suspicious login doesn't prove that a particular company had a reportable breach. Treat it as a lead. Say what you know and what you only suspect.

  1. Confirm the claim through the company's official website, privacy notice, or customer-support channel.
  2. Check whether the company published a notice or remediation instructions.
  3. Preserve the source without downloading or redistributing stolen data.
  4. Report credible concerns to the FTC and your state AG.
  5. If you're an employee or contractor, use the organization's security or compliance channel when safe, and follow regulator instructions for supporting material.

Don't try to access company systems, buy exposed data, or test a leaked password. Those steps can create security and legal problems and can damage evidence.

What to include

A short factual timeline usually beats a long accusation. Include:

Use dates and facts, not conclusions. If the company didn't confirm that your Social Security number was exposed, say it's unknown instead of treating it as certain.

Complaint template

Subject: Suspected data breach complaint about [Company]

I am a [customer/patient/account holder] of [Company]. I learned about the possible incident on [date] through [notice, account message, or other source].

The company said that [quote or summarize the notice]. The information identified or potentially involved was [categories of information]. I don't know whether [uncertain fact], but [describe supporting evidence].

The incident affected me as follows: [unauthorized transaction, identity theft, expense, account lockout, or no known financial harm]. I contacted the company on [dates] and received [response or no response].

I'm asking your office to review whether the company complied with applicable consumer-protection, privacy, or breach-notification requirements. Attached are redacted copies of [notice, correspondence, statements, or reports].

You can contact me at [safe email or phone], or I prefer no follow-up contact.

Compensation and lawsuits

A regulator complaint and a money claim do different jobs.

For direct financial fraud, start with the bank, card issuer, payment provider, or account provider. Ask for its fraud or dispute procedure, and record the date and method of your report. A data-breach complaint doesn't replace the deadlines or documentation needed to dispute an unauthorized payment.

For other losses:

There's no single federal lawsuit for every U.S. breach. Potential claims depend on state law, contracts, the type of information, actual injury, causation, arbitration terms, and filing deadlines. A private claim may be hard if you only have a theoretical risk and no documented harm, though the law varies.

If you're weighing a class action or individual case, preserve the notice and records before contacting a lawyer. California consumers should pay close attention to CCPA limits and pre-suit notice rules. An agency complaint can be filed separately, but it doesn't pause every court deadline.

Anonymous complaints and privacy

Some systems let you report without contact information. Others need your identity to investigate or may share the complaint with the business. FTC reporting may be possible without identifying yourself, but read the current form's privacy options. State AG and HHS OCR procedures can differ.

An anonymous report may limit follow-up, clarification requests, and eligibility for an individual remedy. If you provide contact details, use an account and phone number the affected company or another person can't access. Never include passwords or live authentication codes to prove a breach.

If the data involves the EU or UK

Keep U.S. FTC, state, and federal complaints separate from a European complaint. If an organization processed personal data within GDPR scope, you can generally complain to the relevant national supervisory authority. The European Data Protection Board explains national authorities and cross-border supervision.

For a UK GDPR concern, the usual route is the UK Information Commissioner's Office, not a U.S. state AG.

The GDPR's often-mentioned 72-hour period is usually the controller's deadline to notify a supervisory authority when a qualifying breach creates risk. It isn't a 72-hour deadline for you to complain. A later complaint can still be useful, especially if the company gave incomplete information or ignored a privacy request.

A regulatory complaint may lead to investigation or corrective action, but compensation under European law is a separate question that can depend on proof of damage and the available court or dispute process.

After you file

Save the confirmation page, email, or reference number. Keep a copy of what you submitted and note any response date.

An agency may acknowledge the complaint without opening a formal investigation. It may combine reports about the same business, refer the matter elsewhere, or decline to give status details. If you learn a new fact or suffer more harm, send a focused update through the agency's stated process instead of filing repeated forms.

Keep monitoring your accounts. A complaint doesn't freeze credit, close an exposed account, reverse a payment, or change a password for you.

Quick answers

Need proof before filing? No. Report what you know, mark what is uncertain, and attach credible evidence such as the company's notice or a redacted account message. Don't present rumors as confirmed facts.

Can you file with both the FTC and your state AG? Yes, when the conduct may involve federal consumer-protection concerns and state law. Explain the specific issue to each agency. One filing doesn't automatically reach the other.

Does filing guarantee money? No. Enforcement penalties and settlements don't automatically pay every complainant. Payment disputes, company reimbursement programs, settlement claims, and lawsuits have separate rules.

Is the GDPR 72-hour rule your deadline? No. It generally applies to the organization's notification to a supervisory authority. Your complaint or compensation deadline depends on the jurisdiction and procedure.

If a breach notice arrived today, save it, change any reused password, call your financial institution about suspicious activity, and place credit freezes with all three bureaus if that fits your situation. Then send the factual complaint to the regulator that matches the organization.