If a company says your information was exposed, take two tracks at once: reduce the risk to your accounts and report the part of the problem to the office that handles it. There isn't one federal consumer form for every data breach.

The best route depends on what happened. The Federal Trade Commission (FTC) is a common starting point for fraud, identity theft, or potentially misleading privacy and security claims. HHS's Office for Civil Rights (OCR) handles possible HIPAA violations. A state attorney general may handle state privacy or consumer-protection concerns. The Consumer Financial Protection Bureau (CFPB) may help when a bank or another consumer financial company mishandles your account or fraud claim. The FBI's Internet Crime Complaint Center (IC3) is designed for suspected hacking and other internet crimes.

A complaint can give an agency useful information for enforcement. It usually won't replace a bank fraud claim, recover your money automatically, or prove that the company broke the law.

Choose the complaint route that fits

What happened Where to start What to keep in mind
You suspect identity theft, fraud, or misleading privacy or security claims FTC's fraud reporting service The FTC generally does not act as your private lawyer or resolve an individual dispute
A health plan, health care provider, clearinghouse, or business associate may have mishandled protected health information HHS's HIPAA information and the OCR complaint portal HIPAA does not cover every company that stores or processes health-related information
A bank, lender, payment app, debt collector, or other financial company mishandled your account or fraud claim The company's fraud department, followed by the CFPB complaint portal when appropriate A CFPB complaint does not replace the provider's fraud or transaction-dispute process
You suspect hacking, unauthorized system access, ransomware, or extortion IC3's data breach guidance IC3 is a reporting channel, not emergency response or a guaranteed recovery service
A business may have violated your state's breach-notification, privacy, or consumer-protection law The official consumer complaint page for your state attorney general Authority, deadlines, and available remedies vary by state

You can use more than one route when the reports concern different conduct. For example, an unauthorized bank-account transfer may justify a claim with the bank, an IC3 report, and an FTC report. Keep each report factual. Don't send the same unsupported accusation to every agency.

Secure your accounts before filing

Don't wait for a regulator to respond before reducing the chance of more harm.

  1. Start with your email account. Change the compromised password and any other password you reused. Sign out of unfamiliar sessions, turn on multifactor authentication, and replace exposed recovery codes or security questions.
  2. Call your bank or card issuer. Use the number on your card, statement, or the institution's official website. Ask how to block or replace the affected payment method and follow the provider's fraud or transaction-dispute process.
  3. Consider a credit freeze. The FTC says freezes are free and remain in place until you ask the credit bureaus to remove them. A freeze can help prevent someone from opening new credit accounts in your name. Place one separately with Equifax, Experian, and TransUnion. It won't secure an existing account, so keep checking statements and credit reports.
  4. Compare a fraud alert with a freeze. They are different tools. The FTC's guidance on credit freezes and fraud alerts explains what each one does and how to place or renew it.
  5. Expect follow-up scams. Someone may call or message you pretending to offer monitoring, a refund, or account assistance. Don't give an unsolicited contact your password, one-time code, full Social Security number, or complete bank-account number.
  6. Save the breach notice. Keep the original email, letter, or account message, along with the company's case number and the date you received it.

Free credit monitoring offered after a breach may be useful, but signing up doesn't replace changing passwords, freezing credit, or disputing unauthorized transactions.

Read the breach notice carefully

The notice may not answer every question, but it should give you a starting timeline. Look for:

If the notice is vague, ask the company for clarification in writing. Questions that may help include:

Don't turn an unanswered question into a confirmed fact. In your complaint, separate the three categories: what you know, what the company says, and what you suspect.

Build a simple evidence file

A short timeline is easier for an agency, bank, or company to follow than a folder of unsorted screenshots. Use four columns:

Date What happened Evidence Action taken
[date] Received the breach notice Saved email or letter Contacted the company
[date] Saw an unfamiliar login or account change Screenshot or account record Changed password and enabled MFA
[date] Noticed an unauthorized transaction Bank alert and claim number Reported it to the bank

Collect the records that relate to your complaint:

Redact unnecessary sensitive information before uploading or mailing anything. Unless an official form specifically asks for it, don't include a full Social Security number, full bank-account number, complete payment-card number, password, or entire medical record. Keep the unredacted originals in a secure place in case an agency later requests a specific document.

Give the company a chance to respond

The company may control the account, the fraud investigation, or the explanation of what happened. Contact it using information from the breach notice or the company's official website, not from a suspicious email or text.

Ask for a written response. State:

  1. When you learned about the incident
  2. Which account or service is involved
  3. What information the notice says may have been exposed
  4. Any suspicious activity, loss, or continuing risk you have observed
  5. The action you want, such as account restoration, a written explanation, or fraud assistance

You don't have to wait for the company's answer before filing with an agency. If the company doesn't respond, record the dates and methods of your attempts and include that information in the complaint.

Reporting fraud, identity theft, or misleading claims to the FTC

The FTC may be a suitable route when a breach is connected to identity theft, fraud, or claims about privacy or security that may have misled consumers. A breach notice by itself doesn't establish that the company violated a particular FTC rule.

To submit a report:

  1. Open the FTC's fraud reporting service.
  2. Select the category that most closely matches the problem, such as identity theft, fraud, or a deceptive business practice.
  3. Identify the company, website, app, or service involved.
  4. Provide the incident and discovery dates if you know them, the information involved, and a concise account of what happened.
  5. Describe suspicious activity or financial loss separately from the possible security failure.
  6. Upload only relevant, redacted documents if the form accepts attachments.
  7. Save the confirmation number and a copy of what you submitted.

Consumer reports help the FTC identify patterns and support possible enforcement. The FTC generally won't determine whether you are owed compensation or negotiate a personal settlement. If you lost money, contact the bank, card issuer, payment provider, or other company responsible for the transaction separately. The FTC contact page has additional directions if the online reporting route doesn't fit.

Avoid declaring that a company violated a specific FTC rule simply because it lacked a security feature. That conclusion depends on the company, the information involved, the promises it made, and the facts of the incident.

Filing a HIPAA complaint with HHS OCR

HIPAA applies to covered entities such as health plans, health care providers that conduct certain electronic transactions, health care clearinghouses, and their business associates. It does not automatically cover every health app, employer, school, life insurer, or technology company that handles health-related information.

A complaint may fit when a covered organization improperly used or disclosed protected health information, failed to provide required access, or may have violated the HIPAA Privacy, Security, or Breach Notification Rules.

Before filing, check that:

You can use the OCR complaint portal, or start with HHS's HIPAA information. Include the breach notice and limited supporting evidence. Don't send an entire medical file unless the form or OCR specifically requests it.

OCR generally expects a complaint within 180 days after you knew, or should have known, about the possible violation. It may allow more time for good cause, but an extension isn't something to assume.

The 60-day period often associated with HIPAA is generally the organization's deadline to notify affected people of a reportable breach. It is not a 60-day deadline for a patient to file an OCR complaint. A breach notice also doesn't prove that a HIPAA violation occurred. OCR may find no violation, request corrective action, provide technical assistance, or pursue enforcement based on the facts.

An employer acting only as an employer, for example, may not be covered by HIPAA even if it has health information about its workers. Another law or complaint route could still apply.

Complaining to a state attorney general

A state attorney general may accept complaints about unfair business practices, inadequate breach notices, or conduct that may violate state privacy or data-security law. Find the official consumer-protection page for the state where you live, where the company operates, or where the harm occurred. The office may refer the matter elsewhere or decide not to open an individual investigation.

Give the office a clear record of:

State laws don't create identical rights or remedies. California's privacy and security rules, for example, shouldn't be treated as a promise that every breach produces a payment to each affected person. A government penalty and a private damages claim are separate issues. California residents can review the California Attorney General's CCPA information, while still checking how the facts and current law apply to their situation.

When the CFPB belongs in the picture

Use the CFPB route when a consumer financial company mishandles your account, fails to address identity theft, or gives you trouble after a security incident. Possible examples include a bank, lender, payment app, debt collector, or consumer reporting company.

For an unauthorized transfer or card transaction, file the bank or provider's fraud claim first. Then use the CFPB complaint portal if the company fails to handle the claim, investigate the issue, or otherwise address a problem with a covered financial product or service.

A CFPB complaint is sent to the company for a response, but the timing and result can vary. Don't assume that filing with the CFPB replaces or extends the deadline or procedure for disputing an electronic transfer, debit transaction, or credit-card charge. Keep the provider's claim number and every transaction record.

A retailer's data breach doesn't automatically become a CFPB matter because you used a card to pay. The payment dispute belongs with the card issuer or bank. The retailer's security practices may be better suited to an FTC or state complaint.

Reporting hacking or internet crime to IC3

Use IC3's data breach guidance for suspected hacking, unauthorized system access, ransomware, extortion, or another internet crime. Include the company or account involved, dates, affected systems if known, the types of data involved, communications from the attacker, and any financial loss. IC3 asks filers to use the words "data breach" in the incident description when appropriate.

IC3 and local law enforcement reports can support an investigation, but neither guarantees that stolen money or data will be recovered. Continue working with your bank, card issuer, or account provider.

Contact local law enforcement for identity theft, threats, stalking, or an immediate safety concern. Call emergency services for an emergency; an online report isn't a substitute for urgent help.

Complaint letter template

Use the structure below for an agency form or a mailed complaint when that agency accepts one. Adjust it to the office and leave out information the form doesn't require.

Subject: Complaint about a suspected data breach at [Company]

I am a resident of [state]. On [date], I received a notice from [company] stating that [briefly describe the incident]. The notice says that the following information may have been involved: [list only the categories identified].

I observed or experienced the following: [describe suspicious activity, account changes, financial loss, or continuing risk]. I contacted [company] on [dates] using [method]. The company responded that [summarize the response], or did not respond.

I have taken these steps: [password changes, MFA, credit freeze, bank fraud claim, police report, or other action]. I request that your agency review whether the company's conduct complied with the laws or rules within your authority and advise me of any next steps available to me.

Attached are: [breach notice, timeline, correspondence, screenshots, and claim numbers]. I have redacted unnecessary account and identity information.

Sincerely,
[Name]
[Safe contact information]

Stick to dates, documents, and observable events. A factual timeline is more useful than a long list of penalties or legal conclusions.

After you submit

Save the confirmation page, case number, submitted text, and attachments. Add each agency contact to your incident log.

An agency may:

A complaint doesn't guarantee a refund, credit-monitoring service, settlement, or finding of wrongdoing. If the situation changes, update the existing complaint with new facts and its case number instead of filing a duplicate report that leaves out the earlier history.

Mistakes that can make the report less useful

If you live outside the United States

This article covers U.S. complaint routes. If you live in the European Union, the United Kingdom, or another country, use the official data-protection or consumer authority for your country or region. A U.S. complaint won't substitute for a local GDPR, UK data-protection, or other local complaint.

For substantial financial loss, an ongoing account takeover, or a dispute about a legal claim, consider advice from a qualified professional. This is practical consumer information, not legal advice. Start with the account provider for any live fraud, save the claim number, and then send the narrowest well-documented complaint that matches the facts.