If a company says your information was exposed, treat the notice as a reason to act, not as proof that fraud has already occurred. Verify the message independently, save its details, protect your email and reused passwords, and then deal with any payment or identity information named in the notice. Waiting for an unfamiliar charge or account can make the problem harder to contain.

This checklist is for U.S. consumers. State notification laws, financial-account procedures, and industry rules vary. It provides practical information, not legal advice.

What to do first

Don't use a link or phone number from an unexpected email or text until you've confirmed that the message is genuine. Type the company's known web address yourself, open its official app, or use the number on a statement or payment card.

A free credit-monitoring offer from the company may be useful. It doesn't replace password changes, account monitoring, or a credit freeze.

Read the breach notice for specifics

Look for four basic details: what happened, which types of information may be involved, when the company discovered the incident, and what it is doing next. The FTC's breach-response guidance for businesses tells companies to mobilize a response team, use forensic experts where appropriate, and clearly describe what they know about the compromise.

If the notice leaves out information you need, contact the company through a verified website or phone number. Ask:

  1. Which categories of information were involved?
  2. Was my specific account or record affected, or was it part of a larger group?
  3. Were passwords, security questions, payment details, or identity numbers exposed?
  4. Should I reset a password, replace a card, or take another account-specific step?
  5. What monitoring or restoration service is offered, how long does it last, and what is the enrollment deadline?
  6. Where will the company post updates?

"May have been involved" doesn't mean the company has confirmed misuse. It does mean you should base your precautions on the most sensitive information listed when the company can't provide more detail.

Match the response to the exposed data

Information involved Main risk Priority action
Email address and password Account takeover and password reuse Change the password, sign out other sessions, and enable multifactor authentication
Social Security number or other identity number New-account fraud and identity theft Consider a freeze with each nationwide credit bureau and review your credit reports
Credit card number Unauthorized card charges Contact the card issuer, ask whether the card should be replaced, and monitor statements
Bank account or debit details Unauthorized withdrawals or account takeover Contact the bank promptly and ask about account, card, PIN, and transaction protections
Medical information False claims, altered records, or medical-identity theft Contact the provider or insurer and review explanations of benefits and account activity
Driver's license or other government ID Impersonation and identity-verification fraud Follow the notice instructions and ask the issuing agency or company which replacement or flagging steps apply

If the notice lists more than one category, start with the most sensitive one. For example, a password calls for account security, while a Social Security number may justify credit-protection steps as well.

If login information was exposed

Start with the email account tied to the affected service, then work through accounts that reused the same password. Someone who gets into your mailbox may be able to reset other passwords.

After changing the password:

If the service requires a password reset, complete it in the official app or by typing the company's known web address yourself.

Credit freezes, fraud alerts, and monitoring

A credit freeze can make it harder for an identity thief to open new credit in your name. The FTC says freezes are free and remain in place until you tell the bureaus to remove them. If sensitive identity information was exposed, consider placing a freeze with Equifax, Experian, and TransUnion. Store the confirmation details securely.

A fraud alert is a different tool. It asks businesses to take additional steps to verify your identity before opening new credit. The FTC's consumer guidance on credit freezes and fraud alerts explains the difference and provides current placement instructions.

Neither tool secures an existing email, bank, shopping, or payment-app account. Continue to:

The FDIC directs consumers to AnnualCreditReport.com for free annual credit reports in its billing-issue guidance.

Deal with unauthorized charges under the correct payment rules

A breach notice and an unauthorized charge are separate issues. The notice alone doesn't prove that a particular transaction is fraudulent. Review the transaction and report activity you don't recognize.

Credit card charges

For a U.S. credit-card billing error, the FTC's dispute guidance says to notify the issuer in writing so that the notice reaches the issuer within 60 days after the first bill containing the error was sent. Keep a copy of the dispute and proof that you sent it.

The FTC says the issuer must acknowledge the complaint in writing within 30 days unless it has already resolved the issue. It generally must complete its investigation within two billing cycles, and no more than 90 days after receiving the complaint.

Those instructions address credit-card billing errors. They don't automatically set the procedure for debit cards, bank transfers, prepaid accounts, wires, or payment apps. Use the payment provider's process for those transactions.

If your card number was exposed, call the issuer even if no charge has appeared. Ask whether it should replace the card and whether recurring merchants will need updated payment details.

Debit cards and bank accounts

Call the bank as soon as you see a suspicious withdrawal or believe account credentials were exposed. Ask about:

Use the bank's official app, card, or statement to make contact. Save the case number, and follow up in writing if the bank requests documentation. Reporting deadlines and procedures can depend on the type of transaction and account, so ask the bank what applies to your situation.

Don't confuse breach-notice deadlines with your deadlines

There's no single U.S. deadline for every data breach. State privacy laws and sector-specific rules may set a deadline for a company to notify residents or regulators. That deadline isn't the same as your deadline to dispute a credit-card charge, report a bank withdrawal, or place a credit freeze.

For example:

These examples don't establish the rule for every state. Check your state attorney general's current guidance if a company hasn't answered basic questions or you need to understand a notification requirement. Don't wait for a company's regulatory deadline before securing your accounts.

When a notice is vague or suspicious

A legitimate-looking notice should give you a way to identify the company, understand the information involved, and ask follow-up questions. A request for payment, your full password, or a one-time code is a warning sign and may indicate phishing.

  1. Find the company's official website independently.
  2. Contact its privacy, security, or customer-support team through a verified channel.
  3. Ask for written confirmation of the exposed data and the steps expected of you.
  4. Don't email a full Social Security number, medical record, password, or account security code.
  5. Keep copies of unanswered messages and promised follow-ups.
  6. Check your state attorney general's website for a possible complaint or reporting route if the business won't provide basic information.

A company may say it has no evidence of misuse. That describes what it knows at that moment; it doesn't remove the need to protect an exposed password, card, bank account, or identity number.

If you find identity theft

Act quickly and keep a written file. Start with the institution connected to the problem:

Whether the company provides reimbursement, monitoring, or another benefit depends on the notice, its written terms, applicable law, or a separate settlement. A breach notice by itself doesn't guarantee payment for losses.

Shortcuts to avoid

If you haven't started yet, save the notice and secure your email account now. Use the exposed-data list to decide what comes next: the card issuer for card data, the bank for account or debit data, and the credit bureaus for sensitive identity information.