If a company says your information was exposed, treat the notice as a reason to act, not as proof that fraud has already occurred. Verify the message independently, save its details, protect your email and reused passwords, and then deal with any payment or identity information named in the notice. Waiting for an unfamiliar charge or account can make the problem harder to contain.
This checklist is for U.S. consumers. State notification laws, financial-account procedures, and industry rules vary. It provides practical information, not legal advice.
What to do first
Don't use a link or phone number from an unexpected email or text until you've confirmed that the message is genuine. Type the company's known web address yourself, open its official app, or use the number on a statement or payment card.
- [ ] Save the notice. Keep the letter or email, case number, date received, and any deadline for enrolling in monitoring or restoration services.
- [ ] Find out what was exposed. Look for passwords, email addresses, Social Security numbers, driver's license numbers, payment cards, bank details, or medical information.
- [ ] Secure your email account. Change its password, turn on multifactor authentication, review recovery addresses and phone numbers, and sign out unfamiliar sessions. Email comes first because it may be used to reset other accounts.
- [ ] Change reused passwords. Update the breached account and every other account that used the same or a similar password. Use a different password for each account from now on.
- [ ] Contact the right financial institution. Use the number on your card, statement, or official banking app. Don't use contact details supplied in a suspicious message.
- [ ] Consider a credit freeze. If your Social Security number or another identity number was exposed, review the FTC's credit-freeze and fraud-alert guidance.
- [ ] Review activity. Check bank, card, payment-app, phone, and medical accounts for transactions, contact changes, or other activity you don't recognize.
- [ ] Keep an action log. Write down dates, representatives, confirmation numbers, password resets, replacement cards, and disputes.
A free credit-monitoring offer from the company may be useful. It doesn't replace password changes, account monitoring, or a credit freeze.
Read the breach notice for specifics
Look for four basic details: what happened, which types of information may be involved, when the company discovered the incident, and what it is doing next. The FTC's breach-response guidance for businesses tells companies to mobilize a response team, use forensic experts where appropriate, and clearly describe what they know about the compromise.
If the notice leaves out information you need, contact the company through a verified website or phone number. Ask:
- Which categories of information were involved?
- Was my specific account or record affected, or was it part of a larger group?
- Were passwords, security questions, payment details, or identity numbers exposed?
- Should I reset a password, replace a card, or take another account-specific step?
- What monitoring or restoration service is offered, how long does it last, and what is the enrollment deadline?
- Where will the company post updates?
"May have been involved" doesn't mean the company has confirmed misuse. It does mean you should base your precautions on the most sensitive information listed when the company can't provide more detail.
Match the response to the exposed data
| Information involved | Main risk | Priority action |
|---|---|---|
| Email address and password | Account takeover and password reuse | Change the password, sign out other sessions, and enable multifactor authentication |
| Social Security number or other identity number | New-account fraud and identity theft | Consider a freeze with each nationwide credit bureau and review your credit reports |
| Credit card number | Unauthorized card charges | Contact the card issuer, ask whether the card should be replaced, and monitor statements |
| Bank account or debit details | Unauthorized withdrawals or account takeover | Contact the bank promptly and ask about account, card, PIN, and transaction protections |
| Medical information | False claims, altered records, or medical-identity theft | Contact the provider or insurer and review explanations of benefits and account activity |
| Driver's license or other government ID | Impersonation and identity-verification fraud | Follow the notice instructions and ask the issuing agency or company which replacement or flagging steps apply |
If the notice lists more than one category, start with the most sensitive one. For example, a password calls for account security, while a Social Security number may justify credit-protection steps as well.
If login information was exposed
Start with the email account tied to the affected service, then work through accounts that reused the same password. Someone who gets into your mailbox may be able to reset other passwords.
After changing the password:
- Turn on multifactor authentication with an authenticator app or security key where available.
- Review recent sign-ins, connected devices, forwarding rules, recovery information, and third-party applications.
- Revoke unknown sessions and integrations.
- Check whether payment, shipping, or contact details were changed.
- Be wary of follow-up calls or messages offering to recover your account. A legitimate company shouldn't need your full password or a one-time security code.
If the service requires a password reset, complete it in the official app or by typing the company's known web address yourself.
Credit freezes, fraud alerts, and monitoring
A credit freeze can make it harder for an identity thief to open new credit in your name. The FTC says freezes are free and remain in place until you tell the bureaus to remove them. If sensitive identity information was exposed, consider placing a freeze with Equifax, Experian, and TransUnion. Store the confirmation details securely.
A fraud alert is a different tool. It asks businesses to take additional steps to verify your identity before opening new credit. The FTC's consumer guidance on credit freezes and fraud alerts explains the difference and provides current placement instructions.
Neither tool secures an existing email, bank, shopping, or payment-app account. Continue to:
- Review credit reports for unfamiliar accounts, inquiries, addresses, or collection activity.
- Check bank and card statements regularly.
- Watch for unexpected tax, insurance, medical, or utility correspondence.
- Follow up quickly on unfamiliar accounts. The FTC says an account in your name that you don't recognize could be a sign of identity theft.
The FDIC directs consumers to AnnualCreditReport.com for free annual credit reports in its billing-issue guidance.
Deal with unauthorized charges under the correct payment rules
A breach notice and an unauthorized charge are separate issues. The notice alone doesn't prove that a particular transaction is fraudulent. Review the transaction and report activity you don't recognize.
Credit card charges
For a U.S. credit-card billing error, the FTC's dispute guidance says to notify the issuer in writing so that the notice reaches the issuer within 60 days after the first bill containing the error was sent. Keep a copy of the dispute and proof that you sent it.
The FTC says the issuer must acknowledge the complaint in writing within 30 days unless it has already resolved the issue. It generally must complete its investigation within two billing cycles, and no more than 90 days after receiving the complaint.
Those instructions address credit-card billing errors. They don't automatically set the procedure for debit cards, bank transfers, prepaid accounts, wires, or payment apps. Use the payment provider's process for those transactions.
If your card number was exposed, call the issuer even if no charge has appeared. Ask whether it should replace the card and whether recurring merchants will need updated payment details.
Debit cards and bank accounts
Call the bank as soon as you see a suspicious withdrawal or believe account credentials were exposed. Ask about:
- Locking or replacing the debit card
- Changing the PIN or online-banking credentials
- Replacing the account number if necessary
- Temporary credits and the bank's reporting deadline
- Monitoring or blocking unusual transactions
Use the bank's official app, card, or statement to make contact. Save the case number, and follow up in writing if the bank requests documentation. Reporting deadlines and procedures can depend on the type of transaction and account, so ask the bank what applies to your situation.
Don't confuse breach-notice deadlines with your deadlines
There's no single U.S. deadline for every data breach. State privacy laws and sector-specific rules may set a deadline for a company to notify residents or regulators. That deadline isn't the same as your deadline to dispute a credit-card charge, report a bank withdrawal, or place a credit freeze.
For example:
- Colorado's official business guidance says notice to affected residents must be provided as quickly as possible and no later than 30 days after the company determines that a security breach occurred. It also describes thresholds for notifying the attorney general and consumer-reporting agencies.
- Texas requires qualifying businesses that affect 250 or more Texans to report to the attorney general as soon as practicable and no later than 30 days after discovering the breach. Businesses must also notify affected consumers.
- Illinois requires certain businesses and state agencies to notify the attorney general in addition to affected Illinois residents.
These examples don't establish the rule for every state. Check your state attorney general's current guidance if a company hasn't answered basic questions or you need to understand a notification requirement. Don't wait for a company's regulatory deadline before securing your accounts.
When a notice is vague or suspicious
A legitimate-looking notice should give you a way to identify the company, understand the information involved, and ask follow-up questions. A request for payment, your full password, or a one-time code is a warning sign and may indicate phishing.
- Find the company's official website independently.
- Contact its privacy, security, or customer-support team through a verified channel.
- Ask for written confirmation of the exposed data and the steps expected of you.
- Don't email a full Social Security number, medical record, password, or account security code.
- Keep copies of unanswered messages and promised follow-ups.
- Check your state attorney general's website for a possible complaint or reporting route if the business won't provide basic information.
A company may say it has no evidence of misuse. That describes what it knows at that moment; it doesn't remove the need to protect an exposed password, card, bank account, or identity number.
If you find identity theft
Act quickly and keep a written file. Start with the institution connected to the problem:
- Contact the bank, card issuer, lender, provider, or payment service involved.
- Freeze your credit if you haven't already done so.
- Change credentials and remove unfamiliar devices or account access.
- Save statements, screenshots, notices, emails, and case numbers.
- Ask the institution what affidavit, identity documents, or police report it needs.
- Dispute unfamiliar credit accounts or charges through the institution's specified process.
- Keep checking reports and statements after the immediate issue appears resolved.
Whether the company provides reimbursement, monitoring, or another benefit depends on the notice, its written terms, applicable law, or a separate settlement. A breach notice by itself doesn't guarantee payment for losses.
Shortcuts to avoid
- Changing only the breached password: Reused credentials can expose other accounts.
- Monitoring only your credit: An attacker can take over an existing account without opening a new loan or card.
- Treating monitoring as a freeze: The two services serve different purposes.
- Waiting for a fraudulent charge: Contact the financial institution when you suspect payment data was exposed.
- Applying the 60-day credit-card rule to every payment type: Debit, ACH, prepaid, wire, and payment-app procedures differ.
- Trusting follow-up offers: Someone who knows about the breach may pose as the company and ask for credentials, codes, payment, or personal documents.
If you haven't started yet, save the notice and secure your email account now. Use the exposed-data list to decide what comes next: the card issuer for card data, the bank for account or debit data, and the credit bureaus for sensitive identity information.