Breach notices arrive by email, by letter, or as a headline about a company you had forgotten you used. They all say roughly the same thing: some of your information was accessed by someone who should not have had it. What they rarely tell you is what to do first.
The order matters. Criminals work through breached data quickly, and the steps below close the most valuable doors first.
Step 1: Confirm what was exposed
Read the notice carefully and note exactly which fields were involved. There is a big difference between an email address and a Social Security number.
- Email address and name. Expect phishing. Not much else changes.
- Password. Treat every account that used that password as exposed.
- Phone number. Expect more spam and possibly targeted scam calls.
- Date of birth, address, driver's license number. These help a thief pass identity checks.
- Social Security number. This enables new accounts, tax fraud, and medical fraud in your name. It cannot be changed, so protection has to come from freezes and monitoring.
If the notice is vague, check whether the company has posted details on its website, and be suspicious of any notice that asks you to click a link to verify your account. Real breach notices tell you what happened. They do not ask you to log in through the email.
Step 2: Change reused passwords first
Do this before anything else if a password was involved. Criminals take breached email and password pairs and try them on hundreds of other sites automatically. It works because most people reuse passwords.
Start with the account that was breached. Then change the password on every account that used the same one or a close variation. Prioritize email, banking, and any account that stores a payment method, because your email account can reset the rest.
Use a different, long password for each account. A password manager makes that practical. Turn on two-factor authentication where it is offered, and prefer an authenticator app over text messages when you have the choice, because texts can be intercepted through a SIM swap.
Step 3: Freeze your credit at all three bureaus
If the breach included your Social Security number, date of birth, or driver's license number, freeze your credit at Equifax, Experian, and TransUnion. A freeze stops new creditors from pulling your report, which means a thief cannot open a loan or card in your name. It is free, it does not affect your score, and you can lift it temporarily whenever you apply for credit yourself.
Freeze all 3. A lender can pull from any bureau, so 1 freeze leaves 2 doors open. Our guide on how to freeze your credit walks through each bureau.
If a freeze feels like too much friction, a fraud alert is the lighter option. It asks lenders to verify your identity before opening credit, lasts 1 year, and you only need to place it at 1 bureau. It is less protective than a freeze.
Step 4: Watch for phishing that references the breach
Breached data is used to make scams more convincing. In the weeks after a breach, expect messages that mention the company by name, reference a real order or account, and ask you to confirm details, reset a password, or claim compensation.
A few rules keep you safe:
- Go to the company's site by typing the address yourself, not through a link in a message
- Treat any request for a full Social Security number, a password, or a payment as a red flag, no matter how real the sender looks
- Be especially careful of phone calls. A caller who already knows your address or the last 4 digits of an account is using breached or broker data to sound legitimate
- Slow down. Urgency is the scammer's main tool
If you clicked something you should not have, change the affected password immediately and check the account's recent activity and recovery settings.
Step 5: Turn on monitoring
You cannot pull your data back out of a breach. Once it is copied and traded, it stays out there. What you can do is find out quickly when it surfaces and when someone tries to use it.
Dark web monitoring watches the markets and forums where breached data is traded and alerts you when your email, passwords, or, on some plans, your Social Security number appears. Credit monitoring catches a new inquiry or account before the first bill arrives. Alerts on court records, address changes, and new utility accounts catch the forms of identity theft that never touch your credit report.
The point of monitoring is speed. A password you change the day it leaks is useless to a criminal. A loan you dispute in week 1 is easier to unwind than one you find in month 6.
Keep a short record
Save the breach notice, the date, and the steps you took. If you become a victim of identity theft later, that record supports a police report, an FTC identity theft report, and any insurance claim. It takes 5 minutes and you will be glad you did it.
How Task Force helps
Task Force watches dark web markets, forums, and breach dumps for your email addresses and passwords on every plan, and for your Social Security number and medical identifiers on Complete. When something appears, you get an alert with the source, what was exposed, and the exact next step. Complete adds credit alerts from two bureaus and monitoring of court records, address changes, and new utility accounts. Read about Dark Web and SSN Monitoring, or start with the free scan.