Help an individual respond proportionately to a legitimate data-breach notice.
A breach means information was exposed or accessed; it does not automatically mean every affected person’s accounts are controlled. The response depends on whether the data includes passwords, recovery information, identity numbers, financial details, health records, private communications, or security questions.
Verify the notice independently
Navigate to the organization’s official website or use a known contact instead of clicking the notice. Confirm the incident, affected service, dates, data types, protective offer, and official contact. Be alert for scammers impersonating the breached organization.
Map data to likely misuse
- Email and password: credential stuffing and phishing
- Recovery phone or email: reset attempts and impersonation
- Identity numbers and birth data: new-account or benefit fraud
- Card or bank data: unauthorized transactions
- Health, location, or communications: privacy, coercion, or targeted scam risk
- Security answers or documents: long-lived identity and recovery exposure
Choose proportionate protection
| Exposure | First action | Ongoing check |
|---|---|---|
| Password or password hash | Change unique credential; replace reused variants | Login and recovery alerts |
| Payment data | Contact issuer as directed; inspect activity | Statements and transaction alerts |
| Identity data | Use official country-specific protection options | Credit, tax, benefit, or account misuse |
Complete the response plan
- Verify the breach and exposed fields.
- Secure the affected account and primary email.
- Replace reused credentials and strengthen MFA.
- Contact financial or identity institutions where relevant.
- Enroll in legitimate monitoring only after reviewing terms.
- Document actions and watch for targeted follow-up scams.
Avoid breach-response mistakes
- Entering identity data into a fake monitoring offer
- Changing one password but leaving reused copies elsewhere
- Assuming no immediate fraud means long-lived data is safe
- Closing an account before preserving needed records or benefits
Maintain an exposure record
Record organization, incident dates, notice source, exposed data, account identifiers only as necessary, official case number, actions, password and MFA completion without recording secrets, financial contacts, monitoring term, reports, suspicious follow-ups, and next review.
Continue with the next decision
Sources and further reading
Primary and contextual sources used to verify definitions or give readers a relevant next resource.
- IdentityTheft.gov Official U.S. identity-theft recovery-planning resource.
- CISA Secure Our World Official public guidance on account protection and phishing-resistant practices.