Loading

What to Do After a Data Breach

A data breach does not mean identity theft is inevitable; fast, targeted action can protect your accounts, money, credit, and identity.

Your Information Was Exposed — Here’s What Matters First

Finding out that your personal information was involved in a data breach can be alarming. But not every breach creates the same risk, and not every response needs to be the same.

An exposed email address is very different from a stolen password, bank account number, Social Security number, passport, driver’s license, or health record.

Your first goal is to determine what information was exposed and what criminals could realistically do with it. From there, you can secure vulnerable accounts, protect your finances and identity, prepare for follow-up scams, and monitor for signs of misuse.

The most important principle is simple:

Respond to the information that was exposed, not just to the fact that a breach happened.

1. Confirm the Data Breach Is Real

Cybercriminals often take advantage of real data breaches by sending fake security notices.

A message may tell you to reset your password, verify your identity, claim compensation, protect your account, or call an urgent support number. Even if the message mentions a real breach, that does not make the message itself genuine.

Instead of using links or contact details in an unexpected email or text:

  • Go directly to the organization’s official website or app.
  • Look for its official breach or security notice.
  • Sign in through the normal website or app.
  • Find the organization’s contact information independently.
  • Confirm whether your information was actually affected.

The U.K. National Cyber Security Centre recommends independently checking breach-related communications because criminals may impersonate an organization involved in a genuine incident.

2. Find Out Exactly What Information Was Exposed

Once you know the breach is genuine, determine what information relating to you was compromised.

Read the organization’s official notification carefully. If it does not clearly explain what data was involved, contact the organization and ask.

Match your response to the exposed information

Information exposedMain riskFirst response
Email address or phone numberPhishing, scam calls, impersonationExpect more targeted scams
PasswordAccount takeover and credential stuffingChange it and any reused passwords
Email credentialsWider account takeover through password resetsSecure your email immediately
Credit or debit card detailsUnauthorized purchasesContact the card issuer
Bank account informationFinancial fraud or account compromiseContact your financial institution
Social Security number, SIN, or similar identifierIdentity, credit, or tax fraudUse country-specific identity protections
Driver’s license or passport detailsIdentity impersonationFollow guidance from the relevant issuing authority
Medical or health informationMedical identity or insurance fraudMonitor claims, bills, and health accounts
Security questions or profile dataAccount recovery attacks and impersonationReplace exposed recovery answers where possible

The type of personal information involved should determine the response. Australian cybersecurity and privacy guidance similarly recommends assessing what information was compromised before deciding which protective steps are necessary.

3. Secure Compromised Accounts Immediately

If login information was exposed, treat account security as an immediate priority.

Change exposed and reused passwords

Change the password on the affected account first.

Then change the password anywhere else you used the same password or a closely related version of it.

Attackers commonly use credentials stolen from one service to try logging in to other services, a technique known as credential stuffing. The U.K. NCSC specifically warns that password reuse allows one breach to threaten multiple accounts.

Use a unique password for every important account. A reputable password manager can make this easier by generating and storing different passwords for you.

Secure your email first

If your email account may have been compromised, prioritize it.

Email is often the recovery channel for banking, shopping, social media, cloud storage, government services, and other accounts. Someone with access to your inbox may be able to reset passwords elsewhere.

Review your email account for:

  • Unknown devices or login sessions
  • Changed recovery email addresses
  • Changed recovery phone numbers
  • Unexpected forwarding rules
  • Suspicious filters
  • Messages you did not send
  • Password resets you did not request
  • Connected apps you do not recognize

If necessary, change the password, restore your correct recovery details, and sign out other devices and sessions.

NCSC account-recovery guidance recommends checking the associated email account, changing compromised passwords, and logging out devices and apps after an account has been hacked.

Turn on stronger authentication

Enable multi-factor authentication on important accounts, especially:

  • Email
  • Banking and payment services
  • Password managers
  • Cloud storage
  • Social media
  • Government accounts
  • Work accounts
  • Cryptocurrency accounts

Where available, consider a passkey or hardware security key. Passkeys can provide strong protection against phishing because they do not work like reusable passwords that can simply be entered into a fake website. Where passkeys are unavailable, use a strong unique password with multi-factor or two-step verification.

Review active sessions and recovery methods

Changing a password is important, but do not assume that it automatically fixes every form of account compromise.

Check:

  • Active sessions
  • Trusted devices
  • Recovery phone numbers and email addresses
  • Authentication methods
  • Authorized third-party applications
  • Security keys
  • Recent account changes

Remove anything you do not recognize and use the service’s option to sign out other sessions where appropriate.

If workplace credentials or a work device are involved, notify your employer’s IT or security team promptly rather than trying to handle the incident entirely on your own.

4. Contact Your Bank if Financial Information Was Exposed

If card details, bank information, payment credentials, or information capable of helping someone access your finances was compromised, contact your bank or card issuer.

Do not wait for money to disappear before taking action.

Depending on what was exposed, the institution may recommend:

  • Replacing a payment card
  • Blocking or restricting an account
  • Changing online banking credentials
  • Adding additional security
  • Monitoring transfers
  • Disputing unauthorized transactions
  • Watching for new payees or account changes

Australian government guidance advises people affected by identity or financial compromise to contact their financial institution quickly, and Canada’s Financial Consumer Agency similarly recommends contacting financial institutions when accounts or financial information may have been compromised.

Keep checking the account afterward. Stolen information is not always used immediately.

5. Protect Your Credit and Identity

If the breach exposed enough personal information for someone to impersonate you or apply for credit, consider stronger identity protections.

The options differ significantly by country.

United States

If sensitive identity information such as your Social Security number has been exposed, consider placing a credit freeze with Equifax, Experian, and TransUnion.

A credit freeze restricts access to your credit report, making it harder for an identity thief to open new credit accounts. U.S. credit freezes are free, remain in place until you lift them, and must be placed separately with all three nationwide credit bureaus.

You can also place a fraud alert. An initial fraud alert is free, lasts one year, and requires businesses to take additional steps to verify your identity before issuing new credit. You only need to contact one of the three nationwide credit bureaus to initiate the alert; that bureau must notify the other two.

Also review your credit reports for accounts and inquiries you do not recognize.

If your Social Security number or taxpayer information was exposed, you may also want an IRS Identity Protection PIN (IP PIN). An IP PIN is a six-digit number that prevents someone else from filing a federal tax return using your SSN or Individual Taxpayer Identification Number.

United Kingdom

Check your credit files for applications, accounts, or searches you do not recognize.

If sensitive personal information has been stolen and identity fraud is a concern, you can also consider Cifas Protective Registration. It places a warning against your details so participating organizations can perform additional identity checks when applications are made using your information. Protective Registration is a paid service and currently lasts two years.

Report suspicious credit applications to the relevant lender or provider immediately.

Australia

Check your credit reports for loans, accounts, or credit applications you do not recognize.

If you are concerned that someone may attempt to obtain credit using your identity, you can request a temporary ban on your credit report. Australian Moneysmart guidance specifically recommends this option when identity theft or unauthorized credit applications are a concern.

IDCARE also provides specialized identity and cyber support for people in Australia and New Zealand who are dealing with identity-related risks.

Canada

Check your credit reports with Canada’s two major credit bureaus, Equifax and TransUnion.

If identity fraud is a concern, ask the credit bureaus about placing a fraud alert or identity alert on your file. This tells lenders that additional identity verification may be necessary before approving new credit.

If your Social Insurance Number was involved, monitor your credit, financial accounts, tax records, and government benefits for unauthorized use.

Simply having a SIN exposed in a breach does not mean you automatically need to notify the SIN Program or obtain a new SIN. Service Canada states that a new SIN is generally not recommended because the original number may still continue to be used by criminals.

Credit freeze vs. credit monitoring

These are not the same thing.

Credit freezes and similar restrictions are preventive. They can make it harder for someone to obtain new credit using your identity.

Credit monitoring is detective. It can alert you after suspicious credit activity appears.

Monitoring is useful, but it should not be mistaken for a tool that prevents identity theft.

6. Handle Compromised Identity Documents Carefully

Government identity information deserves special attention because it cannot be changed as easily as a password.

However, there is no universal rule that applies to every passport, driver’s license, national identifier, tax number, or health card.

The correct response depends on both the document and the country that issued it.

You may need to:

  • Request a replacement document
  • Have a document number flagged
  • Strengthen security on a government account
  • Monitor tax or benefits records
  • Report fraudulent use
  • Obtain a case or reference number

For example, Australia’s Cyber Security Centre advises people whose driver’s-license details were compromised to contact the relevant state or territory authority because they may be eligible for a replacement. It separately advises contacting the Australian Taxation Office when tax-related identity theft has occurred.

Do not assume that replacing a physical document makes all previously leaked information harmless. Names, dates of birth, addresses, old document numbers, and other persistent information may remain useful for impersonation.

7. Expect More Convincing Phishing, Calls, and Text Messages

One of the most common consequences of a data breach is that scammers gain enough personal information to make their messages more believable.

Someone may know your:

  • Full name
  • Phone number
  • Email address
  • Employer
  • Bank or service provider
  • Account type
  • Address
  • Date of birth
  • Recent breach history

That information can make a fraudulent call or message sound legitimate.

For example, someone might call and say:

“We’re calling from your bank because your details were exposed in the recent security incident.”

Knowing that a breach happened — or knowing several accurate facts about you — does not prove the caller represents your bank.

Be especially cautious with unexpected messages involving:

  • Password resets
  • Fraud investigations
  • Account verification
  • Refunds or compensation
  • Tax problems
  • Package deliveries
  • Credit monitoring
  • Remote computer access
  • One-time authentication codes
  • Requests to move money to a “safe” account

The NCSC warns that criminals may use data obtained from breaches to create convincing emails, text messages, and phone calls, including messages that impersonate the organization involved in the breach.

If someone unexpectedly claims there is a problem with your account, end the conversation and contact the organization using a phone number, website, or app you independently know is genuine.

Do not rely on caller ID alone, and never give an unexpected caller a password or authentication code.

8. Check Whether Your Email Appeared in Other Known Breaches

A breach may not be the first time one of your accounts has been exposed.

Services such as Have I Been Pwned can help identify known breaches associated with an email address. The U.K. NCSC references the service in its guidance for people affected by data breaches.

If you find an old account in another breach, consider:

  • Changing any reused password
  • Enabling stronger authentication
  • Reviewing the account for suspicious activity
  • Closing the account if you no longer need it

A clean result does not prove your information has never been exposed. Breach-checking services can only identify datasets they know about.

Never enter your current account password into an unfamiliar “breach checker.”

9. Monitor for Signs of Identity Theft and Account Misuse

Do not assume the danger has passed because nothing happened during the first few days.

Stolen information may be stored, resold, combined with information from other breaches, or used later. Australian cybersecurity guidance specifically recommends continuing to check for unusual account activity after identity information has been compromised.

Watch for:

  • Unrecognized bank transactions
  • Small unexplained card charges
  • Credit applications you did not make
  • New accounts on your credit report
  • Unexpected password-reset emails
  • Unknown account logins
  • Changes to account recovery information
  • Mobile phone accounts you did not open
  • Government-account changes
  • Tax notices you do not understand
  • Health insurance claims you did not make
  • Messages sent from your accounts without your knowledge

Long-term monitoring is particularly important when permanent or difficult-to-change information such as your date of birth or government identifiers has been exposed.

10. Report Fraud if Someone Actually Uses Your Information

A data breach and identity theft are not the same thing.

A data breach means unauthorized people may have obtained information.

Identity theft or fraud occurs when someone uses that information improperly — for example, to open an account, take money, obtain credit, file a fraudulent tax return, or impersonate you.

If that happens, report it promptly.

Where to report identity theft or fraud

CountryMain reporting options
United StatesReport identity theft through IdentityTheft.gov and contact affected banks, lenders, or businesses
United KingdomContact your bank immediately for financial losses; report fraud through Report Fraud in England, Wales, and Northern Ireland, or contact Police Scotland where appropriate
AustraliaUse ReportCyber for cybercrime and seek identity support through IDCARE
CanadaReport through Canada’s Report Cybercrime and Fraud service and contact affected financial institutions or creditors
ElsewhereContact your national cybersecurity or fraud-reporting service, police where appropriate, financial institutions, credit agencies, and relevant identity-document issuers

The FTC directs U.S. identity-theft victims to its recovery process; the U.K. NCSC directs fraud victims to Report Fraud or Police Scotland as appropriate; Australia provides ReportCyber; and Canada’s national reporting system accepts cybercrime and fraud reports for the RCMP and Canadian Anti-Fraud Centre.

11. Keep Records of What Happened

Save evidence relating to the breach and the steps you take afterward.

Keep copies of:

  • The original breach notification
  • Official breach announcements
  • Emails with the affected organization
  • Bank and card correspondence
  • Credit bureau communications
  • Fraud reports
  • Police reference numbers
  • Replacement-document requests
  • Screenshots of suspicious activity
  • Dates when passwords or security settings were changed

Record who you contacted, when you contacted them, and what action was recommended.

If fraud appears later, those records can make it easier to reconstruct what happened and dispute unauthorized transactions, credit applications, or identity records.

12. Watch for Data Breach Recovery Scams

A breach can create a second opportunity for scammers.

Someone may unexpectedly claim that they can:

  • Recover stolen money
  • Delete your information from criminal databases
  • Track the hackers
  • Restore your identity
  • Provide guaranteed protection
  • Recover cryptocurrency
  • Clean your computer remotely

Be extremely cautious if an unsolicited person or company wants an upfront payment, cryptocurrency, banking details, passwords, authentication codes, or remote access to your device.

Use your bank, government agencies, official reporting services, and independently verified providers instead.

A Practical Data Breach Checklist

Do immediately

  • Confirm that the breach notification is genuine.
  • Find out exactly what information was exposed.
  • Change compromised and reused passwords.
  • Secure your email account.
  • Review recovery methods and active sessions.
  • Enable multi-factor authentication or passkeys where available.
  • Contact your bank immediately if money or financial credentials are at risk.

Do the same day

  • Review important accounts for unauthorized changes.
  • Contact the appropriate authority if an identity document was compromised.
  • Consider credit protections if identity information was exposed.
  • Save the breach notification and other evidence.
  • Warn your employer’s IT or security team if workplace credentials were involved.

Over the next several days

  • Review your credit reports where relevant.
  • Check other accounts that used the same old password.
  • Watch closely for phishing emails, text messages, and calls.
  • Replace compromised documents if the issuing authority recommends it.
  • Report unauthorized transactions or account activity immediately.

Keep doing

  • Monitor financial and credit activity.
  • Keep unique passwords for important accounts.
  • Maintain multi-factor authentication or passkeys.
  • Review security alerts and login notifications.
  • Treat unexpected security communications cautiously.
  • Keep records relating to the breach and any later fraud.

What Not to Do After a Data Breach

A rushed response can create another security problem.

Avoid these common mistakes:

  • Do not click a password-reset link just because a breach email looks legitimate.
  • Do not change only one password if you reused it elsewhere.
  • Do not give authentication codes to unexpected callers.
  • Do not assume credit monitoring alone prevents identity theft.
  • Do not ignore small unauthorized transactions.
  • Do not assume every exposed government identifier needs to be replaced.
  • Do not pay unsolicited “recovery experts” who promise to retrieve stolen money or data.
  • Do not assume you are safe because nothing happened immediately after the breach.

The objective is not to panic about every piece of leaked information. It is to close the paths criminals are most likely to exploit.

Conclusion: Respond to What Was Actually Exposed

The right response to a data breach depends on what information was compromised.

If a password was exposed, change it and eliminate password reuse. If email credentials were compromised, secure your inbox and account-recovery settings. If financial information was stolen, contact your bank or card issuer. If sensitive identity information was exposed, use the credit and identity protections available in your country.

Then prepare for the next stage: targeted phishing, scam calls, suspicious account activity, and possible identity fraud.

Most importantly, do not treat a data breach as a one-day problem. Personal information can remain useful to criminals long after the original incident has disappeared from the news.

You cannot take leaked information back, but you can make it substantially harder for someone to turn that information into fraud.