![]() |
| What to Do After a Data Breach |
Getting a breach notification email is the worst. It doesn't matter if it's from your bank, your favorite online store, a hospital, or some app you barely remember signing up for — the message is basically always the same: "your information may have been exposed."
Here's the thing though: a breach doesn't automatically mean your identity gets stolen. What actually matters is what you do in the days right after. Below are ten steps that'll actually make a difference — no fluff, just what to do.
1. Actually Read the Notice
Don't skim it. Figure out exactly what got exposed — your name and email? Your password? Your Social Security number? Card info? Medical records?
This matters a lot because your next move depends entirely on what leaked. Losing an email/password combo is annoying but manageable. Losing your SSN is a whole different level of concern. And if the notice itself is vague or confusing, go straight to the company's official site rather than trusting whatever's floating around online.
2. Change Your Passwords — Now, Not Later
If your login got caught up in the breach, change that password immediately. Then think hard: did you reuse that password anywhere else? If yes, go change those too.
This is honestly how one small breach turns into five accounts getting hacked. Attackers take leaked email/password pairs and just try them everywhere else — a trick called credential stuffing, and it works way more often than it should. Get a password manager if you don't have one already. It makes generating and remembering unique passwords for everything painless.
And Turn On Two-Factor Authentication
While you're in there changing passwords, flip on two-factor authentication too, especially for email and banking. Even if your password leaks again down the road, 2FA is that extra lock on the door that stops most attackers cold.
3. Consider a Fraud Alert or Credit Freeze
If your SSN or driver's license number was part of what leaked, it's worth looking at a fraud alert or a full credit freeze.
- Fraud alert — makes lenders double-check your identity before opening new credit in your name. You only need to call one bureau (Equifax, Experian, or TransUnion), and they're required to loop in the other two. Lasts a year, renewable.
- Credit freeze — locks your credit report down completely, so basically no one can open new credit, including you, until you unfreeze it. It's free, doesn't touch your credit score, but you do have to contact all three bureaus separately since each one runs its own freeze.
A lot of people just keep their credit frozen permanently and only thaw it briefly when they actually need to apply for a loan or card.
4. Pull Your Free Credit Reports and Actually Look at Them
You get a free report from each bureau via AnnualCreditReport.com, and after a breach you can often request extras beyond your normal yearly allowance.
While you're going through them, keep an eye out for:
- Accounts you don't recognize
- Credit inquiries you never made
- Old addresses that aren't yours
- Balances on cards or loans you never opened
See something off? Dispute it with both the bureau and the company involved. They're generally required to look into it within about 30 days.
5. Keep an Eye on Your Bank and Card Statements
Credit reports won't catch everything — that's what your bank and card statements are for. Check them regularly, even for tiny charges. Scammers love testing stolen cards with small purchases first before going big.
If your card number leaked, just ask your bank to cancel and reissue it. Don't wait around to see if fraud actually shows up.
6. Sign Up for Any Free Monitoring They Offer
Companies that get breached will often throw in free credit monitoring or identity protection for a year or so. Take it — it won't erase what already happened, but it'll flag new accounts opened in your name faster than you'd catch it yourself.
No monitoring offered? You can still do it yourself for free — check your reports periodically and turn on the account alerts most banks already offer.
7. Watch for the Scams That Follow
Right after a big breach hits the news, scammers swoop in pretending to be the company, "helping" you secure your account. Classic breach-phishing.
Red flags to watch for:
- A link asking you to type in your password or card number
- Pressure and urgency ("your account closes today!")
- Requests for payment to "protect" you
- An email address that looks almost right but isn't
If you actually need to check something, type the company's website in yourself instead of clicking anything in the email or text.
8. Report It If Identity Theft Actually Happens
Found real evidence — accounts you didn't open, charges your bank won't reverse? Head to IdentityTheft.gov, the FTC's official recovery site.
It'll walk you through a recovery plan tailored to what happened and can generate an official FTC report, which gives you legal backup to get fraudulent stuff removed from your credit report faster.
For bigger stuff, like loans taken out in your name, file a police report too. Banks sometimes want that report number when you're disputing larger fraud.
Don't Forget Tax and Medical Fraud
If your SSN was exposed, two sneakier types of fraud to watch for:
- Tax identity theft — someone files a return in your name to grab your refund
- Medical identity theft — someone uses your info to get treatment or file insurance claims
Both are harder to catch than a weird credit card charge, so double-check IRS notices and insurance statements for a while after.
9. Tighten Up Your Habits Going Forward
Use a breach as a wake-up call, not just a one-time fix:
- Get a password manager, use unique passwords everywhere
- Turn on 2FA for anything important
- Go through what apps have access to your email/social accounts and cut the ones you don't use
- Think twice before handing out personal info on random forms or surveys
None of this guarantees a breach never touches you again — most breaches happen because a company messed up, not because of anything you did. But good habits shrink the damage every time.
10. Keep a Paper Trail
Write down what you did and when. Keep:
- The original breach notice
- Dates you changed passwords or set up a freeze/alert
- Confirmation numbers from the bureaus
- Any emails or letters from your bank, card issuer, or the FTC
If a dispute stretches on for months, and sometimes they do, having a clean timeline saves you a ton of headache later.
So How Long Does This Actually Take?
Depends entirely on what leaked and whether it actually gets misused. If nothing weird shows up after you've changed passwords and set a freeze or alert, you're probably fine with just routine monitoring from here.
If fraud does hit, clearing up one bad account usually takes a few weeks to a few months — banks and bureaus have built-in investigation windows. Tax fraud or multiple accounts can drag on six months to a year since more institutions get involved. Good records (see Step 10) are what speed this whole thing up.
Quick Questions People Ask
Should I just close my bank account after a breach? Not usually. If it's just your card number, get it reissued instead — closing the account can mess up direct deposits and auto-payments. Closing is more of a last resort for ongoing fraud the bank can't otherwise stop.
Is a freeze better than an alert? Yeah, generally. A freeze blocks access outright, while an alert just makes lenders verify you first. A lot of security-minded people just leave their credit frozen and thaw it only when needed.
Do I actually need to pay for identity protection? Not really. Free freezes, free annual reports, and checking your own statements cover most of what paid services do. Paid options add convenience — automated alerts, recovery insurance — but they're a nice-to-have, not a must.
What if the breached company doesn't offer any help at all? Doesn't matter — every step here works fine on your own. Freezing your credit, watching statements, using IdentityTheft.gov — none of that depends on the company doing anything for you.
Can a breach tank my credit score? The breach itself, no. It's only if fraudulent accounts or missed payments from that fraud actually land on your report — which is exactly why checking your reports quickly matters so much.
Bottom Line
A breach notice is scary to read, but it's not a guarantee that identity theft is coming. Change reused passwords, freeze or monitor your credit, keep an eye on your statements, and don't fall for the follow-up scams — that covers almost all of the real risk. If something does go wrong anyway, IdentityTheft.gov and your bank are your two best friends for fixing it.
The goal isn't to panic every single time some company announces a breach. It's building habits so that one leaked password never snowballs into something much worse.
Sources
- Federal Trade Commission, "What To Do After a Data Breach"
- Federal Trade Commission, Identity Theft | Consumer Advice
- IdentityTheft.gov, Report identity theft and get a recovery plan
- Federal Trade Commission, Identity Theft: A Recovery Plan (PDF)
- ConsumerAffairs, "What to Do After a Data Breach (2026)"
Disclaimer: This article is for general informational purposes only and isn't legal or financial advice. Steps and requirements vary by location, the nature of the breach, and your own situation. For advice specific to you, check IdentityTheft.gov, talk to your bank, or consult a qualified professional.
