Skip to content
Stay Safe

What to do after a data breach notice

By Editorial Team Published 4 min read
os general by editorial team
Quick Fix
01 First, don't click links in the notice — go to the company's site yourself. Then change that account's password to something new and unique, and turn on two-factor authentication.
02 If you reused that password anywhere else, change it there too — those accounts are now at risk even if they weren't breached.
tested general

Getting a data breach notice can be alarming, but it’s important to stay calm and take practical steps to protect yourself. Most of the time, a methodical approach is all you need to minimize the damage. One common recommendation you might hear isn’t actually necessary for the majority of breaches.

Key Takeaways

  • Verify the breach notice is legitimate before taking any action.
  • Immediately secure your breached account with a new, strong password and two-factor authentication.
  • Change any reused passwords, especially for critical accounts like email and banking.
  • Take additional steps if sensitive information like your SSN or financial details were exposed.
  • Consider using tools like Have I Been Pwned to monitor future breaches.

How do I confirm the breach notice is real?

Scammers often use breach notifications as a disguise for phishing attacks, so it’s key to verify the notice’s authenticity. Do not click on any links or call any numbers in the message. Instead, open your browser and visit the company’s official website directly. You can also use a bookmark you’ve saved previously. Look for an official announcement about the breach on their site. If you can’t find any information, contact the company’s customer support through their official channels to confirm the notice’s legitimacy.

How do I secure my breached account?

Once you’ve confirmed the breach, it’s time to secure your account. Start by changing your password to something new, long, and unique. If you use a password manager, let it generate a strong password for you. Password managers are excellent tools for creating and storing complex passwords that are difficult for attackers to guess.

Next, enable two-factor authentication (2FA) if you haven’t already. 2FA adds an extra layer of security by requiring a second form of verification, such as a code sent to your phone, when logging in. This makes it much harder for attackers to gain access to your account, even if they have your password.

Why is fixing password reuse important?

This is a critical step that protects you beyond the breached account. If you used the same password on other websites, those accounts are now at risk. Cybercriminals often try breached email and password combinations across multiple platforms. To protect yourself, change the password for any account where you reused the compromised password. Start with your most critical accounts, such as your email and banking services.

After this incident, make it a rule to never reuse passwords. A password manager can help you generate and store unique passwords for each site, so you don’t have to remember them all.

How should I respond based on what information was leaked?

The steps you need to take depend on the type of information that was exposed. Here’s how to respond based on what the breach notice says:

  • Just email and password: Follow the steps above to secure your account and change any reused passwords.
  • Payment card information: Keep an eye on your account statements for any suspicious activity. Your bank will usually issue a new card if they detect fraudulent charges. If you notice anything unfamiliar, report it to your bank immediately.
  • Social Security number, national ID, or full financial details: Consider placing a credit freeze at the major credit bureaus. This is a free and effective way to prevent attackers from opening new accounts in your name. You can unfreeze your credit later if needed. Only take this step if sensitive information was exposed — most breaches don’t require such a drastic measure.

How can I stay informed about future breaches?

To protect yourself from future breaches, consider setting up an early-warning system. Register your main email addresses with Have I Been Pwned (haveibeenpwned.com). This service will alert you automatically if your email appears in any new breaches. Many password managers also offer features that flag reused or breached passwords, helping you stay on top of your security.

What shouldn’t I do after a data breach?

  • Don’t click links or call numbers from the breach notice. Always go directly to the company’s official website or contact them through their official channels.
  • Don’t rush to pay for “identity protection” services. The free steps outlined above are often sufficient to protect you.
  • Don’t ignore the breach. Reused passwords can turn one breach into many, so take action to secure your accounts.

Frequently Asked Questions

The breach happened years ago — do I still need to act?

If there’s a chance you still use the compromised password on any account, then yes, you need to take action. Old leaked credentials can be used to try and gain access to your accounts for years after the breach.

Should I delete the account that was breached?

If you don’t use the account, closing it can eliminate future risk. However, if you need to keep the account, simply securing it with a new password and enabling 2FA is enough.

How do I know if I’m affected by a breach if I didn’t receive a notice?

You can check if your email address has been involved in any known breaches by visiting haveibeenpwned.com. This site lists breaches your email appears in.

What if I don’t trust the company’s response to the breach?

If you have concerns about the company’s handling of the breach, consider reaching out to them for more information. You can also monitor your accounts for any suspicious activity and take additional security measures, such as changing passwords and enabling 2FA.

Should I consider legal action after a data breach?

Legal action is an option if the breach has caused significant harm. Consult with a legal professional to understand your options and the potential outcomes.

Sources