Skip to content
Cyber Security Firms

What to Do After a Data Breach: A Step-by-Step Plan

A breach notice tells you something happened and very little about what to do. The right response depends on exactly what was exposed, and most of it takes an hour.

Beginner11 min readUpdated
What to Do After a Data Breach: A Step-by-Step Plan

The letter says your information "may have been involved in a security incident," offers a year of credit monitoring, and apologizes. It does not say what to do, in what order, or which of the steps actually matter for the data that was taken. This page does. Most of it takes an hour, and the two steps that matter most are free.

How to Tell If a Data Breach Notice Is Real

Breach notices are themselves a favorite phishing lure, because the fear they create is exactly what an attacker wants. A message saying "your data was exposed, click here to secure your account" may be the breach.

Do not use anything in the message. Open the company's website by typing its address, look for a security notice or newsroom page, or search the company's name with "data breach" and read a news report. Legitimate notices also appear on state attorney general breach portals and, for healthcare, on the federal HHS breach portal. If the breach is real, Have I Been Pwned will usually list it within days and will tell you whether your specific email address is in the data.

The reports on this site do the same job for the breaches we have written up, with the source for every figure: recent data breaches.

What Data Was Exposed in the Breach?

This is the step most guides skip, and it is the one that decides what you do. A breach that leaked your email address and a breach that leaked your Social Security number are different events with different responses.

What was exposedWhat it enablesWhat to do
Email addressTargeted phishing for monthsExpect it; enable two-factor authentication on the email account
PasswordLogin to that account and anywhere you reused itChange it there and everywhere it was reused, now
Name, phone, home addressConvincing scams, SIM swap attemptsSet a PIN with your mobile carrier; doubt calls that know your details
Date of birthIdentity verification questions answeredFreeze credit; it combines with a Social Security number to open accounts
Social Security numberNew credit accounts, tax fraud, benefits fraudFreeze credit at all three bureaus; get an IRS Identity Protection PIN
Payment card, full numberFraudulent chargesTell the bank; it replaces the card
Payment card, last four digits and expiryConvincing "this is your bank" callsNothing to replace; hang up and call the number on the card
Health or insurance informationMedical identity theft, benefits fraudRead every explanation of benefits for a year; dispute unknown visits
Driver's license numberIdentity verification, fake IDsContact the state DMV; some states issue a new number

The notice should say which of these applies. If it does not, the breach report or the Have I Been Pwned entry will list the data classes.

What to Do Immediately After a Data Breach

  1. Change the password on the breached account, and on every other account where you used the same password. Attackers run leaked passwords against hundreds of sites automatically within hours of a leak.
  2. Turn on two-factor authentication on the breached account and on your email, which is the account that resets all the others. CISA's advice is that any second factor is better than none, with an authenticator app or a passkey better than a text code.
  3. Sign out of all sessions on the breached service, in its security settings, so an attacker who already logged in is removed.
  4. Check the account for changes: recovery email and phone, forwarding rules, connected apps, shipping addresses. Attackers leave these behind to keep access.
  5. Check your other accounts at Have I Been Pwned while you are there. A breach you did not know about is often the one that matters.

How to Freeze Your Credit After a Data Breach

If a Social Security number was exposed, this is the step. If it was not, it is still worth doing, because the number has probably been exposed somewhere before.

A credit freeze stops anyone opening a new credit account in your name, including you, until you lift it. Per the FTC's guidance, it is free to place and lift, it does not affect your credit score, it lasts until you remove it, and anyone can place one for any reason. You lift it temporarily when you apply for credit, a job that checks credit, an apartment or insurance, and put it back afterward.

You have to place it separately at each of the three bureaus, which is the part people skip.

A fraud alert is the lighter option: it asks lenders to verify your identity before opening an account rather than blocking them. It lasts one year, is placed at one bureau which notifies the others, and is free. A freeze is stronger and costs nothing more, so for an exposed Social Security number the freeze is the right choice.

What to Do If Your Social Security Number Was Leaked

Beyond the freeze, two more steps close the doors a Social Security number opens.

Get an Identity Protection PIN from the IRS. It is a six-digit number that must accompany any tax return filed under your Social Security number, which stops someone filing a fraudulent return to claim your refund. Anyone can request one through an IRS online account.

If you find an account you did not open, a debt you do not recognize, or a tax return already filed in your name, report it at IdentityTheft.gov. The site produces a recovery plan and the pre-filled letters and affidavits that banks and bureaus require. It is the FTC's official channel and the one that creates the paper trail you will need.

Phishing Scams That Follow a Data Breach

Whatever else was in the breach, your email address and probably your phone number were. The company that lost them, the data that was with them, and the fact of the breach itself are now all raw material for the next round.

Messages that quote your real details are not proof of legitimacy anymore. A caller who knows your name, address and the last four digits of your card is reading from the breach. Hang up and call the number on the card or the statement. The tells that survive even a well-made lure are in what phishing looks like.

Is Identity Theft Protection Worth It After a Breach?

Contested, so here is the trade-off. The credit monitoring a breach notice offers is free for a year and worth activating: it alerts you when a new account or inquiry appears on your file. Paid services add dark web monitoring, insurance and a recovery concierge. The monitoring is largely what Have I Been Pwned does for free, the insurance rarely pays out in practice because the losses from identity theft are mostly time rather than money, and the concierge is real but so is IdentityTheft.gov.

Can You Get Compensation for a Data Breach?

Sometimes, and rarely much. Large breaches usually produce class action lawsuits within days, and settlements typically offer a few years of credit monitoring plus a cash payment that, once divided among millions of claimants, often lands in the tens of dollars, more if you can document actual losses. It is worth filing a claim when a settlement is announced, because it costs nothing, and worth keeping receipts for any time or money the breach cost you. It is not worth changing your response to the breach itself in the hope of a payout.

How Long Does a Data Breach Affect You?

Longer than the credit monitoring. A leaked password is dangerous until it is changed. A leaked email address is a phishing target for years, which is why two thirds of the addresses in a typical new breach are already in Have I Been Pwned from earlier ones. A Social Security number does not expire, which is why the freeze is the right answer rather than a year of watching. Health and insurance data supports fraud for as long as the plan exists.

Key takeaways

  • Confirm the notice through the company's own site, never through the message. Breach notices are a phishing lure.
  • Match your response to the data: password leaked means change it everywhere; Social Security number leaked means freeze credit at all three bureaus.
  • A credit freeze is free, does not affect your score, and stops new accounts being opened. Place it at Equifax, Experian and TransUnion separately.
  • An IRS Identity Protection PIN stops tax refund fraud. IdentityTheft.gov is where to report and recover.
  • Expect targeted phishing for months, including messages about the breach itself. Verify by phone on a number you already had.
  • Activate the free monitoring the notice offers; the paid tier is for people who have already been victims.

Common questions

What should I do if my data has been breached?

Confirm the notice is real on the company's own site, then respond to what was exposed: change a leaked password everywhere you reused it and turn on two-factor authentication; freeze your credit at all three bureaus if your Social Security number was involved; and expect targeted phishing for months. Report any resulting identity theft at IdentityTheft.gov.

How do I know if I was affected by a data breach?

The company must notify affected individuals under state and, for health data, federal law, usually by letter or email. Have I Been Pwned lets you check any email address against verified breaches for free. Breach reports on this site list the data classes for each incident.

Should I freeze my credit after a data breach?

Yes if your Social Security number was exposed, and it is a reasonable default even if it was not, because the number has likely been exposed before. A freeze is free, does not affect your score, and can be lifted temporarily whenever you apply for credit.

What is the difference between a credit freeze and a fraud alert?

A freeze blocks new credit accounts entirely until you lift it and must be placed at each of the three bureaus. A fraud alert asks lenders to verify your identity first, lasts one year, and is placed at one bureau which tells the others. Both are free. The freeze is stronger.

Do I get compensation for a data breach?

Sometimes. Class action settlements usually offer credit monitoring and a small cash payment, often in the tens of dollars per person once divided among everyone affected, with more available for documented losses. File a claim when a settlement is announced; it costs nothing.

Is it worth suing over a data breach?

Individually, rarely. Proving specific damages from a specific breach is difficult and expensive. Joining a class action, which usually already exists for a large breach, costs nothing and is the practical route.

How long does a data breach last?

The incident itself is over when it is disclosed. The risk to you is not: a leaked email address draws phishing for years and a Social Security number never expires, which is why a permanent credit freeze is the right response rather than a year of monitoring.

Should I change all my passwords after a breach?

Change the breached one and any account where you reused it. If you reuse passwords widely, use the breach as the reason to move everything into a password manager with unique passwords, which is the one change that ends the problem.

What if my Social Security number was leaked?

Freeze your credit at Equifax, Experian and TransUnion, request an IRS Identity Protection PIN, activate any credit monitoring offered, and report at IdentityTheft.gov if any account or return appears that is not yours. The number cannot be changed except in extreme circumstances, so the freeze is the permanent fix.

Can I remove my data from the dark web?

No. Once data has been published or sold it is copied and cannot be recalled. Dark web monitoring services can tell you it is there, which Have I Been Pwned also does for free. The response is to make the data useless: change passwords, freeze credit, and treat unexpected contact as suspect.

On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →