Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

After a government data breach, treat unexpected messages about the incident as unverified—even if they include your name, address, or other accurate details. Don’t click links, open attachments, pay, or share personal information or sign-in codes. Check the agency’s notice and contact details independently, then use the appropriate reporting and recovery steps below. The reporting channels and credit-protection options in this guide are U.S.-specific.

Why breach-related phishing can look convincing

Criminals can reuse exposed personal details to make an impersonation seem legitimate. In a September 2017 alert about the Equifax breach, the Cybersecurity and Infrastructure Security Agency (CISA) warned that phishing scams often increase after major breaches and that stolen information can make messages more credible. That alert is a historical example, not evidence that every government breach causes a measurable rise in phishing.

A familiar name, address, agency seal, employee number, or caller ID display does not prove a message is genuine. Details may be copied, spoofed, or taken from exposed data. Do not use a phone number, link, or contact information supplied in the suspicious message to verify it.

CISA’s archived Equifax breach alert

Warning signs in an alleged breach notice

Phishing can arrive by email, text, social media, phone, or a fake website. Be wary if an unexpected message:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Pressures you to act immediately, threatens loss of benefits, money, or account access, or promises a refund or special compensation.
  • Claims you must click a link or open an attachment to verify your identity, fix an account, or receive a remedy.
  • Asks for a password, Social Security number, bank or card details, or a one-time sign-in code.
  • Demands payment by gift card, wire transfer, cryptocurrency, cash, or payment app.
  • Uses official-sounding titles, seals, caller ID, or personal details as proof that it is legitimate.

The FTC says government agencies do not contact people through calls, emails, texts, or social media to demand money or personal information. As the FTC puts it: “The real FTC will never contact you and ask for money or information like your Social Security, bank account, or credit card number.” Read the FTC’s guidance on government impersonation scams.

Other common warning signs include urgency, supposed account problems, and offers that seem too good to be true. See the CISA phishing tip card and the FTC’s phishing guidance.

How to verify a message safely

  1. Pause. Don’t click, reply, open attachments, call the number in the message, or provide information or a sign-in code.
  2. Find the agency’s official channel yourself. Type an address you already know, use a trusted bookmark, or search for the agency’s official website and navigate from there. Look for its independently posted breach notice and contact details.
  3. Contact the agency using verified details. Ask whether it sent the message and whether the requested action is real. Do not rely on caller ID or a title displayed by the caller; both can be faked.
  4. Report and delete the suspicious message. Use the reporting options below. If you need to preserve it for a report, avoid interacting with its links or attachments.

The FTC advises: “Don’t click on any links in unexpected emails, texts, or social media messages.” Its phishing guidance and government impersonation guidance explain how to verify suspicious contact independently.

How to report suspected phishing in the United States

  • Phishing email: Forward it to reportphishing@apwg.org.
  • Phishing text: Forward it to SPAM (7726).
  • Scam or government impersonation: Report it at ReportFraud.ftc.gov.

These reporting instructions come from the FTC’s phishing guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What to do if you clicked or shared information

Choose the response that matches what happened. If the breach notice identifies exposed information, use the FTC’s IdentityTheft.gov/databreach recovery guidance for breach-specific steps.

If you only opened a link

If you did not enter information or download anything, close the page and do not return to it. The FTC recommends updating your security software and scanning your device if a link downloaded harmful software. If you entered account credentials, take the steps below.

If you entered a password or sign-in code

Go to the real service independently—not through the message—and change the affected password. Change it anywhere else you reused it, and enable multifactor authentication (MFA) where available. MFA helps protect an account; it does not establish whether an unsolicited message is authentic.

If you shared financial or identity information

Contact the relevant bank, card issuer, or service using a verified number or website, explain what you disclosed, and follow its instructions to secure the account. If your Social Security number was exposed, the FTC recommends reviewing your credit reports. Start with IdentityTheft.gov/databreach for the next steps that fit the breach and information involved.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Credit freeze or fraud alert: which should you consider?

A credit freeze and a fraud alert address new-credit risk in different ways. According to the FTC, a freeze is free, does not affect your credit score, and must be placed separately with each of the three national credit bureaus. You can lift it when needed. A fraud alert asks businesses to verify your identity before opening credit; you can place one with a bureau, which must notify the others. An initial fraud alert lasts one year.

Option What it does How to place it Practical consideration
Credit freeze Restricts access to your credit report, which can make it harder for someone to open new credit in your name. Place it separately with Equifax, Experian, and TransUnion. Consider it if you want stronger restrictions on access to your report. You may need to lift it when applying for credit.
Fraud alert Asks businesses to verify your identity before opening credit. Place it with one of the three national credit bureaus; that bureau must notify the others. Consider it if you want businesses alerted but prefer not to restrict report access as a freeze does.

See the FTC’s comparison of credit freezes and fraud alerts and its credit-freeze guidance.

Use breach services and account protections carefully

If the affected organization offers free credit monitoring or identity theft insurance, the FTC says to take advantage of those services. They are optional support for a breach response, not proof that a message is genuine and not a substitute for securing an account whose credentials were exposed.

A password manager can help create and store long, unique passwords, as CISA recommends. For MFA, a security key is one possible factor alongside a passcode or authenticator app. Neither a password manager nor a security key checks whether an unexpected message is legitimate; verify the sender through an independent official channel.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.