Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you receive a data-breach notice, first find out exactly what information was exposed, then protect the accounts and records tied to it. Exposure does not mean someone has already misused your information. The right response depends on whether the breach involved a password, Social Security number, payment details, health information, or something else.

Start with the breach notice

Read the notice closely to identify the affected service, the types of information involved, when the incident occurred if that is stated, and what the organization says it has done. Note any offered credit monitoring or identity-restoration support, along with its enrollment instructions and deadline, if provided.

If you are unsure whether a notice is genuine, do not use its links or phone numbers to verify it. Visit the organization’s official website or app yourself and use a contact channel published there.

Secure exposed accounts and watch for scams

Change exposed and reused passwords

Change the password for the affected account. If you used the same or a similar password elsewhere, change those passwords too. Use a different, strong password for each account; a password manager can help you keep track of unique credentials.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Turn on multifactor authentication (MFA) wherever it is available. Some services support a USB security key as an MFA method, but compatibility varies. A key is optional and does not replace changing an exposed password; keep a backup sign-in method in case a key is lost.

Be wary of breach-themed messages

After a breach, treat unexpected calls, emails, and texts claiming to be from the affected company—or offering urgent help—with caution. Do not click unsolicited links or share passwords or verification codes in response. Contact the organization through its known official app, website, or published phone number instead. The Associated Press guide to exposed personal information explains why a hijacked phone number can also put accounts that rely on text-message codes at risk.

Match your response to the exposed information

Email address or password

Change the exposed password and every reused or similar password, then enable MFA. Be especially careful with unexpected password-reset messages: go directly to the service’s official site or app to check your account.

Social Security number

Review your credit reports and look for accounts or activity you do not recognize. Consider placing a freeze with each of the three nationwide credit bureaus. If you find evidence of identity theft, report it at IdentityTheft.gov for recovery guidance. The FTC also directs people affected by data breaches to IdentityTheft.gov/databreach for steps tailored to the information exposed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Payment card or bank details

Contact the bank or card issuer through its official app, website, or a phone number you already trust. Ask whether the affected card or account credentials should be secured, replaced, or closed. Review transactions and report unfamiliar activity promptly. A credit freeze does not stop charges to an existing card or protect access to a bank account.

Health or insurance information

Check provider bills, explanations of benefits, and medical records for unfamiliar services, errors, or care you did not receive. Contact the provider or insurer about suspicious activity and ask whether an account number or other credential should be changed. The FTC’s Health Breach Notification Rule guidance also discusses checking app or connected-device privacy settings and installing current updates when relevant to the incident.

Phone-company account or phone number

Contact your carrier through an official channel if you suspect someone could take over your phone-company account or number. Set a unique carrier account passcode if the carrier offers one. Consider moving accounts that rely on SMS codes to another available MFA method, particularly if your phone service unexpectedly stops working.

App or connected-device information

If the notice identifies app or device information as exposed, review the relevant privacy settings and install available updates. Follow the provider’s instructions for securing the specific account or device.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Credit freeze or fraud alert: which should you use?

Both are free U.S. consumer protections described by the FTC, but they work differently. A freeze restricts access to your credit file, making it harder for someone to open new credit in your name. An initial fraud alert asks businesses to verify your identity before opening new credit, but does not block access to your credit report.

Protection What it does How to set it up Duration and practical effect
Credit freeze Makes it harder to open new credit accounts by restricting access to your credit file. It does not protect existing bank, email, shopping, or card accounts. Request it separately from Equifax, Experian, and TransUnion. Free and lasts until you lift it. You may need to lift it temporarily when applying for credit, which can delay an application if a lender cannot access your file.
Initial fraud alert Asks businesses to take steps to verify your identity before opening new credit; it does not block access to your credit report. Request it from one of the three nationwide credit bureaus; that bureau must notify the other two. Free and lasts one year, according to the FTC’s credit freeze and fraud alert guidance.

You can have both a freeze and a fraud alert. These measures address the risk of new credit being opened; use separate steps to secure existing accounts and payment methods. The FTC says a freeze does not affect your credit score and remains in place until lifted in its 2025 consumer alert.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If you find signs of misuse

  1. Contact the affected company’s fraud department through an official channel. Ask it to secure or close the affected account as appropriate.
  2. Contact the bank, card issuer, insurer, or provider tied to the suspicious activity and follow its dispute or account-recovery process.
  3. Report identity theft at IdentityTheft.gov, which provides reporting and recovery guidance. The FTC’s “What To Do After a Data Breach” video likewise points people there if they find someone using their information for fraud.
  4. Keep the breach notice and records of disputed transactions, unfamiliar accounts, and your contacts with the relevant organizations.

Use offered support, but do not assume paid monitoring is necessary

If the affected organization offers relevant credit monitoring or identity-restoration help for free, consider using it and follow its enrollment instructions. An offer of monitoring is not proof that a paid service is necessary or that monitoring can prevent every kind of misuse. The FTC’s business data-breach response guide describes support an organization may offer; choose additional paid help only if you have a specific need that free steps do not address.

Know which rules apply to your situation

Breach-notification duties and available remedies depend on location, the type of organization, the information involved, and the incident. This guidance focuses on U.S. consumer steps; people elsewhere should consult their country’s official privacy or identity-theft authorities.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The FTC Health Breach Notification Rule is not a general deadline for every data breach. For breaches covered by that rule involving unsecured personal health information, the FTC says affected people must be notified without unreasonable delay and within 60 calendar days after discovery. The rule also has separate requirements for notifying the FTC and, at certain thresholds, the media; HIPAA-covered entities and business associates follow HHS rules. Do not apply the 60-day figure to unrelated breaches.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.