Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

If a government agency or employer says your personal information was exposed, first verify the notice through an official channel, then find out exactly which data was involved. Use the Federal Trade Commission’s IdentityTheft.gov data-breach guide for steps tailored to the exposed information. A breach notice does not by itself mean someone has used your identity.

What should I do if my employer’s data was stolen—or the government lost my information?

The same first steps apply to either kind of organization. The right response depends on what the notice says was exposed, not simply on who sent it.

  1. Verify the notice safely. Visit the organization’s official website or contact it using a phone number or other channel you already know is genuine. Do not rely on links or phone numbers in an unexpected email, text, or letter until you have independently confirmed them.
  2. Identify the data involved. Read the notice for specific information types, the dates of the incident if provided, and any free services the organization is offering. If the notice is unclear, ask the organization through contact details from its official website.
  3. Follow the tailored recovery steps. Use the FTC’s data-breach recovery page. The FTC advises people to use free credit monitoring or identity-theft insurance offered by the organization responsible for the breach.
  4. Watch for signs of misuse. Check relevant financial, insurance, or other accounts for activity you do not recognize. If you find evidence of identity theft, use IdentityTheft.gov to get a recovery plan.

Keep the notice and records of suspicious activity. Exposure and confirmed identity theft are different: take the steps that fit the data named in the notice, and escalate if you see unfamiliar activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What to do based on the information exposed

The FTC’s guidance is data-specific. A Social Security number calls for attention to credit files; account credentials, payment details, and health information require action with the organizations that manage those accounts.

Social Security number or other identity information

Get your credit reports and look for accounts or inquiries you do not recognize. Consider placing a credit freeze or fraud alert; both are free, but they work differently. The FTC explains how to start either option in its guide to credit freezes and fraud alerts.

Bank, payment-card, or other financial account information

Contact the bank, card issuer, or other institution that maintains the affected account, using its official contact channel. Review transactions and statements, and report anything unfamiliar to the institution.

Health insurance or medical information

Review explanations of benefits and bills for care or claims you do not recognize. Contact the insurer or provider through an official channel to ask about unfamiliar claims or billing. Health-data breach rules have their own scope and requirements; the FTC’s guide to the Health Breach Notification Rule describes one set of rules, but not every health-data incident necessarily falls under that rule.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Other information or an unclear notice

Ask the organization which specific information was involved and what actions it recommends. The FTC’s Data Breach Response guide discusses responses to different types of exposed information; your notice and the account or service involved determine which actions are relevant to you.

Credit freeze or fraud alert: which should you choose?

Option What it does How to start Important limit
Credit freeze Restricts access to your credit report for new-credit decisions, making it harder for someone to open new accounts using your information. Contact Equifax, Experian, and TransUnion separately. A freeze is free and remains until you ask for it to be lifted or removed. It does not stop unauthorized charges on existing bank, card, or insurance accounts.
Fraud alert Asks creditors to take steps to verify your identity before opening new credit. Contact one of the three nationwide credit bureaus; that bureau must notify the other two. The FTC says an initial fraud alert lasts one year. It does not replace monitoring existing accounts.

The FTC says bureaus must place an online or telephone freeze request within one business day and lift it within one hour; a request made by mail must be placed or lifted within three business days. These are bureau processing timeframes, not a guarantee that an identity-theft problem will be resolved within those periods. See the FTC’s credit guidance for details.

Keep checking accounts even if you freeze your credit

A freeze is aimed at access to your credit report for new-credit decisions. It does not protect an existing bank, card, or insurance account from unauthorized use. Continue reviewing statements and account activity, and contact the institution through its official channel if anything looks unfamiliar.

If you find evidence of identity theft

Report the problem and follow the personalized recovery steps at IdentityTheft.gov. The FTC’s identity-theft guidance explains how to respond to different forms of misuse. Keep the breach notice and documentation of suspicious activity together so you can refer to them when contacting organizations.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What a breach notice does—and does not—tell you

A notice should be read for the specific data involved and any steps or free services offered, rather than treated as proof that every kind of personal information was stolen. The FTC’s business guide says breach-notification laws apply in all states, Washington, D.C., Puerto Rico, and the U.S. Virgin Islands, and additional laws may apply depending on the information and incident. The applicable duties and deadlines can vary; general federal guidance is not a determination of your rights in a particular incident.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.