After a Data Breach

A data breach is a disclosure that a company you dealt with no longer controls a copy of what it held about you. That is all the notice tells you. It does not say the copy has been used, or ever will be, and it does not say what happens next — which is why the useful response starts with a narrower question: which fields were in the file?

Updated 2026-08-28Source: CISA and FTC guidance following breach notifications, published breach-notice practice, security research on credential stuffing and account takeover
The short versionBuildFigure
First questionWhich fields leaked, not who leaked them
Password leakedChange it here and everywhere reused
Card leakedLeast bad. Reissue it.
SSN leakedFreeze your credit. It cannot be reissued.
RankingUnique passwords, then app or key MFA, then SMS
Monitoring offerTake it if free, but it detects, not prevents
ExpectA wave of phishing that cites the breach

Which fields leaked decides the response

Breach notices are written by lawyers and tend to describe categories rather than consequences. Translate it into the table below, and note that the categories differ enormously in how much they matter and in how reversible they are.

What was in the fileWhat it enablesYour move
Email address and name onlyBetter-targeted phishing, and a confirmed live address on a listNothing urgent. Be more skeptical of mail referencing that company for a while.
Password, or a hash of oneAttempts to log in to your other accounts with the same pair. This is the single most damaging field.Change it at that service and everywhere you reused it. Do not just add a digit — the reuse is the problem, not the password.
Payment card numberFraudulent charges on that cardThe most recoverable item on this list. Call the issuer, have it reissued, and watch the statement. Cards can be replaced.
Bank account and routing numberAttempted debits, and more convincing impersonation of your bankTell the bank, ask what monitoring or account-change options they offer, and read statements closely for small test debits.
Social Security number, date of birth, address historyNew accounts opened in your name. This is the category that cannot be reissued.Freeze your credit at all three bureaus. See identity theft response for the rest.
Driver's license or passport number, or images of documentsIdentity verification elsewhere, since many services accept a document image as proofReport to the issuing authority and ask what they advise; procedures vary by state and document type
Security questions and answersAccount recovery on other services, which is often the weakest door in the buildingChange the answers wherever you used the same ones. Answers do not have to be true — a random string stored in a password manager is a better answer than your mother's maiden name.
Health or employment recordsTargeted fraud, and consequences that are not financialAsk the notifying organization exactly what was in the record, and keep the notice

Sort by that table and most breach notices turn out to warrant one specific action or none. The ones that warrant real work are the password row and the Social Security number row.

Password reuse is the mechanism

The reason a breach at a company you barely remember can cost you an email account is arithmetic. Attackers take the leaked pairs of address and password and try them, automatically, against hundreds of other services. Nothing is guessed and nothing is cracked; the login is legitimate because the password is correct. The only variable that decides whether it works is whether you used that password anywhere else.

This is why "my password is really strong" misses the point. A long complex password used on twelve sites fails the moment the weakest of the twelve is breached. A mediocre password used on exactly one site fails nowhere else. Uniqueness beats complexity, and it is not close.

Which leads to the ranking that matters:

1. A unique password on every account, held in a password manager. Nothing else on this list comes close in value, because it caps the blast radius of every future breach at one account. The manager is what makes it possible — nobody remembers ninety passwords, and the alternative people actually adopt is a base word with a number on the end, which credential-stuffing tools handle. If you want a feel for how length and unpredictability affect guessing resistance, the password strength checker runs locally in your browser.

2. Phishing-resistant multi-factor authentication where it is offered. Passkeys and hardware security keys are tied to the real site, so they cannot be relayed to a lookalike. An authenticator app is the practical next step and is available almost everywhere.

3. Text-message codes, as a last resort. Better than a password alone, and worth turning on if it is the only option. But codes appear on lock screens, and they can be redirected by a SIM swap — where someone convinces a carrier to move your number onto their device, often using exactly the personal details that leaked in a breach. Where a service offers an app or a key, move off SMS. Adding a port-out PIN or account lock with your mobile carrier is a small step with real value here.

4. Recovery paths, which people forget entirely. Old recovery email addresses you no longer control, security answers that are public facts, and phone numbers you gave up years ago are all ways around everything above. Go through the security page of your main accounts once and prune it.

The notification letter and the monitoring offer

Keep the letter. It is the documentation that a specific organization held your data on a specific date, and if anything comes of it later, that is what you will need.

The offer of free credit monitoring is worth accepting — it costs nothing and it is one more place an alert can come from. Be clear about what it is, though. Monitoring tells you after something has appeared on your credit file. It does not prevent the account being opened. If the breach included your Social Security number, the freeze is the response and the monitoring is a supplement, not a substitute; people frequently enroll in the free year and consider the matter handled, which is the mistake the offer inadvertently encourages.

Watch for the enrollment page being imitated, too. A breach announcement is public, so a fake enrollment site harvesting the exact information the breach concerned is an obvious follow-up. Go to the site by typing the address in the letter, and be suspicious of an email that arrives asking you to enroll.

The phishing wave that follows

Expect messages that reference the breach by name, sometimes accurately. They arrive because the breach is news and because the leaked list is a ready-made target set. The common shapes: an urgent notice from the breached company asking you to verify your account; a call from your bank's fraud department mentioning the breach; an offer of compensation or a settlement payment requiring your details; and, if a password leaked, a message quoting it back to you as proof of a compromise that has not happened.

That last one deserves a note because it frightens people effectively. A message containing a real password of yours, demanding payment and claiming to have recordings, is almost always mass-sent from a breach list. The password is genuine and everything else is not. Change the password anywhere it is still in use, and delete the message. The phishing guide and phone scam guide cover the rest of the pattern, and the rule from both applies here: never respond using a route the message supplied.

Some categories cannot be undone

It is worth saying plainly, because a great deal of breach advice implies otherwise. A card number can be reissued. A password can be changed. A Social Security number, a date of birth, a name and an address history cannot be, and once they are in circulation they stay in circulation, traded and re-traded for years. That is uncomfortable, and it also means the goal is not to keep those details secret — for many people that is already lost — but to make them insufficient.

That is exactly what a credit freeze does. It changes the requirement from "know this person's details" to "be able to unlock this person's file", and the second is a lock the attacker cannot pick with data. It is the reason the freeze keeps coming up on these pages: it is the only widely available control that survives the permanent exposure of permanent data.

A routine, so this is not a project each time

WhenDo
On receiving a breach noticeRead which fields were involved. Act on the password row and the SSN row; file the rest.
Once, this monthInstall a password manager, and change the passwords on your primary email, your bank, and any account holding a saved payment method
Once, this monthTurn on the strongest MFA offered by your email, bank and password manager, and add a port-out PIN with your mobile carrier
Once, this monthFreeze your credit at all three bureaus if you are not actively applying for something
Twice a yearCheck a breach-exposure lookup for your addresses, review the connected-apps list on your mail and cloud accounts, and prune stale recovery emails and phone numbers
Once a yearPull your free credit reports from all three bureaus at annualcreditreport.com and read the addresses and inquiries, not just the accounts
OngoingKeep a current backup of anything you would hate to lose, so a compromised or locked account is an inconvenience rather than a loss — see backup strategy

What a page like this cannot tell you is whether your data has actually been used, or will be. Nobody can, including the company that sent the notice — they know what left, not what was done with it. The honest framing is that a breach shifts your odds rather than deciding your outcome, and the reason the short list above is worth an evening is that it lowers those odds permanently, for every breach that has not happened yet.

Questions people ask

I got a breach notice. What do I actually have to do?

Read it for one thing only: which fields were exposed. If a password was involved, change it at that service and everywhere you reused it, which is the part that matters. If a card number was involved, call the issuer for a reissue. If your Social Security number, date of birth or address history was involved, freeze your credit at all three bureaus, because those cannot be reissued and they are what new-account fraud runs on. If it was only your name and email, there is no urgent action — just expect better-aimed phishing referencing that company. Keep the letter either way.

Why does one breach put my other accounts at risk?

Because the leaked email-and-password pairs get tried automatically against hundreds of other services. Nothing is cracked; the login succeeds because the password is genuinely correct. Whether that works on you depends entirely on whether you reused the password. This is why uniqueness matters more than complexity: a long clever password used on a dozen sites fails as soon as the weakest of those dozen is breached, while an ordinary password used on exactly one site fails nowhere else. A password manager is what makes uniqueness practical.

Is the free credit monitoring they offered worth signing up for?

Take it, since it is free, but understand what it is. Monitoring alerts you after something appears on your credit file — it is detection, not prevention, and it does not stop an account from being opened. If your Social Security number was in the breach, the freeze is the actual response and the monitoring is a supplement. The common mistake is enrolling in the free year and treating the matter as handled. Also be careful how you enroll: fake enrollment pages follow public breach announcements, so type the address from the letter rather than following a link in an email.

Is text-message two-factor authentication good enough?

It is much better than a password alone, so turn it on if it is the only option offered. It is also the weakest of the common options. Codes are visible on a lock screen, they can be phished by someone who asks you to read them out, and the number itself can be moved to another device through a SIM swap, which is often accomplished using the same personal details that leak in breaches. Where a service supports an authenticator app, a passkey or a hardware security key, use that instead — those are bound to the real site and cannot be relayed to a fake one. Adding a port-out PIN with your mobile carrier is a cheap extra step.

Someone emailed me one of my real passwords and demanded payment. Is it real?

Almost certainly not the part that scares you. These are sent in bulk from breach lists: the password is genuine because it leaked from some service, and the claims about recordings or access to your device are not. Do not pay and do not reply, since replying only confirms a live address. Do change that password anywhere it is still in use, and if you have reused it, change it there too — that is the actual exposure the message revealed. Then treat it as one more reason to move to unique passwords and stronger authentication.

Related