You got the notice. A company you use lost control of customer data. Your email address, password, phone number, or Social Security number may now be exposed. Scammers can use that data within hours. They test stolen passwords across banks, email, and shopping sites. They may open new accounts or file fake tax returns. It is a stressful moment. But you can reduce the damage with a clear checklist. Start by understanding what data was exposed and how data brokers collect and sell your information.
The first 48 hours matter most. Criminals may have already started credential stuffing. That is when they try one stolen password on many sites. If you reused a password, every account that shares it is at risk. A stolen Social Security number can lead to new credit accounts. A stolen payment card can lead to immediate charges. You do not need to panic. You need to work through a fixed sequence: lock credit, reset passwords, check accounts, and monitor. Many of these protections are free and take less than an hour.
The FTC advises acting quickly after a breach. Freeze or alert your credit reports first. Then reset passwords and enable two-factor authentication. Do not wait for evidence of fraud. The goal is to stop thieves before they act. We will walk you through each step. You can complete the basics in one evening. This checklist covers password resets, credit freezes, fraud alerts, and monitoring. Later you can take longer-term steps like removing yourself from the internet.
This guide is for ordinary people, not security experts. You do not need paid software for the first protections. You do need a computer or phone, a notebook, and about ninety minutes. Keep a log of every action you take. Save confirmation numbers and credit bureau PINs. Some steps, like a credit freeze, are free by law. Others, like a password manager, make recovery easier. Place a fraud alert or freeze before you do anything else. Begin now, and follow each step in order.
What You’ll Need
- Computer or smartphone
- Secure notebook or password manager
- Breach notification details
- List of accounts using the breached password
- Access to bank and credit card apps
- Credit bureau account access
How Do You Respond to a Data Breach?
- Confirm what was exposed and save the notice
Start with the notification. Search your email for the breach notice. Check the company website or app for a security advisory. If you use Have I Been Pwned, check whether your email appears in recent breaches. Save a screenshot or PDF of the notice. Note the date and what data was exposed: email address, password, payment card, Social Security number, or medical records.
The type of data determines your next moves. A stolen password means resetting that password and any reused passwords. A stolen Social Security number means placing a credit freeze. A stolen payment card means calling the card issuer for a replacement. A stolen phone number means securing your mobile account against SIM swap. Do not ignore a breach notice just because the company says no financial data was exposed. Email and phone data feed phishing.
Contact the company only through its official website or app. Do not call phone numbers or click links from the breach email. Scammers send fake breach notices to collect your login details. If you are unsure, search for the company name plus security incident. The company may offer free credit monitoring. Write down the offer code or enrollment link.
After you know what was exposed, move to password resets. Do not skip this step. You need to know whether the breach included passwords. If it did, speed matters. Even if it did not, reset the password on the breached account as a precaution. Connect this step to the next: protect your email first because it is the key to every other account.
- Reset passwords and enable two-factor authentication
Start with your email account. Password reset links from every other site go there. If a thief controls your email, they can reset your bank account. Change your email password to a unique passphrase. Aim for at least 16 characters. Use three random words, numbers, and symbols. A password manager makes this easier. Compare options in our guide to the best password managers.
Then change the password on the breached account. If you reused that password anywhere else, change it on every one of those sites. Make each new password unique. A password manager can generate and store them. Do not just add a number to the old password. Thieves use tools that guess common patterns. Turn on two-factor authentication, or 2FA, for email, bank, social media, and cloud accounts.
Use an authenticator app for 2FA when possible. Apps like Google Authenticator or Authy create one-time codes. SMS codes are weaker because attackers can hijack your phone number through a SIM swap. If SMS is the only option, use it temporarily. Then contact your mobile carrier and add a port-out PIN or account lock. Save backup codes in a safe place.
Check your recovery email and phone number on each account. Attackers sometimes add their own recovery details. Review active sessions and sign out devices you do not recognize. Turn on login alerts if the service offers them. Then move to credit protection. Even if your financial data was not in the breach, a freeze stops future misuse.

- Place a fraud alert or credit freeze
A fraud alert tells businesses to verify your identity before opening new credit. It is free. Contact one of the three major credit bureaus and that bureau must notify the other two. According to the FTC, a fraud alert lasts one year and can be renewed. An extended fraud alert lasts seven years but requires an identity theft report.
A credit freeze is stronger. It blocks new creditors from accessing your credit report. Without that access, lenders will not open new accounts. You must contact each bureau separately: Equifax, Experian, and TransUnion. Freezes are free by law. They do not affect your credit score. They do not stop existing creditors from reviewing your report.
If your Social Security number was exposed, place a freeze. If only your email or password was exposed, at least place a fraud alert. You can do both, but a freeze is the strongest protection. Keep the PIN or password each bureau gives you. You will need it to lift the freeze when you apply for credit, rent an apartment, or start a new job.
Do not pay for a credit freeze. Some websites charge for services that are free. Go directly to the credit bureau websites or call them. Set aside about 20 minutes to complete all three. After the freeze and alert are in place, review your accounts. This step prevents new credit lines, but it does not catch charges on existing accounts.

- Review financial accounts and check your credit reports
Log into every bank, credit card, and loan account. Look for small test charges, often $1 or $2. Scammers may test a card before making larger purchases. Check for address changes, new authorized users, or new cards you did not request. Report anything suspicious to the fraud department immediately. Use the number on the back of your card or the official website.
Pull your credit reports. You can get them free weekly from AnnualCreditReport.com. Review each of the three reports from Equifax, Experian, and TransUnion. Look for inquiries you did not make, new accounts, collections, or wrong personal information. Dispute errors directly with the bureau. A mistake may be a sign of fraud, so do not ignore it.
Turn on transaction alerts for every card and bank account. Set alerts for any transaction over $1. Many banks let you get real-time email, text, or app notifications. The earlier you see a charge, the faster you can dispute it. Check your accounts daily for the first two weeks after the breach. Then switch to weekly checks.
If you find fraud, act immediately. Call the bank or card issuer and tell them you are an identity theft victim. Ask for a new card or account number. File a report at IdentityTheft.gov and save the recovery plan. You may also need a police report. If you want help with monitoring and recovery, compare identity theft protection services.
- Set up free monitoring and consider paid protection
If the breached company offers free credit monitoring, sign up now. Many companies provide one or two years of monitoring after a breach. The offer may include credit report monitoring, dark web alerts, or identity restoration support. Use the enrollment link from the official notice. Watch for fake enrollment emails. Go to the company website and navigate to the security page.
Set a calendar reminder before the free monitoring expires. When it ends, scammers may still have your data. You can continue self-monitoring through weekly credit report checks and bank alerts. A paid identity theft protection plan can add convenience, but it is not required. Look for plans that include credit monitoring, identity theft insurance, and recovery assistance.
Do not rely on monitoring alone. It tells you after something happens. The credit freeze from earlier stops many new accounts before they are opened. The fraud alert adds another verification layer. Use monitoring as an early warning system, not your only defense. You can also reduce your exposure by removing your profiles from data broker sites. See how to opt out of data brokers.
For broader reduction, compare data removal services. These services remove your personal details from people search sites. That limits the information scammers can find later. This step is not urgent, but it helps over time. After monitoring is set, secure your devices and email to stop phishing attempts.

- Secure your devices and learn to spot phishing
Breach data fuels phishing. You may receive emails or texts that mention the breach. They may say your account was locked or your card was charged. They create pressure so you click. Do not click links in unsolicited messages. Instead, open a new browser tab and go to the official website. Or call the company using a number you already trust.
Check sender addresses carefully. Scammers use domains that look close, like support-alerts.com instead of your bank’s domain. Hover over links to see the real URL. Do not open attachments you did not expect. If a message asks for your password, Social Security number, or one-time code, treat it as fraud. Legitimate companies do not ask for these through email or text.
Update your devices. Install operating system, browser, and app updates. Enable automatic updates. Run a security scan with your built-in antivirus or a trusted tool. Remove apps you no longer use. Check your browser extensions and remove anything unfamiliar. These steps close holes that scammers can use to steal new passwords.
Lock down your mobile account. Call your carrier and add a port-out PIN or SIM lock. This makes it harder for a thief to hijack your number and receive your 2FA codes. Then review your email security. Add a recovery email and phone number you control. Sign out of unused sessions. Continue to the final step: document everything.
- File reports and keep a recovery file
If you see fraud, report it. Go to IdentityTheft.gov and follow the steps. The site is run by the Federal Trade Commission. It creates a personal recovery plan and gives you an identity theft report. That report helps when you dispute charges or accounts. You may also need to file a police report. Some creditors require one to remove fraudulent accounts.
Keep a recovery file. Save the breach notice, your credit freeze confirmations, PINs, identity theft report, and notes from every phone call. Record the date, the person you spoke with, and the result. Store this file in a secure place. A password manager can hold digital copies. A locked drawer can hold paper copies. This file proves what you did and helps if fraud appears later.
Check your state’s data breach notification laws. Companies must notify you if certain personal information is exposed. Some states give you rights to free credit freezes or identity theft services. If you live in California, review the California Consumer Privacy Act for additional rights. Check your state attorney general’s website for local guidance.
Schedule a 30-day review. After a month, pull your credit reports again. Look for new accounts or inquiries. Check your bank statements for the last 30 days. If everything is clean, keep your freeze and alerts in place. Long-term privacy also helps you avoid repeated exposure.
Red Flags & Warnings
- 🚨 Do not click links in a breach notice. Type the company website into your browser or use the app instead.
- 🚨 Never reuse the same new password across multiple sites. Use a password manager to create a unique phrase for each account.
- 🚨 A credit monitoring alert comes after fraud begins. It does not prevent new accounts. Use a credit freeze or fraud alert first.
- 🚨 You never have to pay for a credit freeze or a one-year fraud alert. Go directly to Equifax, Experian, and TransUnion.
- 🚨 Do not wait for evidence of fraud before freezing your credit. Freeze first, then investigate.
- 🚨 Write down your credit freeze PINs and store them safely. Losing them makes it harder to lift the freeze later.
Frequently Asked Questions
What should I do first after a data breach?
Place a fraud alert or credit freeze with the three major credit bureaus. Then reset passwords for your email and the breached account. After that, review your bank and credit card statements and check your credit reports for new accounts.
Is a fraud alert better than a credit freeze?
A credit freeze is stronger because it blocks new creditors from seeing your report. A fraud alert asks businesses to verify your identity but does not block access. Use a freeze if your Social Security number was exposed. Use a fraud alert as a minimum if you are not ready to freeze.
How long does a fraud alert last?
A standard fraud alert lasts one year. You can renew it each year. An extended fraud alert lasts seven years but requires an identity theft report.
Do I need to pay for credit monitoring after a breach?
No. The breached company may offer free credit monitoring. You can also check your credit reports weekly for free through AnnualCreditReport.com. Paid monitoring is optional.
Can I still open new accounts with a credit freeze?
Yes. You can lift the freeze temporarily when you apply for credit. Contact each credit bureau and use the PIN you saved. You can also lift it for a specific creditor or for a set period.
What if I reused the breached password on many sites?
Change that password on every site where you used it. Use a password manager to make each new password unique. Turn on two-factor authentication everywhere you can. This stops a credential stuffing attack from spreading.
What Should You Remember?
- Freeze your credit: Contact all three bureaus and place a credit freeze or fraud alert immediately.
- Reset passwords fast: Start with email, then change every account that reused the breached password.
- Turn on 2FA: Use an authenticator app for email, bank, and social accounts.
- Check account and credit activity: Review bank statements and weekly credit reports for test charges and new accounts.
- Save your evidence: Keep breach notices, freeze PINs, recovery plans, and call logs in one secure file.
- Watch for phishing: Breach data fuels fake emails and texts. Go directly to official websites.
- Reduce future exposure: Opt out of data brokers and remove your personal details from people search sites.
This article is for general informational purposes only and is not legal or financial advice. Data broker policies, privacy laws, and service pricing change frequently, so verify current details with the official source before acting. Some links may be affiliate links that support this site at no cost to you.


