Skip to content
All guides

Phishing & Scams

How to Know If a Data Breach Notification Is Real

A real data breach notification should identify the affected organization and provide a way to verify the incident independently. A scammer can also copy a real breach story to steal passwords, verification codes, or money. Do not rely on links or phone numbers inside an unexpected message. Verify the breach through the company’s official website or another trusted source, then take security steps based on the information actually exposed.

By the 4safer teamUpdated August 29, 202612 minutes read

How to Know If a Data Breach Notification Is Real

A genuine breach notice should survive independent verification.

That means you should be able to step away from the email, text message, or phone call and confirm the basic story somewhere else.

The most important idea is independent verification.

The FTC recommends that when an unexpected message appears to come from a company you know, you avoid relying on the link or phone number supplied in the message and instead contact the organization using a website or phone number you know is legitimate.

That advice is especially important with breach notifications because fear creates urgency.

  • Is the organization real?
  • Do I actually have or remember having a relationship with it?
  • Has the company published an official security notice?
  • Does the incident date make sense?
  • Does the company describe which information may have been affected?
  • Can I reach its security or support information without using the links in the message?

Why scammers send fake breach notifications

A breach notification creates the perfect phishing story.

The message can say:

Your personal information has been exposed.

That immediately makes most people want to know:

A scammer can then offer a convenient button:

The link may lead to a fake login page.

Instead of telling you about stolen credentials, the page may be designed to steal the credentials you still have.

NIST defines phishing as a form of social engineering in which an attacker impersonates a legitimate organization and tricks a person into interacting with a fraudulent site or revealing sensitive information.

The irony is important:

Can a fake notification reference a real breach?

This is one of the hardest versions to recognize.

Suppose a major company genuinely announces a security incident.

The event becomes public.

Scammers do not need to invent anything.

They can simply send messages saying:

We are contacting you regarding the recently announced breach.

The company name is real.

The breach is real.

The scammer is not.

That means searching the company name and confirming that a breach occurred is only the first step.

You must also confirm that the instructions you are following came from the actual organization.

Does knowing my personal information prove the message is real?

A scammer knowing your name, address, email, phone number, or even account-related information does not make the person trustworthy.

The FTC specifically warns that scammers may know real information about you because personal information can be bought, stolen, or obtained elsewhere and then used to make a fraudulent story more convincing.

A message might say:

Hello John Smith, we are contacting you about the account registered to [john@example.com](mailto:john@example.com).

Both pieces of information may be correct.

That does not establish who sent the message.

This is why verification should be based on control of an official communication channel, not simply knowledge of personal details.

What information should a legitimate breach notice contain?

The exact content varies according to the incident and applicable requirements, but useful legitimate notices often explain some combination of:

A legitimate notice should not need to frighten you into immediately revealing the same types of information supposedly at risk.

Be particularly cautious when a message claiming to be about a breach immediately asks for:

Those requests do not fit the normal purpose of notifying someone that their information may have been exposed.

  • Which organization experienced the incident
  • When the incident occurred or was discovered
  • What happened
  • Which categories of information may have been affected
  • What the organization has done in response
  • What affected people may consider doing
  • How to contact the organization through official channels
  • Your password
  • Authentication code
  • Recovery code
  • Bank PIN
  • Full Social Security number
  • Payment
  • Remote access to your computer

What are the biggest warning signs of a fake breach notification?

No single sign proves phishing, but combinations matter.

Extreme urgency.

Messages may claim:

NIST identifies urgency as a common warning sign in phishing and recommends independently verifying unexpected requests through known contact information.

A legitimate breach can be serious without requiring you to abandon normal judgment.

Requests for credentials.

A notification informing you that credentials may be at risk should not require you to reply with your password.

Requests for verification codes.

One-time codes are authentication factors.

Do not provide them because someone claims the code is needed to confirm whether you were affected.

Requests for money.

Be skeptical if a supposed breach response requires immediate payment for:

FTC guidance on recovery scams warns that criminals often contact people claiming they can fix prior fraud or recover money, while actually trying to obtain additional money or personal information.

Strange sender addresses.

A message claiming to be from a major institution but sent from an unrelated address deserves scrutiny.

However, do not rely only on the visible sender address.

Email addresses can be imitated, and sophisticated phishing messages may look highly professional.

Suspicious links.

If the visible text says the company name but the destination appears unrelated, stop.

You do not need to inspect every technical detail of the URL.

Simply avoid the link and navigate to the company independently.

  • You have 30 minutes to respond
  • Your account will be permanently closed
  • Your funds are already being transferred
  • Your identity will be sold unless you act
  • You must verify immediately
  • Data removal
  • Identity restoration
  • Account protection
  • A guaranteed refund
  • Government assistance

How do I verify a breach without clicking the message?

Use a clean path.

Step 1: Identify the company.

Write down or remember the name.

Do not click.

Step 2: Open a new browser window.

Type the company's official address yourself or use an official app you already have installed.

Step 3: Look for a security notice.

Search within the official website for terms such as:

Step 4: Compare the information.

Step 5: Contact the company independently if needed.

Use the contact information published through the official website, statement, card, or app.

The FTC recommends this independent-contact approach for suspicious messages precisely because criminals can provide fake phone numbers and links inside their communications.

  • Security incident
  • Data breach
  • Incident notice
  • Customer notice
  • Security update
  • Dates
  • Description
  • Types of information involved
  • Customer instructions
  • Contact channels

Should I search Google for the support number?

Be careful.

The safest option is the company's own official website, app, statement, or card.

In its January 2026 guidance, the FTC specifically warned that scammers can use paid search advertisements so fraudulent customer-support numbers appear prominently in search results.

For a bank, for example, use:

Do not assume the first phone number in search results is legitimate.

  • The official mobile application
  • The website you already know
  • The number printed on your card
  • A recent official statement

What if the notice contains a link to free credit monitoring?

That can be legitimate.

Companies sometimes offer monitoring or identity-protection services after incidents involving sensitive personal information.

But the offer should still be independently verified.

Do not create an account through a random link simply because the message says the service is free.

Verify the breach and enrollment instructions through the affected company's official website.

This prevents a scammer from using a genuine type of breach remedy as phishing bait.

What if the message says my password was leaked?

Do not type the password into another page to “confirm” it.

If the notice is verified and a current password may have been exposed:

If the message itself displays an old password, determine whether that password still works anywhere.

A retired password has far less value than an active reused credential.

  • Visit the official service directly.
  • Change the password.
  • Replace it anywhere else you reused it.
  • Enable MFA.
  • Review active sessions.

Review the email or username mentioned in the notice

An exposure check may help determine whether an identifier has known exposure history.

That can support your investigation, but it does not authenticate the notification itself.

Do not copy a password from the notification into an exposure checker.

What if the company says my email was exposed?

An exposed email is not the same as an exposed email account.

The breach may have occurred at:

while your actual email provider remained secure.

The main risks from an email-address exposure may include:

Make sure your inbox uses:

  • A retailer
  • Application
  • Subscription service
  • Vendor
  • Employer
  • Other organization
  • More phishing
  • Spam
  • Password-reset attempts
  • Targeted scams
  • A unique password
  • MFA
  • Current recovery information
  • Login alerts

What if financial information was involved?

Verify the notice carefully and review the relevant financial account directly.

Do not contact the “fraud department” using a phone number supplied in a suspicious message.

If you see unauthorized activity, contact the institution using a verified official channel.

  • Transactions
  • Transfers
  • Cards
  • Account alerts

What if my Social Security number may have been exposed?

This deserves additional identity-protection steps, but do not respond to a supposed breach by giving your full SSN to the sender.

Verify the incident first.

Then use official credit and identity-theft resources as appropriate.

A breach notice about sensitive information can attract follow-up scams precisely because attackers know affected consumers are anxious.

What if the breach message asks me to call immediately?

You can contact the organization.

Just do not necessarily use the phone number in the message.

Find an independently verified number.

A common scam pattern begins with an alarming claim about fraud or account compromise and then moves the target into a phone conversation where the attacker requests money, account information, remote access, or authentication codes.

FTC guidance warns that criminals may know real details and still be fraudsters.

Can caller ID prove the call is from the company?

Caller information can be manipulated.

If someone calls saying they are responding to a breach:

A legitimate fraud or security department should tolerate independent verification.

  • Ask for the company name and basic issue.
  • Do not provide sensitive information.
  • End the call.
  • Contact the organization independently.

What if the sender tells me not to contact anyone else?

Treat secrecy as a major warning sign.

A scammer may say:

FTC guidance notes that legitimate fraud departments will not demand that consumers keep the situation secret while moving money or surrendering account information.

  • Do not contact your bank
  • Do not speak to your family
  • The investigation is confidential
  • You will interfere with the case
  • You must act before calling anyone else

What if the notification is real?

Once verified, switch from verification to response.

Determine exactly which information was involved.

Secure the email account and expect phishing.

Replace active passwords and eliminate reuse.

Be careful with text-message scams and unexpected verification codes.

Financial information.

Review accounts and follow the institution's official guidance.

Social Security number.

Review credit and identity protections.

Do not take every possible security action simply because the word “breach” appeared.

Match the response to the data.

What if the notification is fake and I already clicked?

Your response depends on what you did.

You opened the email.

That alone does not necessarily compromise an account.

You clicked the link but entered nothing.

Close the page.

If you downloaded something or suspect malware, update security software and scan the device.

You entered a password.

Treat it as compromised.

Change it immediately through the real service and replace it anywhere else it was reused.

You entered a verification code.

Review the affected account immediately.

You gave remote computer access.

Disconnect and secure the device.

FTC guidance recommends updating security software, running a scan, changing passwords, and enabling two-factor authentication if a scammer gained access to a computer or phone.

You sent money.

Contact the relevant bank, card provider, payment company, or transfer service immediately and report the fraudulent transaction.

Should I report a fake breach notification?

Yes, particularly if it is clearly phishing or fraud.

The FTC accepts scam reports through ReportFraud.ftc.gov and uses reports to identify fraud patterns and support enforcement and consumer education.

Phishing emails can also be reported through mechanisms provided by your email service or the impersonated company.

Why real breach notifications can lead to later scams

Even after you verify a genuine breach, remain alert.

A real incident may make you more vulnerable to follow-up social engineering.

Scammers can contact you days or weeks later saying:

We are following up about the breach.

We can remove your information.

We can recover compensation for you.

FTC guidance on recovery scams explains that scammers may buy, sell, or trade information about previous victims and then use accurate details to create believable follow-up stories.

A genuine past incident does not authenticate a future caller.

Practical checklist for verifying a data breach notification

  • [ ] Do not react only because the message looks professional
  • [ ] Do not click the message immediately
  • [ ] Identify the organization named
  • [ ] Open its official website independently
  • [ ] Look for an official incident notice
  • [ ] Compare incident dates and information
  • [ ] Use official contact details
  • [ ] Avoid phone numbers supplied only in an unexpected message
  • [ ] Be cautious with search-result customer-service numbers
  • [ ] Never send your password
  • [ ] Never send an authentication code
  • [ ] Never send recovery codes
  • [ ] Do not provide unnecessary sensitive identity information
  • [ ] Be skeptical of urgent payment requests
  • [ ] Verify free monitoring offers independently
  • [ ] Check the affected identifier for known exposure when useful
  • [ ] Determine which information may have been involved
  • [ ] Change active exposed passwords
  • [ ] Eliminate password reuse
  • [ ] Enable MFA
  • [ ] Review account sessions
  • [ ] Monitor financial activity when relevant
  • [ ] Use official identity-theft resources for sensitive identity exposure
  • [ ] Report phishing or fraud
  • [ ] Remain alert for follow-up recovery scams

Frequently asked questions

How do I know if a data breach notification is real?

Verify the incident independently through the organization's official website or another trusted official source instead of relying only on links, phone numbers, or claims inside the message.

Can a phishing email mention a real data breach?

Yes. Scammers can use a genuine public breach as the story behind a fraudulent email.

Does the company knowing my name and email prove the notice is legitimate?

No. Scammers can obtain real personal information and use it to make fraudulent messages more believable.

Should I click the link to see what was exposed?

Use the company's official website independently whenever possible rather than clicking an unexpected breach link.

Should a company ask for my password after a breach?

Be extremely suspicious of any unexpected message that asks you to provide a current password or authentication secret.

What if the notice contains one of my real passwords?

Determine whether the password is still active. If it is, change it immediately and replace it everywhere it was reused. The password's presence does not automatically authenticate the sender.

Can I trust the phone number inside the notice?

Verify it against the company's official website, app, card, or statement before calling.

Sources

This guide is reviewed against official guidance. External pages may be updated by their respective owners.