Skip to content
All guides

Breach response

What Should I Do After a Breach Notification

Read the notice, match the data type to the right action, secure logins, and use IdentityTheft.gov when identity misuse is possible or already happening.

By the 4safer teamUpdated August 29, 20268 minutes read

Read the letter for data types, not drama

A useful notice names categories: email, password, date of birth, Social Security number, driver’s license, bank account, medical record number, and so on. Your plan should follow those categories. The FTC built IdentityTheft.gov/databreach around that idea. The site asks what was exposed, then shows actions that fit. Ignore countdown language that demands payment, cryptocurrency, or a “restoration fee.” Official U.S. consumer recovery paths do not start with you wiring money to a stranger.

First hour: contain the logins

If the notice is about an account you no longer use, do not skip it. Reuse is the bridge from a dead shopping profile to a living email or bank login.

  • Type the real domain of the company or agency.
  • Change the password if credentials were involved, or if you reused that password anywhere important.
  • Turn on multifactor authentication.
  • Review sessions and recovery options.
  • Take any free monitoring the company offers, if it comes from the firm named in a notice you have verified. The FTC has said those offered services can be worth accepting.

If a password or login was listed

Unique new password. MFA or passkey. Session review. Then repeat for every reused site, starting with email.

If a card or bank account was listed

Call the number on the card or official site. Ask about alerts, a replacement card, and unrecognised charges. Watch statements.

If a Social Security number was listed

Get your free credit reports through AnnualCreditReport.com. Consider a fraud alert or a credit freeze. File taxes on time if that applies to you, and do not treat unexpected IRS-style texts as real. IdentityTheft.gov walks through those SSN-specific steps.

If a driver’s license or other ID was listed

Follow the ID-specific steps on IdentityTheft.gov and the official state motor vehicle site you type yourself. If you already see new accounts, jobs, tax filings, or medical bills that are not yours That is identity theft, not only exposure. Report it at IdentityTheft.gov to generate a report and a recovery plan. The CFPB points consumers to the same starting place.

The week after: watch, record, refuse fake help

Keep a simple log: date of the notice, data types named, accounts you changed, reference numbers from banks, and copies of official letters. That paperwork helps if you later need a freeze lift, a dispute, or an Identity Theft Report. Stay skeptical of follow-up calls. The FTC warns that scammers impersonate agencies and well-known companies after information is exposed. Do not use the number in the unexpected message. Look it up separately. A notification also does not create an automatic right to payment, deletion of every copy, or a successful lawsuit. Outcomes depend on the facts, the company, and the law that applies. Use “may” and “can,” then do the practical work anyway.

Make the next notice smaller

CISA’s four household essentials — updates, strong unique passwords, MFA, and phishing caution — are the right closing posture after you finish the notice-specific steps. Knowing what should I do after a breach notification is less about panic and more about matching the named data type to an official next step.

  • Password manager and unique secrets
  • Passkeys where they exist
  • Login alerts
  • Fewer leftover accounts
  • Software updates
  • A household rule: no passwords in chat, ever

Practical checklist

  • Verify the notice on a typed official URL.
  • List the data types the notice actually named.
  • Change involved and reused passwords.
  • Enable MFA or a passkey.
  • Accept verified free monitoring if offered.
  • Use IdentityTheft.gov/databreach for SSN, ID, and financial categories.
  • Freeze or alert credit if new-account fraud is a concern.
  • Report confirmed misuse at IdentityTheft.gov.
  • Keep notes. Ignore paid “guaranteed deletion” pitches.

Frequently asked questions

The account is old. Can I ignore the letter?

You can close the account after you secure it, but do not ignore a credential exposure if that password was reused.

Does a notice mean I must pay for identity insurance?

No. Review what the company is offering at no cost and what official free tools already cover. Paid products are a separate choice.

When should I call the police?

If you have evidence of fraud or identity theft, local reporting can be part of the recovery file. IdentityTheft.gov still remains the federal starting point for the consumer plan.

Sources

This guide is reviewed against official guidance. External pages may be updated by their respective owners.