Data Breach Response
What to Do After Receiving a Data Breach Notice
Read the notice carefully, verify that it is genuine, identify which information was involved, and follow the organization's official instructions. Then change reused passwords, enable MFA, monitor relevant accounts, and be alert for targeted scams.
Does a breach notice mean I was hacked?
A notice usually means an organization believes some information in its systems was affected. It does not automatically prove that every customer was affected, that your account was accessed, or that identity theft occurred.
The notice should explain the organization, dates, data categories, and recommended steps.
- Read the data categories.
- Check the date.
- Do not assume every claim is true.
How can I spot a fake notice?
Check the sender domain, links, spelling, contact details, and unusual payment requests. A real incident can be imitated by a scammer, so verify through the organization's official website.
- Avoid urgent links.
- Do not pay for verification.
- Use official contact details.
What should I save?
Keep the notice, date received, incident reference, and screenshots. Do not upload the notice or exposed documents to an unknown service.
Verify the organization
Open the organization's website manually and compare the notice with its security or privacy announcement. If unsure, contact support through a published channel.
- Type the site address manually.
- Verify the notice.
- Save confirmation.
Take action based on the data
Change reused passwords when credentials were involved. Monitor cards and accounts when financial information was involved. Follow official instructions for identity documents or government identifiers.
- Change reused passwords.
- Monitor statements.
- Follow official instructions.
Expect targeted phishing
Treat messages that mention the incident, refunds, account closure, or verification with caution. Use the organization's app or website instead of message links.
- Verify every request.
- Do not share codes.
- Report phishing.
Use 4safer as context
An owned email may be checked for known exposure context, but the result does not replace the organization's notice. A negative result does not guarantee that no information was affected.
Frequently asked questions
Should I click the link in a breach notice?
Verify the notice first and open the organization's official site directly when possible.
What if the notice does not say what was exposed?
Contact the organization through its official privacy or support channel and ask for clarification.
Do I need to change every password?
Change reused or affected credentials first, especially email and financial accounts.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
