Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Data Breaches

What to Look For in a Breach Notification Letter

That dreaded letter or email has arrived. This guide explains what a data breach notification must tell you, how to spot red flags, and what the law requires.

By · Published · 12 min read

A close-up shot of a person's hands holding an official-looking letter that has been opened, with a concerned expression on their face blurred in the background.

A data breach notification is a company's formal acknowledgment that your personal information has been compromised. A good notification clearly explains what happened, what specific data was taken, and precisely what you need to do to protect yourself. It serves as both a warning and a guide, but its quality can vary dramatically depending on the company's transparency and the applicable laws.

The Anatomy of a Legitimate Breach Notification

Receiving a notification can be alarming, but a well-written one should provide clarity, not confusion. While format and wording differ, a comprehensive and trustworthy notification letter—whether delivered by email or postal mail—will almost always include several key components. Look for a clear, direct subject line if it's an email, like "Notice of Data Security Incident."

A legitimate notice should contain:

  • A Summary of the Incident: It should state plainly that a security incident occurred. It will describe, in general terms, how the breach happened (e.g., unauthorized access to a server, a third-party vendor compromise, a ransomware attack) and when it was discovered and contained.
  • The Specific Data Types Exposed: This is the most critical part of the letter. A good notice won't just say "contact information"; it will list exactly what was accessed, such as full name, email address, password, date of birth, or Social Security number.
  • What the Company Is Doing: The organization should outline the steps it has taken in response. This includes securing their systems, investigating the breach (often with third-party forensic experts), and reporting the incident to law enforcement and regulatory authorities.
  • What You Should Do: The letter must provide actionable advice. This usually includes recommendations to change your password, monitor your accounts, and be wary of phishing attempts.
  • An Offer of Assistance: For serious breaches involving sensitive data, companies typically offer free credit monitoring or identity theft protection services for a year or more. The letter will provide instructions and a unique code to enroll.
  • Contact Information: There should be a way for you to get more information, such as a toll-free number or a dedicated website with FAQs about the incident.

What Data Was Exposed? The Most Critical Section

Pay the closest attention to the list of compromised data elements. This list directly determines your level of risk and the urgency of your response. The theft of an email address and a hashed password carries a different threat than the exposure of a Social Security number. Understanding the distinction is key to prioritizing your actions.

Here’s a breakdown of common data types and the primary risks they carry:

Data Type ExposedPrimary RiskRecommended Action
Email Address & PasswordCredential stuffing attacks on other sitesImmediately change your password on the breached site and anywhere else you reused it. Enable 2FA.
Name, Address, Date of BirthIdentity theft, highly targeted phishingMonitor your credit reports, be vigilant for scams using your personal details.
Social Security Number (SSN)Severe identity theft, new account fraudThis is a top priority. You should [how to freeze your credit](/posts/how-to-freeze-your-credit) immediately with all three major bureaus.
Payment Card InformationDirect financial fraud, unauthorized purchasesContact your bank to cancel the card and get a new one. Scrutinize your account statements.
Health Information (PHI)Medical identity theft, insurance fraud, blackmailReview medical bills and Explanation of Benefits (EOBs) for services you didn't receive.
Driver's License NumberIdentity fraud, impersonationMay require contacting your state's DMV. Place a fraud alert on your credit file.

If your SSN is involved, a credit freeze is not optional; it is the single most effective defense against an identity thief opening new credit accounts in your name.

The Legal Landscape: Why Companies Send These Letters

Breach notifications aren't just good practice; they are a legal requirement in many parts of the world. However, the laws dictating when and how companies must notify you are a complex patchwork, which explains why the timing and quality of these letters vary so much.

In Europe, the General Data Protection Regulation (GDPR) sets a high standard. Companies must report significant breaches to their data protection authority within 72 hours of discovery. If the breach is likely to result in a "high risk to the rights and freedoms" of individuals, the company must also notify those affected without undue delay.

In the United States, there is no single federal data breach law. Instead, all 50 states, the District of Columbia, and several territories have their own statutes. These laws differ on key points, including:

  • Definition of Personal Information: Some states have a narrow definition (e.g., Name + SSN), while others include biometric data, health information, or online credentials.
  • Threshold for Notification: Some laws only trigger if there's a perceived "risk of harm," allowing companies to avoid notification if they decide the risk is low.
  • Notification Deadlines: Deadlines range from "in the most expedient time possible" to specific timelines like 30, 45, or 60 days. This is why you might receive a letter about a breach that happened six months ago.

This inconsistent legal environment means that the letter you receive is often drafted to meet the bare minimum legal requirements of the strictest applicable law. To learn more about this complex web of regulations, you can read our guide on how US state breach notification laws differ.

Red Flags: Spotting a Vague or Deceptive Notification

Not all breach notifications are created equal. Some are models of transparency, while others are exercises in corporate spin, designed to minimize panic and liability. Watch out for these red flags, which suggest a company may not be telling you the whole story.

  • Vague or Evasive Language: Be wary of phrases like "a security incident involving some user data" or "unauthorized access to our network." A transparent company will tell you what was accessed. If the letter can't or won't specify the data types, treat it as if the most sensitive information was taken.
  • Downplaying the Risk: A common line is, "We have no evidence that your information has been misused." While technically true at the time of writing, it's a meaningless statement. Hackers steal data to use or sell it later. The absence of immediate misuse does not mean there is no risk.
  • Burying the Details: Some notifications are intentionally long and legalistic, with the crucial list of exposed data hidden deep within the text or in a tiny font. The most important information should be front and center.
  • A Long Delay: If the letter states the breach occurred many months, or even a year, prior to you being notified, it is a massive red flag. It indicates either a severe failure to detect the intrusion or a deliberate choice to delay informing customers, leaving them exposed for an extended period.

Watch Out for Phishing and Scams

Unfortunately, cybercriminals know that people are on high alert after a major breach. They exploit this by sending out fake breach notification emails that are actually phishing attacks. These scams are designed to trick you into revealing passwords or financial data.

Before you click anything, look for signs of a phishing attempt:

  • It asks for personal information: A real breach notification will never ask you to provide your password, full SSN, or credit card number via email or a linked form. Never.
  • It contains suspicious links or attachments: Hover your mouse over any links to see the true destination URL. If it looks strange or uses a URL shortener, don't click it. Never open attachments in an unexpected security alert.
  • It uses a generic greeting: Phishing emails often use vague greetings like "Dear User" or "Valued Customer." A real notification from a company you do business with will likely use your name.
  • It creates a false sense of urgency: Phishing attacks often use threats and urgent warnings to rush you into making a mistake, like "Your account will be suspended unless you verify your identity now!"

To verify if a notification is real, ignore the links in the email. Open your web browser and manually type in the company's official website address. Look for a press release, a blog post, or a banner on their homepage addressing the incident. For a deeper dive into spotting fakes, review our guide on how to spot a phishing email or text.

Your Post-Breach Action Plan

Once you've confirmed the notification is legitimate, it's time to act. Don't panic. Follow a methodical process to secure your accounts and identity.

  1. Assess Your Personal Risk: Read the letter carefully. Is it just your email, or is your Social Security number involved? Use the table in this article to understand the threat level associated with the exposed data.
  2. Change Your Passwords: If a password or login credentials were leaked, change the password for the breached service immediately. Crucially, you must also change it on every other website where you have reused that same password. Use a password manager to create and store unique, strong passwords for all your accounts.
  3. Enable Two-Factor Authentication (2FA): 2FA is one of the most effective ways to protect your accounts, even if a criminal has your password. Enable it wherever possible, especially for your email, banking, and social media accounts.
  4. Enroll in the Free Credit Monitoring: If the company offers free credit monitoring or identity theft protection, sign up. It costs you nothing and can provide early warnings of fraudulent activity. Be sure to use the official URL or code provided in the letter.
  5. Place a Credit Freeze: If your Social Security number was exposed, place a security freeze with all three major credit bureaus: Experian, Equifax, and TransUnion. This is free and restricts access to your credit report, making it much harder for thieves to open new accounts in your name.
  6. Stay Vigilant: For the next several months, be on high alert for targeted phishing emails, text messages, and phone calls. Criminals will use your stolen data to make their scams more convincing and personal.

Navigating the fallout of a data breach is an unfortunate reality of our digital lives. By understanding what a notification letter is telling you—and what it might be hiding—you can take the right steps to secure your digital identity. For a complete checklist, see our comprehensive guide on what to do after your data is exposed in a breach.

Read next