Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Guides

What to do after your data is exposed in a breach

A step-by-step checklist for the first 24 hours, the first week and the months after you receive a data breach notice.

By · Published · Updated · 4 min read

What to do after your data is exposed in a breach

Data breach notices are now routine — this month alone the Pentagon, the FBI, McKesson and Revolut have all disclosed one. Here is what to do when it is your data.

First 24 hours

  1. Check the notice is real. Scammers send fake breach letters. Visit the company's website directly rather than clicking links.
  2. Find out what was exposed. Passwords, card numbers and Social Security numbers each need a different response.
  3. Change the password for that account, and anywhere else you used the same one.
  4. Turn on multi-factor authentication, ideally an app or passkey rather than SMS.

First week

  • If your card was exposed: ask your bank for a new card.
  • If your Social Security number or ID was exposed: freeze your credit with Equifax, Experian and TransUnion. See our credit freeze guide.
  • Take up free monitoring if the company offers it.
  • Check [Have I Been Pwned](https://haveibeenpwned.com) to see what other breaches include your email.

The months after

  • Expect targeted phishing. Criminals use leaked details to sound convincing. Be wary of calls or emails that mention the breach.
  • Review bank, card and insurance statements monthly.
  • Get your free credit reports at AnnualCreditReport.com.

If you spot identity theft

Report it at IdentityTheft.gov, which gives you a personalised recovery plan.

Sources

Read next