What to do after your data is exposed in a breach
A step-by-step checklist for the first 24 hours, the first week and the months after you receive a data breach notice.
By Mira Castell · Published · Updated · 4 min read

Data breach notices are now routine — this month alone the Pentagon, the FBI, McKesson and Revolut have all disclosed one. Here is what to do when it is your data.
First 24 hours
- Check the notice is real. Scammers send fake breach letters. Visit the company's website directly rather than clicking links.
- Find out what was exposed. Passwords, card numbers and Social Security numbers each need a different response.
- Change the password for that account, and anywhere else you used the same one.
- Turn on multi-factor authentication, ideally an app or passkey rather than SMS.
First week
- If your card was exposed: ask your bank for a new card.
- If your Social Security number or ID was exposed: freeze your credit with Equifax, Experian and TransUnion. See our credit freeze guide.
- Take up free monitoring if the company offers it.
- Check [Have I Been Pwned](https://haveibeenpwned.com) to see what other breaches include your email.
The months after
- Expect targeted phishing. Criminals use leaked details to sound convincing. Be wary of calls or emails that mention the breach.
- Review bank, card and insurance statements monthly.
- Get your free credit reports at AnnualCreditReport.com.
If you spot identity theft
Report it at IdentityTheft.gov, which gives you a personalised recovery plan.


