You got a data breach notification letter. Now what?

When the exposed data is your Social Security number, date of birth and address, there is nothing to reset — those follow you for life. Here is the order that actually reduces your risk, starting with the free step most people skip.

ByNikita Silianov· Founder & CEO ·LinkedIn
Quick answer

Freeze your credit at Equifax, Experian and TransUnion — free, and it is the only step that blocks a new account being opened with your SSN. Then enroll in the monitoring the letter offers before the deadline printed on it. Assume phishing calls and emails referencing the breach are coming, and never hand over data to anyone who contacts you about it. Finally, remove your address, phone and relatives from data-broker sites — the breached file is gone, but that half is still yours to take down.

Why so many letters right now

Notices from the Conduent Business Solutions incident have been landing in U.S. mailboxes in waves since late 2025, and the count has been revised upward repeatedly as the review continued — press reporting in mid-2026 put the figure filed with the federal health regulator at more than 62 million individuals, which would rank it among the largest U.S. breaches on record. Conduent processes government-benefits, healthcare and claims data on behalf of other organizations, so most recipients get a letter branded with their insurer, employer or state agency rather than a company they recognize. The exposed categories reported include names, dates of birth, Social Security numbers and claims information — the profile this guide is written for.

Figures above are as reported by the press and in regulatory filings, not our own data.

1. Read what was actually exposed — that decides everything else

Every notice lists the data categories involved, and that list is the whole story. If it is an email address and a password, you change the password and move on. If it names your Social Security number, date of birth or home address, you are in a different situation: there is no password to reset, because none of those things can be changed. The rest of this guide assumes the second case, which is what most healthcare, benefits and payroll breach letters describe.

2. Freeze your credit at all three bureaus — first, and free

This is the one step that actually blocks harm rather than reporting it afterwards. A security freeze stops anyone from opening a new account in your name, it is free by federal law, and it does not affect your credit score. You have to do it separately at Equifax, Experian and TransUnion — a freeze at one does not carry to the others. Keep the PIN each bureau gives you; you will need it to lift the freeze when you apply for credit yourself. If you have children whose data was in the same file, freeze theirs too — child identity theft usually goes unnoticed for years.

3. Enroll in the monitoring they offered, before the deadline

The letter comes with an enrollment code for complimentary credit and identity monitoring, typically for one to two years, and there is a cut-off date after which the code stops working. Enroll — it is free and it catches things you would not see on your own. Just be clear about the trade: monitoring notifies you after your file changes. The freeze in step 2 is what prevents the change. Note the deadline printed on your own letter rather than a date you read elsewhere; enrollment windows differ between senders in the same incident.

4. Expect the phishing that follows the letter

A notification wave is a gift to scammers: they know millions of people are now expecting official-looking mail and calls about their data. The follow-up contact tends to reference the breach by name, offer help enrolling, or promise settlement money — and it asks for the SSN or bank details the breach already exposed. Treat any inbound contact about the breach as unverified, hang up, and go to the company’s published breach page yourself. Our spam-call guide covers the filters worth turning on while the wave lasts.

5. Shrink the public half of your profile

The breached file is out of your hands. What is still in your hands is the data-broker and people-search layer — your current address, phone number, relatives and employment history, published and sold openly. That is the part that turns a leaked SSN into a convincing phone call, and unlike the breach, you can have it taken down. Start with our data-broker opt-out guide for the free route, site by site.

6. Set the watch, because this does not end in a month

Breached records get resold and recombined for years, and broker listings rebuild themselves within weeks of removal. Two habits matter after the initial cleanup: check your email against known breach databases periodically, and re-check the broker sites on a schedule instead of treating the opt-out as one-and-done. Also pull your free credit reports at annualcreditreport.com and read them — the freeze blocks new accounts, but it does not surface an account opened before you froze.

See what is still public about you

PersProtect finds where your details are listed across 499 broker and people-search sites, removes them, and keeps re-checking as listings come back. Start with a free scan.

Check my exposure — free →
Common questions

Breach letters, answered

Is the breach notification letter itself a scam?

Usually not — companies are required by state law to send these — but scammers do mail and email copycats during a big notification wave. A real letter describes what happened, names the specific categories of data involved, and gives you an enrollment code for monitoring. It will not ask for your Social Security number, your bank details or a payment. If anything in the letter asks you to “verify” personal data, look up the company’s breach page yourself instead of using the phone number or link printed on the notice.

Why did the letter come from my insurer or employer instead of the company that was breached?

Large breaches often hit a vendor that processes data for hundreds of other organizations — payment processors, claims administrators, benefits platforms. The vendor is where the intrusion happened; the notice goes out under the name of whoever you actually had the relationship with. That is why people receive letters about companies they have never heard of, and why one incident can generate letters from several different senders.

My Social Security number was exposed. Can I change it?

Only in narrow circumstances, and the Social Security Administration rarely approves it — you generally have to show you are already being harmed by ongoing misuse, and a new number does not erase the records tied to the old one. For almost everyone the practical answer is different: freeze your credit so the number cannot be used to open accounts, and assume it stays in circulation permanently.

Should I sign up for the free credit monitoring they offered?

Yes — it costs nothing and there is usually a deadline printed on the letter, after which you cannot enroll. But understand what it does: it tells you after something happens on your credit file. A credit freeze is what actually blocks a new account from being opened. Do the freeze first, then enroll.

I do not remember doing business with the company — do I still need to act?

Yes. The letter went to you because your records were in the affected files, whether or not you recognize the sender. The exposure is real regardless of how the data got there, and the steps are the same: freeze credit, enroll in the monitoring, watch for targeted phishing.

What about the emails about a class-action settlement?

Legitimate settlement notices come through the court-appointed administrator and are usually announced on the company’s own breach page. Scammers follow big breaches with fake “claim your compensation” emails that harvest exactly the data the breach exposed. Never file a claim from a link in an unsolicited email — find the official settlement site through the company or the court docket.

The exposed data is already out there. Is removing it from data brokers still worth it?

The breach file and the broker listings are two separate supplies. Breach data circulates in closed markets; broker and people-search profiles are what make you cheap and easy to find at scale — current address, phone, relatives, employer. Targeted phishing and identity fraud after a breach usually combine the two. You cannot recall the breached file, but you can shrink the public half.

You cannot recall the breach. You can shrink the rest.

See which sites are publishing your address, phone and relatives right now — free, in about a minute.

Run a free exposure scan →