What to do after a data breach

Seven steps, in the order that actually reduces the damage. Most of them are free, the first one takes a minute, and the one people skip is the only one that stops a new account being opened in your name.

ByNikita Silianov· Founder & CEO ·LinkedIn
Quick answer

Check which breaches your email appears in and what each one leaked. Change that password everywhere you reused it and turn on two-factor authentication. If a Social Security number or date of birth was involved, freeze your credit at all three bureaus — it is free and it is the step that blocks new accounts. Then assume phishing that quotes the breach is coming, watch the accounts that match the leaked data, and take your address and phone off data-broker sites.

1. Find out what was actually exposed

Every other decision depends on this. An email and a password is a bad afternoon; a Social Security number and a date of birth is a different problem, because you cannot reset either one. Read the notice you received and look for the list of data categories — it is always there, usually buried under the apology. If you have no notice and just saw the news, run your address through a free breach check to see which known breaches it appears in and what each one leaked.

2. Change the password — and every place you reused it

Attackers do not stop at the site they breached. They take the leaked email and password and try the pair against banks, email providers and shopping sites in bulk, which is why one old leak so often becomes a hijacked inbox. Change the password on the breached account first, then anywhere you used the same one or a near-identical version. If you are not sure which passwords of yours are already circulating, our password check tests one against known breach databases without ever sending it to us.

3. Turn on two-factor authentication where it counts

A stolen password is worth much less against an account that asks for a second factor. Do email first, then banking, then anything holding a saved card. An authenticator app or a hardware key beats SMS codes, which can be stolen through a SIM swap — and a leaked phone number makes a SIM swap easier to attempt. If SMS is the only option a site offers, it is still far better than nothing.

4. Freeze your credit if the SSN or date of birth leaked

This is the step people skip and the only one that blocks a new account being opened in your name. Freezing is free by federal law at Equifax, Experian and TransUnion, has no effect on your score, and takes a few minutes at each bureau. Freeze all three, keep the PINs somewhere you can find them, and lift the freeze temporarily when you apply for credit yourself. Parents: you can freeze a child’s file too, and for a child there is almost never a reason to leave it open.

5. Expect the phishing wave that follows the breach

The most expensive part of a breach is usually not the leak — it is the scam built on top of it weeks later. Someone calls claiming to be the fraud department, recites the real details that leaked to prove they are legitimate, and walks you into moving money or reading out a code. The rule that survives all of it: nobody who contacts you first gets verified information or a code, ever. Hang up, find the number yourself on your card or statement, and call back.

6. Check the accounts that match what leaked

Match the watching to the data. Payment details leaked: read your card statements line by line for a couple of months, small test charges included. Health or insurance records leaked: read the explanation-of-benefits notices for treatment you never had, because medical identity theft shows up there long before it shows up on your credit file. SSN leaked: pull your free reports at annualcreditreport.com and look for accounts you did not open. A freeze blocks new accounts but does not reveal one opened before you froze.

7. Remove the half of your profile that is still public

Breached files circulate in closed markets. Data brokers and people-search sites publish the rest of you openly — current address, phone number, relatives, employer, age — and sell it to anyone. Fraud after a breach almost always combines the two: leaked account details for credibility, broker data for reaching you and answering security questions. You cannot recall the breach, but that public half comes down. Start with our data-broker opt-out guide for the free, site-by-site route.

Start with step one

See which breaches your email turns up in, then which of the 499 broker and people-search sites are publishing your address and phone right now. Free, about a minute.

Check my exposure — free →

Got a breach notification letter? Check it is real first

Most letters are genuine — state law requires them — but big notification waves attract copycats by mail, email and text. A real notice describes what happened, names the specific categories of data involved and gives you an enrollment code. It never asks for your Social Security number, your bank details or a payment. Two more things that confuse people: the letter often arrives under the name of your insurer, employer or state agency rather than the company that was actually breached, because the intrusion happened at a vendor that processes data for hundreds of organizations; and there is usually an enrollment deadline printed on it. If anything in the notice asks you to verify personal data, look the company up yourself instead of using the number or link printed on the page.

Full guide: what to do when the letter says your SSN was exposed →

Breach settlements: what a payout actually covers

Large breaches routinely end in class-action settlements, and 2026 has been a busy year for filings — the notification waves rolling out of several big vendor incidents have been followed by lawsuits within weeks, as reported in the legal and security press. If you are covered by one, expect a claim form offering some mix of three things: reimbursement for documented losses, a flat payment for time spent dealing with the fallout, and a couple of years of credit monitoring. Deadlines are strict, payouts are usually modest by the time the fund is divided, and the money lands a year or more after you file.

Worth filing. Just be clear about what it is not: a settlement compensates you for a leak, it does not delete anything. Your records stay in circulation afterwards exactly as they were, which is why the removal work in step seven is the part that changes your actual exposure. And treat unsolicited “claim your compensation” emails as hostile — fake settlement pages are a standard follow-up scam, harvesting precisely the details the breach exposed. Real notices come from the court-appointed administrator, and the official claim site is linked from the company’s own breach page.

General information, not legal advice. Terms differ from one settlement to the next — read the notice.

Common questions

After a breach, answered

How long after a breach am I actually at risk?

Years, not weeks. A stolen file gets copied, resold and merged with older leaks for as long as anyone is willing to pay for it, which is why people get hit with a convincing phishing call about a breach that happened four years earlier. The urgent window is the first few days — passwords and credit freeze — but the monitoring habit is permanent.

Do I need to change every password I have?

No. Change the password on the breached account, then every other account where you used that same password or a small variation of it. That reuse chain is what turns one leaked login into five hijacked accounts. If you cannot remember where you reused it, start with email, banking and anything with a saved card, because those are what an attacker goes for first.

Is a credit freeze the same as credit monitoring?

No, and the difference matters. Monitoring tells you after someone has already used your details. A freeze stops a new account from being opened in your name in the first place. Freezing is free at all three bureaus, does not affect your credit score, and you can lift it temporarily when you actually apply for something.

The company offered free credit monitoring. Should I take it?

Take it — it costs nothing and there is usually an enrollment deadline. Just do not treat it as the fix. Enroll, then freeze your credit anyway, because the monitoring is a smoke alarm and the freeze is the locked door.

What is a data breach settlement, and will I get money?

When a breach leads to a class action, it often ends in a settlement fund that pays claimants for documented losses and lost time, plus a period of monitoring. Realistic payouts are usually modest, claims take a year or more to pay out, and you have to file before the deadline. Legitimate notices come through the court-appointed administrator, not from an email urging you to claim compensation right now.

I did not lose any money. Is there still anything to do?

Yes, because most breach damage is delayed. The data sits in circulation until someone builds a scam around it — a fake fraud-department call that recites your real account details, or a loan opened with your SSN a year later. The steps in this guide cost nothing except the removal work, and they are what stops the delayed version.

Can I get my information deleted after it has leaked?

Not from the breach file itself. Once records are traded on forums there is no recall and anyone promising to delete them is selling you something that does not exist. What can be removed is the other half of your profile — the address, phone, relatives and employment history that data brokers and people-search sites publish. That is the part scammers combine with the breach to sound convincing, and it is genuinely removable.

The breach is done. Your exposure is not.

See which sites are publishing your address, phone and relatives right now — free, in about a minute.

Run a free exposure scan →