← All posts

What to do when you get a data breach notification letter

An envelope or an email arrives from a company you have an account with, or one you barely remember, telling you that some of your personal information may have been exposed in a security incident. The wording is careful and a little vague. It might mention your name, email address, password, Social Security number, or card details, and it usually offers a year of free credit monitoring. If your first reaction is a small jolt of worry, that is understandable, but a breach letter is not the same as someone actually using your information. It is a heads-up, and it gives you a chance to close the doors before anyone tries them.

These notices are common now, and getting one does not mean you did anything wrong. The company holding your data is the one that was breached. What matters is what you do with the next hour, and it is less than you might expect.

First, make sure the letter itself is real

Scammers know that a breach notice is a moment when people are primed to click and act, so fake ones circulate too. A genuine notification will not ask you to confirm your password, pay a fee, or click a link to “secure” your account right now. If the letter pushes you toward urgency or asks for money or credentials, treat it as suspect. Rather than using any link or phone number in the message, go to the company’s website by typing the address yourself, or search for the breach by the company’s name to see whether it has been publicly reported. Only once you trust the source should you act on what it says.

Match your response to what was actually exposed

The right steps depend entirely on which pieces of information were involved, and the letter should spell this out. If only your email address and a password were exposed, the priority is changing that password everywhere you used it, and turning on two-factor authentication so a stolen password alone is not enough to get in. If a payment card or bank account number was part of the breach, contact your bank or card issuer, ask them to watch for or block suspicious activity, and consider having the card reissued. If your Social Security number was exposed, that is the one worth taking seriously, because it is the key to opening new accounts in your name.

For a plain, step-by-step version tailored to exactly what leaked, the FTC’s IdentityTheft.gov/databreach walks you through the specific follow-ups for each type of data, and the FTC’s identity theft pages cover recovery if something has already happened.

If your Social Security number was in it, freeze your credit

A credit freeze is the single most effective thing you can do after a Social Security number is exposed, and it is free. A freeze blocks new lenders from pulling your credit file, which stops most people from opening accounts, loans, or cards in your name. You place it separately with each of the three bureaus, and you can lift it just as easily whenever you need to apply for credit yourself. If you would rather not freeze, a fraud alert is a lighter alternative that asks lenders to verify your identity first. We walk through both, and how to clean up anything that slipped through, in our guide on what to do if someone opened accounts in your name. While you are at it, pull your free reports at annualcreditreport.com and look for anything you do not recognize.

Expect more phishing, and slow down for it

Once your details are floating around, the practical risk is not usually dramatic account theft, it is a rise in convincing scam messages. Criminals combine leaked data to make texts, emails, and calls look legitimate, sometimes citing a real password or the last digits of a card to earn your trust. A leaked phone number can also feed a SIM swap, where someone takes over your number to intercept security codes. None of this is a reason to panic, but it is a good reason to treat unexpected messages with an extra beat of doubt, and to never act on a link or a caller’s instructions without confirming through a channel you chose yourself.

Lock down the accounts that matter most

Your email account is worth protecting first, because it is the reset point for almost everything else. Give it a unique password and turn on two-factor authentication, and do the same for your bank, and for any social accounts tied to your identity. If you reuse passwords, a breach at one company quietly becomes a risk at all the others, and a password manager makes it painless to give each account its own. If an account has already been taken over, our post on what to do if your account was hacked covers getting back in and locking it down.

About that free credit monitoring

The monitoring service companies offer after a breach is worth accepting, since it is free and it flags new activity, but it is worth understanding what it does and does not do. Monitoring tells you after something has happened, it does not prevent it. A credit freeze is what actually stops new accounts from being opened. Think of the monitoring as a smoke detector and the freeze as the locked door, and lean on the freeze if a Social Security number was exposed.

A breach letter lands in a lot of mailboxes, and the vast majority never turn into real harm. Taking half an hour to change a reused password, switch on two-factor authentication, and freeze your credit if your Social Security number was involved puts you well ahead of anyone who might try to use what leaked. That is a calm, finished response, and it is enough.

— Gus