Data Breach Response (What to Do When a Company Says Your Data Was Exposed)
What it is (1-liner)
A breach notice means your info may be in someone else's hands. You can limit damage fast with the right steps.
Red flags (top 5)
Email/letter saying your account or data was exposed.
Logins from unknown devices/locations; password-reset emails you didn't start.
New-account alerts or card charges you don't recognize.
Medical EOBs for care you didn't receive.
"Free monitoring" offer—but no mention of freezing your credit.
Do this now (60-second checklist)
Don't click links in the notice. Go directly to the company's site/app to verify. (Breach emails get phished, too.)
Change the password on the affected account and anywhere it was reused; turn on 2FA/passkeys.
If SSN/financial data was exposed: place credit freezes at Equifax/Experian/TransUnion (free).
Monitor/close cards; set alerts; dispute unfamiliar charges.
If you suspect misuse, start a plan at IdentityTheft.gov/databreach.
Report & support
IdentityTheft.gov: personalized recovery plan + reports/letters.
ReportFraud.ftc.gov: report scams or misuse tied to a breach.
Medical data involved? Review EOBs, correct records, and you can complain to HHS OCR if a provider won't give you records or privacy rights were violated.
Tax risk (SSN leaked): request IRS IP PINs for you/dependents to block fraudulent returns.
Tools you can use
- Have I Been Pwned — check if your email's in known breaches (use to inform which passwords to rotate).
Mental health & immediate safety
Breach stress is real. Breathe, follow the steps, and Call/Text 988 if anxiety spikes. You're not alone—this is fixable.
Scripts you can copy
To the company: "Please confirm exactly what data was exposed, the exposure window, and whether you'll cover free credit freezes instructions and monitoring for at least 12–24 months."
To your bank/card: "My data was in a breach. Please add alerts, reissue the card, and monitor for fraud."
To family/team: "Breach at [Company]. I've changed passwords, enabled 2FA, and frozen credit. Please do the same if you reused this password."
Lock down & recover
Passwords: move to a password manager; rotate breached/reused passwords; enable 2FA/passkeys everywhere.
Freezes: set/keep credit freezes; lift temporarily only when applying for credit.
Email hygiene: check for forwarding rules/filters added by attackers; remove unknown app access.
Special cases: phone-company breaches → add carrier account PIN; health breaches → scrutinize EOBs; tax → IP PINs.
Platform-specific steps
FTC "What to do after a data breach" quick guide + video.
IRS—data breach info for taxpayers (Form 14039, next steps).
Printable Quick Card (1-page content)
Don't click breach-email links.
Go to site/app → Change password + 2FA → Freeze credit (if SSN/financial) → Watch accounts → Start plan at IdentityTheft.gov/databreach.
FAQs
Is "credit monitoring" enough? Helpful, but freezes are stronger at stopping new-account fraud.
How long should I keep a freeze? As long as you like; lift briefly when you apply for credit. (Free by law.)
Should I use Have I Been Pwned? Yes—as a signal to rotate passwords and add 2FA, not as a panic button.
Last updated: Sept 28, 2025 • Reviewed by: ZoraSafe Safety Team

