Something's wrong right now

Got a data breach notice? Here's exactly what to do

A letter or email arrives saying a company you use had a "data security incident" and your information "may have been involved." It's unsettling, and also extremely common. Here's what it actually means and what to do about it, based on the FTC's official guidance.

First, read the letter properly

These notices are usually vague on purpose, written by lawyers to limit liability, but they do contain the two things that matter most. Look for:

If a password was exposed

  1. Change that password immediately, on the affected service's real website or app.
  2. Change it anywhere else you used the same password. This is the single most important step if you reuse passwords, because that's exactly what attackers try next.
  3. Turn on two-step verification for that account if you haven't already.

If your card or bank details were exposed

  1. Call your bank or card issuer using the number on the back of your card, not one from the letter.
  2. Ask them to reissue the card if they haven't already flagged it.
  3. Watch your statements for unfamiliar charges over the following months.

If your Social Security number or ID details were exposed

This is the more serious case, and the FTC has a specific, free process for it.

  1. Go to identitytheft.gov/databreach. Enter what kind of information was exposed and it gives you a personalised checklist.
  2. Get your free credit reports at annualcreditreport.com, the official site, and check for accounts you don't recognise. This is the only site authorised to provide the free reports guaranteed by law; sites that look similar but charge a fee are not it.
  3. Consider a credit freeze or fraud alert. Contact the credit bureaus to place one. A freeze makes it harder for anyone, including you, to open new credit in your name until you lift it. A fraud alert is lighter and lasts about a year.
  4. Take the company's free monitoring offer if one was included in the letter.

If you later find signs of identity theft

Unfamiliar accounts, a debt collector calling about something you didn't buy, or a tax return rejected because one was already filed in your name are all signs. If that happens, file a report at IdentityTheft.gov, which produces an official Identity Theft Report and a personal recovery plan.

Watch for a follow-up scam. After a well-known breach, criminals send fake "we can protect you" emails pretending to be the affected company, trying to get you to click a link or pay for protection you already have for free. Go to the company's real website yourself to check on any offer, rather than clicking a link in an email.

Is this the company's fault?

Usually, yes, at least in part. That doesn't undo the exposure, but it's why many breach settlements include free monitoring or compensation. It's worth acting on the letter rather than ignoring it because it feels like spam.

Longer term

A breach notice is a good moment to check the habits that limit the damage of the next one, particularly unique passwords and two-step verification. See six habits that matter more than any antivirus.