Got a data breach notice? Here's exactly what to do
A letter or email arrives saying a company you use had a "data security incident" and your information "may have been involved." It's unsettling, and also extremely common. Here's what it actually means and what to do about it, based on the FTC's official guidance.
First, read the letter properly
These notices are usually vague on purpose, written by lawyers to limit liability, but they do contain the two things that matter most. Look for:
- What kind of information was exposed. A password is a very different problem from a Social Security number.
- What the company is offering. Many offer a year or more of free credit monitoring. If they do, sign up. It costs nothing and it's a genuine benefit.
If a password was exposed
- Change that password immediately, on the affected service's real website or app.
- Change it anywhere else you used the same password. This is the single most important step if you reuse passwords, because that's exactly what attackers try next.
- Turn on two-step verification for that account if you haven't already.
If your card or bank details were exposed
- Call your bank or card issuer using the number on the back of your card, not one from the letter.
- Ask them to reissue the card if they haven't already flagged it.
- Watch your statements for unfamiliar charges over the following months.
If your Social Security number or ID details were exposed
This is the more serious case, and the FTC has a specific, free process for it.
- Go to identitytheft.gov/databreach. Enter what kind of information was exposed and it gives you a personalised checklist.
- Get your free credit reports at annualcreditreport.com, the official site, and check for accounts you don't recognise. This is the only site authorised to provide the free reports guaranteed by law; sites that look similar but charge a fee are not it.
- Consider a credit freeze or fraud alert. Contact the credit bureaus to place one. A freeze makes it harder for anyone, including you, to open new credit in your name until you lift it. A fraud alert is lighter and lasts about a year.
- Take the company's free monitoring offer if one was included in the letter.
If you later find signs of identity theft
Unfamiliar accounts, a debt collector calling about something you didn't buy, or a tax return rejected because one was already filed in your name are all signs. If that happens, file a report at IdentityTheft.gov, which produces an official Identity Theft Report and a personal recovery plan.
Is this the company's fault?
Usually, yes, at least in part. That doesn't undo the exposure, but it's why many breach settlements include free monitoring or compensation. It's worth acting on the letter rather than ignoring it because it feels like spam.
Longer term
A breach notice is a good moment to check the habits that limit the damage of the next one, particularly unique passwords and two-step verification. See six habits that matter more than any antivirus.