Home / Learn / Privacy / Data Breach Survival Guide
Data Breach Survival Guide: What to Do After Your Information Is Exposed
A practical timeline for verifying a breach, securing accounts, protecting credit, responding by data type, avoiding scams, and recovering from identity theft.
A data breach can turn an ordinary day into a confusing security problem. You may receive an email saying a company you used years ago was compromised. A bank may replace your card without warning. A healthcare provider may notify you that records were accessed. You may hear about a breach in the news before the company contacts you. Or you may notice suspicious activity first and only later learn that your information was exposed.
The most important thing is to respond based on what information was exposed, not merely on the fact that a breach occurred.
An exposed email address creates a different risk from an exposed Social Security number. A stolen password requires different action from a stolen payment card. Medical information, driver's license data, tax records, phone numbers, authentication secrets, and children's information each create different follow-on risks.
This FreeTempTools Learning Center guide provides a practical response framework for individuals. It explains what to do in the first 15 minutes, first hour, first day, first week, and following months; how to verify a breach notice; how to secure accounts; when to consider a credit freeze or fraud alert; how to respond to exposure of specific data types; how to recognize scams that follow a breach; and when identity-theft recovery becomes necessary.
This guide is educational and is written primarily for U.S. consumers where it discusses FTC, IdentityTheft.gov, credit bureaus, and U.S. identity-theft procedures. People in other countries should use the equivalent consumer-protection, financial, data-protection, and identity-recovery resources in their jurisdiction.
Quick Answer: What Should You Do After a Data Breach?
If you receive a legitimate breach notice:
- Verify the notice through the company's official website or another trusted channel.
- Determine exactly what information was exposed.
- Change the affected password if login credentials were involved.
- Change any other account that reused the same password.
- Turn on or review multi-factor authentication.
- Check your email and account recovery settings.
- Monitor bank, card, payment, and account activity.
- If sensitive identity information such as a Social Security number was exposed, review your credit reports and consider a credit freeze.
- Use legitimate monitoring services offered by the breached company when appropriate.
- Watch for phishing and impersonation attempts that use details from the breach.
- If someone actually uses your information, report identity theft at IdentityTheft.gov and follow the personalized recovery plan.
- Save the breach notice and keep records of every action you take.
Do not panic, but do not ignore the notice.
Key Takeaways
- A data breach is an exposure event; identity theft is misuse of information.
- Your response should match the data that was exposed.
- Password exposure requires immediate credential changes.
- Social Security number exposure deserves stronger identity and credit protections.
- Payment-card exposure requires issuer notification and transaction monitoring.
- Email and phone exposure commonly lead to phishing, impersonation, and account-recovery attacks.
- Medical and insurance information can create risks that do not appear on a credit report.
- A credit freeze can make it harder for someone to open new credit in your name.
- A fraud alert tells lenders to verify your identity but does not block access to the report.
- A freeze and fraud alert do not stop misuse of existing accounts.
- Breach notices themselves can be imitated by scammers.
- Post-breach phishing may be more convincing because attackers know real details about you.
- IdentityTheft.gov provides a U.S. reporting and recovery workflow if information is actually misused.
- Good records make disputes and recovery easier.
- Temporary privacy tools can reduce future exposure in appropriate low-risk situations, but they do not repair a compromised identity.
What Is a Data Breach?
A data breach occurs when information is accessed, disclosed, copied, stolen, or otherwise exposed without authorization.
Breaches may involve:
- Customer databases
- Employee records
- Healthcare systems
- Financial institutions
- Retailers
- Schools
- Government agencies
- Cloud storage
- Software providers
- Third-party vendors
- Mobile applications
- Email systems
- Backup systems
- Physical records
A breach may result from:
- Hacking
- Credential theft
- Malware
- Ransomware
- Phishing
- Insider misuse
- Lost devices
- Misconfigured cloud storage
- Accidental disclosure
- Third-party compromise
- Physical theft
- Software vulnerabilities
A breach does not automatically mean every exposed record will be misused. But the exposed information may remain useful to criminals for years.
Breach vs Leak vs Identity Theft
| Event | What happened | Immediate focus |
|---|---|---|
| Data breach | Unauthorized access or disclosure | Determine exposed information and reduce risk |
| Data leak | Information becomes accessible through error or poor configuration | Remove exposure and assess who could access it |
| Credential compromise | Password, token, session, or key is exposed | Revoke and replace credentials |
| Account takeover | Someone controls an existing account | Recover account and investigate connected services |
| Identity theft | Personal information is used without permission | Stop fraud, report, dispute, and recover |
| Payment fraud | Unauthorized transaction occurs | Contact financial provider and protect account |
These events can overlap. One breach may lead to several later incidents.
The Breach Response Timeline
A timeline prevents you from trying to solve everything at once.
First 15 Minutes: Stop and Verify
1. Do Not Click the Breach Email Yet
If the notice arrived by email or text, do not immediately click its links.
A real breach can trigger fake breach notices from scammers.
Instead:
- Open the company's official app.
- Type the company's known website address.
- Check its security or incident page.
- Search for an official notice through a trusted source.
- Call a known number from a statement, card, or official website.
2. Save the Notice
Keep:
- Letter
- Screenshot
- Date received
- Company name
- Incident date
- Information reportedly exposed
- Services offered
- Contact information
Do not delete the original notice after taking action.
3. Identify Whether Immediate Account Access Is at Risk
Urgent signs include:
- Password exposed
- Session token exposed
- Email account compromised
- Payment account compromised
- Unauthorized login
- Changed recovery information
- Unexpected MFA prompts
If credentials are involved, move directly to account security.
First Hour: Secure the Accounts That Can Spread the Damage
1. Change the Affected Password
Use a trusted device.
Create a completely new password.
Do not make a minor variation of the old password.
2. Change Reused Passwords
If the breached password was reused, treat every reused instance as compromised.
Start with:
- Primary email
- Password manager
- Banking
- Payment accounts
- Cloud storage
- Social media
- Shopping
- Work systems
- Domain or hosting accounts
3. Review Multi-Factor Authentication
Turn on MFA where available.
Prefer phishing-resistant methods such as passkeys or hardware security keys when supported.
4. Revoke Sessions
Changing a password may not terminate every existing session.
Review:
- Signed-in devices
- Active sessions
- API tokens
- App passwords
- Browser sessions
- Connected apps
Sign out anything unfamiliar.
5. Secure the Primary Email Account
Your email may recover other services.
Review:
- Password
- MFA
- Recovery email
- Recovery phone
- Forwarding rules
- Filters
- Delegated access
- Connected applications
- Recent login activity
An attacker who controls email may intercept reset messages and security alerts.
First 24 Hours: Match the Response to the Exposed Data
Create a simple incident sheet.
| Data exposed | Your action |
|---|---|
| Email address | Expect targeted phishing and review account security |
| Password | Replace it everywhere it was reused |
| Phone number | Protect carrier account and expect smishing or impersonation |
| Payment card | Contact issuer and monitor transactions |
| Bank account | Contact bank and monitor transfers |
| Social Security number | Review credit reports and strongly consider a credit freeze |
| Driver's license | Monitor identity activity and follow state replacement guidance if advised |
| Passport | Follow official passport guidance if misuse or theft is suspected |
| Medical information | Review insurer and provider records |
| Tax information | Protect tax accounts and follow IRS guidance |
| Username/security questions | Change recovery questions and related identifiers |
| Authentication token/session | Revoke sessions and tokens |
| Child information | Consider child credit protections and monitor records |
Do not apply the same response to every breach.
First Week: Monitor, Document, and Close Gaps
During the first week:
- Review credit reports when identity information was exposed.
- Consider or place credit freezes.
- Place a fraud alert if appropriate.
- Review financial activity.
- Review medical or insurance records if relevant.
- Review tax accounts if relevant.
- Accept legitimate monitoring if useful.
- Save confirmation numbers.
- Document calls.
- Remove vulnerable recovery methods.
- Update old passwords.
- Watch for post-breach phishing.
- Review family accounts that share contact information.
- Review work accounts if the breach affects business credentials.
The first week is also a good time to remove old accounts you no longer need.
First Month and Beyond: Long-Term Monitoring
Some stolen information does not expire.
Continue monitoring:
- Credit
- Bank accounts
- Payment cards
- Tax notices
- Medical claims
- Insurance benefits
- Email security
- Mobile carrier
- Social accounts
- Government benefits
- Child identity records when relevant
Recheck privacy settings and breach-related protections periodically.
Step 1: Verify That the Breach Is Real
A convincing fake notice may:
- Claim your Social Security number was leaked.
- Offer fake credit monitoring.
- Ask you to "confirm" a password.
- Ask for payment.
- Request remote access.
- Send you to a fake login page.
- Ask for an authentication code.
- Attach malware.
Verification Checklist
- [ ] Is the company one you actually used?
- [ ] Does the official website mention the incident?
- [ ] Does the notice match official dates and details?
- [ ] Does the sender domain exactly match the company?
- [ ] Does the company request information it should already know?
- [ ] Is there pressure to act through one specific link?
- [ ] Is payment demanded?
- [ ] Does the offer require a password or authentication code?
Even a real incident can be exploited by unrelated scammers.
Step 2: Determine Exactly What Was Exposed
The breach notice should explain the categories of information involved.
Create an exposure inventory.
Low-to-Moderate Sensitivity
- Username
- Public profile
- General demographic information
- Marketing preferences
Higher Sensitivity
- Passwords
- Security questions
- Phone number
- Date of birth
- Address
- Account numbers
- Customer IDs
High Sensitivity
- Social Security number
- Taxpayer ID
- Driver's license
- Passport
- Bank account
- Payment-card data
- Medical records
- Health-insurance information
- Authentication tokens
- Biometric information
Sensitivity also depends on combinations. Name + birth date + address + phone + Social Security number is more dangerous than any one item alone.
What to Do if Your Email Address Was Exposed
An exposed email address often leads to more spam and phishing.
Actions
- Review your email security.
- Use a unique password.
- Enable MFA.
- Watch for password-reset attempts.
- Review forwarding rules.
- Review filters.
- Review recovery settings.
- Watch for targeted scams referencing the breached company.
- Avoid clicking breach-related links in unsolicited messages.
If the email itself was not compromised, changing the email address may not be necessary.
For future disposable sign-ups, consider using Temp Mail when the account is low risk and future recovery is unnecessary.
Related guides:
What to Do if Your Password Was Exposed
Treat a known exposed password as unusable.
Immediate Response
- Change it at the breached service.
- Change it anywhere else it was reused.
- Review active sessions.
- Enable MFA.
- Review recovery settings.
- Review recent activity.
Do Not
- Add a number to the old password.
- Reuse an older password.
- Use the same replacement everywhere.
- Store the replacement in an unsecured note.
If a password manager reports that a saved credential was compromised, replace it promptly.
What to Do if Your Phone Number Was Exposed
A phone number can support:
- Smishing
- Voice phishing
- SIM swapping
- Account recovery
- Impersonation
- Data matching
Actions
- Protect the carrier account with a unique password.
- Add or review a carrier PIN.
- Enable number-lock or port-out protection where available.
- Be suspicious of requests for authentication codes.
- Review accounts that depend on SMS recovery.
- Prefer stronger MFA methods when available.
- Investigate unexpected loss of cellular service.
FreeTempTools temporary phone numbers are still listed as coming soon in the current site snapshot and should not be linked until they appear in a future sitemap.
What to Do if Payment-Card Information Was Exposed
Contact the card issuer through an official number.
Ask whether the card should be:
- Locked
- Replaced
- Monitored
- Reissued with a new number
Review transactions.
Enable alerts.
Dispute unauthorized charges promptly.
A replacement card does not fix other identity information that may have been exposed in the same incident.
What to Do if Bank Account Information Was Exposed
Bank account and routing information can create risks involving unauthorized debits or fraudulent checks.
Contact the bank.
Discuss:
- Account monitoring
- New account number
- ACH protections
- Check controls
- Transfer alerts
- Fraud procedures
Review:
- Transfers
- Withdrawals
- New recipients
- Check images
- Address changes
- Linked accounts
Preserve documentation.
What to Do if Your Social Security Number Was Exposed
This deserves a stronger response because the number can be used in new-account, tax, employment, benefits, and other identity fraud.
Consider These Steps
- Review credit reports.
- Freeze credit at all three nationwide credit bureaus.
- Consider a fraud alert.
- Monitor financial activity.
- Watch for tax and benefits notices.
- Protect your primary email.
- Strengthen MFA.
- Save the breach notice.
- Use IdentityTheft.gov if misuse occurs.
FTC guidance describes a credit freeze as free to place and lift and useful for making new-credit fraud more difficult.
A freeze does not prevent every type of identity theft, so monitoring still matters.
Credit Freeze vs Fraud Alert After a Breach
| Feature | Credit Freeze | Fraud Alert |
|---|---|---|
| Main purpose | Restricts access to credit report | Tells lenders to verify identity |
| Cost | Free | Free |
| Where to place | Each of the three bureaus | One bureau; it notifies the others |
| Duration | Until lifted | Initial alert: one year |
| Stops existing-account fraud | No | No |
| Affects credit score | No | No |
| Must be lifted for new credit | Usually | No |
Credit Freeze
A freeze is a strong preventive measure against new credit accounts.
Fraud Alert
An initial fraud alert adds a verification requirement but does not block access to the report.
Identity-theft victims may qualify for an extended fraud alert.
What to Do if Driver's License Information Was Exposed
Driver's license information may be used for identity verification.
Actions may include:
- Monitor accounts.
- Save the breach notice.
- Review credit.
- Follow the issuing state's guidance.
- Replace the license if the issuing authority advises it.
- Report actual misuse.
Do not assume a replacement license automatically changes every identifier.
What to Do if Passport Information Was Exposed
Passport exposure may require:
- Monitoring for identity misuse.
- Contacting the appropriate passport authority.
- Reporting a lost or stolen passport if the physical document is missing.
- Following official replacement instructions.
- Protecting copies.
Do not post passport images online.
What to Do if Medical Information Was Exposed
Medical data can involve:
- Diagnoses
- Prescriptions
- Insurance IDs
- Provider records
- Claims
- Billing
- Contact details
Actions
- Review explanation-of-benefits statements.
- Review patient portals.
- Review claims.
- Review prescription history.
- Contact provider privacy or fraud teams.
- Contact insurer.
- Correct inaccurate medical information.
- Dispute fraudulent bills.
Medical identity theft may not appear on a credit report.
Keep the next breach away from your real inbox
You cannot undo a breach, but you can shrink the next one. Use a disposable address for sign-ups that do not need your permanent identity.
Open Temp Mail →What to Do if Health Insurance Information Was Exposed
Protect:
- Member IDs
- Claims
- Dependents
- Provider records
- Benefits
Watch for unfamiliar:
- Claims
- Providers
- Procedures
- Prescriptions
- Bills
Contact the insurer using an official number.
What to Do if Tax Information Was Exposed
Tax data can include:
- Social Security numbers
- Employer data
- Income
- Filing status
- Refund details
- Bank information
Protect tax accounts.
Use official IRS resources.
Consider an IRS Identity Protection PIN if appropriate.
Watch for:
- Unknown returns
- Unknown employers
- Tax notices
- Refund problems
Do not use links in unexpected tax messages.
What to Do if Your Date of Birth and Address Were Exposed
These details are often treated as ordinary profile data, but they can help scammers:
- Answer identity-verification questions.
- Build convincing phishing.
- Search public records.
- Impersonate you.
- Combine data from other breaches.
Actions:
- Avoid using birth information in passwords.
- Change security questions that rely on public facts.
- Reduce public profile exposure.
- Watch for targeted scams.
What to Do if Security Questions Were Exposed
Change them.
Where permitted, treat answers like passwords:
- Random
- Unique
- Stored securely
- Not based on public facts
Do not reuse the same security-question answers across services.
What to Do if Authentication Tokens or Sessions Were Exposed
Tokens can sometimes allow access without a password.
Actions may include:
- Revoke all sessions.
- Sign out all devices.
- Rotate tokens.
- Revoke API keys.
- Change password.
- Review connected apps.
- Review account activity.
- Re-register MFA when appropriate.
This can be more urgent than a simple email exposure.
What to Do if Biometric Information Was Exposed
Biometric information may include:
- Fingerprints
- Facial templates
- Voiceprints
- Other measurements
Unlike a password, biometric traits may be difficult or impossible to change.
Follow the breached organization's guidance and applicable legal or regulatory resources.
Be especially cautious with future identity-verification requests.
What to Do if a Child's Information Was Exposed
Child identity data may be valuable because misuse can remain unnoticed.
Protect:
- Social Security number
- Birth certificate
- School records
- Medical information
- Account credentials
Parents or guardians may consider child credit freezes using the procedures provided by the credit bureaus.
Watch for:
- Credit offers
- Collection notices
- Benefit problems
- Tax notices
- Unexpected accounts
Keep the breach notice for future reference.
What to Do if Employee or Payroll Information Was Exposed
Workplace breaches may include:
- Social Security numbers
- Payroll
- Direct deposit
- Tax forms
- Home addresses
- Benefits
- Credentials
Actions:
- Secure work accounts.
- Secure personal email.
- Review bank activity.
- Watch for payroll-change scams.
- Verify direct-deposit changes.
- Review tax records.
- Follow employer incident instructions.
Do not provide payroll credentials through an unexpected message.
What to Do if Your Username Was Exposed
A username is usually lower risk than a password, but it helps attackers locate accounts.
If the username is an email address, expect phishing.
If it is reused publicly, consider whether it connects identities across platforms.
Changing a username is not always necessary. Focus first on password and MFA security.
What to Do if Your IP Address Was Exposed
An IP address can identify a public network endpoint and support approximate network/location information.
It is normally less sensitive than authentication credentials.
Use What Is My IP to see the current public IP address presented by your connection.
Changing an IP address does not repair a compromised account or remove data from a breach.
How to Use Credit Monitoring After a Breach
A breached company may offer:
- Credit monitoring
- Identity monitoring
- Dark-web monitoring
- Identity-restoration assistance
- Insurance
Before enrolling:
- Verify the offer through the official company site.
- Confirm the service is actually free.
- Read the enrollment deadline.
- Understand the coverage period.
- Review what data the monitoring service requires.
- Understand what alerts it provides.
Monitoring detects certain changes. It does not prevent every type of fraud.
A credit freeze can provide stronger prevention against new-credit fraud.
Should You Pay for Identity Monitoring?
Paid monitoring may offer convenience, alerts, restoration support, and insurance.
Ask:
- What is monitored?
- Which bureaus?
- How quickly are alerts sent?
- What restoration help is included?
- What insurance covers?
- What is excluded?
- Can you get similar alerts for free?
- Does it actually freeze credit or merely recommend it?
- How securely does the monitoring company handle your information?
Do not confuse monitoring with prevention.
Post-Breach Phishing: Why the Next Scam May Look Real
After a breach, scammers may know:
- Your name
- Phone
- Address
- Company used
- Account type
- Purchase history
- Last four digits
- Employer
- Insurance provider
This allows more convincing messages.
A scam may say:
"We noticed suspicious activity related to the breach. Confirm your account now."
The details may be real even when the message is fake.
Rule
Real personal information inside a message does not prove the sender is legitimate.
Breach Follow-On Scam Checklist
- [ ] Do not trust caller ID.
- [ ] Do not trust a display name.
- [ ] Do not share authentication codes.
- [ ] Do not install remote-access software.
- [ ] Do not send gift cards.
- [ ] Do not send cryptocurrency because a caller demands it.
- [ ] Do not move money to a "safe account."
- [ ] Verify requests independently.
- [ ] Use official websites and apps.
- [ ] Report suspicious messages.
How to Protect Your Primary Email After a Breach
Your primary email should receive special attention because it often controls recovery.
Review:
- Password
- MFA
- Recovery phone
- Recovery email
- Active sessions
- Forwarding rules
- Filters
- Delegated access
- Connected apps
Look for suspicious rules that:
- Forward messages.
- Delete security alerts.
- Hide bank emails.
- Mark messages as read.
- Archive reset messages.
An attacker may try to maintain access quietly.
How to Protect Your Phone Carrier Account
After a breach that includes phone or identity information:
- Use a unique carrier password.
- Add a PIN.
- Enable port-out protection.
- Review authorized users.
- Remove old contacts.
- Watch for loss of service.
Contact the carrier immediately if your phone suddenly loses service and you also see security alerts.
How to Protect Social Media Accounts
Breached email and password information may lead to social account takeover.
Actions:
- Replace reused passwords.
- Enable MFA.
- Review sessions.
- Review recovery methods.
- Review connected apps.
- Remove unknown administrators.
- Check messages and posts.
- Warn contacts if impersonation occurred.
How to Protect Cloud Storage
Cloud accounts may contain:
- Identity documents
- Tax files
- Photos
- Contracts
- Backups
- Medical records
After a credential breach:
- Change password.
- Enable MFA.
- Review sessions.
- Review shared links.
- Review connected apps.
- Review recent file activity.
- Remove unknown devices.
How to Protect Financial Accounts
Review:
- Login activity
- Transactions
- Transfers
- Linked accounts
- Beneficiaries
- Addresses
- Phone numbers
- Alerts
Contact the institution directly if anything changed.
How to Protect Shopping Accounts
Shopping accounts may store:
- Payment cards
- Addresses
- Order history
- Gift-card balances
- Loyalty points
Actions:
- Replace reused passwords.
- Review saved payment methods.
- Review orders.
- Review shipping addresses.
- Enable MFA when available.
- Remove old cards.
Use a stable email for purchases because future support and refunds may be necessary.
How to Protect Documents After a Breach
Sometimes breach recovery requires collecting notices, identity reports, letters, and statements.
FreeTempTools provides document utilities such as:
Use these tools only when the document is appropriate for the workflow.
Sensitive records may require an approved secure system.
Do not assume scanning, OCR, or signing removes sensitive metadata or makes a document private.
Temporary Sharing During Recovery
You may need to share non-regulated, short-lived information with a trusted person.
FreeTempTools includes:
Important limitations:
- Recipients can copy.
- Screenshots may be possible.
- Temporary access does not guarantee secrecy.
- Highly sensitive identity information belongs in an approved secure channel.
Do not use an unverified temporary tool to share Social Security numbers, complete financial records, medical records, recovery codes, or regulated business data.
Do You Need to Change Your Email Address?
Usually not solely because the address appeared in a breach.
Consider changing or retiring an email address if:
- The email account itself is compromised.
- Spam and targeted scams become unmanageable.
- The address is tied to extensive public exposure.
- It is no longer appropriate for important accounts.
A better strategy is often to protect the permanent address and reduce future exposure.
Use temporary email for appropriate disposable activity.
Do You Need to Change Your Phone Number?
Not automatically.
A number change creates disruption and does not remove old data.
Prioritize:
- Carrier security
- Account recovery review
- Scam awareness
- Strong MFA
- Port protections
Change the number when the carrier, law enforcement, safety professional, or your circumstances justify it.
Do You Need to Replace Your Driver's License?
Follow official state guidance.
Exposure of license data does not always mean a new physical license is necessary.
If the license itself is lost or stolen, or misuse is documented, the issuing agency may recommend replacement.
Do You Need to Replace Your Passport?
Follow official passport authority guidance.
If the physical passport is lost or stolen, use the official reporting process.
If only data was exposed, the correct response depends on the circumstances.
Data Breach Recovery for Families
A household may share:
- Addresses
- Phone plans
- Cloud storage
- Password recovery
- Insurance
- Devices
- Payment accounts
When one member is affected:
- Check shared accounts.
- Review family recovery methods.
- Warn household members about phishing.
- Create a verification phrase.
- Protect children.
- Monitor shared financial services.
Do not assume only the named recipient is at risk.
Data Breach Recovery for Children
Keep records of a child-related breach.
Consider:
- Credit freeze procedures.
- School record monitoring.
- Healthcare records.
- Benefits.
- Tax notices.
- Collection mail.
Children may not discover misuse for years.
Data Breach Recovery for Older Adults
Older adults may be targeted with:
- Tech-support scams
- Government impersonation
- Investment scams
- Medical scams
- Family-emergency scams
Useful protections include:
- Trusted contacts
- Account alerts
- Credit freeze
- MFA
- Independent verification
Support should preserve independence while reducing scam risk.
Data Breach Response for Small Businesses
A business data breach requires legal, technical, operational, and communications decisions beyond a consumer response.
Organizations should:
- Activate incident-response plans.
- Preserve evidence.
- Contain access.
- Determine affected data.
- Involve security, legal, privacy, insurance, and leadership teams.
- Review notification obligations.
- Coordinate with vendors.
- Restore safely.
- Document decisions.
- Monitor recurrence.
NIST SP 1800-29 provides technical guidance for organizations on detecting, responding to, and recovering from data-confidentiality attacks.
FreeTempTools consumer guides should not be used as a substitute for professional incident response or legal advice.
What to Document After a Breach
Keep an incident log.
Breach Details
- Company
- Date discovered
- Date notice received
- Incident period
- Data exposed
- Notice method
Actions Taken
- Password changed
- Sessions revoked
- MFA reviewed
- Credit frozen
- Fraud alert placed
- Bank contacted
- Card replaced
- Monitoring activated
- IdentityTheft.gov report created
Contacts
- Company
- Bank
- Credit bureau
- Insurer
- Healthcare provider
- Tax agency
- Law enforcement
- Employer
Records
- Case numbers
- Confirmation numbers
- Letters
- Emails
- Screenshots
- Reports
Documentation becomes extremely valuable if problems appear later.
Data Breach Incident Worksheet
Use this as a printable working sheet.
Incident
- Company: ____________________
- Date notice received: ____________________
- Incident date or period: ____________________
- Official incident URL: ____________________
Exposed Information
- [ ] Password
- [ ] Phone
- [ ] Address
- [ ] Date of birth
- [ ] Payment card
- [ ] Bank account
- [ ] Social Security number
- [ ] Driver's license
- [ ] Passport
- [ ] Medical information
- [ ] Tax information
- [ ] Authentication token
- [ ] Other: ____________________
Immediate Actions
- [ ] Verified notice
- [ ] Changed password
- [ ] Changed reused passwords
- [ ] Enabled MFA
- [ ] Revoked sessions
- [ ] Reviewed email security
- [ ] Contacted bank/card issuer
- [ ] Reviewed credit
- [ ] Froze credit
- [ ] Placed fraud alert
- [ ] Enrolled in legitimate monitoring
Follow-Up
- [ ] Reviewed statements
- [ ] Watched for phishing
- [ ] Reviewed medical records
- [ ] Reviewed tax notices
- [ ] Saved documentation
- [ ] Reported identity theft if misuse occurred
Decision Tree: What Was Exposed?
Only Email or Username?
Secure the account and expect phishing.
Password?
Replace it and every reused copy immediately.
Phone?
Secure carrier account and watch for SIM-swap and smishing attempts.
Card?
Contact issuer and monitor transactions.
Bank Account?
Contact bank and review transfer/debit protections.
Social Security Number?
Review credit and strongly consider a freeze.
Medical Information?
Review provider and insurance records.
Tax Information?
Protect tax accounts and follow official tax guidance.
Authentication Token?
Revoke sessions and credentials immediately.
Actual Fraud Already Happened?
Move from breach prevention to identity-theft recovery at IdentityTheft.gov.
When to Use IdentityTheft.gov
Use IdentityTheft.gov if someone actually uses your personal information without permission.
Examples:
- New account
- Purchase
- Loan
- Job
- Tax filing
- Government benefits
- Medical services
- Fraudulent debt
The site creates a personalized recovery plan and FTC Identity Theft Report.
It also provides guidance for information that was lost or exposed even when misuse is not yet known.
When to Contact Law Enforcement
A police report may be useful when:
- Required by a company.
- Physical theft occurred.
- Criminal impersonation occurred.
- You know the identity of a suspect.
- Local law requires reporting.
- A legal or recovery professional recommends it.
IdentityTheft.gov can explain when a police report may support recovery.
When to Contact an Attorney
Consider legal advice when:
- Loss is substantial.
- A business dispute is unresolved.
- Criminal records are affected.
- Employment is affected.
- Housing is affected.
- Medical records create harm.
- A breach involves regulated business data.
- Class-action or individual rights are unclear.
- You need jurisdiction-specific advice.
This guide is not legal advice.
When to Contact a Cybersecurity Professional
Professional assistance may be appropriate when:
- Email remains compromised.
- Malware is suspected.
- Multiple devices are affected.
- Business systems are involved.
- Administrator accounts are compromised.
- Sensitive files were exfiltrated.
- Sessions keep reappearing.
- Domain, hosting, or cloud accounts are taken over.
Common Mistakes After a Data Breach
Mistake 1: Clicking the First Breach Email
Verify independently.
Mistake 2: Changing Only One Reused Password
Every reused copy is exposed.
Mistake 3: Ignoring Email Security
Email controls recovery.
Mistake 4: Paying for a Freeze
Credit freezes are free.
Mistake 5: Believing Monitoring Prevents Fraud
Monitoring detects certain activity; it is not a universal prevention system.
Mistake 6: Assuming a New Card Fixes Everything
The breach may contain other identity information.
Mistake 7: Using Temporary Email for Important Recovery
Disposable contact information can create permanent account loss.
Mistake 8: Trusting a Caller Who Knows Personal Details
Those details may come from the breach.
Mistake 9: Throwing Away the Notice
Keep it.
Mistake 10: Waiting for Fraud Before Taking Basic Precautions
A breach is an opportunity to reduce risk before misuse happens.
The FreeTempTools Data Breach Toolkit
FreeTempTools does not replace financial institutions, credit bureaus, IdentityTheft.gov, law enforcement, legal professionals, or cybersecurity incident responders.
It can support certain practical tasks.
| Need | Verified FreeTempTools resource | Limitation |
|---|---|---|
| Reduce future primary-email exposure | Temp Mail | Not for critical recovery |
| View current public IP | What Is My IP | IP is only one privacy signal |
| Digitize a paper notice | Document Scanner | Protect sensitive files |
| Extract text from a notice image | Image to Text | Verify OCR accuracy |
| Sign a PDF | Sign PDF | Verify legal requirements |
| Share short-lived non-sensitive note | Self-Destructing Notes | Recipient can preserve it |
| Share temporary text/code | Temporary Pastebin | Avoid regulated or highly sensitive data |
| Transfer a file | P2P File Transfer | Verify recipient and security needs |
| Create fictional test information | Fake Name Generator | Testing only; no impersonation or fraud |
| Compress an image | Image Compressor | Does not remove all metadata |
| Remove an image background | Background Remover | Not a complete privacy cleanup |
| Create a QR code | QR Code Generator | Verify destination before sharing |
Long-Term Protection After a Breach
A breach is a good moment to improve your security system.
Account Separation
Use:
- Protected primary email for critical services.
- Secondary email or aliases for routine accounts.
- Temporary email for appropriate disposable interactions.
Password Separation
Use a password manager and unique passwords.
Authentication
Enable MFA.
Credit
Freeze credit when appropriate.
Monitoring
Use:
- Bank alerts
- Card alerts
- Credit review
- Healthcare review
- Tax notices
- Identity alerts
Data Minimization
Share less optional information.
Device Security
Update software and protect devices.
30-Day Breach Recovery Plan
Day 1
- Verify breach.
- Secure credentials.
- Review MFA.
- Determine exposed data.
- Contact financial providers if needed.
Days 2–3
- Review credit.
- Freeze if appropriate.
- Enroll in legitimate monitoring.
- Review email and carrier security.
Days 4–7
- Review financial statements.
- Review healthcare or tax records if relevant.
- Remove old accounts and sessions.
- Document actions.
Week 2
- Review public exposure.
- Replace weak security questions.
- Audit password reuse.
- Review family accounts.
Weeks 3–4
- Recheck alerts.
- Review credit.
- Confirm disputes.
- Update incident log.
- Continue phishing vigilance.
Your email is the account that spreads the damage
Every reset link lands there. Keep it private and stop handing it to sites that only need to send you one message.
Get a temporary inbox →90-Day Monitoring Plan
For the next three months:
- Review financial activity weekly.
- Review security alerts.
- Watch for phishing.
- Review credit periodically.
- Follow up on disputes.
- Review medical or tax records when relevant.
- Keep freezes in place as appropriate.
- Preserve documentation.
Some risks last longer than 90 days, especially when permanent identifiers were exposed.
One-Year Breach Review
At the anniversary:
- Review credit.
- Review whether monitoring expired.
- Keep or reconsider freezes.
- Review security improvements.
- Check for unresolved disputes.
- Review public exposure.
- Update important account recovery.
Do not assume the risk ends when a monitoring subscription expires.
Breach Severity Matrix: How Urgent Is Your Situation?
Not every breach deserves the same level of response.
Use this matrix to prioritize.
| Exposure | Typical urgency | Main risk | First response |
|---|---|---|---|
| Email address only | Moderate | Phishing and spam | Secure email and watch for scams |
| Username only | Low to moderate | Account discovery | Protect matching accounts |
| Password | High | Account takeover | Replace password and reused copies |
| Phone number | Moderate | Smishing, SIM-swap attempts | Secure carrier account |
| Payment card | High | Unauthorized charges | Contact issuer |
| Bank account | High | Unauthorized debits/transfers | Contact bank |
| Social Security number | High | New-account and identity fraud | Review credit and consider freeze |
| Driver's license | High | Identity verification misuse | Follow state guidance and monitor |
| Passport | High | Identity-document misuse | Follow passport authority guidance |
| Medical records | High | Medical identity theft and privacy harm | Review insurer/provider records |
| Tax records | High | Tax identity theft | Secure tax accounts and follow IRS guidance |
| Session token/API key | Critical | Immediate unauthorized access | Revoke immediately |
| Authentication seed/recovery codes | Critical | MFA bypass | Rotate recovery and MFA credentials |
| Biometric template | High and long-term | Non-replaceable identifier misuse | Follow breach-specific guidance |
A company may describe information as "encrypted," "hashed," "tokenized," or "masked." Those details can matter, but ordinary consumers often cannot independently determine how strong the protection was. Follow the company's incident explanation, then take reasonable actions based on the information category and whether usable credentials were exposed.
If Your Email Account Itself Was Breached
This is more serious than an email address appearing in a customer database.
If someone accessed the mailbox:
- Change the password from a trusted device.
- Revoke all active sessions.
- Review MFA.
- Review recovery email and phone.
- Remove unknown passkeys or security keys.
- Review forwarding rules.
- Review filters.
- Review delegated access.
- Review connected apps.
- Search sent mail for messages you did not send.
- Search deleted and archived folders for hidden alerts.
- Review password-reset messages from other accounts.
Then secure accounts that rely on that mailbox for recovery.
Start with:
- Password manager
- Bank
- Credit card
- Cloud storage
- Social networks
- Shopping accounts
- Government accounts
- Tax accounts
- Domain registrar
- Work accounts
Warn contacts if malicious messages were sent.
If Your Password Manager Was Involved in a Breach
A password-manager breach does not automatically mean every stored password was readable. The correct response depends on what the provider says was exposed and how the vault is protected.
Review the provider's official incident guidance.
Potential actions include:
- Change the master password if recommended.
- Strengthen the master password.
- Turn on MFA.
- Revoke active sessions.
- Rotate exposed API tokens.
- Review recovery settings.
- Replace particularly sensitive credentials.
- Prioritize accounts without MFA.
- Watch for phishing that imitates the password-manager provider.
Do not abandon unique passwords and return to password reuse. A good password manager remains one of the most practical ways to maintain unique credentials.
If a Bank or Financial Institution Was Breached
A financial breach may expose more than payment details.
Review whether the notice mentions:
- Account number
- Routing number
- Card number
- Online banking username
- Password
- Social Security number
- Address
- Transaction history
- Loan information
Contact the institution through its official app, website, or number on your card or statement.
Ask:
- Is my account number changing?
- Is my card being replaced?
- Are transfers restricted?
- Are additional alerts available?
- Was online banking access affected?
- Should I change credentials?
- Is monitoring being offered?
Continue reviewing transactions after the incident.
If a Healthcare Provider Was Breached
Healthcare breaches may expose highly detailed personal information.
Potentially exposed data can include:
- Name
- Date of birth
- Address
- Social Security number
- Insurance ID
- Diagnoses
- Procedures
- Prescriptions
- Provider information
- Billing
- Payment details
Review:
- Patient portal
- Explanation of benefits
- Claims
- Prescriptions
- Bills
- Insurance records
If unfamiliar medical information appears, contact both the provider and insurer.
Medical identity theft can create incorrect records, so correcting the medical record may be as important as disputing a bill.
If a School or University Was Breached
Education systems may hold:
- Student IDs
- Parent information
- Addresses
- Birth dates
- Social Security numbers
- Financial-aid data
- Grades
- Health records
- Login credentials
- Emergency contacts
Students and parents should:
- Change affected passwords.
- Review reused passwords.
- Secure school email.
- Review financial-aid records.
- Protect child identity information.
- Review linked payment systems.
- Watch for phishing pretending to be school administrators.
- Save the breach notice.
School accounts may expire after graduation, so long-term recovery should not depend exclusively on them.
If an Employer or Payroll Provider Was Breached
Employment systems can contain:
- Social Security numbers
- Home addresses
- Tax forms
- Direct-deposit information
- Benefits
- Insurance data
- Emergency contacts
- Payroll records
- Credentials
After a breach:
- Secure employee accounts.
- Review direct-deposit settings.
- Watch for fake HR or payroll messages.
- Verify requests to change bank information.
- Review tax records.
- Review benefits.
- Review credit when sensitive identity data was exposed.
Scammers may imitate HR because they know the employer's name.
If a Data Broker or People-Search Service Was Breached
Data brokers may already contain information collected from many sources.
A breach may combine:
- Name
- Addresses
- Phone numbers
- Relatives
- Age
- Property records
- Interests
- Purchase information
- Public records
This can make future phishing more personalized.
Actions:
- Reduce public contact exposure.
- Opt out from people-search services where practical.
- Review security questions based on public facts.
- Warn family members about impersonation.
- Strengthen primary accounts.
- Watch for targeted scams.
A data-broker breach may not expose a password but can still improve an attacker's ability to impersonate you.
If Biometric or Facial Data Was Exposed
Biometric information deserves special care because it may not be replaceable like a password.
Depending on the system, biometric data may be stored as templates rather than raw images, but consumers should not assume that makes the incident harmless.
Follow:
- The provider's incident instructions.
- Relevant government guidance.
- Applicable privacy rights.
- Identity-verification precautions.
If a service allows alternative authentication, consider reducing reliance on the affected biometric system until the incident is understood.
What "Dark Web Monitoring" Can and Cannot Tell You
A monitoring service may report that an email, phone number, password, or identity detail appears in criminal or leaked datasets.
A dark-web alert can be useful, but it does not prove:
- Who has the data.
- Whether it was used.
- Whether every listed password is current.
- Whether identity theft occurred.
Treat an alert as a reason to review the affected credentials and accounts.
If a password appears:
- Replace it.
- Replace reused copies.
- Review MFA.
- Review sessions.
If a Social Security number or identity record appears:
- Consider stronger identity and credit protections.
Do not pay a stranger who claims they can "delete your information from the dark web."
How to Prioritize When Multiple Breaches Happen
Many people receive several breach notices over time.
Prioritize based on:
- Usability of exposed information , a current password is more urgent than an old marketing preference.
- Permanence , Social Security numbers and birth dates cannot easily be replaced.
- Account value , banking and primary email deserve priority.
- Recovery role , accounts that recover others come first.
- Evidence of misuse , actual fraud moves the incident into recovery mode.
- Combination risk , multiple breaches may combine data into a detailed identity profile.
Create one master incident log rather than keeping breach information scattered across inboxes.
What Not to Do After a Breach
Do Not Pay Someone Who Contacts You Unexpectedly
Legitimate breach recovery does not require sending gift cards or cryptocurrency to a caller.
Do Not Move Money to a "Safe Account"
Scammers use this phrase.
Do Not Share Authentication Codes
A code may give the caller account access.
Do Not Download Remote-Access Software
Unless you independently contacted a trusted provider and understand why it is necessary.
Do Not Replace Every Account Randomly
Prioritize the accounts and data types that matter most.
Do Not Close Long-Standing Financial Accounts Without Advice
Closing accounts can create disruption. Discuss options with the institution.
Do Not Throw Away Evidence
Keep notices and correspondence.
Do Not Assume the Company Will Fix Everything
The company may offer monitoring, but you still control passwords, credit freezes, bank alerts, and recovery settings.
A Breach Notice Reading Checklist
When reading the notice, look for:
- [ ] Company name
- [ ] Incident date
- [ ] Discovery date
- [ ] Date the company contained the incident
- [ ] Types of information involved
- [ ] Whether passwords were exposed
- [ ] Whether Social Security numbers were exposed
- [ ] Whether financial data was exposed
- [ ] Whether health data was exposed
- [ ] What the company has changed
- [ ] What consumers are being asked to do
- [ ] Whether monitoring is offered
- [ ] Enrollment deadline
- [ ] Official contact information
- [ ] State or regulator information
- [ ] Whether law enforcement is involved
Do not assume the notice answers every question. Use the company's official support channels if clarification is needed.
A Password Replacement Priority Checklist
Replace passwords in this order when reuse is involved:
- Primary email
- Password manager
- Financial accounts
- Cloud storage
- Phone carrier
- Government and tax accounts
- Work and business administration
- Social media
- Shopping and payment accounts
- Lower-value services
If every account has a unique password already, the impact of one exposed credential is much easier to contain.
A Family Breach Communication Template
A simple family message can reduce scam risk:
A company we use reported a data breach. Please do not respond to unexpected calls, texts, or emails claiming to fix it. Do not share passwords or verification codes. If someone asks for money or personal information, contact me through the number you already have so we can verify it independently.
Use your own wording, but keep the rule simple.
A Small-Business Employee Breach Checklist
If employees receive a notice that a service used for work was breached:
- [ ] Notify the appropriate internal security or IT contact.
- [ ] Do not independently install tools offered in an unsolicited message.
- [ ] Change affected work credentials through official systems.
- [ ] Review reused personal passwords if reuse occurred.
- [ ] Report suspicious follow-on messages.
- [ ] Preserve the notice.
- [ ] Follow employer incident instructions.
- [ ] Verify vendor-payment or payroll-change requests independently.
A personal breach can become a business problem when work credentials were reused.
Breach Response by Persona
Student
Focus on school email, financial aid, identity records, and reused passwords.
Parent
Check whether children's information, insurance, school records, or family accounts were involved.
Freelancer
Review client accounts, payment platforms, cloud storage, email, and business credentials.
Small-Business Owner
Protect banking, payroll, domain registrar, hosting, email administration, vendors, and customer systems.
Older Adult
Strengthen account alerts and warn trusted contacts about post-breach impersonation scams.
Developer
Rotate exposed API keys, tokens, credentials, and secrets; review repositories and deployment systems.
Breach Recovery Metrics You Can Track
A personal incident log can track completion rather than relying on memory.
| Item | Status |
|---|---|
| Notice verified | Not started / Complete |
| Exposed data identified | Not started / Complete |
| Affected password changed | Not applicable / Complete |
| Reused passwords changed | Not applicable / Complete |
| MFA reviewed | Not started / Complete |
| Sessions revoked | Not applicable / Complete |
| Credit reviewed | Not applicable / Complete |
| Credit frozen | Not applicable / Complete |
| Bank contacted | Not applicable / Complete |
| Card replaced | Not applicable / Complete |
| Monitoring enrolled | Not applicable / Complete |
| IdentityTheft.gov report | Not applicable / Complete |
| Documentation saved | Not started / Complete |
This turns an emotional event into a manageable process.
Before You Mark the Breach "Resolved"
A breach response should not end simply because you changed a password or enrolled in monitoring.
Before closing your incident notes, confirm that:
- The breach notice has been saved.
- Every exposed credential has been replaced or revoked.
- Reused passwords have been eliminated.
- MFA is enabled on critical accounts.
- Email forwarding and recovery settings have been reviewed.
- Financial institutions were contacted when needed.
- Credit protections were considered when permanent identity information was exposed.
- Monitoring alerts are configured.
- Any disputed account, charge, claim, or record has a case number.
- Family members or coworkers who could be targeted by impersonation know what happened.
- Temporary protections have a reminder date for later review.
- You know when any free monitoring offer expires.
- You have recorded which company exposed which data.
Then schedule a follow-up review rather than assuming the incident is permanently over.
Recommended Follow-Up Dates
Seven days: confirm that immediate account and credit protections are in place.
Thirty days: review financial activity, security alerts, disputes, and monitoring enrollment.
Ninety days: recheck credit and follow up on unresolved identity, medical, tax, or benefits issues.
One year: review whether the incident created any lasting changes to your account-security or privacy strategy.
Permanent identifiers can remain useful long after the public attention around a breach has disappeared. A short written record of what was exposed and what you did can save substantial time if suspicious activity appears months or years later.
Frequently Asked Questions
What should I do first after a data breach?
Verify that the breach notice is legitimate, identify what information was exposed, and immediately secure any affected credentials or accounts.
Should I change my password after a breach?
Yes if the password or account credentials were exposed, and you should also change the password anywhere else it was reused.
Should I freeze my credit after a breach?
A freeze is especially worth considering when Social Security numbers or other information useful for new-credit fraud was exposed. Anyone can place a free credit freeze.
Is a credit freeze free?
Yes. FTC guidance states that credit freezes are free to place and lift.
Does a credit freeze hurt my credit score?
No.
What is the difference between a freeze and fraud alert?
A freeze limits access to your credit report. A fraud alert tells lenders to verify identity before opening new credit.
Should I accept free credit monitoring after a breach?
A legitimate free offer can be useful, but verify it through the company's official site and understand that monitoring does not prevent every type of fraud.
What if only my email address was exposed?
Secure the email account, enable MFA, and expect more targeted phishing. Changing the address is not always necessary.
What if my password was exposed?
Replace it immediately and replace every other account using the same password.
What if my Social Security number was exposed?
Review credit reports, strongly consider freezing credit, monitor identity-related accounts, save the breach notice, and use IdentityTheft.gov if misuse occurs.
What if my credit card was exposed?
Contact the issuer, discuss replacement or locking, enable alerts, and monitor transactions.
What if my medical information was exposed?
Review provider and insurer records, claims, prescriptions, and bills. Medical identity theft may not show on a credit report.
What if a child's information was exposed?
Keep the notice, protect identifying records, consider a child credit freeze, and monitor for unexpected accounts, collections, benefits, or tax activity.
Can scammers use real breach information?
Yes. Attackers may use real names, companies, addresses, or account details to make phishing more convincing.
Should I pay for identity monitoring?
Paid monitoring may offer convenience and recovery assistance, but compare what it provides with free protections such as freezes, alerts, financial notifications, and credit reports.
Does a VPN protect me after a data breach?
No. A VPN changes network routing and IP exposure but does not repair stolen credentials or identity information.
Can temporary email prevent data breaches?
No. Temporary email can reduce exposure of your permanent address in appropriate low-risk situations, but it cannot stop a company from being breached.
Should I change my phone number after a breach?
Not automatically. Secure the carrier account and recovery settings first. Change the number when circumstances justify the disruption.
How long should I monitor after a breach?
The appropriate period depends on the information exposed. Permanent identity information can remain useful to criminals for years, so ongoing monitoring may be appropriate.
When does a breach become identity theft?
When someone actually uses your personal or financial information without permission, such as opening an account, making a purchase, filing taxes, obtaining benefits, or using your identity for employment.
Final Recommendations
A data breach does not require panic. It requires classification and action.
Start by verifying the incident. Determine what information was exposed. Secure credentials. Protect the email and phone accounts that recover other services. Contact financial providers when payment information is involved. Review credit and consider a freeze when identity information could support new-account fraud. Monitor healthcare, tax, benefits, and child identity information when those records are affected.
Expect follow-on phishing. A criminal who knows real details can create a very convincing message.
If information is actually misused, move from breach response into identity-theft recovery and use IdentityTheft.gov for a personalized plan.
Most importantly, do not treat every breach the same. A stolen password needs immediate replacement. A stolen payment card needs issuer involvement. A stolen Social Security number deserves long-term identity and credit precautions. Matching the response to the exposed data is the most efficient way to reduce risk without creating unnecessary disruption.
Continue Learning
Additional flagship guides should be added to PLANNED_RELATED_GUIDES only after their live URLs are confirmed in a newer FreeTempTools sitemap.
Frequently asked questions
What should I do first after a data breach?
Verify that the breach notice is legitimate, identify what information was exposed, and immediately secure any affected credentials or accounts.
Should I change my password after a breach?
Yes if the password or account credentials were exposed, and you should also change the password anywhere else it was reused.
Should I freeze my credit after a breach?
A freeze is especially worth considering when Social Security numbers or other information useful for new-credit fraud was exposed. Anyone can place a free credit freeze.
Is a credit freeze free?
Yes. FTC guidance states that credit freezes are free to place and lift.
Does a credit freeze hurt my credit score?
No.
What is the difference between a freeze and fraud alert?
A freeze limits access to your credit report. A fraud alert tells lenders to verify identity before opening new credit.
Should I accept free credit monitoring after a breach?
A legitimate free offer can be useful, but verify it through the company's official site and understand that monitoring does not prevent every type of fraud.
What if only my email address was exposed?
Secure the email account, enable multi-factor authentication, and expect more targeted phishing. Changing the address is not always necessary.
What if my Social Security number was exposed?
Review credit reports, strongly consider freezing credit, monitor identity-related accounts, save the breach notice, and use IdentityTheft.gov if misuse occurs.
When does a breach become identity theft?
When someone actually uses your personal or financial information without permission, such as opening an account, making a purchase, filing taxes, obtaining benefits, or using your identity for employment.
What if my email account itself was hacked during a breach?
Change the password from a trusted device, revoke sessions, review MFA and recovery methods, inspect forwarding rules and connected apps, and secure accounts that use the mailbox for recovery.
What should I do if a password manager reports a breach?
Follow the provider's official incident guidance, secure the master account, review MFA and sessions, and rotate any credentials that were actually exposed or are considered at risk.
Can a data broker breach increase phishing risk?
Yes. Data brokers may contain names, addresses, phone numbers, relatives, and public-record information that can make impersonation and phishing more convincing.
What should I do if payroll information was exposed?
Secure employee accounts, review direct-deposit settings, watch for fake HR messages, review tax and financial activity, and verify payroll changes independently.
Should I trust dark-web monitoring alerts?
Treat them as a signal to review the listed information, but they do not prove identity theft occurred or show who currently has the data.
Authoritative references
- IdentityTheft.gov: What To Do if Your Information Was Lost or Stolen, or Part of a Data Breach
- Federal Trade Commission: What To Do After a Data Breach
- Federal Trade Commission: Credit Freezes and Fraud Alerts
- Federal Trade Commission: What To Know About Identity Theft
- NIST: Data Confidentiality: Detect, Respond to, and Recover from Data Breaches