When your data is in a breach, the first hour is for changing the leaked password everywhere it was reused and turning on two-factor authentication, starting with your email account. The first day is for finding out exactly what leaked and revoking active sessions. The first week is for credit freezes, identity protections and the wave of targeted phishing that reliably follows.

What a breach actually exposes you to

A breach notification is alarming but vague, and the useful response depends on the answer to one question: what can an attacker do with the specific data that leaked? Breached data is used in three ways. Leaked passwords are tried against other services, which is credential stuffing, and it succeeds wherever you reused the password. Leaked personal details, which include name, address, date of birth, phone number and account history, are used to make phishing convincing, to pass identity checks at other companies and, with government identifiers, to open accounts in your name. Leaked payment data is used directly, and usually quickly, before the card is cancelled.

Two timing facts shape everything. First, breach notifications are late: companies frequently discover a breach months after it happened, and in most jurisdictions have days to weeks after discovery to notify. The data has usually been sold or posted before you hear about it. Second, the follow-up attacks start immediately, because attackers know that a notification prompts people to expect messages about the breach. The phishing guide is the companion to this one for that reason.

The first hour

  1. Change the password at the breached service, from the real site reached through your own bookmark, not through a link in the notification.
  2. Change it everywhere it was reused, and do it in order of consequence: your email account first, because it resets every other account; then banking and payment accounts; then anything with stored payment details. If you are not sure where it was reused, that is the answer: assume everywhere.
  3. Turn on two-factor authentication at each of those services. The two-factor guide ranks the methods; an authenticator app, passkey or hardware key is preferred, but SMS today beats a better method next week.
  4. Do not click anything in the notification until you have confirmed it is genuine. Attackers send fake breach notifications; a real one will be reflected in the company's own site and, for large breaches, in the news.

Use a password manager to generate the replacements; the password guide explains why a modified version of the old password is the first thing an attacker tries and why a new random one is the only sound replacement.

Never change a password by following a link in an email or text about a breach. Type the address, use a bookmark, or open the app. The notification itself is the most common phishing lure after a breach.

The first day: establish what leaked

Notifications describe the leaked data in categories, and the categories decide the rest of the response. Read the notice for the list of data classes, then confirm it against an independent source. Have I Been Pwned indexes breaches by email address and lists the data classes for each; searching your address there shows every known breach it appears in, not just this one, and its notification service tells you about future ones. Check every email address you use, including old ones.

Data class leakedAttacker's useYour action
Email address onlySpam, phishing listsExpect targeted phishing; nothing else needed
Password (hashed or plain)Credential stuffingChange it everywhere it was used, enable 2FA
Name, address, date of birth, phoneConvincing phishing, identity checks, SIM swap pretextsCarrier port-out PIN; extra scepticism for a year
Government ID number, tax ID, passportAccount opening, tax fraudCredit freeze, tax-agency identity PIN, document reissue if advised
Payment cardFraudulent chargesAsk the bank to reissue; watch statements
Bank account detailsDirect debit and transfer fraudNotify the bank; consider a new account number
Security questions and answersAccount recovery elsewhereChange the answers everywhere they were reused

Then close the doors the attacker may already have opened:

  • Revoke active sessions at the breached service and at your email provider. Most services have a "sign out everywhere" control in security settings. A stolen session cookie survives a password change unless sessions are revoked.
  • Review connected apps and forwarding rules in your email account. Attackers who reach a mailbox commonly add a forwarding rule so they keep receiving copies after you lock them out.
  • Check recent activity at the breached service: orders, address changes, added payment methods.
  • Verify the rest of your passwords. Run your important ones through the password checker; the breach lookup uses k-anonymity and never receives the password itself, and anything it flags should be replaced regardless of this breach.

The first week: financial and identity protections

If a government identifier, date of birth or financial data leaked, the risk becomes identity fraud, which unfolds over months and is far more costly to unwind than an account takeover. The protections are jurisdiction-specific but follow a pattern.

Credit freezes and fraud alerts

In the United States, a credit freeze at each of the three national bureaus (Equifax, Experian and TransUnion) blocks new credit checks in your name, which stops most fraudulent account opening. Freezes have been free by federal law since 2018, can be lifted temporarily when you apply for credit, and are the single most effective step. A fraud alert is a weaker alternative that asks lenders to verify identity. The FTC's IdentityTheft.gov provides a recovery plan and the forms lenders accept. In the UK, the equivalent is registering with Cifas for protective registration; in the EU and elsewhere, ask the national credit bureaus what notice they offer.

Tax and government identifiers

In the US, an IRS Identity Protection PIN prevents anyone else from filing a return with your Social Security number. Other tax agencies offer similar controls. If a passport or driving-licence number leaked, the issuing authority will advise whether reissue is warranted; the number alone rarely justifies it.

Phone number

A leaked phone number with personal details is the raw material for SIM swapping. Set a port-out PIN or account passcode with your carrier, and move any account still using SMS codes to an authenticator app or passkey.

Payment details

Ask the bank to reissue a leaked card; do not wait for a fraudulent charge. Review statements for small test transactions, which attackers use to confirm a card is live before larger purchases.

Watch for the follow-up phishing

Every large breach is followed by campaigns that use it. The messages reference the breach by name, quote the details that leaked to prove authenticity, and ask you to "secure your account", "claim compensation" or "verify your identity" through a link. Because the details are real, the messages pass the sniff test that generic phishing fails. Apply the domain test regardless: read the link's hostname from the right, and if the registrable domain is not the company's, it is an attack. When unsure, paste the link into the phishing URL checker, which flags lookalike domains and brand names in the wrong place. Then go to the company's site by your own route and look for the same message there.

The same caution applies by phone. A caller who knows your account number, address and recent order is not thereby proven to be the company; that information was in the breach. Hang up and call back on the number from the company's site or your card.

Your rights and the company's obligations

Under the GDPR in the EU and UK, a company must notify the regulator within 72 hours of becoming aware of a breach and must tell affected individuals without undue delay when the breach is likely to result in a high risk to them (Articles 33 and 34). You also retain the right to ask what data the company holds on you and to have it erased, which is worth exercising against a company that has just shown it cannot protect it. US state breach laws set notification requirements that vary by state; several require companies to offer credit monitoring when identifiers leak. Accept the monitoring if it is offered, but do not mistake it for prevention: monitoring reports fraud after it happens, whereas a freeze prevents it.

Breaches also feed the profiles that data brokers build, and a broker that has your leaked details makes the next attacker's job easier. The removal process in that guide is a reasonable follow-up once the urgent steps are done.

Reducing the damage of the next one

There will be a next one, because you cannot control the security of every company that holds your data. What you control is how much one breach can cascade:

  • A unique password everywhere, generated by a manager, means a leaked password is worthless outside the breached site.
  • A phishing-resistant second factor on email, the manager and financial accounts means a leaked password is worthless even there.
  • A separate email address for accounts you do not care about limits how a low-value breach reveals your main address.
  • Giving companies less: skip the optional date of birth and phone number when a form allows it.
  • Monitoring your addresses in the breach corpus so you hear about a breach from an independent source, often before the company's notification.

The privacy hub brings these together with the tracking and exposure guides.