What to do after a data breach notice
Data breach emails are common and easy to panic over. Most of the time a calm, ordered response is all you need — and one of the “steps” everyone repeats isn’t actually necessary for most breaches.
1. Confirm the notice is real
Breach notices are a favourite disguise for phishing. Don’t click anything in the message. Open a browser and go to the company’s website yourself (or use your saved bookmark), and check the account and their official breach announcement there.
2. Secure the breached account
Change that account’s password to something new, long and unique (let your password manager generate it), and turn on two-factor authentication if it isn’t already.
3. Fix password reuse everywhere else
This is the step that actually protects you. If you used that same password on any other site, those accounts are now at risk too — attackers try breached email/password combos across every popular service. Change the password anywhere you reused it, starting with email and banking. (After this, never reuse a password again — that’s what the manager is for.)
4. Match the response to what leaked
The notice usually says what data was exposed. Respond in proportion:
- Just email + password: steps 2–3 cover it.
- Payment card: watch your statement; the bank will usually reissue the card. Report anything unfamiliar.
- Social Security number / national ID or full financial details: consider a credit freeze at the credit bureaus (free, quick). Only this level of breach needs it — most breaches don’t, so don’t freeze your credit over a leaked email address.
5. Set up an early-warning system
Register your main email addresses with Have I Been Pwned (haveibeenpwned.com) to get alerted automatically when they appear in future breaches. Many password managers also flag reused or breached passwords for you.
What not to do
- Don’t click links or call numbers from the notice — go direct.
- Don’t pay for “identity protection” reflexively; the free steps above cover most situations.
- Don’t ignore it — reused passwords make one breach into many.
Frequently asked questions
The breach was years ago — do I still need to act?
If you might still use that password anywhere, yes. Old leaked credentials get tried for years.
Should I delete the account?
If you don’t use it, closing it removes future risk. Otherwise, securing it (new password + 2FA) is enough.
How do I know if I’m affected without a notice?
Check haveibeenpwned.com with your email address — it lists known breaches your address appears in.