Skip to content
Stay Safe

What to do after a data breach notice

By Editorial Team Published 2 min read
os general tested 2026-09-09 retest 2027-03 by editorial team
Quick Fix
01 First, don't click links in the notice — go to the company's site yourself. Then change that account's password to something new and unique, and turn on two-factor authentication.
02 If you reused that password anywhere else, change it there too — those accounts are now at risk even if they weren't breached.
tested general · 2026-09-09

Data breach emails are common and easy to panic over. Most of the time a calm, ordered response is all you need — and one of the “steps” everyone repeats isn’t actually necessary for most breaches.

1. Confirm the notice is real

Breach notices are a favourite disguise for phishing. Don’t click anything in the message. Open a browser and go to the company’s website yourself (or use your saved bookmark), and check the account and their official breach announcement there.

2. Secure the breached account

Change that account’s password to something new, long and unique (let your password manager generate it), and turn on two-factor authentication if it isn’t already.

3. Fix password reuse everywhere else

This is the step that actually protects you. If you used that same password on any other site, those accounts are now at risk too — attackers try breached email/password combos across every popular service. Change the password anywhere you reused it, starting with email and banking. (After this, never reuse a password again — that’s what the manager is for.)

4. Match the response to what leaked

The notice usually says what data was exposed. Respond in proportion:

  • Just email + password: steps 2–3 cover it.
  • Payment card: watch your statement; the bank will usually reissue the card. Report anything unfamiliar.
  • Social Security number / national ID or full financial details: consider a credit freeze at the credit bureaus (free, quick). Only this level of breach needs it — most breaches don’t, so don’t freeze your credit over a leaked email address.

5. Set up an early-warning system

Register your main email addresses with Have I Been Pwned (haveibeenpwned.com) to get alerted automatically when they appear in future breaches. Many password managers also flag reused or breached passwords for you.

What not to do

  • Don’t click links or call numbers from the notice — go direct.
  • Don’t pay for “identity protection” reflexively; the free steps above cover most situations.
  • Don’t ignore it — reused passwords make one breach into many.

Frequently asked questions

The breach was years ago — do I still need to act?

If you might still use that password anywhere, yes. Old leaked credentials get tried for years.

Should I delete the account?

If you don’t use it, closing it removes future risk. Otherwise, securing it (new password + 2FA) is enough.

How do I know if I’m affected without a notice?

Check haveibeenpwned.com with your email address — it lists known breaches your address appears in.

Sources