Security Data breaches and identity theft
Your data was in a breach: the checklist that actually helps
A prioritized response to a breach notification: what to change, what to freeze, what to monitor, and which of the offered protections is worth accepting.
The short answer
- Work in order: change reused passwords, then protect payment methods, then lock your identity, then set up monitoring.
- Changing the password on the breached site is the easy half, and changing it everywhere you reused it is the half that actually matters.
- A credit freeze prevents a new account being opened in your name, while monitoring only tells you after it happened, so the freeze is worth more.
- Ask your mobile carrier for a port out PIN or number lock, because a leaked name, address and phone number is enough to attempt a SIM swap.
- Accept the free monitoring offer since it costs nothing, but expect it to cover one credit bureau and to expire.
- Expect a wave of convincing scam calls and emails quoting real details from the breach, and only ever call back on a number you looked up yourself.
Work in this order: passwords first, then money, then identity, then monitoring. That sequence is not arbitrary. It runs from the things you can fix in minutes and that close the biggest hole, down to the things that only pay off over months. Most people do it backwards, spending the first evening enrolling in a free credit monitoring offer while the reused password that actually matters sits unchanged. Before anything else, find out which fields were exposed, because the whole checklist depends on that one answer.
The first thirty minutes
Five moves, in this order, and none of them require you to know anything technical.
- Change the password on the breached account. Do it by typing the site address yourself, never through a link in the notification.
- Change it everywhere you reused it. This is the whole point. A breach at a hobby forum matters only because the same password opens your email. Include variations with a different number or year on the end, because cracking tools generate those automatically.
- Secure email first if email was involved. Your inbox can reset almost every other account, so it outranks your bank.
- Turn on two-factor authentication on email, banking and anything holding a saved card. An app or a hardware key beats SMS, and how a second factor actually blocks a stolen password explains why.
- Check for sessions and devices you do not recognize. Most major services have a security page listing active sessions. Sign them all out. A changed password does not always kill a stolen session cookie, and that is the step people skip.
If you are staring at a long list of reused passwords, this is the moment a password manager stops being optional. Doing forty by hand takes a weekend and you will not finish it.
Match the action to the field that leaked
Different fields need different responses, and doing all of them for a breach that leaked only email addresses is wasted effort.
| What leaked | Do this | Urgency |
|---|---|---|
| Password (any form) | Change it there and everywhere reused, sign out all sessions | Same day |
| Email address only | Nothing structural. Expect better targeted phishing for years | Awareness only |
| Full card number | Ask the bank to reissue. Do not just watch the statement | Same day |
| Bank account and routing or sort code | Tell the bank, ask about direct debit or ACH protections | This week |
| Phone number | Add a port out PIN or number lock with your carrier | This week |
| Date of birth and address | Lock or freeze your credit file, expect verification abuse | This week |
| National ID number | Freeze credit, watch for tax and benefits fraud | This week, then ongoing |
| Passport or driver's license number | Report to the issuing authority, keep the reference | This week |
| Security question answers | Change them on every account, treat as passwords | Same day |
| Health or medical records | Watch for unfamiliar claims and providers on statements | Ongoing |
Security answers deserve their own note. Mother's maiden name and first school never change, so once they are in a dump they are a permanent key to phone support at every company still using them. Stop answering them truthfully: store a random string as the answer, the same way you store a password.
Freezing your credit and the equivalents elsewhere
This is the single highest value move after passwords when identity data leaked, and in several countries it is free. What follows is general information rather than advice for a specific situation, and the exact mechanics change, so confirm the current process with each agency.
United States. A security freeze locks your credit file so a lender cannot pull it, which means a new account cannot be approved in your name. Federal law requires the nationwide bureaus to place and lift freezes free of charge, and you must do it with each bureau separately, since there is no single switch. Lifting one for a real application takes minutes online. A fraud alert is the weaker sibling: it tells lenders to verify identity but does not block anything, it expires, and placing it with one bureau obliges that bureau to tell the others. If you have a confirmed case of identity theft, an extended alert lasts considerably longer than the standard one. Freeze beats alert whenever you are not about to apply for credit.
United Kingdom. There is no identical statutory freeze. The nearest equivalent is a protective registration with the national fraud prevention service, which flags your details so lenders apply extra checks, renewed annually for a small fee. You can also add a Notice of Correction to your file at each credit reference agency explaining the situation, which forces manual review of applications.
Elsewhere in Europe. Practice varies by country. Some have a national credit bureau where you can register a fraud note, some have a central bank register, and some have nothing consumer facing at all. The reliable universal step is telling your own bank that your identity data is exposed, and checking your credit record with whichever agency operates where you live.
What the free monitoring offer is actually worth
Most breach letters include a year or two of free credit or identity monitoring. Accept it, because it costs nothing, but understand what you are getting.
Monitoring is detection, not prevention. It tells you after the fact: a new account appears on your file, your details show up in a fresh dump, an address change is filed. Useful, but a freeze prevents the event that monitoring only reports. Given one choice, take the freeze.
Three limits are worth knowing before you rely on it. Many offers cover only one of the credit bureaus, so activity at another goes unseen. Dark web scanning sounds impressive but mostly reports that your email appeared in a list you can look up yourself for free, which checking whether your credentials have leaked covers. And the enrollment window usually expires, so if you want it, sign up within the deadline in the letter rather than filing it away.
The identity theft insurance attached to these offers typically reimburses costs such as lost wages, notarization and legal fees rather than the stolen money itself, and it comes with a deductible and exclusions. Read what it actually covers before treating it as a safety net.
Cards, carriers and SIM swap protection
If a full card number leaked, ask for a replacement rather than relying on fraud detection. Card fraud is the most reversible kind of loss, though the protections differ by region, and this is general information rather than advice. In the US, credit card liability for unauthorized charges is capped at a small statutory amount and issuers commonly waive it, while debit card protection depends on how fast you report. In the UK and the EU, the rules on unauthorized payments generally require a refund unless you acted fraudulently or with gross negligence. Everywhere, reporting speed is what protects you. A payment you authorized that turns out to be a scam follows a different route, covered in how chargebacks and payment disputes work.
The phone number deserves more attention than it gets. If your number, name and address leaked together, someone has enough to attempt a SIM swap: convincing your carrier to move your number to their SIM, after which every SMS code goes to them. Call your carrier and ask for a port out PIN, a number lock or a transfer freeze, which is free with every major carrier and takes one call. Then move your important accounts off SMS codes and onto an authenticator app or a passkey.
The phishing wave that follows
Expect contact. Two kinds arrive after any breach that makes the news, and both work because they contain real details.
The first impersonates the breached company: a notice linking to a convincing password reset page. The second impersonates a bank fraud team, calling about suspicious activity and walking you through moving money to a safe account. That script works unusually well in the weeks after a public breach, because the story matches something you already believe.
One rule handles both: you contact them, never the reverse. Hang up, find the number on your card or in the official app, call back. No real fraud team objects, and none will ever ask you to read out a code or move money. The wider pattern is in how phishing gets past careful people.
The week after, and then the year after
Once the urgent work is done, spend twenty minutes making the next breach cheaper. Review account recovery everywhere that matters, because a stale backup email or dead phone number is the gap an attacker walks through, and setting recovery up before you need it is the one piece you can only do in advance. Replace SMS second factors with an authenticator app. Keep the notification and any reference numbers in one folder.
Then set two reminders. At three months, pull your credit report and read it line by line. At twelve months, do it again, because identity data gets used long after the news cycle ends, for reasons explained in what a breach actually exposes and when it gets used. If something unfamiliar does appear, the response is a different and more procedural one, set out in the early signs of identity theft and the first moves.
Common questions
Does freezing my credit hurt my credit score?
No. A freeze restricts who can see your file. It does not change what is in it, and scores are calculated from the contents. Lenders you already have keep reporting as normal, and existing cards keep working. The only cost is the minute it takes to lift the freeze before you apply for something new.
How long should I keep worrying after a breach?
Treat the password work as finished once it is done, and the identity side as a long slow watch. Credentials lose value quickly after you change them. Identity data keeps working for years because a date of birth and a national ID number never expire. A credit check at three months and again at twelve is a reasonable level of attention.
Should I close the account at the company that got breached?
Usually not immediately. Closing it does not delete the data already taken, and you may need access to see notices or claim a settlement. Change the password, remove any saved card and address, and then delete the account later if you have no use for it. Deleting in anger before securing your reused passwords is the wrong order.
The breach was years ago and nothing has happened, am I fine?
Probably, but the reasoning is worth correcting. Nothing happening means your record has not been worked yet, not that it was destroyed. Old identity data gets bought and used long after the event. If the passwords are changed and your credit file is frozen, the exposure is genuinely managed, which is different from being lucky.
Can I sue or claim compensation for a breach?
Sometimes, and this is general information rather than legal advice. In the United States, breaches often produce class action settlements, usually paying small amounts or reimbursing documented losses. In the EU and the UK, the GDPR allows claims for material and non material damage, but you generally have to show actual harm. Keep receipts and a dated log either way.