Data breaches and identity theft
What actually happens when a company loses your data, how that data gets used months later, and the prioritized checklist that protects the accounts and the credit that matter.
Your details end up in a breach because a company you handed them to lost control of them, usually telling you late and vaguely, sometimes not at all. The notification email arrives months after the event, the wording is careful, and it is genuinely hard to tell whether you need to do anything. These pages answer that: what was taken, how it gets used later, and which of your own accounts has just become the weak point.
Read what a breach actually involves first, because a leaked marketing list calls for nothing like the response to leaked passwords or copies of identity documents. Then work through the checklist in priority order, which starts with your email account rather than the company that was breached. It is also worth running a check on whether a password you still use has already leaked, since old breaches tend to surface long after the news has moved on.
If unfamiliar charges, letters or accounts are already appearing, treat that as a separate problem and read the early signs of identity theft and the first moves to make.
Articles in this hub
- What a data breach is and what it means for youWhat actually leaks in a breach, why hashed passwords are not all equal, how the data gets used months later, and what you should do when the notification email arrives.
- Your data was in a breach: the checklist that actually helpsA prioritized response to a breach notification: what to change, what to freeze, what to monitor, and which of the offered protections is worth accepting.
- Identity theft: the early signs and the first movesHow stolen identity data is used, the early warning signs people miss, and the order of operations that limits the damage when someone opens an account in your name.