Consumer Guides · Reviewed/updated 24 August 2026

What to Do After a Data Breach: A Step-by-Step Consumer Checklist

What to change, freeze, monitor and document after a company says your personal information was exposed in a data breach.

Reviewed: 24 August 2026 · Scope: U.S. identity-theft and consumer-security guidance. This article is general educational information, not individual legal, medical or financial advice.

A data-breach notice tells you that information held by an organization may have been exposed. The right response depends on what was involved: a password creates a different risk from a Social Security number, bank account number or medical-insurance identifier. Start by confirming the notice is real, then take actions matched to the information that was exposed.

1. Verify the breach notice without using links in a suspicious message

If you received the notice by email or text, do not rely on the message itself to prove it is genuine. Go to the company’s website by typing the address yourself or use a phone number you already trust. Scammers often imitate real breach notices to collect passwords or payment details.

2. Change exposed or reused passwords

If a password was involved, change it on the affected account and anywhere else you reused it. Reusing the same password across sites turns one breach into several possible account takeovers. Use a unique password for each important account and enable multi-factor authentication where available.

3. If sensitive identity information was exposed, check and freeze your credit

IdentityTheft.gov recommends checking your credit reports for accounts you do not recognize and considering a credit freeze when information such as your Social Security number has been exposed. A freeze can make it harder for an identity thief to open new credit in your name. Keep the PINs or account credentials needed to manage the freeze later.

4. Review financial accounts and turn on alerts

Check bank, credit-card and payment-app activity for unfamiliar transactions. Turn on transaction and login alerts. If you see something you did not authorize, contact the financial institution using the number on the back of the card or its official website rather than a number supplied in an unexpected message.

5. Use any legitimate monitoring service offered after the breach

Some breached organizations offer free credit monitoring or identity-protection services. The FTC notes that these services can be useful, but they are not a substitute for checking your own reports and statements. Enroll only through a verified breach-notification page.

6. Watch for follow-on phishing

Breached information can make later scams more convincing. A scammer who knows your name, email address or the company you use may sound legitimate. Be especially cautious about messages that create urgency, ask for verification codes, or tell you to move money to “protect” it.

7. If someone is already using your identity, move from prevention to recovery

If you find a new account, purchase, loan or other activity you did not authorize, report identity theft at IdentityTheft.gov. The service creates a recovery plan and provides steps for contacting businesses and credit bureaus.

Primary sources and further help

We reviewed this guide against the following public consumer resources. Rules and procedures can change, so use the linked agency guidance for the latest details.

About this guide

Current News Today publishes general consumer education checked against primary public sources. We do not claim personal experience or professional credentials that we do not have. For individual legal, medical or financial decisions, use the official resources cited in the article and qualified professional help when appropriate.

Editorial standards · Report a correction