Skip to main content
AI & Technology

You Got a Breach Notification. Here's What to Actually Do.

Most breach advice tells you to change the password on the affected site. That is the wrong first move. Here is the correct order of operations, and why your email account comes before everything else.

12 min read
Share:
Close-up of a laptop keyboard, the everyday place where account security settings actually get changed
Carissa Rogers (CC BY 2.0)

A breach notification lands in your inbox and the instinct is immediate: go and change the password on the site that got breached.

That is not the wrong thing to do. It is just not the first thing, and doing it first can waste the window that matters. Your email account is the reset path for almost every other account you own. If an attacker has a way into your email, changing your banking password accomplishes nothing — they will simply request a reset and intercept it.

So the correct response has an order, and the order does more work than the individual steps. There is also a second thing worth internalising straight away: the leaked password matters far less than where else you used it. A breach at one shopping site is a minor event if that password existed nowhere else, and a serious one if it also opens your email.

This is a common enough situation to be worth having a plan for. In the FIDO Alliance's 2026 survey, one in three people had suffered an account compromise or received a breach notification in the previous year.

First, What a Breach Notification Actually Tells You

A notification means data held by a company about you has been exposed. It does not necessarily mean your account was accessed, and it does not mean money has moved.

What it does tell you is which type of exposure you are dealing with, and that determines nearly everything about the response. Read the notice carefully for what was taken.

What was exposedReal riskWhat it demands
Email address onlyTargeted phishing referencing the breachVigilance, nothing urgent
Email + passwordAccount takeover anywhere you reused itUrgent — see the order below
Payment card numberFraudulent chargesContact the card issuer; they reissue
Bank account detailsDirect debit fraudContact the bank, monitor statements
National ID / SSN / date of birthNew credit opened in your nameCredit freeze — this is what freezes are for
Security question answersRecovery-flow takeoverChange them everywhere; treat as passwords
Passport or driving licenceDocument-based identity fraudReport to the issuing authority

Notice the pattern: a card number is annoying but recoverable, because a card can be cancelled and reissued. Your date of birth cannot be reissued. Exposures of permanent identifiers are the ones that justify the heavier steps.

The Order Matters More Than the Actions

Here is the reasoning that should drive your sequence. Almost every account you own offers "forgot password," and almost every one of those flows sends a reset link to your email address. Your email is therefore not one account among many — it is the master key.

Diagram showing an email account as the root of a tree with branches to banking, social media, shopping and work accounts. Each branch is labelled forgot-password sends a reset link to email. An arrow shows that an attacker who controls the email account can reset every downstream account, with a note that securing the email first is what makes every later step meaningful
Every 'forgot password' link leads back to the same place. Securing email first is not a preference — it is what makes the rest of the checklist worth doing.

This is why sequence beats speed. Ten minutes spent on your email account is worth more than an hour spent changing passwords on twenty shopping sites while the reset path stays open.

The First Hour

1. Secure your email account. Change the password to something unique, then check three settings that people routinely miss:

  • Forwarding rules. An attacker who had access often adds a rule silently copying your mail to their address. Changing the password does not remove it.
  • Connected apps and app passwords. Revoke anything you do not recognise. These can survive a password change.
  • Recovery options. Remove any phone number or backup email you do not control. Get SMS out of recovery if the provider allows it — NIST classifies SMS delivery as a restricted authenticator that "should not be used for new implementations."

Then turn on the strongest second factor available. A passkey if offered, an authenticator app otherwise — our comparison of 2FA methods explains why that ranking is not arbitrary.

2. Change the password anywhere you reused it. This is the actual exposure. Attackers take a leaked email-and-password pair and try it automatically across hundreds of services — the attack is called credential stuffing, and it is the single most common thing that happens after a breach. Every place you used that password is effectively part of the same breach.

3. Now change it on the breached site. Third, not first. By this point the reset path is closed and the reuse has been cleaned up.

The First Day: Financial Locks

If the exposure included permanent identifiers or financial details, the next layer is stopping new accounts being opened in your name. Two tools exist and they are routinely confused.

Fraud alertCredit freeze
What it doesBusinesses must verify your identity before opening new creditCreditors cannot access your report at all
Does it block access to your report?NoYes
How many bureaus to contactOne — it must tell the other twoAll three, separately
How long it lastsOne year (initial), renewable; seven years (extended)Until you remove it
CostFreeFree
Best forPrecaution after a minor exposureConfirmed exposure of ID data
Diagram contrasting a fraud alert and a credit freeze. For a fraud alert you contact one credit bureau and it is required to notify the other two, and businesses must verify your identity before opening new credit, lasting one year initially. For a credit freeze you must contact all three bureaus separately — Equifax, Experian and TransUnion — and creditors cannot access your report at all, lasting until you remove it. Both are free
The asymmetry catches people out: one call is enough for an alert, but a freeze has to be placed with each bureau individually. Both are free.

The three nationwide bureaus are Equifax, Experian and TransUnion, and per the FTC's guidance, a freeze must be placed with each of them to be fully effective. A freeze does not affect your credit score and you can lift it temporarily when you actually need credit.

If a payment card was exposed, call the issuer and ask for a new number rather than just watching the statement. Reissue is free, quick, and removes the problem entirely.

The First Week: Report and Monitor

Report it officially. In the United States, IdentityTheft.gov is the FTC's official reporting route and generates a personal recovery plan plus an identity theft report you can use with creditors. Filing matters: it creates the documentation that makes disputing fraudulent accounts possible later.

Check your credit reports. You are entitled to free reports from all three bureaus via AnnualCreditReport.com, the only federally authorised source. Look for accounts you did not open and enquiries you did not make. This is the same habit that pays off generally — see our guide on how credit scores work.

Expect the follow-up scams. This is the step almost everyone omits, and it is where the real losses often happen. After a public breach, attackers send phishing that references the breach itself — "your account was affected, click here to secure it." The message is credible precisely because the breach was real and you already know about it.

Treat any breach-related message as hostile. Never use a link in an email about a breach; navigate to the site yourself. And be sceptical of phone calls: no legitimate bank asks you to read out a one-time code, and a caller who does is running the relay attack described in our 2FA comparison.

If It Is a Work Account, Stop and Report It

Different rules apply here, and getting this wrong causes real damage.

If the exposed credential belongs to your employer, the priority is not to fix it yourself — it is to tell your IT or security team before you change anything. They need to establish whether the credential was actually used, whether an intruder moved laterally into other systems, and whether the organisation has a legal duty to notify regulators or customers inside a fixed window.

Quietly resetting your own password destroys the evidence trail they need to answer those questions, and can leave a compliance clock running that nobody is watching.

Report it even if you are fairly sure nothing happened, and even if the exposure was your own mistake. Every competent security team would far rather hear about it early and find nothing.

What Not to Bother With

Some standard advice is stale or actively unhelpful.

Do not change the password to a small variation. Going from Summer2024! to Summer2025! defeats nothing, because that is exactly what cracking tools try next. Unique and unrelated, or nothing.

Do not change every password on every site immediately. It sounds thorough and it burns the hour you needed for email and reuse. Prioritise: email, then financial, then anything sharing the leaked password. The rest can wait.

Do not pay for identity monitoring in a panic. Breached companies often offer it free, and the two actions that actually block new credit — a freeze and an alert — are free and immediate. Monitoring tells you after the fact; a freeze prevents it.

Do not rely on rotating passwords on a schedule. Modern guidance moved away from forced periodic changes years ago, because it produces predictable patterns. A long unique password per site, kept in a password manager, is what works.

The Bottom Line

A breach notification is a prompt, not a catastrophe. What determines the outcome is the order you work in.

Email first, because it is the reset path for everything else. Then anywhere you reused the password, because that is the actual exposure — the breach itself is often less important than your own reuse. Then the breached account. If permanent identifiers were exposed, freeze your credit with all three bureaus; if only a card was, get it reissued. Report it, check your reports, and treat every message about the breach as a probable follow-up attack.

The longer-term fix is to make the next notification a non-event: unique passwords everywhere, a real second factor on the accounts that matter, and no SMS in recovery settings. More in our cybersecurity hub.

Frequently Asked Questions

What should I do first after a data breach?

Secure your email account before anything else — change the password, then check for forwarding rules, unfamiliar connected apps, and recovery phone numbers you do not control. Email is the reset path for nearly every other account, so if an attacker has access there, changing your other passwords achieves little because they can simply request a reset. Only after email is locked down should you tackle password reuse and then the breached site itself.

Does a breach notification mean my account was hacked?

Not necessarily. It means data a company held about you was exposed, which is different from your account being accessed or money moving. What matters is what was exposed. An email address alone mostly means expect targeted phishing. An email and password together is urgent, because that pair will be tried automatically across other services. Exposure of permanent identifiers like a date of birth or national ID number is the case for a credit freeze.

Should I get a credit freeze or a fraud alert?

A freeze is stronger: it stops creditors accessing your report at all, so new accounts cannot easily be opened, and it lasts until you remove it. A fraud alert only requires businesses to verify your identity first and lasts one year initially. One practical difference catches people out — for a fraud alert you contact just one bureau and it must notify the other two, but a freeze has to be placed with Equifax, Experian and TransUnion separately. Both are free.

Will freezing my credit hurt my credit score?

No. A freeze restricts who can access your report; it does not change what is in it or how it is scored. You can also lift a freeze temporarily when you genuinely need a lender to check your credit, then reinstate it. This is why a freeze is the default recommendation after identity data is exposed — the cost to you is close to zero.

How do I know if my password was in a breach?

Read the notification, which usually states what data types were involved. Most password managers now check your saved credentials against known breach datasets and flag matches, which is more useful than checking one at a time. The safer assumption is that if a password appeared in any breach, treat every account using that password as exposed — reuse, not the breach itself, is what turns one incident into several.

Is it worth paying for identity theft protection after a breach?

Usually not in the immediate aftermath. The two measures that actually prevent new credit being opened — a freeze and a fraud alert — are free and take minutes. Breached companies also frequently provide monitoring at no cost, so check before subscribing. Paid monitoring mostly tells you that something has already happened, which is less valuable than blocking it in the first place.

Sources

Cybersecurity#data breach#cybersecurity#identity theft#passwords#phishing
Share:
A large circular steel bank vault door standing open, showing the concentric locking mechanism and heavy bolts around its edge

AI & TechnologyGuide

How Password Managers Actually Work — and What Can Go Wrong

The design that makes a password manager safe is the same design that makes it unforgiving. Here is what happens when you save a password, why a provider breach usually doesn't expose your vault, and where the real risk sits.

Aug 20, 202614 min
Close-up of a hardware security token displaying a six-digit one-time authentication code on a small LCD screen

AI & TechnologyComparison

SMS vs App vs Passkey: Which 2FA Actually Protects You?

Two-factor authentication is not a ladder from weak to strong. There is one hard line — phishing resistance — and only one common method sits on the right side of it. Here is what each option actually stops.

Aug 20, 202615 min
Three hardware security keys on a plain surface — a black USB-A key with a gold contact strip, a smaller black USB-C key, and a white wireless key with a fingerprint button

AI & TechnologyGuide

Passkeys, Honestly: What They Fix and What They Don't

Passkeys are genuinely better than passwords, and five billion are already in use. But your account's real security is set by its weakest recovery path — not its strongest login method. Here is the honest picture.

Aug 16, 202616 min