The response to a breach depends almost entirely on what was exposed, and the breach notification you received probably buried that in paragraph four. This is a triage guide: the handful of things worth doing in the first hour regardless, then what each specific category of exposed data actually requires. Most breaches need less from you than the panic suggests. A few need considerably more, quickly.
Find out what was actually exposed
Before doing anything, locate the specific list of data categories. In a notification letter or email it is the sentence beginning "the information involved may have included". On Have I Been Pwned it is the "Compromised data" line on the breach entry. Everything below branches off that list.
The first hour
Do these in order. The ordering is deliberate: your email account is the reset route for everything else, so it goes first even if it was not the account that was breached.
triage
- 01
Secure your email account first
Set a unique password on the mailbox you use for password resets, and turn on two-factor authentication. Whoever controls that inbox controls every account attached to it, which makes it the only thing that genuinely has to be fixed before anything else.
- 02
Change the password on the breached service
Make it unique and long. If the service offers two-factor, enable it in the same visit — you are already there and you will not come back.
- 03
Change it everywhere you reused it
This is the step that actually matters. The attacker will try that email and password pair on hundreds of other sites automatically, which is why a breach at a company you barely used ends with your real accounts compromised. Run the password audit in your browser or password manager to find the reuse rather than trying to recall it.
- 04
Sign out every other session
Look for "sign out of all devices", "active sessions" or "where you are logged in" in the security settings of the breached account and your email. A stolen session cookie keeps working after a password change, so rotating the password without killing the sessions leaves the door open.
- 05
Check for changes an attacker would make
In your email settings, check forwarding rules, filters that auto-delete or auto-archive, the recovery email and phone number, app passwords and connected apps. A quiet forwarding rule is the standard way an intruder keeps reading your mail after you lock them out, and almost nobody checks for it.
- 06
Remove stored payment methods
On the breached service, delete any saved card or bank detail. If the breach included card numbers, treat the next section as urgent rather than optional.
What each exposed data class requires
| What leaked | Do this | How urgent |
|---|---|---|
| Password or password hash | Rotate it on the service and everywhere you reused it. Enable two-factor. | Today |
| Session tokens, or the breach came from infostealer malware | Rotate passwords and sign out all sessions. Then scan the device the credentials were saved on, because the malware is the actual problem. | Today |
| Card number | Call the issuer and ask for a replacement card. Do not simply watch for fraud — a new number costs you nothing. | Today |
| Bank account and routing number | Tell the bank, ask what protections they can apply, and watch for small test debits. | Today |
| National ID — SSN, NI number, tax ID | Freeze your credit at every bureau. See below. This is the one category where the exposure can follow you for years. | This week |
| Address, phone, date of birth | No single fix — this is the raw material for convincing phishing and for passing identity checks. Expect targeted contact and treat unsolicited calls about the breach as hostile. | Awareness |
| Passport, driving licence, ID scan | Report it to the issuing authority and ask about reissue. In the UK, consider Cifas protective registration. | This week |
| Health or medical data | Little technical recourse. Watch for insurance statements listing care you did not receive, which indicates medical identity fraud. | Awareness |
| Security question answers | Change them everywhere, and answer with random strings stored in your password manager rather than true facts. | This week |
Freezing your credit
If a national identity number was exposed, this is the single most effective thing available to you, and in the US it is free by law.
A freeze stops new credit being opened in your name, because a lender cannot pull your file to approve it. You lift it temporarily when you need to apply for something yourself. It does not affect your existing accounts and it does not affect your credit score.
- United States — freeze separately at all three bureaus: Equifax, Experian and TransUnion. Free to place and to lift. Also consider the IRS Identity Protection PIN if a tax ID was exposed.
- United Kingdom — there is no equivalent statutory freeze. Cifas protective registration flags your record so lenders carry out extra checks, and it carries a small fee. Check your file with Experian, Equifax and TransUnion.
- Elsewhere — ask your national credit reference agencies what fraud flag or notice of correction they offer. Most have something, under a different name.
What comes next: the follow-up attacks
The second wave is usually more dangerous than the breach, because the attacker now knows real details about you and can be convincing. Expect all of these.
- Phishing that references the breach. Mail or SMS offering to help you secure your account, using your real name and sometimes the real company name. The timing feels like a coincidence. It is not.
- The extortion email. A message claiming to have your passwords or webcam footage, quoting a real old password as proof. The password came from the breach corpus; there is no footage. Delete it and make sure that password is retired everywhere.
- The voice call. Someone claiming to be the breached company fraud team, or your bank, asking you to confirm a code or move money "somewhere safe". No legitimate institution will ever ask for a one-time code. Hang up and call back on the number printed on your card.
- SIM swapping. If your phone number leaked alongside identity data, an attacker may try to port it to take over your SMS two-factor. Add a port-out PIN with your carrier, and move two-factor off SMS onto an authenticator app or hardware key.
- Fake class-action and compensation sites. Settlement scams follow large breaches within days. Only use the claim site named in the official notice or court documents.
Do not bother with
- Changing your email address. Enormous effort, and it rejoins the corpus at the next breach. Use aliases for new signups instead.
- Trying to get the leaked data deleted. It was copied and traded within hours. There is no recall mechanism. Asking the company to delete its live record of you is still worth doing, but it does not undo the leak.
- Buying a monitoring subscription in a panic. Place the free credit freeze first. Then decide calmly whether you want monitoring on top; it is a notification service, not a protection.
- Deleting all your accounts today. It is the right project and the wrong moment. Deleting accounts destroys the mapping between breached credential and account, and rotating passwords is what the next hour needs. Come back to the cleanup once the fire is out.
Then do the wider check
Once the immediate work is done, the useful follow-up is to find out whether this breach was the only one. Check every address you own against the breach corpus — the method is in how to check if your email has been leaked — and then work out which accounts you actually have, because you cannot rotate a credential on an account you no longer remember.
That second part is what Tracebase does: account discovery across supported platforms from your emails and usernames, with breach records from your verified addresses attached to the same list, and the removal steps for the platforms we have documented. It does not replace the triage above, and nothing should delay the triage above.
common_questions
What is the first thing to do after a data breach?
Secure the email account you use for password resets — unique password, two-factor on. Then change the password on the breached service, then change it everywhere you reused it, then sign out all other sessions. Email first even if email was not what got breached, because it is the reset path to everything else.
Do I need to freeze my credit after every breach?
No. A freeze is the right response when a national identity number, or a combination like full name plus date of birth plus address, was exposed — the ingredients for opening credit in your name. For a breach of email addresses and passwords it is unnecessary; rotate the password instead.
Is it worth paying for identity theft protection?
Place the free credit freeze first, because it prevents what monitoring merely reports. After that, these services are a convenience: consolidated alerts and somebody to help with the paperwork if fraud does occur. Useful to some people, not a substitute for the freeze.
I got an email saying they have my password and will release a video. Is it real?
No. It is a template sent to millions of addresses, and the password it quotes came from a public breach corpus. There is no video. Delete it, and make sure that password is no longer in use anywhere.
Should I sue, or join the class action?
Joining a certified class action costs you nothing and takes a few minutes, so there is little reason not to. Set expectations low — individual payouts are typically small. Only use the claim site named in the official notice; settlement scams follow every large breach.
How long should I stay worried?
Credential exposure is resolved the moment you rotate the password and kill the sessions. Identity data is different: a national ID number does not expire, so a freeze and periodic credit file checks are a long-term habit rather than a one-off task.