LIVE: New phishing campaigns targeting mobile users —View latest threats →

Back to Tutorials
Beginner 8 min read

Your Data Was Breached — Now What?

When a breach exposes your personal data, the first 48 hours are critical. Follow this step-by-step action plan to limit damage and protect your accounts.

20 July 2026

Understanding What Just Happened

A data breach occurs when unauthorized individuals gain access to a company's systems and steal customer data. In 2026, billions of records were exposed across thousands of breaches. At some point, your information — email address, password, phone number, or more — will almost certainly be included in one.

The first thing to understand: how serious is this particular breach? Not all breaches carry the same risk. An exposed email address is different from an exposed password hash, which is different from an exposed Social Security number or credit card.

When you receive a breach notification or discover your data was exposed, your response should be proportional to what was actually stolen.

Step 1: Confirm the Breach Is Real

Before taking action, verify the notification is legitimate. Unfortunately, phishing emails often impersonate breach notifications to harvest your credentials.

  • Don't click links in breach notification emails. Instead, go directly to the company's website by typing the address yourself.
  • Use HaveIBeenPwned.com — a trusted, independent service run by security researcher Troy Hunt that lets you check if your email has appeared in known breaches.
  • Check whether the breach has been reported by reputable news sources or security firms.

If the breach is confirmed, proceed immediately.

Step 2: Change the Compromised Password

If a password was exposed — even as a hash — change it on that service right away. Then check whether you've reused that password anywhere else. This is critical.

Password reuse is one of the most dangerous practices in digital security. If your LinkedIn password from a 2012 breach is the same as your current bank password, attackers are trying it right now. This attack is called credential stuffing and it's extremely common.

  • Change the exposed password on the breached site
  • Change it on every other site where you used the same password
  • Use a password manager to generate and store unique passwords for every account going forward

Step 3: Enable Two-Factor Authentication

Even if an attacker has your username and password, two-factor authentication (2FA) stops them from accessing your account without the second factor.

After a breach:

  • Enable 2FA on the breached account immediately
  • Use an authenticator app (Google Authenticator, Authy, or your password manager's built-in TOTP) rather than SMS when possible — SMS can be intercepted
  • Consider enabling 2FA on all important accounts proactively: email, banking, cloud storage

Step 4: Assess What Information Was Exposed

The breach notification should tell you what data was compromised. Your response depends on the severity:

Email address only:

  • Update your spam filters; expect increased phishing attempts targeting your address
  • Low immediate risk but monitor for follow-on attacks

Password exposed:

  • Follow Steps 2 and 3 above immediately

Payment card numbers:

  • Contact your bank or card issuer immediately — they will cancel and reissue the card
  • Review recent transactions for unauthorized charges
  • Dispute any fraudulent charges

Social Security number, date of birth, or government ID:

  • Freeze your credit at all three bureaus (Equifax, Experian, TransUnion) right away
  • Place a fraud alert
  • File a report at IdentityTheft.gov
  • Monitor all financial accounts closely for the next 12+ months

Step 5: Watch for Phishing Follow-Up Attacks

Breached data is sold on underground markets. Within days or weeks, you may receive highly targeted phishing attempts — emails, calls, or texts that reference the breached company or your specific information to appear credible.

  • Be deeply skeptical of any contact that references the breached company asking you to "verify your identity" or "confirm account details"
  • Legitimate companies will not ask for your password over email or phone
  • Report suspicious messages to the company's official security team

Step 6: Update Your Security Questions

If the breach exposed information like your address, birthday, or mother's maiden name, attackers may use it to answer your security questions and reset your passwords.

  • Review the security questions on your most important accounts
  • Replace real answers with random, nonsensical strings stored in your password manager — treat security question answers like passwords
  • Switch from security questions to authenticator app 2FA wherever possible

Step 7: Monitor Your Credit and Accounts

For significant breaches, set up ongoing monitoring:

  • Check your credit reports (free weekly at AnnualCreditReport.com in the US)
  • Set transaction alerts on all bank and credit card accounts
  • Sign up for a credit monitoring service — many banks offer these free, and some companies provide them as part of breach remediation
  • Watch for new accounts opened in your name or changes to your credit report

Building Breach-Resilient Habits

The most effective long-term protection comes from reducing the impact of any single breach:

  • Unique passwords everywhere — a breach at one site doesn't cascade
  • 2FA on critical accounts — stolen passwords become useless without the second factor
  • Minimal data sharing — only provide information that's actually required
  • Separate email addresses — use an alias or secondary address for less important signups
  • Regular monitoring — catch problems early when they're easier to resolve

Breaches are inevitable. Your response speed and preparation determine whether they become minor inconveniences or major crises.

#data breach#incident response#passwords#identity theft