What to Do After Your Data Is in a Breach
Breaches are constant, and most of what circulates afterwards ends up feeding the same data brokers you are trying to escape. Here is the order that actually matters.
1. Find out what is exposed
- Check haveibeenpwned.com for your email addresses and phone numbers — it is free, run by a respected security researcher, and does not spam you.
- Turn on notifications there so you hear about future breaches automatically.
- Check every email address you have used, not just your main one.
2. Lock the doors (same day)
- Change the password on the breached service, and anywhere you reused that password.
- Turn on two-factor authentication — an authenticator app or passkey, not SMS where you can avoid it.
- If payment details leaked, ask your bank for a new card number.
3. Freeze your credit (the step people skip)
A credit freeze is free, takes about 10 minutes per bureau, and is the single most effective protection against identity theft. It blocks new accounts being opened in your name. Do all four: Equifax, Experian, TransUnion and Innovis. You can thaw it temporarily whenever you need credit.
4. Clean up the fallout
- Breach data gets resold and ends up on people-search sites — work through the Start Here checklist.
- Expect a spike in phishing and spam using the leaked details; treat any unexpected message about the breach as suspicious.
- If your Social Security number leaked, request an IRS Identity Protection PIN to block fraudulent tax returns.
- Watch for medical identity theft if a healthcare provider was breached — check your explanation-of-benefits statements.
5. If your identity is already being used
Report it at IdentityTheft.gov, the FTC’s official service. It generates a personalised recovery plan and the affidavit letters that banks and creditors require.