Illustration for A Plain-Language Guide to Data Breach Notifications: What to Do When You Get One

A Plain-Language Guide to Data Breach Notifications: What to Do When You Get One

An email shows up with a subject line like “Important Security Notice” and your stomach drops a little. You open it and find out a company you’ve done business with, maybe a retailer, a healthcare portal, or an app you barely remember signing up for, just told you your information was involved in a breach. Now what?

Most people read a notice like this, feel a flash of worry, and then close the email and move on with their day. That’s understandable. The notices are often vague, full of legal hedging, and short on clear instructions. But a breach notification is one of the few times a company is legally required to tell you something went wrong, and it’s worth a few focused minutes rather than a shrug.

Here’s how to work through one calmly and actually get something useful done.

First, read the notice slowly and look for specifics

Breach notices vary a lot in how much they actually tell you. Some are detailed. Others are carefully worded to sound serious while saying very little. Either way, look for these specifics before you do anything else:

What kind of data was involved. Names and email addresses are a lower-stakes exposure than passwords, Social Security numbers, or financial account details. The type of data involved should shape how urgently you respond.

When the breach happened and when it was discovered. A gap between the two isn’t unusual, but it matters for how long your information may have already been circulating.

What the company is offering. Many notices include free credit monitoring or identity protection for a period of time. It’s usually worth signing up, even if you’re skeptical it’ll catch much. It costs you nothing and adds a layer of watchfulness you didn’t have before.

If the notice is confusing or you’re not sure it’s even real, don’t click anything inside it. Go directly to the company’s official website by typing the address yourself, and look for a security or trust page describing the incident. Scammers often use real breaches as cover for phishing, sending fake versions of these notices to people who are already anxious and primed to click. Treat an unexpected “your data was breached” email with the same caution you’d give any unsolicited link.

Change the password, and don’t stop at one account

If a password was part of the exposure, change it immediately on that account. Then take the extra step most people skip: check whether you’ve reused that password anywhere else.

This is the part that actually reduces your risk long term. People reuse passwords constantly, and attackers know it. If you’ve used the same password across multiple sites, a breach at one company can lead to break-ins at completely unrelated accounts, since attackers routinely try leaked usernames and passwords against other services to see what still works.

Use a password manager if you don’t already. It makes generating and storing unique passwords for every account far less painful, and it’s one of the more useful habits you can build for family digital safety in general.

Turn on multi-factor authentication wherever it’s offered, especially for email, banking, and anything tied to your identity. A stolen password is a lot less useful to an attacker if they also need a code from your phone.

If the breached account was your email, treat it with extra urgency. Email is often the key that opens password resets for everything else you own, so a compromised inbox is a bigger deal than it might first seem. If that’s the situation you’re in, this guide on what to do if your email account gets hacked walks through the recovery steps in more detail.

Watch for what comes after the breach, not just the breach itself

The initial exposure is only half the story. What tends to follow is a wave of scams that use the breach as cover.

  • Emails pretending to be the breached company, asking you to “verify your account” or “confirm your identity”
  • Phone calls claiming to be from your bank’s fraud department, referencing the breach to sound legitimate
  • Text messages with links to fake password reset pages
  • Fraudulent charity or fundraising asks that pop up after any high-profile incident, preying on people’s general sense of unease

That last pattern shows up a lot after disasters and major news events too, not just data breaches. If you want a sense of how these opportunistic scams get built and spread, how fake charity scams spike during late-summer disaster season covers the pattern well, and the warning signs translate directly to breach-related scams.

The general rule holds regardless of the scenario: a company that already has your information doesn’t need you to click a link to “confirm” it. If you’re worried, contact the company directly through a phone number or website you already trust, not one provided in the email or text you’re questioning.

Check your financial accounts and credit reports

If financial information, Social Security numbers, or account numbers were part of the breach, it’s worth a closer look at your broader financial picture, not just the one affected account.

Review recent statements on the accounts tied to the breach for any charges you don’t recognize.

Check your credit report. Reviewing your credit report lets you spot new accounts opened in your name that you didn’t authorize. Check with your country’s consumer protection agency or the major credit bureaus for how to request a copy and how often you can do so at no cost.

Consider a credit freeze if the exposure included something as sensitive as a Social Security number. A freeze restricts new lenders from accessing your credit file, which makes it harder for someone to open new accounts using your identity. Check with the credit bureaus directly for current costs and steps, since rules vary, but it’s generally considered one of the stronger protective steps available for serious exposures.

None of this guarantees nothing bad will happen. Security is layered, not absolute, and no single step here makes you immune to identity theft. But each layer makes you a harder, less appealing target, and that’s really what you’re going for.

If the breach affects a service your kid uses

Breaches aren’t limited to banks and retailers. Gaming platforms, school apps, and kid-focused services get breached too, and the notice might land in your inbox rather than theirs.

If a service your child uses is involved, walk through the same steps: change the password, check for reuse, and watch for follow-up scams that might target the child directly rather than you. It’s also a reasonable moment to have a broader conversation about the accounts and platforms they use day to day, including the online friends they’ve made over the summer and how comfortable they’d feel telling you if something seemed off. A breach notice is a good, low-drama excuse to open that conversation without it feeling like an interrogation.

A habit worth building either way

You’ll probably get more than one of these notices over the years. That’s just the reality of how much of daily life runs through accounts and apps now. The goal isn’t to panic every time one arrives, and it isn’t to ignore them either. It’s to have a routine: read it carefully, change what needs changing, watch for the scams that follow, and check your accounts for a while afterward. Once that routine is familiar, a breach notice stops feeling like a crisis and starts feeling like what it actually is: a prompt to do a few minutes of maintenance on your own security.

A quick safety note

This article is general information, not professional security, legal, or medical advice. No single tool or setting makes anyone completely safe; security works in layers. If you are dealing with a live incident, such as active fraud, ransomware, or a child in danger, contact the appropriate professionals or authorities. For a threat to a child, report it to the NCMEC CyberTipline at report.cybertip.org and to local law enforcement.

Tags: , , , , , ,
Previous Post
Illustration for How to Set Up a New Smartphone Safely, Step by Step
Safe Devices & Apps

How to Set Up a New Smartphone Safely, Step by Step

Next Post
Illustration for Understanding Ransomware: How It Gets In and Why Paying Isn't a Simple Fix
Malware & Ransomware

Understanding Ransomware: How It Gets In and Why Paying Isn’t a Simple Fix