Got a Data Breach Notice Letter? What It Means and What to Do
In the next 10 minutes
- Don't use the links or phone numbers in the notice. Look up the company's website or number yourself and confirm the breach is real.
- If a password was exposed, change it on that account and anywhere you reused it, then turn on two-factor authentication.
- If a card or bank account number was exposed, call your bank using the number on your card or statement.
- Freeze your credit at Equifax, Experian and TransUnion, especially if your Social Security number was exposed. It's free to place and lift.
- Enroll in any free credit monitoring the company offers, through a link or number you've verified. It alerts you but doesn't block new accounts.
- Check your credit reports free every week at AnnualCreditReport.com, and report any misuse at IdentityTheft.gov.
A letter or email says your information was part of a company’s data breach. Getting a notice doesn’t necessarily mean you’re an identity theft victim, California’s attorney general notes, but it is a reason to act. Here’s how to check that the notice is real, what each type of exposed data could be used for, and whether to take the free credit monitoring.
1. Check that the notice is real
Scammers pose as companies you know. They may claim there’s a problem with your account, or say you need to confirm personal or financial information (FTC). So check a breach notice before you do anything it asks.
- Don’t use its links or phone numbers to check it. For an email or text from a company you do business with, IdentityTheft.gov says not to click its links, even if you think it’s real, and not to use the contact details it gives you or the number on your caller ID (IdentityTheft.gov). Treat a paper letter the same way. A real notice should say how to reach the company, since the FTC tells businesses to include that (FTC). Confirm those details first.
- Contact the company yourself. Type its web address into your browser, or call a number from your statement, card or account. Some companies post breach updates on their own website (FTC). Ask whether the notice is theirs and what it covers.
- Look for it on a state list. Some state attorneys general publish the breach notices companies send them, such as California and Washington. California posts a sample of any notice sent to more than 500 California residents, so you can compare it with your letter.
- Notice what it asks for. The FTC tells companies to explain how the breach happened, what information was taken, what they’re doing about it, what help they’re offering and how to reach them (FTC). A message that asks you to confirm personal or financial information, or to click a link to make a payment, fits the FTC’s description of phishing (FTC).
2. Match your steps to what was exposed
Your notice should list the types of information involved. IdentityTheft.gov starts with one question: has anyone used your information, for example to open an account, make a purchase, file taxes or get government benefits?
- Yes: report it at IdentityTheft.gov and get a personal recovery plan.
- No, or you don’t know: take the protective steps below.
| What was exposed | What a thief could try to do | What to do |
|---|---|---|
| Social Security number | Open accounts, take out a loan, file taxes or get a job | Freeze your credit (step 3). Review your work history in a my Social Security account. Get an IRS Identity Protection PIN, which stops others from filing a tax return with your number. File taxes early and answer IRS letters right away. |
| Password or login | Shop with your account, pose as you on social media, send spam, or reach your personal or financial information | Change the password (and username, if you can) there and anywhere you reused it. Turn on two-factor authentication. Locked out? Contact the company (FTC). If your card is saved on the site, check for charges you don’t recognize. |
| Debit or credit card number | Make purchases | Call your bank or card company, using the number on the back of your card, to cancel it and get a new one. Review your transactions. Update any automatic payments. |
| Bank or investment account information | Get into your account or withdraw money | Tell your bank or investment company, close the account and open a new one. Review your transactions. Update automatic payments. |
| Driver’s license | Pretend to be you | Report it to your state motor vehicle agency. The state might flag your license number or suggest you apply for a duplicate. |
| Passport | Pretend to be you | Report it to the U.S. State Department at 1-877-487-2778 (TTY 1-888-874-7793). |
| Medicare, Medicaid or health insurance | Get medical care | Contact Medicare (1-800-633-4227), Medicaid or your insurer to report it and get a new card if needed. Watch for bills or benefit statements for care you didn’t get (FTC). |
| Your child’s information | Open accounts or get loans | Ask each bureau for a free credit freeze for your child, and ask each one whether your child has a credit report (FTC). |
Based on IdentityTheft.gov unless another source is linked.
For most types, IdentityTheft.gov also points you to the credit steps below. Only your name, email or phone number? It says to contact the organization involved and ask what you can do to keep an identity thief from using your information. Then use the step 1 checks on every message about the breach.
3. Freeze your credit, or at least add a fraud alert
The FTC calls a credit freeze always a good idea, and even more important when a data breach exposes your Social Security number or other information (FTC). While it’s on, nobody, including you, can open a new credit account in your name. It’s free to place and lift, and it doesn’t affect your credit score.
- Credit freeze: contact each bureau separately: Equifax, Experian and TransUnion. To apply for credit or a job, rent an apartment or buy insurance, lift it (ideally only at the bureau the lender uses), then put it back.
- Fraud alert: contact one bureau, and it must tell the other two. An initial alert lasts one year and can be renewed. You can add one even if you already have a freeze.
- Children under 16: you can request a free freeze for your child. Each bureau has its own process for minors.
Walkthrough: how to freeze (and unfreeze) your credit. Track all three bureaus with the credit freeze tracker. For more Social Security number steps, like an E-Verify lock, see I gave a scammer my Social Security number.
4. Should you accept the free credit monitoring?
In most cases, yes. IdentityTheft.gov’s advice is to accept free credit monitoring if a company offers it (IdentityTheft.gov). The FTC also tells companies to consider offering at least a year of it, especially when Social Security numbers or financial information were exposed (FTC).
Just know what it is: an alarm, not a lock.
| Credit freeze | Fraud alert | Credit monitoring | |
|---|---|---|---|
| What it does | Blocks new credit in your name while it’s on | Businesses must check with you before opening new credit; they can still see your report | Watches your credit reports and alerts you to changes |
| Stops new accounts? | Yes | Makes it harder | No |
| Cost | Free | Free | Usually a monthly or yearly fee, unless a company pays for it |
| How long it lasts | Until you lift it | One year, renewable | Depends on the offer |
| How to get it | Contact all three bureaus | Contact one bureau | Enroll in the company’s offer, or buy a service |
Sources: FTC, IdentityTheft.gov, FTC, California attorney general.
What monitoring won’t do:
- It won’t stop the theft. The CFPB says most monitoring services don’t keep your information from being stolen. They alert you after it happens.
- It won’t catch everything. Credit monitoring won’t alert you when someone takes money from your bank account, or uses your Social Security number to file a tax return and collect your refund (FTC). So keep the bank and IRS steps from the table.
Before you enroll:
- Get to the sign-up page through the company’s official website or a number you’ve checked, as in step 1.
- Check any “free” offer for hidden fees or cancellation requirements (CFPB).
- Ask which bureaus it watches and how often it checks them (FTC).
Free options: weekly credit reports for everyone (step 5), and free electronic credit monitoring from each bureau for active duty servicemembers and National Guard members (FTC).
5. Keep checking your credit reports
The three bureaus have permanently extended a program that lets you check your report from each one once a week for free at AnnualCreditReport.com (FTC). Checking your reports there won’t affect your credit scores, the site says.
If you see an account or debt you don’t recognize, contact the company. If someone used your information, report it at IdentityTheft.gov (IdentityTheft.gov). If a card or loan was opened in your name, see someone opened a credit card in my name.
Type that address yourself. The FTC warns that other sites pretend to be linked to AnnualCreditReport.com, and that neither it nor the bureaus will email you asking for your Social Security number (FTC).
What happens next
If nothing suspicious turns up, keep your freeze on and keep checking your reports.
If someone does use your information, report it at IdentityTheft.gov. If you create an account there, it walks you through each recovery step, tracks your progress and pre-fills letters and forms for you (IdentityTheft.gov).
Some breaches later lead to a settlement with benefits for the people affected, as the 2017 Equifax breach did (FTC). Check a settlement notice the same way as the breach notice, and find the settlement’s website yourself instead of clicking a link.
How to report it
- Someone used your information: report it at IdentityTheft.gov. To report in a language other than English or Spanish, call 1-877-438-4338 and press 3 (FTC).
- Charges or withdrawals you didn’t make: call your bank’s or card company’s fraud department, at the number on your card or statement, and ask to have them removed (IdentityTheft.gov).
- A fake breach notice: forward phishing emails to reportphishing@apwg.org and phishing texts to SPAM (7726). Then report it at ReportFraud.ftc.gov (FTC). The FTC shares reports with law enforcement but can’t resolve individual reports.
Watch for the follow-up scam
A breach gives scammers a believable story. The FTC tells companies to say how they’ll contact people afterward (for example, only by mail) to help victims avoid phishing scams tied to the breach (FTC). If your notice says that, a call “about the breach” is a red flag.
Watch for these, too:
- “Your information is for sale on the dark web.” Some list all or part of your Social Security number, your birth date or your driver’s license number. Don’t click links or call numbers in the message. If it might be real, contact the company through a website or number you know is real (FTC).
- Fake FTC calls. Scammers pose as the FTC and say someone used your information to open accounts. The FTC will never tell you to move your money to “protect it,” withdraw cash or buy gold (IdentityTheft.gov).
- Requests for your Social Security number. The IRS, your bank and your employer won’t call, email or text to ask for it (FTC).
- Fake settlement websites. The FTC warned that people may have started putting up fake websites that look like the official Equifax settlement claims site. It said you’d never have to pay to file a claim for those benefits, and that anyone who called pushing you to file was almost certainly a scammer (FTC).
What varies
- Your state’s law. All states, D.C., Puerto Rico and the U.S. Virgin Islands require breach notices, and state laws typically say what a notice must or must not include (FTC). That’s one reason letters look so different.
- What the company offers. Some notices include free monitoring and some don’t, and the length varies. The FTC suggests companies consider offering at least a year (FTC).
- Who sends the letter. It may come from a business other than the one that was breached. A bank, for example, may write about a card number stolen at a store (California attorney general).
- Tax timing. You get a new IP PIN every year, and it’s generally available in your IRS online account from mid-January through mid-November (IRS).
Sources
- Federal Trade Commission (IdentityTheft.gov): What To Do if Your Information Was Lost or Stolen, or Part of a Data Breach (accessed September 24, 2026)
- Federal Trade Commission (IdentityTheft.gov): IdentityTheft.gov (accessed September 24, 2026)
- Federal Trade Commission: How To Recognize and Avoid Phishing Scams (accessed September 24, 2026)
- Federal Trade Commission: Data Breach Response: A Guide for Business (accessed September 24, 2026)
- California Department of Justice, Office of the Attorney General: Search Data Security Breaches (accessed September 24, 2026)
- Washington State Office of the Attorney General: Data Breach Notifications Directory (accessed September 24, 2026)
- California Department of Justice, Office of the Attorney General: Identity Theft First Aid (accessed September 24, 2026)
- Social Security Administration: my Social Security (accessed September 24, 2026)
- Internal Revenue Service: Get an identity protection PIN (accessed September 24, 2026)
- Federal Trade Commission: Creating Strong Passwords and Other Ways To Protect Your Accounts (accessed September 24, 2026)
- Federal Trade Commission: How To Recover Your Hacked Email or Social Media Account (accessed September 24, 2026)
- USAGov: State motor vehicle services (accessed September 24, 2026)
- Federal Trade Commission: What To Know About Medical Identity Theft (accessed September 24, 2026)
- Federal Trade Commission: How To Protect Your Child From Identity Theft (accessed September 24, 2026)
- Federal Trade Commission: Credit Freezes and Fraud Alerts (accessed September 24, 2026)
- Equifax: Security Freeze | Freeze or Unfreeze Your Credit | Equifax® (accessed September 24, 2026)
- Experian: Freeze or Unfreeze Your Credit File for Free (accessed September 24, 2026)
- TransUnion: Credit Freeze | Freeze My Credit | TransUnion (accessed September 24, 2026)
- Federal Trade Commission: What To Know About Identity Theft (accessed September 24, 2026)
- Consumer Financial Protection Bureau: What is a credit monitoring service? (accessed September 24, 2026)
- Federal Trade Commission: Free Credit Reports (accessed September 24, 2026)
- AnnualCreditReport.com: Annual Credit Report (accessed September 24, 2026)
- Federal Trade Commission: Equifax Data Breach Settlement (accessed September 24, 2026)
- Federal Trade Commission: ReportFraud.ftc.gov (accessed September 24, 2026)
- Federal Trade Commission: Did you get an email saying your personal info is for sale on the dark web? (accessed September 24, 2026)
- Federal Trade Commission: Equifax Data Breach: Beware of Fake Settlement Websites (accessed September 24, 2026)
Related guides
How to Freeze (and Unfreeze) Your Credit: Equifax, Experian, TransUnion and the Ones People Forget
Official links and phone numbers to freeze and unfreeze your credit for free at Equifax, Experian and TransUnion, plus the extra bureaus people forget.
I Gave a Scammer My Social Security Number: What to Do Now
Gave your Social Security number to a scammer? What to do first: freeze your credit, protect your tax and Social Security records, and report it.
Someone Opened a Credit Card in My Name: What to Do
Found a credit card account you never opened? How to shut it down, report it at IdentityTheft.gov, freeze your credit and get it off your credit reports.
This guide is general information, not legal, financial or tax advice. Banks, card issuers and agencies change their procedures; always follow the official sources linked above. Found an error? Tell usand we will correct it.