- Privacy & Data
What To Do After a Data Breach: A Timed Checklist for the Person Whose Data Leaked (2026)
Every guide says freeze your credit and monitor forever. Here's the ordered version with the actual mechanics to help you move forward after a data breach.

If you just got a breach notification, do these in order. Find out exactly what was exposed, because the right response depends entirely on that. Change the password on the breached account and anywhere you reused it, starting with your email. If a Social Security number or financial data leaked, freeze your credit at all three bureaus. It's free and takes about a business day. Then go to identitytheft.gov/databreach for a plan built around what actually leaked. Then do the step the monitoring companies skip: decide whether you still want an account there at all.
That's the whole checklist. The rest is detail.
First, find out what actually leaked, because the answer changes everything
Breach notifications are vague on purpose. "Some of your information may have been affected" tells you nothing. But the response to a leaked email is not the response to a leaked Social Security number, and treating them the same wastes the one thing you have less of than money: attention.
What you do next depends entirely on what leaked. If only your email address was exposed, the immediate risk is phishing and credential stuffing — watch for scams that reference the breached company by name, since attackers will use that detail to sound credible. If your email and password both leaked, every account where you reused that password is now at risk of takeover; change it everywhere, starting with your email account. A compromised payment card enables fraudulent charges, so call your issuer, get the card replaced, and update your recurring payments. A leaked Social Security number or national ID is the most serious outcome — it lets someone open new accounts in your name, which means a credit freeze at all three bureaus is your first move. And if your address, phone number, or date of birth was exposed, that data can be used to bypass identity verification and fuel long-tail social engineering; place a fraud alert and treat any incoming call asking you to "verify your identity" as hostile until proven otherwise.
What you do next depends entirely on what leaked. If only your email address was exposed, the immediate risk is phishing and credential stuffing — watch for scams that reference the breached company by name, since attackers will use that detail to sound credible. If your email and password both leaked, every account where you reused that password is now at risk of takeover; change it everywhere, starting with your email account. A compromised payment card enables fraudulent charges, so call your issuer, get the card replaced, and update your recurring payments. A leaked Social Security number or national ID is the most serious outcome — it lets someone open new accounts in your name, which means a credit freeze at all three bureaus is your first move. And if your address, phone number, or date of birth was exposed, that data can be used to bypass identity verification and fuel long-tail social engineering; place a fraud alert and treat any incoming call asking you to "verify your identity" as hostile until proven otherwise.
Here's the part that determines how much of your year this eats. Some of this data expires. Some of it doesn't. A leaked password is fixable in ten seconds. A leaked date of birth is yours forever, and so is the person who now has it.
Sort your response by what leaked and the whole thing shrinks to an hour. Skip that step and you spend a year reacting to everything at once.
If your notification doesn't say what was exposed, check yourself. Breach Beacon is free, needs no signup, and runs on Have I Been Pwned data. One click tells you which breaches include your email. Start there, then come back.
The first hour
Do these in order. The order matters more than the speed.
- Change your email password first. Your inbox is the reset mechanism for every other account you own. Someone in your email can reset your bank, your card, your everything. It is the single point of failure, so it goes first. Make the new password long and unique.
- Turn on two-factor authentication for that email. A stolen password is useless if the login also needs a code on your phone. Do this now, while you're already in the settings.
- Change the breached account's password. The account named in the letter. Obvious, but people forget it in the panic of securing everything else.
- Change it everywhere you reused it. This is the step everyone skips, because it requires admitting how many places you reused that password. Be honest with yourself. Credential stuffing works precisely because most people reuse. If your breached password unlocks four other accounts, attackers will find all four.
One more thing about payment cards, since nobody mentions it. Replacing a compromised card is the right move. It also silently breaks every subscription billing to that card. You won't find out all at once. You'll find out one failed payment at a time, over the following months, usually when a service you actually wanted goes dark.
So after you replace the card, pull up your list of recurring charges and update each one. If you don't have that list, finding your subscriptions is worth doing now rather than discovering them by outage.
The first day, if financial or identity data was exposed
Everything above is free and fast. So is this. The numbers below are federally guaranteed, so any page that hedges on them is padding.
The credit freeze. A freeze stops anyone from opening new credit in your name. It's free to place and free to lift. It doesn't affect your credit score. It lasts until you lift it. You have to contact all three bureaus separately, because they don't talk to each other for this.
The timing, per usa.gov: placed within one business day if you request it online or by phone. Lifted within one hour, same channels. By mail it's three business days either way, which is why nobody uses mail.
The fraud alert. Lighter touch. You contact one bureau, and that bureau must notify the other two. It lasts one year and you can renew it. If identity theft has actually happened and you've filed an Identity Theft Report, you can get an extended alert that lasts seven years.
Here's the distinction the competitor pages blur. A freeze blocks new credit entirely, including credit you want to open yourself. A fraud alert doesn't block anything. It just tells lenders to verify you first. Different tools for different situations. A freeze is the wall. An alert is the doorbell.
Then go to identitytheft.gov/databreach directly, not to some blog's summary of it. The FTC builds you a recovery plan based on what leaked, and it covers the cases the antivirus blogs ignore: tax identity theft, medical identity theft, debt collectors, stolen government ID.
If the breached company offers free credit monitoring, take it. It costs you nothing, and free is free. Just don't mistake it for a fix. Monitoring tells you after something happens. It doesn't stop the thing from happening.
The step every other guide leaves out
Every breach guide ends the same way. Monitor your credit. Monitor your statements. Monitor your inbox. Forever.
Notice who writes that advice. Companies that sell monitoring. It isn't wrong, exactly. It's just incomplete in a very convenient direction. It treats a breach like weather — a thing that happens to you, that you brace for and endure — instead of what it actually is: a consequence of an inventory you built one signup at a time.
So here's the plainer version. The breach happened at a company. Which company? Most people can't say, because it was one they used once. A store they bought one thing from in 2019. A trial they forgot to cancel. That company still had their data, and now so does everyone else.
You cannot get breached at a company you left.
Now the honest part, because pretending this is easy would be its own kind of lie. Deletion is the right answer and it is also unreliable. Yorba analyzed nearly 22,000 formal deletion submissions in 2025. Only 48% resulted in verified deletion by the end of the year — and these were properly submitted and documented, not casual unsubscribe clicks. The stalled ones consumed an estimated 1,226 hours of professional labor. The obstacles were the same each time: repeat identity verification, redundant document requests, and companies simply refusing to deal with an authorized representative. Consumer Reports has seen the same pattern through its Permission Slip work.
So we're not selling you a magic button. We're telling you the button is worth pressing anyway, and that it's harder than it should be.
The practical version. Don't delete the breached account while you still need it for remediation — you may need to log in, dispute a charge, or read their updates. Delete it after. Then audit everything else, and prioritize by what a company holds, not how often you use it. A retailer with your card on file is a bigger liability than a newsletter you never open.
And keep one definition straight, because most companies count on you not knowing it. Deleting an account is not the same as deleting your data. A delete button often just deactivates a login while the record sits in a database, intact. Closing the door is not the same as emptying the room.
What to do for the next year, without buying anything
The panic passes. The vigilance shouldn't cost you anything.
Pull your free credit reports at AnnualCreditReport.com. You can check all three weekly, for free. Look for accounts you don't recognize, addresses that aren't yours, and inquiries from lenders you never contacted. Those are the early signs someone is using what leaked.
Then brace for the phishing wave, because it's coming. Attackers know exactly which company just breached you — the same name that's printed on the letter in your hand. That gives them a script. An email or call that references the real company, by name, at the exact moment you're expecting to hear from it.
That's the tell. A legitimate company recovering from a breach will not call you and ask you to verify your identity by reading back your details. Scammers will, because they're filling in the gaps in what they stole. When a call names the breached company and then asks you to confirm anything, hang up. Call back on a number you looked up yourself, never the one they gave you.
You don't need to buy protection to do any of this. You need to stay a little suspicious for a while.
Frequently asked questions
What should I do first after a data breach?
Find out what was exposed, then change your email password before anything else, since your inbox resets every other account. If a Social Security number or financial data leaked, freeze your credit. Then visit identitytheft.gov/databreach for a plan matched to what leaked.
Is a credit freeze free?
Yes. Placing and lifting a credit freeze is free at all three bureaus, and it doesn't affect your credit score. You just have to contact Equifax, Experian, and TransUnion separately, because they don't share the request.
How long does a credit freeze take to place and lift?
Placed within one business day if you request it online or by phone. Lifted within one hour, same channels. By mail, both take up to three business days. Online or phone is faster for everything.
Should I freeze my credit or set a fraud alert?
A freeze blocks all new credit in your name, including yours, until you lift it. A fraud alert doesn't block anything — it just makes lenders verify you first. Freeze if a Social Security number leaked. Alert for lighter situations.
Does deleting my account remove my data from a breach?
Deleting an account and deleting your data are not the same thing. A delete button often just deactivates your login while the record stays in the company's database. Once data has leaked in a breach, it's already out — but closing and deleting the account limits future exposure.
Can I be breached again at the same company?
Yes, as long as they still have your data. A company that leaked once can leak again, and keeping an unused account there means keeping your information in the target. You can't get breached at a company you've actually left.
You can't undo a breach. You can shrink what it touches next time. Start with Breach Beacon — free, no signup — to see exactly what leaked, then work down this list in order.
Less exposure. More quiet.
