What to do after a data breach: the first hour, day, week and month
Breach / exposure. Updated 2026-09-13. About 5 minutes to read.
Secure your main email account first, then change every reused password, then deal with cards and credit.
A breach notice or a breach check result tells you that a copy of your data is out. What you do in the next hour matters more than anything you do next month, because criminals test stolen email and password pairs against other sites quickly.
Follow one rule before everything else: secure your email account first, even if the breached company had nothing to do with your email. Whoever controls your inbox can reset the password on your bank, your shopping accounts and your social media.
The email-account-first rule
Almost every online account lets you reset its password by email. That makes your inbox the master key. If an attacker gets into it, they can quietly reset other accounts and delete the warning emails before you see them.
So the first password you change is your email password, and the first account where you turn on two-factor authentication is your email account. Only then move on to the site that was breached.
Do not click links in a breach notice. Scammers send fake notices after real breaches. Type the company's web address yourself.
The first hour
Change your email password to a new, unique one of at least 15 characters. A few random words works well.
Turn on two-factor authentication for your email, using an authenticator app or a passkey rather than text messages where you can.
In your email settings, check forwarding rules, filters, recovery phone number, recovery email and connected apps. Remove anything you did not set up, then sign out of all other sessions.
Change the password on the breached site, then on every other site where you used the same or a similar password.
If card details were in the breach, call your bank or card issuer on the number on the back of the card and ask for a replacement card.
The first day: read what was taken
The notice or breach record lists data types. Each one points to a specific action.
Password or password hash: change it everywhere it was used and move to a password manager so every site gets a different password.
Email address only: expect targeted phishing that mentions the breached company by name.
Phone number: ask your carrier for a port-out PIN or number lock, and expect scam texts.
Card number: have the card reissued and turn on transaction alerts.
Date of birth, address or security answers: change any security questions that use them on banking and email accounts.
Social Security number, tax file number, passport or licence number: move to the week one steps below today, not next week.
The first week: lock down credit and identity
United States: place a free credit freeze at Equifax, Experian and TransUnion. Freezes have been free under federal law since September 2018 and do not affect your credit score.
United States, optional: place a one-year fraud alert at any one bureau, which must pass it to the other two.
Australia: request a ban on your credit report with Equifax and Experian (illion is now part of Experian). A ban lasts 21 days and can be extended. Call IDCARE on 1800 595 160 for a free response plan.
United Kingdom: check your statutory credit reports at Experian, Equifax and TransUnion, and consider Cifas Protective Registration, which costs 30 pounds for two years.
Canada: place a fraud alert with Equifax Canada and TransUnion Canada, or a free freeze if you live in Quebec or Ontario.
If a passport or licence number was taken, ask the issuing agency whether it recommends a replacement.
The first month: watch for misuse
Pull your US credit reports each week for the first month at AnnualCreditReport.com, where weekly reports are free permanently.
Read every bank and card statement line by line, looking for small test charges as well as large ones.
Watch your mail. Missing statements or a sudden stop in post can mean someone redirected it.
US taxpayers whose Social Security number was exposed can get an Identity Protection PIN from the IRS to block fake returns.
Expect phishing that quotes the real breach, offers compensation or asks you to verify your account. Treat all of it as a scam until you confirm through the company's own site.
Should you accept the free credit monitoring?
Usually yes. It costs nothing, and the enrollment deadline is often short. But monitoring tells you after someone applies for credit in your name, while a freeze stops the application in the first place. Take the monitoring and place the freeze.
Enroll using the code in the official letter, and type the web address from the letter yourself. Never enroll through a link in an email you cannot verify.
Frequently asked questions
How do I know if a breach notification is real?
Do not use any link or phone number in the message. Go to the company's website by typing the address, or call a number from a statement or the back of your card, and ask. Real notices do not ask for your password.
Should I change my email address after a breach?
Usually not. A new password and two-factor authentication protect the account. Changing addresses makes sense only if the old one receives so much spam and phishing that you cannot manage it.
How long should I watch my accounts after a breach?
Watch closely for the first 90 days, then keep bank alerts and breach notifications on permanently. Stolen identity data can be used years later, which is why a credit freeze you leave in place is worth more than short-term watching.
Can I claim compensation after a data breach?
Sometimes. In the US, compensation usually comes through class action settlements. In the UK, data protection law allows claims for damage and distress. In Australia you can complain to the OAIC. Never pay an upfront fee to a firm that contacts you out of the blue.
Is it safe to keep using the breached website?
It can be, once you have a unique password and two-factor authentication on it. If the company handled the breach badly or you no longer need the account, delete it so there is less of your data left to lose.