Scams & Consumer Rights

    What to Do After a Data Breach Notice, in Order

    The response depends entirely on what leaked. Sort the notice into tiers, freeze if a Social Security number is involved, and know what the free monitoring is really worth.

    7 min readPublished August 19, 2026Last reviewed August 27, 2026
    WW

    The Wallet Wisdom Team

    Editorial Team

    The letter arrives months after the event, written by a lawyer, and it takes four paragraphs to say that a company you may not remember doing business with lost a file containing your name and Social Security number. Enclosed: a code for a year of free credit monitoring.

    The instinct is either to panic or to file it in the drawer with the last three. Neither is right. What matters is a short, ordered set of steps whose priority depends entirely on one question — what specifically was exposed.

    Read the notice for the one detail that changes everything

    Breach notices are vague by construction, but they nearly always identify the data elements involved. Sort them:

    • Social Security number, driver's license or state ID number, passport number: the serious tier. These are the keys to opening new accounts in your name, and unlike a card number they can't be reissued. Freeze your credit.
    • Card or account number with the security code or password that would allow access: call the issuer and get the card reissued. Your liability on a credit card is capped at $50 by federal law and issuers routinely waive it.
    • Username or email plus a password or security answer: change that password everywhere you reused it, starting with your email account, which is the master key to resetting everything else.
    • Medical information, health insurance identifiers, or biometric data: harder to act on, but worth watching explanation-of-benefits statements for care you never received.
    • Name, address, phone number alone: annoying, not urgent. This information is already largely public.

    The tiers matter because acting on all of them at the same intensity is how people burn out on step two and never get to the freeze.

    The order of operations

    1. Freeze your credit at all three nationwide bureaus — Equifax, Experian, TransUnion — if a Social Security number was exposed. It's free, it doesn't affect your score, and while it's in place nobody can open a new credit account in your name, including you. You have to do it separately at each bureau; there's no single switch.
    2. Change the passwords that were exposed, and any account where you reused them. Email first. Turn on two-factor authentication, app-based rather than text where you're offered the choice.
    3. Pull your credit reports and read them line by line — accounts you don't recognize, hard inquiries you didn't authorize, addresses you've never lived at. AnnualCreditReport.com is the only federally authorized source and reports are free weekly from all three bureaus. Never pay for your own report.
    4. Get an IRS Identity Protection PIN at irs.gov/ippin if your Social Security number was in the breach. It's six digits and it stops anyone else from filing a return under your number.
    5. Turn on transaction alerts at your bank and card issuers. This is the free monitoring that actually catches things, because it fires in minutes rather than weeks.
    6. Only if something has already been misused: go to IdentityTheft.gov, which generates the FTC Identity Theft Report that unlocks the blocking and dispute rights described in our identity theft recovery guide.

    Steps one through five take about an hour total and cost nothing. That hour is the entire realistic response to a breach.

    Freeze vs. fraud alert, since the notice will offer you the weaker one

    A credit freeze blocks access to your file, so a lender can't pull it and therefore won't approve new credit. It lasts until you lift it. Free to place, free to lift, temporary lifts take minutes online when you actually need credit.

    A fraud alert only tells businesses to verify your identity before granting credit. It doesn't stop them from seeing your file. Three versions exist: an initial alert lasting one year, an extended alert lasting seven years that requires an FTC identity theft report or a police report and takes you off prescreened credit and insurance marketing lists for five years, and an active duty alert for servicemembers. For fraud alerts you contact one bureau and it must notify the other two — the opposite of freezes.

    Freeze beats alert in almost every case. Place both if you like; they stack.

    If you have children, freeze theirs too. Freezes are free for children under 16 and each bureau has a separate process for minors. Child identity theft typically goes undiscovered until the kid applies for a student loan at eighteen, at which point there are ten years of accounts to unwind.

    The bureaus nobody mentions

    The big three aren't the only companies keeping files on you. The CFPB maintains a public list of consumer reporting companies covering employment screening, tenant screening, bank account and check screening, insurance, telecom and utilities, and general fraud-risk data — 60-plus companies, many of which accept freeze requests.

    A few that come up repeatedly and are worth knowing by name: the National Consumer Telecom & Utilities Exchange, which utilities and phone companies check when you open service; Innovis, a fourth credit file most people have never heard of; and the LexisNexis products insurers use for claims and driving history. There are also bank-account screening companies that decide whether you can open a checking account at all — our identity theft guide covers pulling and disputing those.

    Freezing all of them is overkill for a routine breach. It's proportionate when someone is actively opening accounts in your name and the credit freeze pushed them toward utilities and bank accounts instead.

    When the law entitles you to monitoring — and when it doesn't

    There is no single federal breach notification law for consumer data. Every state has its own, and they differ on what triggers notice, how fast, and what the company owes you.

    California's is the one most often cited because it's broad and because so many companies simply apply it nationwide rather than run 50 versions. Under California Civil Code section 1798.82, a business must notify any California resident whose unencrypted personal information was acquired without authorization. And if the notifying business was itself the source of the breach and the exposed data included a Social Security number, driver's license, state ID, passport, or similar government identifier, it must offer identity theft prevention and mitigation services at no cost for at least 12 months.

    That's the origin of most of those enclosed codes. It's a floor, not a favor, and it's a state statute — your entitlement depends on where you live and what leaked. Some states set longer minimums; some set none at all.

    California also requires any business notifying more than 500 California residents about a single breach to file a sample notice with the state Attorney General, who publishes them in a searchable public database. That database is genuinely useful: if you're trying to work out whether a vague letter is real, or what a company actually disclosed, the filed copy is there.

    What free credit monitoring is actually worth

    Enroll — it's free, and the FTC's advice when a breached company offers it is to take it. Just be clear about what you're getting.

    Monitoring watches your credit file and tells you after something appears on it. That's detection, not prevention. A freeze is prevention: the account never gets opened, so there is nothing to alert you about. Monitoring is the smoke alarm; the freeze is not keeping gasoline in the kitchen.

    It's also usually single-bureau, so it can miss activity reported elsewhere; it expires in 12 or 24 months, after which the same product costs money; and the bundled "$1 million identity theft insurance" mostly reimburses incidental expenses like notarization and lost wages, not stolen funds — which your bank and card issuer already cover under the federal liability rules.

    So take the free year. Do not convert it to a paid subscription when it lapses, and do not buy one preemptively. Our review of identity protection services runs the full comparison, and the conclusion is short: the free tools are the strong ones.

    Things not to do

    • Don't click links in the breach notice email. Breach notifications are a favorite phishing template precisely because people are expecting them. Type the company's address yourself, or use the enrollment code on a page you navigated to independently.
    • Don't respond to a call about the breach. Nobody legitimate calls you about a data breach to "verify" your Social Security number.
    • Don't join the class action expecting money. Consumer data breach settlements commonly pay out small amounts per person after fees, and take years. Sign up if you want; budget zero.
    • Don't skip the freeze because it sounds like a hassle. It is roughly fifteen minutes per bureau the first time, and a two-minute thaw thereafter.

    One realistic note to close on. Your Social Security number has very likely already been exposed somewhere, more than once, and no amount of vigilance undoes that. What you can control is whether it's useful to anyone — which is what a freeze does, permanently and for free. Do it this week for everyone in your household and stop thinking about the letters.

    Sources and further reading

    The claims in this article were checked against the primary sources below. Programs, limits and costs change, so the official pages are always the final word.

    1. Credit Freezes and Fraud AlertsFederal Trade CommissionHow freezes work, the three types of fraud alert and their durations, and freezing a child's credit.
    2. Free Credit ReportsFederal Trade CommissionAnnualCreditReport.com as the only authorized source and the free weekly report entitlement.
    3. California Civil Code section 1798.82California Legislative InformationBreach notification duty, the definition of personal information, and the requirement to offer at least 12 months of identity theft prevention services at no cost.
    4. Data Security Breach ReportingCalifornia Office of the Attorney GeneralThe 500-resident filing threshold and the state's searchable public database of submitted breach notices.
    5. List of consumer reporting companiesConsumer Financial Protection BureauThe specialty reporting companies beyond the big three, including which accept freeze requests.

    Related Articles