What to Do After a Data Breach: A Step-by-Step Checklist

Receiving a notice that your data was part of a breach is stressful, but the response is fairly standard. Work through the checklist below in order, starting with the accounts that matter most.
1. Confirm the notice is real
Scammers send fake breach alerts. Go to the company’s official website or app yourself rather than clicking a link in the message.
2. Find out what was exposed
The notice should say which data was affected, for example email addresses, passwords, payment cards or identity numbers. The response depends on what leaked.
3. Change the password
Change the password on that service and on any other account where you used the same one. Use a unique password for each account from now on.
4. Turn on two-factor authentication
This protects the account even if the password is already in criminals’ hands.
5. If financial details were exposed
- Contact your bank or card issuer, and request a replacement card if needed.
- Review statements for unfamiliar transactions.
- Set up transaction alerts.
6. If identity details were exposed
Where available, place a fraud alert or credit freeze, check your credit reports and be alert to attempts to open accounts in your name.
7. Watch for follow-up scams
Criminals use leaked data to craft convincing phishing messages. Treat unexpected emails and calls, even those quoting accurate details, with suspicion.
8. Keep records
Save the breach notice and note the steps you took, in case you need to dispute fraud later.


