Got a Data Breach Notice? What to Do Now
Data Breach · Consumer Response Guide

Got a Data Breach Notice? What to Do Now—and Whether You May Receive Compensation

Published September 12, 2025
Updated August 11, 2026

A breach notice is a signal to act, but the right response depends on what was exposed. Use this guide to protect your identity, accounts, payment cards and medical records—and to preserve the proof a later class action settlement may require.

Computer screen displaying a data breach warning while a person reviews what to do next

Quick answer: Save the notice, verify it without using an unexpected message link, identify the exposed data and take the matching protective steps below. If you see actual identity theft or fraud, start a recovery plan at IdentityTheft.gov.

This page provides general educational information, not legal, financial, medical or cybersecurity advice. Follow instructions from verified account providers and government agencies for your circumstances.

The First Five Steps After a Data Breach Notice

  1. Preserve the notice. Keep the email or letter, its envelope, any incident dates, and every claimant, enrollment or reference number. Take a screenshot or scan in case the original is lost.
  2. Verify it independently. Reach the organization through an app, account bookmark or web address you locate yourself. Do not enter credentials through a link in an unexpected email or text. A convincing notice can still be a phishing attempt.
  3. Find the exposed-data list. Names and email addresses call for a different response than Social Security numbers, payment-card data, medical records or government IDs. Look for language explaining what the investigation found about your information—not only what the company collected generally.
  4. Use free protective services carefully. If the notice offers credit or identity monitoring, confirm the enrollment site and deadline independently. Save the confirmation. Do not assume monitoring prevents new-account fraud.
  5. Escalate if information was misused. The Federal Trade Commission directs consumers with identity theft to IdentityTheft.gov’s breach recovery process, which creates steps tailored to the information and misuse involved.


What to Do, Organized by the Data Exposed

The notice may list several categories. Complete every row that applies; taking action for a stolen card does not address an exposed Social Security number, and a credit freeze does not secure a reused password.
Exposed data Do now Then monitor Main risk
Social Security number or tax ID Freeze credit with all three nationwide bureaus; review credit reports; consider a fraud alert and an IRS Identity Protection PIN. New accounts, unfamiliar inquiries, address changes, Social Security earnings and tax-return problems. Long-term identity, employment, benefit and tax fraud.
Password or online login Change the affected password and every reused version; secure recovery details; sign out unknown sessions; turn on multi-factor authentication. Login alerts, changed settings, forwarding rules, purchases, password-reset messages and recovery attempts. Account takeover and attacks on other accounts using reused credentials.
Payment card or bank data Contact the issuer through the number or app you already use; report suspicious activity; replace the card or PIN if advised; update automatic payments after replacement. Pending and posted transactions, small test charges, transfers, new payees and account alerts. Unauthorized use of an existing account.
Medical or insurance information Review bills and explanation-of-benefits statements; request records; dispute care you did not receive; secure the patient portal and insurer account. Unknown treatment, prescriptions, equipment, insurance claims, benefit changes and medical debt. Medical identity theft, false records, benefit use and privacy harm.
Driver’s license or state ID Ask the issuing motor vehicle agency whether it can flag or replace the credential; follow state-specific instructions; protect any other exposed identity data. Credit reports, traffic or identity notices, account-verification attempts and actual use of the ID. Impersonation, account opening and fraudulent identification.

If Your Social Security Number Was Exposed

A Social Security number cannot be made secret again, so the goal is to restrict new credit and watch the systems where the number could be misused.

Place a free credit freeze separately with Equifax, Experian and TransUnion. Then obtain your reports through AnnualCreditReport.com and look for accounts, inquiries or addresses you do not recognize. The FTC says a freeze is available to anyone, lasts until lifted and does not affect a credit score. You can temporarily lift it when legitimately applying for credit.

A fraud alert is another free option. It asks lenders reviewing the file to take extra steps to verify identity, but it does not restrict file access as a freeze does. If you see actual misuse, report it through IdentityTheft.gov rather than relying only on monitoring or an alert.

Also review your earnings record through your personal Social Security account for work you do not recognize. For tax-return protection, the IRS allows eligible taxpayers to request a free Identity Protection PIN, which helps stop someone else from filing a federal return using that SSN or ITIN.

For one ordered response, use OCA’s Social Security number exposure checklist. If you find actual misuse rather than exposure alone, move to the identity-theft recovery timeline for the first day, week and month.

If a Password or Login Was Exposed

Change the affected password immediately. If it was used anywhere else—even with a small variation—change those accounts too. Use a different, long password for every account; a password manager can generate and store them.

Turn on multi-factor authentication. The FTC’s account-security guidance explains that a second factor makes a stolen password less useful to an attacker. When the service offers options, an authenticator app or security key can avoid some risks associated with text-message codes.

Review recent login activity, active sessions, connected apps, account recovery email and phone settings, and any mail-forwarding rules. Sign out devices you do not recognize. If the breached account stored a payment method, inspect its transactions too. Do not treat a credit freeze as a substitute: freezes generally address new credit, not access to an existing account.

If Payment-Card or Bank Information Was Exposed

Reach the card issuer or bank through its official app, a saved web address or the contact information already printed on your card. Review pending and completed activity, report anything suspicious promptly and follow the issuer’s instructions about locking or replacing the card and changing a PIN.

The Consumer Financial Protection Bureau advises consumers to keep checking their accounts after card data is compromised and to report suspicious transactions promptly. If a replacement card is issued, update legitimate subscriptions and automatic payments only after receiving the new details. Keep the old and new card’s last four digits, report dates, dispute confirmations and any reimbursement records in your breach file.

If Medical or Health-Insurance Information Was Exposed

Medical identity theft may appear as a service, prescription, device or insurance claim you never received. Review medical bills, insurer explanation-of-benefits statements and patient-portal activity. Ask providers and insurers for the records relevant to the suspected use, and challenge inaccuracies in writing.

The FTC’s medical identity theft guidance recommends checking records and credit reports for unfamiliar medical activity or debt. A credit freeze may help when an SSN or other identity data was also exposed, but it will not correct a false diagnosis, treatment or insurance entry. Protect the portal password, turn on multi-factor authentication where offered, and use IdentityTheft.gov if someone actually used your identity.

OCA’s medical identity theft guide explains how to review claims, dispute entries and protect future care from information that belongs to someone else.

If a Driver’s License or State ID Was Exposed

Rules for compromised licenses differ by state. Contact the issuing state’s motor vehicle agency through its official website and ask whether it recommends a replacement, a record flag or another state-specific step. USA.gov’s document-replacement directory routes consumers to state motor vehicle agencies.

Replacing the physical credential may not erase a copied license image or number. Continue monitoring for account-verification attempts and check your credit reports. If the notice also lists an SSN, date of birth or financial information, complete the steps for those categories too. Document any actual attempt to use the ID and report identity theft through IdentityTheft.gov.

Credit Freeze vs. Fraud Alert vs. Credit Monitoring

These tools solve different problems. The strongest response often combines prevention with detection.
Tool What it does What it does not do Key detail
Credit freeze Restricts access to a credit file, helping stop new credit accounts opened in your name. Does not prevent misuse of an existing card, bank, medical or online account. Free; place it with all three nationwide bureaus; remains until you lift it.
Fraud alert Tells a prospective lender to take added steps to verify identity before extending credit. Does not lock the credit file. Free; an initial alert is useful when you suspect fraud but still want creditors to access the file.
Credit or identity monitoring Notifies you about covered changes or signs of misuse after they are detected. Usually does not block fraud and may not watch every account or identity system. Enroll only through a verified service and keep the confirmation and expiration date.
The FTC’s current credit-freeze and fraud-alert guidance explains how the options differ and links to the nationwide bureaus. A company’s free monitoring offer can be worth accepting, but it should not delay a freeze when sensitive identity information was exposed.

See OCA’s side-by-side freeze, fraud-alert and credit-monitoring comparison for duration, cost and practical limits.

What to Document—and Why It Matters

Good records help with account disputes, identity-theft recovery and any later request for documented settlement losses. Create one folder and keep: Keep unredacted identity documents secure. A legitimate settlement claim may request supporting records, but do not send originals and do not provide more sensitive information than the verified form requires.

How to Use Free Monitoring Without Overestimating It

Verify the enrollment website independently, register before the notice deadline and retain the confirmation. Record when coverage ends so an expiring service does not create a blind spot.

Monitoring is an alarm, not a lock. It can help identify covered activity, but it may not stop a fraudulent application or detect a charge on an existing card, a changed medical record, a false tax filing or a takeover of an unrelated account. Read what the offer actually monitors and whether identity-restoration help or insurance is included. Free monitoring is a protective service; it is not the same thing as a cash settlement payment.

Does a Data Breach Notice Mean You May Receive Compensation?

It means the notice and your records are worth keeping. It does not mean a settlement exists, a class has been certified or money is automatically available.

An incident notice usually comes from the breached organization and describes a security event. A settlement notice comes later, if litigation resolves, and identifies a case, a defined class, benefits, deadlines and a court-appointed administrator. Some breaches never produce a class action. Some lawsuits are dismissed or remain unresolved. Some settlements provide monitoring or identity-restoration services, while others may offer a cash payment, reimbursement for documented losses, compensation for lost time, or a combination.

Eligibility is settlement-specific. Check whether: Filing a standard class settlement claim is generally free. Do not pay someone to “unlock” a payout, and do not assume a message is genuine because it uses the breached company’s name. Open Class Actions tracks current cases in the open data breach settlement hub, but the court-approved notice and administrator remain the controlling sources for each claim.

The volume of litigation is one reason to preserve records early. The International Association of Privacy Professionals reported that a privacy attorney speaking at its 2026 summit cited more than 3,000 data-breach class actions filed in 2025. That reported filing count does not mean every incident produces a payment—or that filing a lawsuit is the same as obtaining a settlement.

Watch for a Second Wave of Scams

Breach notices give scammers a timely story. Be skeptical of callers or messages that demand payment, rush you to “confirm” an SSN, ask for a one-time authentication code, or promise guaranteed settlement money. Navigate to known accounts yourself, and compare any later settlement message with the official case notice before supplying information.

A legitimate claim form should explain the case, class definition, court, administrator, deadlines and available options. It should not require a fee to submit a routine class member claim. See our separate guide to verifying a class action settlement email when a notice arrives electronically.

Frequently Asked Questions

  1. What should I do first after receiving a data breach notice?
    Save the notice, verify it through a website or account you reach independently, identify exactly which information was exposed, and take the response steps that match that data. Avoid signing in through an unexpected email or text link.
  2. Should I freeze my credit if my Social Security number was exposed?
    A credit freeze is a strong preventive step when a Social Security number or similarly sensitive identity data was exposed. A freeze is free, does not affect a credit score, and must be placed separately with each of the three nationwide credit bureaus.
  3. What is the difference between a credit freeze and a fraud alert?
    A credit freeze restricts access to a credit file and helps block new accounts. A fraud alert keeps the file available but tells prospective lenders to take added steps to verify identity. Credit monitoring is different from both because it generally reports activity after it appears.
  4. Is free credit monitoring enough after a data breach?
    Free monitoring can be useful, but it usually detects certain activity rather than preventing it. It does not replace a credit freeze and may not cover payment-card misuse, medical identity theft, tax fraud or takeovers of existing online accounts.
  5. Does a data breach notice mean I qualify for compensation?
    Not by itself. An incident notice says an organization believes information may have been involved in a breach. Compensation generally requires a later settlement or another legal remedy with a defined class, covered incident, eligibility dates and claim process.
  6. What records should I keep after a data breach?
    Keep the breach notice, envelope or email, notice ID or PIN, monitoring enrollment confirmation, credit-freeze confirmations, credit reports, disputed charges, bank case numbers, medical records or explanation-of-benefits statements, receipts, screenshots and a dated log of time spent responding.
  7. What should I do if medical information was exposed?
    Review explanation-of-benefits statements, bills and patient-portal activity for care you did not receive. Request relevant records, dispute inaccuracies in writing with the provider or insurer, protect the portal account, and use IdentityTheft.gov if someone used your identity.
  8. Do I need a lawyer to file a data breach settlement claim?
    Usually no. Class members can generally submit a claim to the court-appointed settlement administrator without paying a filing fee. Use the official settlement notice and website, follow the class definition and deadline, and keep a copy of everything submitted.


Official Guidance and Research Sources


More Data Breach Help