Independent platform · No upfront fees · We are not a recovery firm

Home › Knowledge Hub › After a data breach notice

You got a data breach email. Now what?

By Golan Ben Moshe · Co-founder, Chain Pursuit · 9 min · Last updated 8 October 2026

Reviewed by the Chain Pursuit editorial team · Last reviewed 8 October 2026

A data breach notification means a company that held your information lost control of it. The right response depends entirely on what was exposed: a leaked email address is an annoyance, a leaked Social Security or national ID number is a years-long risk. Work out which you are facing, act on that, and treat every call, text or email that arrives afterwards as suspect, because breach victims are targeted within days.

Who this is for

Anyone who has received a letter or email saying their personal information was exposed in a breach of a company, app, exchange or service they used. You did nothing wrong, and there are useful things to do.

First, work out what was actually exposed

The notification should say. This is the single most important line in it, because the right response differs enormously, and panicking about the wrong thing wastes energy you will need.

What leakedHow seriousThe core risk
Email address onlyLowMore spam and phishing aimed at you
Email + passwordModerate to highAccount takeover, especially if you reuse passwords
Name, address, phoneLow to moderateMore convincing phishing and impersonation
Payment card numberModerateFraudulent charges; the bank usually covers these
Bank account detailsHighFraudulent transfers; harder to reverse
Social Security or national ID numberHigh, and lastingIdentity theft, fraudulent accounts, tax fraud
Government ID documentHighImpersonation that can pass identity checks

If several things leaked, act on the most serious one first and work down.

If a password was exposed

Change it now, on the breached service, to something you have never used anywhere else. Then change it anywhere you reused it, because attackers take a leaked email-and-password pair and try it on hundreds of other sites automatically. This is called credential stuffing, and reused passwords are what make it work.

Turn on two-factor authentication on the breached account and on your email. The FTC's own guidance is direct about this: two-factor makes it harder for someone to log in even if they have your password. Prefer an authenticator app over text messages where you can.

Start with your email account, before anything else, because whoever controls your email can reset the password on everything connected to it.

If a payment card or bank account was exposed

For a card: contact the issuer, or freeze the card in your banking app, and watch for charges you did not make. Card fraud is usually reversible and the bank typically absorbs it. A new card number closes the exposure.

For a bank account: call your bank, tell them the account details were in a breach, and ask what they recommend. Bank transfers are harder to reverse than card charges, so this one is worth a phone call rather than waiting.

Watch both for small test charges. Fraudsters often send a tiny amount first to check the account works before taking more.

If a Social Security or national ID number was exposed

This is the serious one, because unlike a password you cannot change it, and the risk lasts for years.

In the United States, the FTC recommends two tools, both free:

A credit freeze blocks access to your credit report, so new accounts generally cannot be opened in your name. It is free to place and free to lift, and you place it with each of the three bureaus, Experian, TransUnion and Equifax, separately.

A fraud alert asks businesses to verify your identity before opening new credit. It is free, lasts one year, and you only contact one bureau, which must tell the other two.

You can use both at once. A freeze is the stronger measure; a fraud alert is lighter and easier to live with.

Report the identity-theft risk at IdentityTheft.gov, which generates a personal recovery plan. In other countries the equivalent is your national data-protection authority or identity-theft service.

Watch for tax fraud specifically. Credit monitoring will not catch someone filing a tax return in your name to steal your refund, so it is a separate thing to watch for at tax time.

Outside the US the mechanism differs but the principle holds: a leaked national ID number is a lasting risk, your country's data-protection regulator will have guidance, and acting early is better than waiting for something to go wrong.

The part most people miss: the scams that follow

Here is the danger that the breach notification itself rarely spells out.

A breach puts you on a list. Within days of a breach becoming public, the people who hold the leaked data, or who bought it, start contacting the victims. They already know which company you dealt with, often your name, and sometimes more. That knowledge makes their approach far more convincing than ordinary spam.

The call that says "This is the fraud department at your bank, we've detected suspicious activity on your account following the breach" is the breach being weaponised against you, believable precisely because the breach was real.

The FTC's rule is the one to memorise: legitimate organisations that already have your information, your bank, the tax authority, your employer, will not call, email or text you out of the blue to ask for it. If someone does, it is a scammer, however much they seem to know.

So after a breach:

This overlaps with the impersonation scams we cover more broadly, and with AI voice cloning, which makes the follow-up call sound like someone you know.

If crypto or an exchange was involved

If the breached company was a cryptocurrency exchange or wallet service, the same rules apply with two additions.

No legitimate service will ever ask for your seed phrase, private key or recovery phrase to "secure your account after the breach." That request is the theft. Our guide on verifying support contacts covers how fake support operates.

Turn on withdrawal protections the exchange offers: a withdrawal allowlist, a holding period on new addresses, and app-based two-factor rather than SMS. Our guide to protecting an exchange account covers the settings.

Checklist

Straight away

If an ID number leaked

Then, for weeks afterward

What this guide cannot do

A breach is the company's failure, not yours, and some consequences are outside your control. These steps reduce the risk and do not eliminate it, and no measure makes an exposed ID number safe again. Monitoring and caution are the realistic tools.

This is general information, not legal or financial advice, and the specific tools vary by country.

If the breach has already led to money or accounts being taken, our guide to a compromised account covers the response, and our evidence checklist covers what to preserve.

Use Chain Pursuit's free tools to understand your options, preserve evidence, and identify possible recovery scams. Do not share your seed phrase or private keys with anyone.

Sources

Federal Trade Commission, What To Know About Identity Theft. https://consumer.ftc.gov/articles/what-know-about-identity-theft, credit freeze versus fraud alert, steps after SSN exposure, two-factor guidance, the rule that legitimate organisations do not contact you unexpectedly for personal information.

Federal Trade Commission, IdentityTheft.gov. https://www.identitytheft.gov/, personal recovery plan for identity theft following a breach.

Federal Trade Commission, Data Breach Response: A Guide for Business. https://www.ftc.gov/business-guidance/resources/data-breach-response-guide-business, what a notification should contain and the obligations behind it.

Guidance here reflects US FTC consumer advice as of October 2026. Equivalent tools and authorities differ by country; your national data-protection regulator is the authoritative source for your jurisdiction. Reviewed quarterly.

Frequently asked questions

A company emailed to say my data was breached. Is the email itself a scam?

It might be. Breach notifications are themselves imitated by scammers. Do not click links in the email. Instead, go to the company's website by typing the address yourself and look for the breach notice there, or contact them through details you find independently. A real breach will usually be reported in the news too.

What is the difference between a credit freeze and a fraud alert?

A credit freeze blocks access to your credit report so new accounts generally cannot be opened; you place it with each of the three bureaus separately, and it is free to place and lift. A fraud alert asks businesses to verify your identity before opening credit, lasts a year, and you set it with just one bureau. You can use both.

My password was in a breach but I have not noticed anything wrong. Am I safe?

Change it anyway, immediately, and anywhere you reused it. Attackers often sit on leaked credentials and try them later, or sell them on. The absence of a problem today is not evidence the credentials are safe.

Why am I suddenly getting scam calls after a breach?

Because the breach put your details on a list that scammers use. They know which company you dealt with, which makes their approach convincing. Treat any unexpected call, text or email about the breach as a scam, and never act on its links or numbers.

Someone called saying they are from my bank's fraud team about the breach. Is it real?

Assume not. Legitimate organisations that already hold your information do not call, text or email you out of the blue to ask for it or to have you move money. Hang up, and call your bank back on the number printed on your card.

The breach was at a crypto exchange. What is different?

The same steps apply, plus two things: no legitimate service ever needs your seed phrase or private key to secure your account, and you should turn on the exchange's withdrawal protections such as an address allowlist and app-based two-factor. Anyone asking for your recovery phrase after a breach is trying to steal your funds.

Should I pay for identity-theft protection or credit monitoring?

It is optional and it is not a cure. Monitoring tells you after something has happened; a credit freeze prevents some of it in the first place and is free. If a breached company offers free monitoring, taking it costs nothing, but do not assume it makes you safe.

How long does the risk last?

For a password, until you have changed it everywhere. For a card or bank detail, until the number is replaced. For a Social Security or national ID number, potentially years, because you cannot change it. That is why the ID-number case warrants a freeze and ongoing watchfulness rather than a one-time fix.

Worried the breach has led to something worse?

Eleven questions showing what can realistically be done if money or accounts are now at risk.

Check my case

Keep reading