What to do after a data breach

Change the right passwords, turn on 2FA, ignore the fake helpers, and cut the blast radius.

Article

What to do after a data breach

Change the right passwords, turn on 2FA, ignore the fake helpers, and cut the blast radius.

A data breach is when an organization loses control of information it held about you: emails, passwords, phone numbers, sometimes documents or card data. You hear about it in the news or in a mail that says “we take privacy seriously.” Cyber security after a breach is a checklist, not a vibe.

What probably leaked

The company’s notice should say. If it does not, assume email and password if you had an account, and assume extra profile fields if you filled them. Password reuse is the part you can still fix. The dump is already out.

Have I Been Pwned and similar services can tell you whether an address appeared in known dumps. They are a starting point, not a guarantee that you are clean.

Credit monitoring is a product. Freezing credit where you live is often the more direct move if identifiers like a national ID or a Social Security number were in the pile.

The first day

Change the password on the breached site from a device you trust. If you reused that password, change it everywhere it was reused, starting with email. A password manager makes this visible: you can see the duplicates.

Turn on two-factor on the important accounts if it was off. Review sessions and app passwords. Kick anything you do not recognize.

If a card number was stored, watch the statement and consider a new number from the issuer. If a driver’s license scan was in the cache, treat identity theft as a real path, not a headline.

Do not send extra copies of ID to a “recovery specialist” who mailed you the same day. Scammers ride the news.

What not to do

Do not click the first search-ad “breach help” firm. Do not install a cleaner because a pop-up mentioned the company’s name. Do not reuse the new password.

If the mail looks off — bad domain, urgency, a request to enter the old password to “confirm you are safe” — it may be phishing that only pretends to be the notice.

After the noise fades

  • Unique passwords going forward, stored in a manager.
  • 2FA on mail and money.
  • Fewer optional profile fields on new sites. They cannot leak what you did not give.
  • A calendar note in three months to look at credit and at that site’s login list again.

A breach is the other party’s failure. Your job is to cut the blast radius: different passwords, a second factor, and no extra identity handed to a stranger who is only in your inbox because the news is hot.

Back to Learn