What to Do After a Data Breach
The breach notice is in your inbox. Eight steps, in priority order, completable in one weekend. Do them in sequence — order matters.
- Freeze credit at all three bureaus (30 min). Equifax, Experian, TransUnion — free online freezes that block new-account fraud cold. This is step one, always.
- Change the breached password everywhere reused (30 min). Start with email, banking, and anywhere sharing that password. Unique passwords from here on — see our password manager guide.
- Enable two-factor on email + banking (20 min). Authenticator app preferred over SMS. Email first: it resets everything else.
- Pull free credit reports (15 min). AnnualCreditReport.com — scan all three for accounts you did not open.
- Set bank transaction alerts (15 min). Push alerts for every charge over $1 for the next 90 days. Early detection beats every recovery tool.
- File IRS + FTC paperwork if SSN leaked (30 min). IRS Identity Protection PIN plus an FTC report at IdentityTheft.gov create the paper trail recovery needs.
- Watch for follow-on phishing (ongoing). Breached data arms targeted scams within weeks. Review how to verify anything suspicious.
- Take the free monitoring, skip the panic buys (10 min). Accept the company's offered monitoring; your freeze plus alerts do the heavy lifting.
Quick answers
What is the first thing to do after a data breach?
Freeze your credit with all three bureaus — free, minutes each, blocks new-account fraud. Then change the breached password everywhere you reused it.
Should I pay for identity theft monitoring after a breach?
Take the free monitoring offered, but your own freeze plus free reports do most of the work. Paid monitoring is optional, not essential.
The uncomfortable truth: your data has likely breached already, possibly many times. These steps are not incident response — they are baseline hygiene for modern life. Do them once, keep the freeze on, and breaches become notifications instead of emergencies.