Breaches & Passwords

What to Do Right After a Data Breach

By the RedactZero Team · July 23, 2026 · 8 min read

The short version

A breach notice is a to-do list, not a catastrophe. Work in this order: find out exactly what leaked, change that password everywhere you reused it, turn on two-factor authentication, then freeze your credit at all three bureaus if anything financial or your Social Security number was exposed - it is free by federal law. After that, treat every unexpected email, text, or call about the breach as a possible follow-up scam. Most breach damage happens in the days after the leak, and each step here closes a door before someone walks through it.

First: find out exactly what leaked

Start by reading the breach notice carefully, because what leaked decides everything else. A stolen password calls for different first moves than a stolen Social Security number. Look for the list of exposed data types - passwords, email addresses, phone numbers, financial details - before you change a single thing.

If you heard about the breach secondhand, or the notice is vague, check your email address at Have I Been Pwned, the standard free database of known breaches. As of July 2026 it indexes more than 17.7 billion breached accounts from over 1,000 breached websites, and for each breach it lists exactly which data classes leaked. RedactZero's free exposure scan runs the same check, alongside a look at where else your details appear publicly, and stores nothing you type.

If this keeps happening to you, that is not bad luck. The Identity Theft Resource Center counted 3,322 data compromises in the US in 2025 - a record, up from 3,152 in 2024 - with nearly 279 million victim notices sent. Breaches are now routine; a calm routine response is the right match.

Change the breached password - and every reuse of it

Change the password on the breached account first, then on every other account where you reused it. Reused passwords are how one leak becomes ten: attackers feed stolen email-and-password pairs into other sites automatically. And change your email account's password before almost anything else - email can reset all the rest.

Make the replacements long and unique. CISA, the US government's cybersecurity agency, recommends passwords of at least 16 characters and using a password manager, which generates and stores a different random password for every site and flags weak or reused ones. You only have to memorize the one password that unlocks the manager itself.

Turn on two-factor authentication

Next, switch on two-factor authentication (also called multifactor authentication or 2FA) for the breached account, your email, and your bank. CISA's guidance is blunt: enabling it significantly reduces the likelihood of getting hacked, because a stolen password alone no longer opens the account.

An authenticator app or a hardware key is stronger than codes sent by text message, which can be intercepted through SIM-swap fraud - but any second factor beats none. If a site you use offers 2FA and you skipped it before the breach, this is the moment to fix that.

Freeze your credit at all three bureaus

If the breach exposed your Social Security number, date of birth, or financial account details, freeze your credit. A freeze restricts access to your credit report, which blocks most new accounts from being opened in your name. It is free by federal law, and you must place it separately at each bureau.

The three bureaus are Equifax (800-685-1111), Experian (888-397-3742), and TransUnion (888-909-8872). Under the FTC's rules, a freeze requested online or by phone must be in place within one business day, and lifting it - which you will do whenever you apply for credit yourself - must happen within one hour. Requests by mail get three business days. The freeze lasts until you lift it, and freezing does not stop you from using the credit cards you already have.

Or start with a fraud alert - one call covers all three

A fraud alert is the lighter-weight option: one free request to any of the three bureaus, and that bureau must tell the other two. An initial alert lasts one year and can be renewed. If identity theft actually occurs and you file an FTC identity theft report, an extended alert lasts seven years.

An alert does not lock your file the way a freeze does - it is a flag meant to make lenders verify your identity before opening new credit. Here is how the three tools compare:

Credit freezeInitial fraud alertExtended fraud alert
CostFreeFreeFree
How long it lastsUntil you lift it1 year, renewable7 years
Where you request itEach bureau separatelyOne bureau; it must tell the other twoOne bureau, with an FTC identity theft report
What it doesRestricts access to your credit reportFlags your file for identity verificationSame as an initial alert, for longer

Source: Federal Trade Commission, "Credit Freezes and Fraud Alerts" (consumer.ftc.gov).

Expect the follow-up phishing wave

Assume scammers will contact you pretending to help. Breached data - your email, your phone number, and the name of the company that lost them - is exactly what a convincing fake "security alert" needs. The FTC's core advice: never use links or phone numbers from an unexpected message; go to the company directly.

The FTC warns that phishing messages use familiar company names or pretend to be someone you know, and that legitimate companies will not email or text you a link asking you to update payment information. After a breach, expect messages that reference the breach itself: fake "claim your compensation" emails, fake password-reset prompts, fake fraud-department calls. Slow down, and type the company's address into your browser yourself.

Watch your accounts - and know where to report

For the next few months, read your bank and card statements line by line, and take unfamiliar charges seriously however small they are - testing a card with a tiny charge is a classic move. Check that contact details and forwarding rules on your email account have not been quietly changed.

If you find actual misuse of your information, report it at IdentityTheft.gov, the federal government's one-stop resource for identity theft. It builds you a personal recovery plan with step-by-step advice, pre-fills the letters and forms you will need, and generates the official identity theft report that unlocks the seven-year extended fraud alert. Its breach-specific page at IdentityTheft.gov/databreach tailors the steps to what kind of data was exposed.

The days after: shrink what scammers can find

Once the urgent steps are done, reduce the amount of your data sitting in the open for the next attack. Leaked data gets far more dangerous when it is combined with what data brokers already publish about you - your address, relatives, and phone number - so the follow-up job is shrinking that public footprint.

Delete old accounts you no longer use; every dormant account is a future breach waiting to include you. Then opt out of the people-search sites that republish your details - it is free, and our step-by-step opt-out guides cover 57 major brokers, including high-traffic ones like Whitepages and Spokeo. A scammer who has your leaked email but cannot find your address, phone, or relatives has much less to work with.

For more on passwords, breaches, and what attackers do with stolen data, browse the rest of our Breaches & Passwords series.

Find out what is already exposed

Run a free exposure scan to see the breaches tied to your email and the data brokers likely to list you - no account, nothing stored.

Run a free exposure scan

Frequently asked questions

How do I find out if my email was in a data breach?

Check it at Have I Been Pwned (haveibeenpwned.com), the standard free database of known breaches. Search your email address and it lists each breach it appeared in, along with the types of data that leaked - passwords, phone numbers, addresses, and so on.

Should I change all of my passwords after a breach?

Start with the breached account, your email, and anywhere you reused the same password - those are the accounts attackers will try first. Changing everything else can wait, but a password manager makes it painless to upgrade the rest over time.

Is freezing my credit really free?

Yes. A 2018 federal law made placing, lifting, and removing credit freezes free at all three bureaus. You need to contact Equifax, Experian, and TransUnion separately, and the freeze stays in place until you lift it.

What is the difference between a credit freeze and a fraud alert?

A freeze restricts access to your credit report so new accounts cannot easily be opened; you set it separately at each bureau and it lasts until you lift it. A fraud alert is a flag meant to make lenders verify your identity first - one bureau notifies the other two, and an initial alert lasts one year.

What should I do if my Social Security number leaked?

Freeze your credit at all three bureaus, watch your financial statements closely, and report any misuse at IdentityTheft.gov, which also unlocks a seven-year extended fraud alert. A leaked SSN does not expire the way a password does, so the freeze is the step that matters most.

How long does a fraud alert last?

An initial fraud alert lasts one year and can be renewed. An extended alert, available once you have an FTC identity theft report, lasts seven years. Both are free, and you only need to contact one bureau - it must tell the other two.

Why am I getting scam calls and texts after a breach?

Because your contact details are now circulating along with context scammers can use, such as which company lost them. Treat unexpected calls, texts, and emails about the breach as suspect, and contact companies only through numbers and addresses you look up yourself.

Can I keep my data out of the next breach?

Not entirely, but you can shrink the blast radius: delete accounts you no longer use, give sites the minimum information they ask for, use unique passwords so one leak cannot spread, and remove your details from people-search sites that republish them.

Sources: Federal Trade Commission ("Credit Freezes and Fraud Alerts", phishing guidance, and IdentityTheft.gov); CISA "Secure Our World" password and MFA guidance; Have I Been Pwned (counts as displayed July 2026); Identity Theft Resource Center, 2025 Annual Data Breach Report (January 2026).