What to do after a data breach

    Breaches are now routine, and the difference between a nuisance and a serious loss is mostly speed and sequence. This plan sets out what to do in the first hour, the first day and the following weeks, in the order that actually reduces risk.

    By Rui Matos · Cybersecurity Editor · Updated 18 September 2026

    Confirm what was exposed

    Read the notification carefully and identify the specific data categories involved: passwords, password hashes, payment details, identity documents, addresses or only email addresses. The response differs sharply depending on the answer.

    Treat any breach notification arriving by email as unverified until you check the company's official site directly. Fake breach warnings are themselves a common phishing tactic.

    The first hour

    Change the password on the breached service, then on every account where you reused it, starting with your email. Sign out of all active sessions on those accounts and enable a strong second factor.

    If payment details were exposed, notify your bank or card issuer, enable transaction alerts and consider a replacement card. Freezing a card is faster than recovering a fraudulent payment.

    • Change the breached password and every reuse of it
    • Secure your primary email address first
    • Revoke active sessions and connected apps
    • Enable or upgrade two-factor authentication
    • Alert your bank if payment data was involved

    The first day

    Review recovery settings on important accounts: recovery email, phone number, backup codes and trusted devices. Attackers frequently change these quietly so they can return later even after you reset the password.

    Check connected third-party applications and remove anything you do not actively use, since forgotten integrations retain access long after you stop using them.

    Expect targeted follow-up fraud

    Breached data is used to make later scams convincing. Expect messages that quote a real order number, your address or the last digits of a card, and calls claiming to be from the breached company's security team.

    A genuine organisation will never ask you to move money to a safe account, read out a code or install remote-access software. Treat any such request as fraud regardless of how much the caller knows about you.

    Reduce the standing exposure

    Move to unique passwords stored in a password manager, so a future breach affects exactly one account. Use email aliases for sign-ups where possible, which also tells you which service leaked your address.

    Consider a monitoring or data-removal service if your details are widely exposed. These cannot prevent breaches, but they shorten the time between exposure and action.

    When identity documents are involved

    Exposure of identity numbers, passports or proof-of-address documents deserves a stronger response, because the data enables account opening in your name. Contact the relevant national authority or credit reference agency in your country and ask what protective markers are available.

    Keep a written record of what happened, when you were notified and every step you took. If fraud follows, that timeline is what makes disputes straightforward.

    How to check exposure safely

    Use a reputable breach-checking service to see which of your addresses appear in known incidents, and enable notifications so that future exposures reach you quickly. Do not enter passwords into any site that asks whether they have been leaked; legitimate services check addresses or use privacy-preserving lookups.

    Where a password manager offers breach monitoring, use that instead: it compares your saved credentials against known leaks locally and tells you exactly which entries to change.

    Business and employer breaches

    If the breached service was a workplace system, report it internally before acting alone, because the organisation may need to preserve evidence and notify a regulator within a fixed deadline. Change your own credentials and any personal reuse immediately.

    Employees are also targeted after company breaches with convincing internal-looking messages. Verify unusual payment or access requests through a separate channel for several weeks afterwards.

    Building resilience for next time

    Assume more breaches will happen and design around them: unique passwords everywhere, a strong second factor on the accounts that unlock others, aliases for sign-ups, and minimal data shared with services that do not need it.

    Once those four habits are in place, an average breach becomes an administrative task rather than a crisis, which is the realistic goal.

    Which accounts matter most

    Not every account deserves the same urgency. Rank them by what they unlock: the email address used for password resets sits at the top, followed by your password manager, banking and payment services, cloud storage holding documents and photos, then shopping and social accounts.

    Working in that order means that even if you run out of time, the accounts an attacker would use to reach everything else are already secured.

    Recognising fake breach notifications

    Attackers send breach warnings of their own, because a security alert is one of the few messages people act on immediately. The fake versions include a convenient link to reset your password, which leads to a copy of the real sign-in page.

    Never use the link. Open the service directly from a bookmark or type the address yourself, and check the company's official status or security page for the announcement.

    Frequently asked questions

    How do I know if my data has been breached?

    Use a reputable breach-checking service, watch for official notifications, and treat unexpected password-reset emails or login alerts as warning signs.

    Do I need to change every password?

    Change the breached password and every account where it was reused. With unique passwords stored in a manager, only one account needs attention.

    Is my password safe if it was only a hashed leak?

    Not necessarily. Weak hashing lets attackers recover common passwords quickly. Assume it is exposed and change it.

    Should I pay for identity monitoring?

    It is worth considering if identity documents or extensive personal data were exposed. It shortens reaction time but cannot prevent breaches at the companies holding your data.

    Can I get compensation after a breach?

    It depends on your jurisdiction and the harm suffered. Keep records and follow the official complaint process available to you locally.