Your Rights After a Data Breach: Steps Every U.S. Consumer Should Take
Receiving a data-breach notice can be alarming. It means a company, healthcare provider, employer or other organization discovered that personal information may have been accessed, stolen or exposed.
A breach does not automatically mean that someone has used your identity. However, exposed information may be used weeks, months or even years later, so taking the right precautions quickly can reduce your risk.
The correct response depends on what information was exposed. A stolen password requires different action from an exposed Social Security number, bank account or medical record.
Read the Entire Data-Breach Notice
Do not look only at the name of the affected company. Read the complete notice and identify exactly what information may have been exposed.
The notice may mention:
- Your name and address
- Email address or phone number
- Username and password
- Social Security number
- Driver’s license information
- Credit or debit card details
- Bank account information
- Medical or health-insurance records
- Date of birth
- Security-question answers
Pay attention to when the breach occurred, when the company discovered it and whether the exposed information was encrypted.
Also check whether the company is offering free credit monitoring, identity-theft protection or another recovery service. The FTC advises affected consumers to consider using legitimate free protection services offered after a breach.
Before clicking a link in an email, independently visit the company’s official website or call a verified customer-service number. Criminals often take advantage of publicized breaches by sending fake notices designed to steal even more information.
Change Exposed Passwords Immediately
When a password may have been exposed, change it as soon as possible.
Create a new password that is long, unique and not used for any other account. If you used the same or a similar password elsewhere, change those accounts too.
Attackers sometimes test stolen login details on banking, shopping, email and social-media websites. Reusing a password allows one company’s breach to affect several unrelated accounts. The FTC recommends changing compromised passwords immediately and replacing reused passwords on other services.
Start with your email account because access to your email could allow someone to request password-reset links for many other services.
After changing your password:
- Sign out of other devices and active sessions.
- Review recent login activity.
- Remove unfamiliar devices.
- Check whether recovery email addresses or phone numbers changed.
- Update security-question answers when necessary.
- Store unique passwords in a trusted password manager.
Never share your new password or verification code with someone claiming to represent the affected company.
Turn On Two-Factor Authentication
Two-factor authentication requires a second form of verification in addition to a password.
The second factor may be:
- A code from an authentication app
- A security key
- A device notification
- A fingerprint or facial scan
- A one-time text message
Even when an attacker has your password, two-factor authentication may prevent access without the second credential. The FTC says authentication apps and security keys generally provide stronger protection than codes delivered through text messages or email.
Enable two-factor authentication first on accounts containing sensitive information, including:
- Online banking
- Credit cards
- Payment applications
- Cloud storage
- Social media
- Shopping accounts
- Tax and government accounts
Save backup recovery codes somewhere secure and separate from the device used to access the account.
Contact Your Bank When Financial Information Is Exposed
Contact your bank or card issuer immediately when a breach involves a debit card, credit card or bank account.
Use the phone number printed on the card, bank statement or official banking application. Do not use a phone number supplied in an unexpected message unless you have verified it independently.
Ask whether the financial institution recommends:
- Replacing the affected card
- Changing the account number
- Updating the personal identification number
- Adding additional account verification
- Blocking electronic transfers
- Monitoring the account for unusual activity
Review recent transactions carefully. Small unfamiliar charges can be important because criminals may test stolen payment information before attempting a larger transaction.
Report unauthorized activity immediately. The protections and reporting deadlines may differ depending on whether the transaction involves a credit card, debit card, bank transfer or payment application.
Continue monitoring the account even after receiving a replacement card. A replacement card may protect the card number, but it does not necessarily solve every risk if other personal information was also exposed.
Freeze Your Credit When Sensitive Information Is Exposed
A credit freeze restricts access to your credit report, making it harder for an identity thief to open a new credit account in your name.
Credit freezes are free to place and lift. They do not affect your credit score and remain in place until you remove or temporarily lift them.
To receive full protection, you must request a freeze separately from all three nationwide credit-reporting companies:
- Equifax
- Experian
- TransUnion
Freezing your report with only one company does not automatically freeze it with the other two.
A credit freeze is especially worth considering when exposed information includes:
- A Social Security number
- Date of birth
- Driver’s license information
- Complete identity records
- Financial-account information
You can temporarily lift a freeze when you need to apply for a loan, apartment, credit card or another service that requires access to your credit file.
A credit freeze mainly helps prevent new-account fraud. It does not stop someone from misusing an existing account, so you must continue reviewing your financial statements.
Consider Placing a Fraud Alert
A fraud alert tells businesses checking your credit report to take additional steps to verify your identity before opening new credit.
An initial fraud alert is free and generally lasts for one year. Unlike a credit freeze, you only need to contact one of the three nationwide credit-reporting companies. That company must notify the other two.
An extended fraud alert may be available to confirmed identity-theft victims and generally lasts seven years.
A fraud alert may be useful when you suspect identity theft but still want lenders to access your credit report. A freeze usually provides stronger control because it restricts access to the report until you lift it.
Consumers may use both protections depending on their circumstances.
Check All Three Credit Reports
Review your credit reports for accounts, addresses and inquiries you do not recognize.
Look for:
- Credit cards you did not open
- Loans you did not request
- Incorrect addresses
- Unfamiliar employers
- Collection accounts that are not yours
- Credit inquiries from unknown businesses
- Incorrect balances or payment histories
The three nationwide credit bureaus may contain different information, so review all three reports instead of checking only one.
Free weekly online credit reports are currently available from Equifax, Experian and TransUnion through the federally authorized AnnualCreditReport service.
Be cautious of websites with similar names. A website may advertise a free report while trying to sell credit monitoring, identity protection or another subscription.
A suspicious inquiry does not always prove identity theft. It should still be investigated, especially when it appears after a Social Security number or other identity information was exposed.
Report Identity Theft and Create a Recovery Plan
When someone has already used your information, report the identity theft through IdentityTheft.gov.
The service is operated by the Federal Trade Commission and provides a recovery plan based on the type of identity theft reported. It can also generate an Identity Theft Report and provide sample letters for communicating with businesses and credit-reporting companies.
Signs that your information may already be in use include:
- Accounts you did not open
- Purchases or withdrawals you did not make
- Bills for unfamiliar services
- Debt-collection calls about unknown debts
- A rejected tax return because one was already filed
- Medical statements for treatment you did not receive
- Government-benefit claims you did not submit
- Login notifications from unfamiliar locations
Keep a record of every call, letter, complaint and document related to the incident.
Write down:
- The date and time of each conversation
- The name of the company representative
- Any case or confirmation number
- The action promised by the company
- The deadline for the next step
Send important letters through a trackable delivery method when possible, and keep copies rather than mailing original documents.
You Can Request That Fraudulent Credit Information Be Blocked
Identity-theft victims may have the right to ask credit-reporting companies to block fraudulent information from their reports.
The Consumer Financial Protection Bureau explains that victims may need to send:
- An Identity Theft Report
- Proof of identity
- A letter identifying the fraudulent information
Federal law generally requires a credit-reporting company to block qualifying identity-theft information within four business days after receiving the required documents.
Blocking is different from disputing an ordinary error. It specifically concerns information resulting from identity theft.
Send the request to each credit-reporting company displaying the fraudulent information. You should also contact the bank, lender, collector or other business that supplied it.
Keep copies of your report with the fraudulent entries clearly marked.
Dispute Other Credit-Report Errors
Not every incorrect item is identity theft. Some errors result from mixed files, outdated records or incorrect reporting by a lender.
Dispute inaccurate or incomplete information with:
- The credit-reporting company displaying the information
- The business that supplied the information
Explain the problem clearly and attach copies of records supporting your position. Keep the originals.
The CFPB recommends keeping copies of the dispute letter and every document submitted.
If the problem remains after completing the dispute process, consumers may submit a complaint to the CFPB.
Protect Yourself From Tax Identity Theft
A stolen Social Security number may be used to file a fraudulent federal tax return.
Consumers can request an Identity Protection Personal Identification Number from the Internal Revenue Service. An IP PIN is a six-digit number known to the taxpayer and the IRS that helps prevent someone else from filing a tax return using the taxpayer’s Social Security number or Individual Taxpayer Identification Number.
Eligible taxpayers can request an IP PIN even when they have not previously experienced tax identity theft.
A new IP PIN is issued for each calendar year. Anyone enrolled in the program must include the current PIN on federal returns filed during that year.
Do not share an IP PIN with anyone except the IRS and a trusted tax professional preparing your return. The IRS does not contact taxpayers by email, phone or text to request their IP PIN.
Signs of possible tax identity theft include:
- An electronic tax return being rejected as a duplicate
- An IRS notice about a return you did not file
- Income records from an unfamiliar employer
- An unexpected tax transcript
- An online IRS account you did not create
Respond to official IRS notices promptly and keep copies of everything submitted.
Take Special Action After a Medical-Information Breach
Medical data can contain highly sensitive information, including diagnoses, insurance numbers, prescriptions and billing records.
The HIPAA Breach Notification Rule requires covered healthcare organizations and their business associates to provide notification after certain breaches of unsecured protected health information. Notification to affected individuals must generally occur without unreasonable delay and no later than 60 days after discovery.
A medical-breach notice should explain:
- What happened
- What information was involved
- Steps the organization is taking
- Actions affected individuals can take
- How to contact the organization
Review health-insurance explanations of benefits and medical bills for unfamiliar doctors, procedures or prescriptions.
Contact the healthcare provider and insurer when you discover treatment or claims that do not belong to you. Ask for copies of the relevant records and request that inaccurate information be corrected.
Medical identity theft is not only a financial problem. Incorrect information placed in a medical record could potentially affect future treatment.
Individuals who believe a HIPAA-covered organization violated their health-information privacy rights may file a complaint with the Department of Health and Human Services Office for Civil Rights.
Be Alert for Scams Following the Breach
A breach can lead to a second wave of targeted scams.
Criminals may know your name, email address, employer or the name of the breached company. They may use those details to make a message appear legitimate.
Be suspicious of unexpected communications asking you to:
- Confirm your Social Security number
- Provide a password or verification code
- Pay to restore your account
- Move money to a “safe” account
- Download security software
- Open an attachment
- Click a link to receive compensation
- Purchase gift cards or cryptocurrency
- Give remote access to your device
A real company may contact affected customers, but you should independently verify the communication through its official website or a trusted phone number.
Do not assume that a message is real simply because it contains accurate personal information. That information may have come from the breach itself.
Use Free Credit Monitoring Carefully
Credit monitoring can alert you to certain changes in your credit file. It may be useful when offered free after a breach.
Before enrolling, confirm:
- Who is providing the service
- How long the free period lasts
- Whether it renews as a paid subscription
- What information is monitored
- How alerts will be delivered
- Whether identity-theft insurance is included
- What support is available after suspected fraud
Credit monitoring is not the same as a credit freeze.
Monitoring may tell you after a suspicious credit event occurs. A freeze is designed to make opening a new account more difficult in the first place.
Consumers should not pay someone who claims that a special fee is required to freeze a credit report. Placing and lifting a freeze is free under federal law.
What to Do Based on the Information Exposed
When your password was exposed
Change it immediately, update accounts where it was reused and enable two-factor authentication.
When your credit or debit card was exposed
Contact the issuer, request a replacement when recommended and review transactions.
When your bank account was exposed
Contact the bank’s fraud department and ask whether the account number should be changed.
When your Social Security number was exposed
Freeze all three credit reports, review them regularly and consider requesting an IRS IP PIN.
When your driver’s license was exposed
Contact your state motor-vehicle agency to ask about replacement procedures and available protections.
When medical information was exposed
Review insurance claims, medical bills and records, and report unfamiliar activity to the provider and insurer.
When your email address was exposed
Expect targeted phishing attempts, secure the email account and use a unique password with two-factor authentication.
Frequently Asked Questions
Does a data breach mean my identity was stolen?
Not necessarily. A breach means information may have been exposed or accessed. Identity theft occurs when someone uses personal information without permission.
Taking protective action before misuse appears can reduce the possible damage.
Should I freeze my credit after every breach?
A freeze is especially important when a Social Security number, birth date or other information useful for opening financial accounts was exposed.
Anyone can request a free credit freeze at any time, even without evidence of identity theft.
Will freezing my credit lower my credit score?
No. Placing or lifting a credit freeze does not affect your credit score.
Does a credit freeze protect my bank account?
A freeze mainly restricts access to your credit report and helps prevent new-account fraud. It does not stop unauthorized use of an existing bank or credit-card account.
Continue reviewing account statements and report suspicious transactions immediately.
How long should I monitor my information?
There is no single period that guarantees safety. Stolen personal information may remain useful for a long time, particularly when it includes a Social Security number or date of birth.
Continue checking credit reports and financial statements regularly even after a free monitoring service ends.
Where should identity theft be reported?
Identity theft can be reported to the FTC through IdentityTheft.gov. Consumers should also contact the companies where fraudulent accounts or transactions appeared.
Final Takeaway
The most important step after a data breach is to determine exactly what information was exposed.
Change compromised passwords, secure important accounts with two-factor authentication and contact financial institutions when payment details are involved. When a Social Security number or other sensitive identity information is exposed, consider freezing all three credit reports and checking them for unfamiliar activity.
When someone has already misused your information, report the identity theft, create a recovery plan and keep complete written records.
A breach notice should never be ignored, but it should not cause panic. Acting quickly and following the correct steps for the type of information exposed can make identity theft more difficult and recovery more manageable.
This article provides general educational information and is not legal, financial or tax advice. Rights and reporting requirements may vary according to the circumstances, the type of organization involved and applicable federal or state law.