You got a breach letter. Here's what it actually means.

Companies are legally required to notify you when your data is exposed. Most offer free credit monitoring—but that's the minimum response, not comprehensive protection. Here's what to actually do.

First: What data was exposed?

Your response should match what was compromised. Check your letter carefully—it should list the specific data types affected.

Act immediately

Full protections warranted
Social Security Number (SSN)
Bank account numbers
Credit/debit card numbers
Tax documents or tax ID
Driver's license number
State ID or passport number
Health insurance ID or policy number
Medical records or diagnosis info
Biometric data (fingerprints, facial scans)
Login credentials with passwords

Act soon

Freeze recommended + enable 2FA
Full date of birth
Home address (current or past)
Phone number
Security questions/answers
Mother's maiden name
Employment history
Income or salary information
Partial SSN (last 4 digits)

Stay vigilant

Watch for phishing, consider freezing
Email address only
Name only
Username (without password)
Employer name
General demographic info
IP address or device info

Combinations matter

Data types are more dangerous together. Name + DOB + address is enough for some fraud. Email + password means immediate password changes everywhere you reused it. SSN + anything else is high priority regardless of the other data.

Tier 1: Essential (Do These First)

Complete these within 24-48 hours of receiving your notification.

1

Read the letter carefully

5 min Easy

Identify exactly what data was exposed. This determines your response. Look for:

  • Type of data compromised (SSN, financial info, passwords, etc.)
  • Date of the breach (how long your data may have been exposed)
  • What the company is offering (usually credit monitoring)
2

Freeze your credit at all three bureaus

30 min Easy

This is the single most effective step. Freezes are free and prevent new accounts from being opened in your name.

Save your PINs securely—you'll need them to temporarily lift freezes later.

3

Set up IRS Identity Protection PIN

15 min Easy

(If SSN was exposed)

Prevents someone from filing a fraudulent tax return in your name.

4

Create your Social Security online account

10 min Easy

(If SSN was exposed)

If you don't claim your account, someone else might. This also lets you monitor for suspicious activity.

Want a printable version? The Identity Protection Workbook has all these steps in a checklist format you can work through offline. Get the Workbook →

Tier 2: Recommended

Complete these within the first week.

5

Freeze ChexSystems

10 min Easy

Prevents fraudulent bank accounts from being opened in your name.

6

Set up USPS Informed Delivery

5 min Easy

Get email previews of incoming mail. Helps you spot if someone changed your address or is receiving mail in your name.

7

Enable two-factor authentication on financial accounts

20 min Easy

Add 2FA to your bank, credit cards, investment accounts, and email. Use an authenticator app over SMS when possible.

8

Review recent statements

15 min Easy

Check your credit card and bank statements for unauthorized charges. Report anything suspicious immediately.

Tier 3: Optional / Ongoing

Nice to have, but lower priority than the steps above.

9

Accept the free monitoring they offered

10 min Easy

It's supplementary protection, not your primary defense. Worth having, but remember: it only alerts you after fraud occurs.

10

Set up free ongoing monitoring

15 min Easy

Use Credit Karma or similar for ongoing credit monitoring. See our free monitoring guide.

11

Consider freezing specialty bureaus

30 min Moderate

LexisNexis, NCTUE (utilities), and others. See our additional protections guide.

12

Set up annual credit report review

5 min Easy

You're entitled to free credit reports from each bureau annually.

Why this order?

We prioritize prevention over detection. Credit freezes stop fraud before it happens. Monitoring only tells you after someone has already opened an account in your name. Both are useful, but prevention is always better.