Data breaches are common, and most people who check their email address find it in at least one. Showing up in a breach does not mean anyone has stolen your identity. It means some information connected to that email was exposed by a company, and it is worth taking a few practical steps so that information is harder to misuse.
This checklist puts those steps in order, starting with the ones that take minutes and cost nothing. If you have not checked your email yet, start with our guide to checking your email for free.
Step 1: Find out what was exposed
Breach checkers such as Have I Been Pwned and Mozilla Monitor list each breach your email appears in and the types of data involved, for example email addresses, passwords, phone numbers, dates of birth or physical addresses. Companies that are legally required to notify you will usually send a letter or email that says what was exposed and whether they offer anything, such as free credit monitoring.
Make a short list: which account, what data, and roughly when. The type of data decides which of the steps below matter most.
| What was exposed | Most useful steps |
|---|---|
| Email address only | Watch for phishing emails (step 5). Nothing else needs to happen right away. |
| Password (even if "hashed") | Change it on that site and anywhere you reused it (step 2), then turn on two-factor (step 3). |
| Phone number, address, date of birth | Expect more targeted phishing calls and texts (step 5). Consider a credit freeze (step 4). |
| Social Security number, driver's license, bank or card numbers | Freeze your credit (step 4), contact your bank or card issuer, review your credit reports (step 6) and use the IdentityTheft.gov breach steps (step 7). |
Step 2: Change exposed and reused passwords
Attackers often take email and password pairs from one breach and try them on other sites. This is why a breach at a small forum can lead to someone logging into your shopping or email account. Change the password on the breached account first, then on every other account where you used the same or a similar password.
Start with the accounts that unlock everything else: your main email account (it can reset all your other passwords), your bank and card accounts, your mobile carrier account and any account that stores payment details. Each new password should be long and unique. A password manager, covered in our password manager and two-factor guide, makes that realistic.
Step 3: Turn on two-factor authentication
Two-factor authentication (sometimes called 2FA or multifactor authentication) asks for a second proof that it is you, such as a code from an authenticator app, a security key or a passkey, in addition to your password. The FTC and CISA both recommend it because a stolen password alone is no longer enough to get in. Turn it on for email first, then financial accounts, then social media.
Step 4: Consider a credit freeze
A credit freeze stops new lenders from seeing your credit report, which makes it much harder for someone to open a new credit account in your name. According to the FTC, a freeze is free to place and lift, lasts until you lift it, and does not affect your credit score. You set it up separately at each of the three nationwide credit bureaus: Equifax, Experian and TransUnion.
The FTC says a freeze is always a good idea and is even more important if your Social Security number was exposed. You can lift it temporarily when you apply for a loan, a credit card or an apartment. Our credit freeze vs fraud alert guide walks through both options.
Step 5: Expect more convincing phishing
After a breach, the most common follow up is not a hacker in your bank account. It is an email, text or call that uses your real name, address or order history to look believable. Some even mention the breach and offer to "help."
- Do not click links in messages about your accounts. Go to the company's website or app directly.
- Real companies will not ask you to confirm your password, full Social Security number or a one-time code by phone, text or email.
- If a message pressures you to act within minutes, slow down and check it through a channel you already trust.
The FTC's guide to recognizing phishing has examples of what these messages look like.
Step 6: Check your credit reports and accounts
The three nationwide credit bureaus let you check your credit report from each of them for free once a week at AnnualCreditReport.com, the site the FTC points to for free reports. Look for accounts, addresses or inquiries you do not recognize. Also review your bank and card statements, and turn on transaction alerts in your banking app if you have not already.
Step 7: If sensitive data was exposed, use the FTC's recovery steps
The Federal Trade Commission runs IdentityTheft.gov. Its data breach page gives specific steps depending on what was exposed, for example a Social Security number, a bank account or a driver's license. If someone has actually used your information, IdentityTheft.gov is also where you report it and get a personal recovery plan. Our guide on signs of identity theft explains what misuse usually looks like.
If your Social Security number was exposed, the IRS also offers an Identity Protection PIN, a six-digit number that helps stop someone else from filing a tax return using your Social Security number.
Step 8: Decide whether you want ongoing monitoring
Everything above is free. Many people stop here, and that is a reasonable choice. Some people prefer a service that keeps watching for them: free breach alerts from Have I Been Pwned or Mozilla Monitor cover new breaches tied to your email, while paid identity monitoring services add things like Social Security number and credit monitoring, a credit lock in an app, help from restoration specialists and insurance. We compare both honestly in free breach checks vs paid monitoring.
Sources and further reading
- Have I Been Pwned
- Mozilla Monitor
- FTC Consumer Advice: Credit Freezes and Fraud Alerts
- FTC Consumer Advice: Free Credit Reports
- FTC Consumer Advice: Use Two-Factor Authentication to Protect Your Accounts
- CISA Secure Our World: Turn On Multifactor Authentication
- FTC Consumer Advice: How To Recognize and Avoid Phishing Scams
- IdentityTheft.gov: What to do if your information was lost, stolen or part of a data breach
- IRS: Get an Identity Protection PIN (IP PIN)