Your data was in a breach: what actually matters (and what doesn't)
The breach notification letter arrives, offers you 'free credit monitoring,' and leaves you unsure what to do. A calm, prioritized checklist for the aftermath.
If you have accounts anywhere, your data has been in a breach — probably several. The notification letters have become routine, usually apologizing and offering a year of 'free credit monitoring.' The problem is that the letter rarely tells you what to actually do, and the free monitoring it offers is often the least useful response. What matters depends entirely on what was exposed: a leaked email address is a shrug; a leaked Social Security number is a freeze-your-credit emergency. This is how to triage a breach without panic and without ignoring it.
Triage by what was exposed
| Exposed data | Risk | Priority action |
|---|---|---|
| Email address only | Low — more spam and phishing | Stay alert to phishing |
| Password | High if reused anywhere | Change it everywhere it's reused |
| Credit/debit card number | Moderate — existing-account fraud | Watch statements; replace card if charges appear |
| SSN / date of birth | High — new-account & tax fraud | Freeze credit at all three bureaus |
| Medical or account logins | High | Change credentials; enable app-based 2FA |
The highest-value move: a credit freeze
The breach-response checklist
- Read what was exposed. The letter should specify — that determines everything below.
- If a password leaked, change it on that site and anywhere you reused it, and switch to unique passwords via a password manager.
- If your SSN or date of birth leaked, freeze your credit at all three bureaus (and consider ChexSystems for bank accounts).
- Turn on app-based two-factor authentication for email and financial accounts; email is the master key.
- Accept the free monitoring anyway — it's a free tripwire — but don't mistake it for protection.
- Watch for targeted phishing: breach victims get scam calls and emails referencing the breached company to seem legitimate.
What you can safely ignore
- Panic. A single breach of your email address changes little beyond more spam.
- Paid identity-theft services sold on the back of the news — they mostly resell monitoring you can get free, and don't block fraud the way a freeze does.
- Changing every password you own if only one unrelated site leaked — focus on the exposed credential and anywhere it was reused.
- 'Recovery' or 'protection' offers that call you unsolicited after the breach; go direct to the company instead.
The bottom line
A breach notice isn't a five-alarm fire or a piece of junk mail — it's a prompt to do a few specific things based on what leaked. Change and de-duplicate exposed passwords, freeze your credit if your SSN was involved, harden email with app-based 2FA, and stay skeptical of anyone who contacts you about the breach afterward. Do that, and the endless stream of breach letters becomes background noise instead of a recurring crisis.
Check your understanding
1 of 3Not quite — try again.
Get smarter about money every week
One email, no spam — practical guides and Worth updates. Unsubscribe anytime.
Put this into practice
Worth tracks your accounts, budgets, and goals — so the concepts in this article aren't just theory.
Start free trial