Scams & FraudBeginner6 min read

Your data was in a breach: what actually matters (and what doesn't)

The breach notification letter arrives, offers you 'free credit monitoring,' and leaves you unsure what to do. A calm, prioritized checklist for the aftermath.

If you have accounts anywhere, your data has been in a breach — probably several. The notification letters have become routine, usually apologizing and offering a year of 'free credit monitoring.' The problem is that the letter rarely tells you what to actually do, and the free monitoring it offers is often the least useful response. What matters depends entirely on what was exposed: a leaked email address is a shrug; a leaked Social Security number is a freeze-your-credit emergency. This is how to triage a breach without panic and without ignoring it.

Triage by what was exposed

Exposed dataRiskPriority action
Email address onlyLow — more spam and phishingStay alert to phishing
PasswordHigh if reused anywhereChange it everywhere it's reused
Credit/debit card numberModerate — existing-account fraudWatch statements; replace card if charges appear
SSN / date of birthHigh — new-account & tax fraudFreeze credit at all three bureaus
Medical or account loginsHighChange credentials; enable app-based 2FA
What leaked and how much it matters

The highest-value move: a credit freeze

Free monitoring watches; a freeze blocks
The credit monitoring in most breach letters only tells you after someone opens an account in your name. A security freeze at Equifax, Experian, and TransUnion prevents new lenders from pulling your credit at all, so the account can't be opened in the first place. It's free, it's reversible in minutes when you legitimately need credit, and for any breach involving your SSN it's the single most important thing you can do.

The breach-response checklist

  1. Read what was exposed. The letter should specify — that determines everything below.
  2. If a password leaked, change it on that site and anywhere you reused it, and switch to unique passwords via a password manager.
  3. If your SSN or date of birth leaked, freeze your credit at all three bureaus (and consider ChexSystems for bank accounts).
  4. Turn on app-based two-factor authentication for email and financial accounts; email is the master key.
  5. Accept the free monitoring anyway — it's a free tripwire — but don't mistake it for protection.
  6. Watch for targeted phishing: breach victims get scam calls and emails referencing the breached company to seem legitimate.
Two people, same breach, different outcomes
A retailer breach exposes names, emails, and (for some) SSNs. Priya, whose SSN was included, freezes her credit that evening. Two months later a thief tries to open a store card in her name; the frozen bureau kills the application instantly. Marcus, whose SSN was also exposed, files the letter away and relies on the 'free monitoring.' A synthetic account is opened using his SSN; he learns about it months later from a collections notice, and spends the next year cleaning it up. Same breach, same exposure — the freeze was the whole difference.
The breach itself becomes phishing fuel
After a well-publicized breach, scammers call and email pretending to be the breached company's 'security team,' offering to 'secure your account' or 'confirm your identity' — using the real breach as a hook. Treat any inbound contact about a breach as a possible second attack. Go to the company directly through a known address; never click links or give details to someone who contacted you about it.

What you can safely ignore

  • Panic. A single breach of your email address changes little beyond more spam.
  • Paid identity-theft services sold on the back of the news — they mostly resell monitoring you can get free, and don't block fraud the way a freeze does.
  • Changing every password you own if only one unrelated site leaked — focus on the exposed credential and anywhere it was reused.
  • 'Recovery' or 'protection' offers that call you unsolicited after the breach; go direct to the company instead.

The bottom line

A breach notice isn't a five-alarm fire or a piece of junk mail — it's a prompt to do a few specific things based on what leaked. Change and de-duplicate exposed passwords, freeze your credit if your SSN was involved, harden email with app-based 2FA, and stay skeptical of anyone who contacts you about the breach afterward. Do that, and the endless stream of breach letters becomes background noise instead of a recurring crisis.

Check your understanding

1 of 3
A breach letter says your Social Security number was exposed and offers a year of free credit monitoring. What's the highest-value action?

Not quite — try again.

The Worth letter

Get smarter about money every week

One email, no spam — practical guides and Worth updates. Unsubscribe anytime.

Put this into practice

Worth tracks your accounts, budgets, and goals — so the concepts in this article aren't just theory.

Start free trial