Personal data security

Your data was breached. Here is what to do next.

Pick what was exposed. Get a clear, step-by-step response plan organized by time. No jargon. No panic. Just the actions that matter, in the order that matters.

Tell us what was exposed

Select every type of data that was in the breach. You can change this later and the checklist will update.

Types of data exposed in the breach
Risk level Select data types

Pick at least one category above to see your risk level and generate a checklist.

Your response checklist

Work through these in order. Check off each step as you finish it. Your progress is saved in this browser.

0 of 0 steps complete

First hour Lock things down

    First day Secure accounts and notify

      First week Watch and document

        Ongoing Stay alert for months

          Monitoring timeline

          Some risks fade quickly. Others last a year or more. This shows how long to stay alert based on what was exposed.

          Days 1-7

          Watch for fast fraud

          Card charges, new account alerts, password reset emails you did not request. Check bank and email daily.

          Weeks 2-4

          Place freezes and alerts

          Credit freezes, fraud alerts with credit bureaus, review your credit report. Dispute anything you do not recognize.

          Months 2-6

          Watch for slow fraud

          Medical identity theft, tax fraud, accounts opened at institutions you have not checked yet. Pull credit reports from each bureau on a rotating schedule.

          Months 6-12

          Keep monitoring

          Stolen data can resurface months later. Keep credit freezes active unless you need to lift them. Keep an eye on explanation of benefits statements if medical data was exposed.

          Common mistakes and extra notes

          Ignoring an email-only breach

          An exposed email feels minor, but attackers use it to send targeted phishing. They craft messages that look like they come from your bank, your workplace, or a service you use. If you reuse that email login anywhere, change the password and add two-factor authentication.

          Not checking the breach source

          Scammers send fake breach notifications to get you to click bad links. If you get an email about a breach, do not click any links. Open a new browser tab and go to the company's site directly. Call them using a number you already have, not one from the message.

          Skipping the credit freeze

          A credit freeze is free in many places and stops new accounts from being opened in your name. It takes a few minutes to set up with each credit bureau. It is the single most useful step if your Social Security number or date of birth was exposed.

          Forgetting to document

          Keep a folder with the breach notification, any case numbers from credit bureaus, and notes from phone calls (date, time, person you spoke with). If you need to dispute fraud later, this record saves you hours.

          Reusing passwords after a breach

          If a password was exposed, do not just change it on the breached site. Change it on every site where you used that same password. A password manager makes this manageable without having to remember dozens of unique logins.

          Assuming the company will fix it for you

          Some breached companies offer free credit monitoring, but it usually only covers a limited time and one bureau. Set up your own monitoring as well. Do not rely entirely on the company that lost your data.

          Template: Disputing a fraudulent charge
          Date: [Insert date]
          
          To: [Bank or card issuer fraud department]
          
          I am writing to dispute a fraudulent charge on my account ending in [last four digits].
          
          Charge: [Amount] at [Merchant] on [Date]
          
          I did not authorize this charge. I reported the breach on [date]. Please remove this charge, close the affected card, and issue a new card number.
          
          Please send me written confirmation that the charge has been removed and that I am not responsible for it.
          
          Thank you,
          [Your name]
          [Contact information]
          Template: Requesting a credit freeze
          Date: [Insert date]
          
          To: [Credit bureau name]
          
          I am requesting a security freeze on my credit file under [applicable state law or regulation].
          
          My name: [Full name]
          Address: [Current address]
          Date of birth: [DOB]
          SSN: [Last four digits]
          
          Please confirm the freeze is in place within [required timeframe] and send me a written confirmation with my PIN or password for lifting the freeze.
          
          Thank you,
          [Your name]

          How to use this checklist

          Start by selecting the types of data that were exposed in the breach. The page will show a risk level and build a custom checklist for you. Work through the steps in order, starting with the first hour. Check off each item as you finish it. Your progress is saved in your browser, so you can close the page and come back later without losing your work.

          What this page assumes

          This checklist assumes you are an individual responding to a personal data breach. It is not written for businesses or organizations handling a breach that affected customers. If you run a business that lost customer data, you have different legal obligations and should consult a lawyer.

          What to do if you feel overwhelmed

          Focus on three things first. Change the password on your email account. Turn on two-factor authentication for that email. Then call your bank or card issuer if any financial data was exposed. Those three steps cover the most common damage paths. Everything else on the list can follow over the next few days.

          Why the timeline matters

          Most fraud happens within the first 72 hours after a breach, but some types of identity theft take months to appear. Medical identity theft, tax fraud, and accounts opened at smaller institutions may not show up right away. That is why the checklist includes ongoing monitoring steps that last a year or more.

          What to double-check before you act

          Make sure the breach notification is real before you follow any instructions in it. Scammers send fake breach emails to get you to click malicious links. Go to the company's website by typing the address yourself. Call them using a phone number you already trust. Do not use contact information from the notification itself unless you can verify it independently.

          When to get professional help

          If someone has already opened an account in your name, filed a tax return using your Social Security number, or used your identity for medical care, contact local law enforcement and file a report. You may also want to talk to a lawyer who handles consumer protection or identity theft cases. Many offer a free initial consultation.

          How to share this plan

          If you are helping a family member or friend respond to a breach, use the copy button at the bottom of the checklist to share the plan. You can also print it and go through it together. Walking through the checklist with someone else helps catch steps that are easy to miss when you are stressed.