A breach notice creates an uncomfortable problem: you know something went wrong, but you may not know whether anyone has actually used your information.
That distinction matters. IdentityTheft.gov separates exposure from confirmed misuse by first asking whether someone has already used the information to open an account, make a purchase, apply for a loan, get a job, file taxes, or claim government benefits.
If the answer is no — or you simply do not know yet — the job is prevention and monitoring. If the answer becomes yes, the job changes to identity-theft recovery.
First, Find Out Exactly What Was Exposed
Do not treat every breach the same. The practical risk depends heavily on the information involved.
| Information Exposed | Main Risk | First Response |
|---|---|---|
| Password or login credentials | Account takeover and credential reuse | Change the password and enable multifactor authentication |
| Email address | Phishing, password resets, targeted scams | Secure the email account and watch for impersonation |
| Social Security number | New-account, tax, employment, or benefits identity theft | Freeze credit, review reports, and monitor tax activity |
| Credit or debit card number | Unauthorized transactions | Contact the card issuer and monitor or replace the card as directed |
| Bank account information | Unauthorized withdrawals or account misuse | Contact the bank promptly and follow its fraud-security instructions |
| Medical or insurance information | Medical identity theft or fraudulent claims | Review insurer and provider records |
| Driver’s license or other identity document | Impersonation and account-opening risk | Use the breach-specific steps at IdentityTheft.gov and applicable issuing-agency guidance |
The FTC directs people affected by breaches to IdentityTheft.gov’s lost-or-exposed-information workflow because it tailors the response to the type of data involved.
Save the breach notice and record what the company says was exposed, when the breach occurred, when it was discovered, and what protection it is offering.
If a Password Was Exposed, Change It Immediately
The FTC says to change an exposed password right away. If you used the same or a similar password elsewhere, change those accounts too.
Password reuse is what turns one compromised login into several compromised accounts. Attackers can take credentials stolen from one breach and try them at email, banking, shopping, social-media, or other services.
Prioritize:
- the breached account;
- your primary email account;
- bank and credit-card accounts;
- tax and government accounts; and
- any other service where the same or a similar password was used.
Use unique passwords rather than making minor variations of the exposed one.
Then enable multifactor authentication where available. FTC guidance explains that a second authentication factor can prevent someone with a stolen password from logging in by password alone.
If Your Social Security Number Was Exposed, Protect New-Credit Access
A stolen Social Security number creates a broader and longer-lived risk than an exposed password because you cannot simply replace it like a login credential.
The FTC specifically recommends reviewing credit reports when an SSN is exposed and says a credit freeze becomes especially important when a Social Security number or other sensitive information has been exposed in a breach.
A freeze prevents prospective creditors from accessing the frozen bureau file for most new-credit decisions. Under federal law, freezes are free.
To cover the nationwide credit files, place a freeze separately with:
- Equifax;
- Experian; and
- TransUnion.
You can still obtain and review your own reports while a freeze is in place. You can also lift the freeze when you legitimately apply for new credit.
Our Credit Freeze vs. Fraud Alert guide explains the tradeoffs.
Review your reports for unfamiliar accounts and inquiries using the process in Free Credit Reports.
A Freeze Protects New Credit — Not Every Kind of Fraud
A security freeze is powerful, but its protection has a specific boundary.
The CFPB describes a freeze as preventing prospective creditors from accessing your credit file. It does not prevent someone from making unauthorized charges on an existing card or withdrawing money from a compromised bank account.
A freeze also does not universally block employment, tenant-screening, or insurance access under the federal freeze rule.
A breach exposes both your Social Security number and an existing credit-card number.
Freezing all three credit files can make fraudulent new credit harder to open.
But the freeze does not protect the already-issued card number. You still must monitor that card and work with the issuer if the number is compromised.
This is why breach response should match the exposed data rather than relying on one universal tool.
Consider a Fraud Alert if You Suspect Misuse
An initial fraud alert tells businesses that check your credit to take steps to verify your identity before opening new credit in your name.
Current FTC guidance says:
- an initial fraud alert is free;
- it lasts one year and can be renewed;
- you contact only one of the three nationwide bureaus; and
- that bureau must tell the other two to place the alert.
A fraud alert is different from a freeze. It does not block access to the report; it adds an identity-verification requirement.
You can use a fraud alert even when a freeze is already in place.
If identity theft is later confirmed, qualifying victims can obtain an extended fraud alert that lasts seven years after completing the required identity-theft documentation.
If Financial Account Data Was Exposed, Contact the Institution Directly
When card or bank information is compromised, credit-report protection is only part of the response.
Review recent transactions and contact the institution using a trusted channel — the official app, a website you type yourself, a statement, or the number printed on the card.
Do not rely on a phone number or link in an unexpected message that claims to be helping with the breach.
Ask what the institution recommends for the information that was exposed. Depending on the account and incident, that can include replacing a card, changing credentials or PINs, restricting the account, or increasing transaction monitoring.
Continue watching statements after the immediate response. FTC consumer guidance emphasizes that even when credit is frozen, a thief can still misuse existing accounts.
Use Free Credit Monitoring if the Breached Company Offers It
The FTC recommends taking advantage of free credit monitoring offered after a breach.
Monitoring can be useful because it may alert you when something changes on a credit report. But it should not be confused with prevention.
The CFPB says most credit-monitoring services do not protect personal information from being stolen; they generally alert consumers after report activity appears.
That creates a useful division of labor:
| Tool | What It Mainly Does |
|---|---|
| Credit monitoring | Alerts you to changes that appear on monitored credit reports |
| Credit freeze | Restricts prospective creditors from accessing a frozen bureau file for most new-credit decisions |
| Fraud alert | Requires additional identity-verification steps for covered new-credit activity |
| Account alerts | Notify you about transactions, logins, or changes on existing financial accounts |
Free monitoring is therefore worth using when it is offered, but it is not a substitute for freezing credit when exposure creates meaningful new-account risk.
Watch Tax and Government Accounts When an SSN Is Involved
Credit fraud is only one possible use of a stolen Social Security number.
The IRS warns that stolen taxpayer information can be used to file fraudulent returns, obtain employment, or interact with tax accounts.
Current IRS guidance recommends an Identity Protection PIN (IP PIN) as a preventive tool. The six-digit IP PIN helps prevent another person from filing a federal tax return using your taxpayer identification number.
Also watch for:
- IRS notices about activity you do not recognize;
- tax-return filing problems;
- W-2 or 1099 forms from employers you did not work for;
- unexpected unemployment-benefit forms; and
- unrecognized access to tax or Social Security accounts.
The IRS notes that a data breach alone does not prove tax identity theft. Follow current IRS instructions for your specific situation rather than filing forms automatically.
Be Suspicious of Messages That Exploit the Breach
A real breach can create an opportunity for a second scam.
A message may claim that you must “verify” your Social Security number, bank information, password, or one-time security code to receive breach protection.
FTC phishing guidance recommends independently contacting the real organization instead of trusting links or contact details in unexpected messages.
Use the company’s known website or app, and verify any free monitoring or recovery offer there.
If you clicked a suspicious link or opened an attachment that may have installed malicious software, FTC guidance says to update your security software, run a scan, and remove anything the scan identifies.
If Someone Uses the Information, Switch to Identity-Theft Recovery
Exposure and identity theft are different stages of the problem.
If monitoring reveals an account, purchase, withdrawal, tax filing, employment record, medical claim, or benefit application that you did not authorize, report the identity theft through IdentityTheft.gov.
The federal site can generate an Identity Theft Report and a recovery plan tailored to the type of misuse.
At that point, common steps can include:
- closing or securing fraudulent accounts;
- placing or maintaining freezes and fraud alerts;
- reviewing all three credit reports;
- blocking fraudulent credit-report information where FCRA requirements are met;
- changing compromised credentials;
- contacting affected government agencies; and
- keeping written records of every action.
Our Identity Theft Recovery Checklist walks through the full sequence.
If you are still trying to determine whether misuse has occurred, see Identity Theft Warning Signs.
Frequently Asked Questions (FAQs)
Does a data breach mean my identity has been stolen?
No. A breach means information was exposed or accessed in a way it should not have been. Identity theft occurs when someone actually uses your personal or financial information without permission.
Should I freeze my credit after a data breach?
A freeze is especially worth considering when sensitive identity information such as a Social Security number has been exposed. The FTC says freezes are free and can be placed even before any misuse occurs. To cover the three nationwide files, contact Equifax, Experian, and TransUnion separately.
What should I do if my password was exposed?
Change it immediately and change any other account that uses the same or a similar password. Use unique credentials and enable multifactor authentication where available.
Is free credit monitoring after a breach worth using?
Yes. The FTC recommends taking advantage of free monitoring offered after a breach. Remember that monitoring mainly alerts you to report changes; it does not prevent personal information from being stolen or block all new-account fraud.
Should I place both a credit freeze and a fraud alert?
You can. A freeze restricts prospective creditors’ access to the frozen file, while a fraud alert requires additional identity verification for covered credit activity. The tools perform different functions.
Does a credit freeze stop fraud on my existing credit cards?
No. A freeze is aimed primarily at new-credit access. Continue monitoring bank and card accounts because an attacker can still misuse existing account credentials or card numbers.
What if my Social Security number was exposed?
Review your credit reports, consider freezing all three nationwide credit files, monitor financial and tax activity, and consider obtaining an IRS IP PIN. If you discover actual misuse, report identity theft through IdentityTheft.gov.
Where should I go if I find actual identity theft after a breach?
Use IdentityTheft.gov, the federal government’s identity-theft reporting and recovery resource. It provides an Identity Theft Report and a recovery plan based on the type of fraud involved.
Sources
- IdentityTheft.gov — What To Do if Your Information Was Lost, Stolen, or Exposed in a Data Breach
- Federal Trade Commission — What To Do After a Data Breach
- FTC — Steps after a data breach
- FTC — Credit Freezes and Fraud Alerts
- Consumer Financial Protection Bureau — Security freezes
- CFPB — Credit monitoring services
- FTC — Two-factor authentication
- FTC — How To Recognize and Avoid Phishing Scams
- Internal Revenue Service — Identity theft guide for individuals
- IdentityTheft.gov — Identity-theft reporting and recovery






