Key Takeaways
- Stolen data is typically sold on criminal marketplaces within hours or days of a breach.
- Criminals use exposed credentials for account takeovers, fraud, and targeted phishing attacks.
- Freezing your credit is one of the most effective ways to limit identity theft damage.
- Changing compromised passwords immediately and enabling two-factor authentication reduces risk significantly.
- Monitoring your financial accounts and credit reports helps catch misuse early.
What you will need
What Actually Happens to Your Data After a Breach
When a company's database is compromised, stolen records rarely sit idle. Within hours, that data — emails, passwords, names, payment details — is typically packaged and listed for sale on criminal marketplaces operating on the dark web (the portion of the internet not indexed by standard search engines). Buyers then use these lists in several ways.
The most immediate risk is credential stuffing: automated software that tries your exposed username and password combination across hundreds of popular websites. Because many people reuse passwords, attackers gain access to banking, email, and retail accounts with minimal effort. From there, they can drain funds, redirect deliveries, or lock you out entirely.
More sensitive data — Social Security Numbers, birthdates, full financial account numbers — gets used for identity theft, where criminals open new credit lines, file fraudulent tax returns, or take out loans in your name. This type of fraud can take months or years to detect and untangle.
Finally, your exposed details fuel targeted phishing. A criminal who knows your name, email address, and the last four digits of your card can write a convincing fake alert that looks nothing like generic spam. Understanding this pipeline is the first step toward interrupting it. You may also want to review warning signs that a platform handles your data carelessly before trusting services with sensitive information.
Breach Notification Emails Can Be Faked
Phishing attacks often spike after a well-publicized data breach, with criminals sending fake "security alert" emails designed to look like official notifications. Never click links inside breach notification emails — instead, go directly to the company's official website by typing it into your browser. If you're unsure whether a notification is real, contact the company through their official support channel.
How to Respond: Step-by-Step
Knowing what to do — and in what order — can significantly limit the damage a breach causes. Gather the tools you'll need before you start.
What you will need
Credit Freeze (via each major bureau)
Prevents new lines of credit from being opened in your name without your explicit authorization.
Password Manager
Generates and stores unique passwords for all accounts, preventing credential reuse across sites.
Two-Factor Authentication (2FA) App
Adds a second layer of verification so stolen passwords alone cannot unlock your accounts.
Free Credit Report Service
Allows you to review your credit report for unauthorized accounts or inquiries.
Identity Monitoring Service
Scans known data marketplaces and alerts you if your personal information appears in new breaches.
Confirm the breach is real and understand what was exposed
Before taking action, verify the breach through the company's official communications or a trusted source such as the FTC's IdentityTheft.gov or Have I Been Pwned (haveibeenpwned.com). Identify exactly what categories of data were compromised — passwords, email addresses, financial account numbers, or Social Security Numbers each carry different levels of risk and require different responses.
Change passwords on affected accounts immediately
Reset the password on any account directly involved in the breach. Then audit every other account where you used the same or a similar password and change those too. Use long, unique passwords — a mix of letters, numbers, and symbols — for each account. This is the right moment to adopt a password manager if you haven't already.
Enable two-factor authentication on key accounts
Two-factor authentication (2FA) requires a second piece of verification — typically a code from an authenticator app or a text message — in addition to your password. Enable 2FA on your email accounts first, as email is often the recovery route for every other account you own. Then extend it to banking, social media, and any accounts storing payment information.
Place a credit freeze with all three major bureaus
A credit freeze — also called a security freeze — instructs the three major credit bureaus (Equifax, Experian, and TransUnion) to block access to your credit file. This prevents criminals from opening new loans or credit cards in your name, even if they have your Social Security Number. You must contact each bureau separately. Freezes are free by federal law and can be lifted temporarily when you need to apply for credit yourself.
Monitor your financial accounts and credit reports
Review your bank and credit card statements for any unfamiliar transactions — even small ones, since criminals sometimes test accounts with minor charges before making larger withdrawals. You're entitled to free credit reports from each major bureau; stagger your requests throughout the year so you're effectively checking every few months. Report any unauthorized activity to your financial institution immediately.
Watch for phishing and social engineering attempts
After a breach, criminals who have your name, email, and partial account details may craft highly convincing phishing emails or phone calls. They may pose as your bank, the breached company, or even a government agency. Be skeptical of any unsolicited contact asking you to verify information or click a link. Social engineering attacks rely on urgency and trust — take a breath before responding to anything that feels pressured.
Use a Password Manager Going Forward
One of the biggest reasons breaches cascade into multiple account takeovers is password reuse. A password manager generates and stores unique, complex passwords for every account, dramatically reducing the damage any single breach can cause. Most reputable managers work across devices and browsers.
Once you've completed these immediate steps, take time to run a broader audit of your digital security posture. Our complete online security checklist walks you through reviewing passwords, privacy settings, and account access across all your devices. It's also worth remembering that breaches aren't the only way your data gets exposed — public Wi-Fi networks are another common vector that many people overlook. And if you use smart home devices, the same security principles apply — see our guide on keeping connected devices secure over time.
Act Within the First 48 Hours
The window between a breach notification and criminal misuse of your data can be very short. Prioritize changing passwords on affected accounts and placing a credit freeze before taking any other steps. Delaying action significantly increases your exposure to fraud and identity theft.
