lab1908

guides / privacy

I received a data breach notification

What it means, what's actually at risk, and exactly what to do — in the right order.

Question 1 of 3

What kind of data was exposed?

Phishing emails disguised as breach notifications are common. Before doing anything else, confirm the breach actually happened.

If you can't verify it

Treat the email as suspicious — don't click any links in it. If the breach is confirmed, keep reading.

This is what most breach guides don't tell you. If an attacker got into any of your accounts, they may have set up mechanisms to stay in — even after you change your password.

In Gmail:

On your phone carrier:

If you discover actual fraud — not just exposure — document everything. You'll need it.

A breach isn't a single event. The data is out there, and fraud can emerge weeks or months later.

quick reference

ExposedFirst thingMost important stepDon't forget
PasswordChange it on breached siteFind everywhere you reused itCheck email for forwarding rules
Email onlyNo urgent action neededTurn on 2FA everywhereWatch for phishing
FinancialCall your bankCredit freeze at all 3 bureausReview linked accounts
SSNCredit freeze at all 3 bureausIRS Identity Protection PINSSA account lockdown
MedicalReview recent insurance claimsRequest your medical recordsFile HHS complaint if HIPAA breach

resources