Home
» Today
»
What Is a Data Breach? How to Check Your Accounts and Protect Your Data
What Is a Data Breach? How to Check Your Accounts and Protect Your Data
A data breach notice can be unsettling, especially when it arrives by text or email and asks you to act quickly. Start with one calm question: what information was exposed, and what can someone do with it? A breach means data was exposed or accessed without authorization; it does not automatically prove that someone logged in to your account or used your identity. Your best result is a set of verified facts, protected accounts, and a clear plan for any exposed financial or identity information.
Use the steps below in order: verify the notice, check what is known about your email address, secure accounts that share exposed credentials, and follow up based on the type of data involved. This guide reflects U.S. consumer guidance checked September 26, 2026. Individual companies may give additional instructions for their own incidents.
1. Verify the notice before you act
If a company says your information was involved in a breach, do not use the message’s link or phone number to sign in. Open the company’s app or type a website address you already know, then look for a notice in your account or contact support through a trusted channel. The Federal Trade Commission (FTC) gives the same practical advice for unexpected messages: reach the company through a website or phone number you know is real.
Read the notice for the affected service, incident date, categories of information involved, and steps the company recommends. A notice may say that an email address, password, phone number, payment details, Social Security number, or other information was exposed. Those details change the response. Save the notice and its date in case you need to contact the company, bank, insurer, or a government agency later.
A person reviews an online notice at home; verify a message through the service’s known website or app.
Be cautious if the message pressures you to act immediately, asks for a password or one-time code, requests payment, or sends you to an unfamiliar site. A real breach notification does not make every follow-up message legitimate. If the notice might be real, contact the organization independently and ask whether it sent the alert. Do not reply with personal details or give a caller remote access to your device.
2. Check your email address and the affected accounts
You can search an email address on Have I Been Pwned, a breach-search service that reports whether the address appears in breach datasets it has collected. Its FAQ explains that its breach search does not display passwords linked to an address. Use it as one clue, not as a complete security audit. A “no results” page cannot establish that your information was never exposed: a breach may be new, not publicly reported, or not included in the service. Some sensitive incidents also are not publicly searchable.
Enter only the email address you want to check. Do not paste your password into a breach-search page, a message, or a form that claims it can “confirm” your exposure. If you want to check whether a password is known to be exposed, use the security tools built into a trusted password manager or follow the service’s official instructions; the safer immediate choice for an exposed password is to replace it with a new, unique one.
Next, sign in to the affected service by opening its app or known website yourself. Review recent sign-in activity, devices, recovery email addresses and phone numbers, connected apps, and security alerts if the service offers them. In email accounts, also look for unfamiliar forwarding rules or filters. Unknown sessions, a changed recovery address, messages you did not send, or unexpected password-reset notices are stronger signs that an account itself may have been accessed. A breach listing alone is not proof of account takeover.
Review account security on a trusted device; never expose a password or verification code while checking.
3. Secure the accounts in the right order
If the exposed data includes a password, change it on the breached service and anywhere else you reused it. Start with your primary email account, because email often controls password resets for other services. Then secure financial, mobile carrier, cloud storage, shopping, and social accounts that shared the same password. If each account already has a different password and the notice says no password was exposed, a routine password change everywhere may add work without addressing the specific risk.
Create a different, long password for each account. A reputable password manager can generate and store unique credentials so you do not have to remember them all. NIST’s current Digital Identity Guidelines, SP 800-63B Revision 4, say services should not require arbitrary periodic password changes; they should require a change when there is evidence that a password has been compromised. For an exposed or reused password, change it now. For accounts not implicated by a breach and with unique credentials, focus on multifactor authentication (MFA), recovery settings, and suspicious activity rather than changing passwords on a calendar.
Turn on MFA for your email, financial, mobile carrier, and other important accounts when it is available. MFA asks for an additional proof of identity beyond a password, such as an authenticator approval, a security key, a passkey, or a one-time code. Prefer a passkey, security key, or other phishing-resistant method when a service offers one. CISA recommends phishing-resistant MFA where possible and points to number-matching approval as a stronger fallback than an unconfirmed push prompt. If text-message verification is the only option, it still adds a layer beyond a password, but protect the phone number and recovery process too. See CISA’s multifactor authentication guidance for the tradeoffs.
Enable a second sign-in factor on important accounts and keep recovery codes somewhere secure.
After changing a password, use the service’s security page to sign out other sessions and remove devices or connected apps you do not recognize. Check that recovery details still belong to you, and save any backup codes in a secure place separate from your phone. If you cannot get into the account, use the provider’s official account-recovery process. If you see unauthorized financial activity, contact the bank or card issuer immediately using the number on your card or its official app.
4. Match the next action to the information exposed
Information named in the notice
What to do next
Useful sign that you have acted
Email address or username
Expect more convincing phishing attempts. Secure the email account, use unique passwords, and do not trust unsolicited reset links.
You can sign in through the known app or site, and recovery details are still yours.
Password or security answer
Change it at the affected service and everywhere it was reused. Review active sessions and connected apps.
The new password is unique, and unfamiliar sessions have been signed out.
Bank, card, or payment information
Call the bank or card issuer through a trusted number, review recent transactions, and ask whether the account or card should be replaced.
You recognize activity or have disputed and documented anything you do not recognize.
Social Security number or identity details
Use IdentityTheft.gov for tailored recovery steps. Consider a credit freeze with each of the three nationwide credit bureaus.
You have confirmation from each bureau that a freeze is in place, if you chose to freeze.
Health or insurance information
Contact the insurer or provider using its official contact information and ask how to flag suspicious claims or account changes.
You know where to report an unfamiliar claim, policy change, or bill.
In the United States, a credit freeze is free and can make it harder for someone to open new credit accounts in your name. It does not block every kind of fraud, such as charges on an existing payment card, and you may need to lift the freeze temporarily when applying for credit. The FTC explains how freezes and fraud alerts differ. If you suspect identity theft, IdentityTheft.gov can help build a recovery plan; you do not have to wait for a breach notice before using its guidance.
Review statements and contact your financial institution through a trusted number if anything looks unfamiliar.
How to tell whether your response is working
Look for concrete changes, not a promise that a breach can be undone. You should know which service was involved and what categories of data were named; have replaced any exposed or reused password; have enabled MFA where practical; and have removed sessions or connected apps you did not recognize. Check bank and card activity for transactions you cannot explain. If identity details were exposed, decide whether a credit freeze or fraud alert fits your situation, and verify the status directly with the bureaus.
Keep the notification, the company’s response, case numbers, and notes about calls or disputed transactions. Recheck account activity and statements over time, especially after a notice involving financial or identity data. If new password-reset messages, unfamiliar logins, unauthorized charges, or accounts you did not open appear, stop treating the event as a notice-only issue: contact the affected provider or bank and use IdentityTheft.gov’s recovery steps.
What a breach check cannot tell you
A public email lookup only checks the records available to that service; it cannot inspect every private database or predict whether someone will misuse information. A clean search is not proof that you are unaffected, and a match is not proof that an attacker has logged into your account. Likewise, credit monitoring can help you notice some changes, but it does not prevent someone from trying to use exposed data. A password reset protects future sign-ins with that credential; it cannot remove copies of information already disclosed.
Guidance checked September 26, 2026. Security settings and breach databases change, so use each provider’s current help page and account dashboard for exact steps.