
What to Do in the First 24 Hours After a Data Breach Notice
A practical triage order for the day you learn your information may have been exposed.
One situation per guide. No product reviews, no generic cybersecurity filler, and no legal-outcome promises.

A practical triage order for the day you learn your information may have been exposed.

Use the notice as an evidence document: identify scope, dates, affected data, offered services, and the response steps that actually match your risk.

Verify a breach notice without handing more personal information to someone who may be impersonating the breached company.

A durable identifier calls for a longer response than replacing a payment card. Focus on new-account fraud, tax misuse, and records that may surface later.

A three-part checklist for placing, confirming, and safely storing a credit freeze with Equifax, Experian, and TransUnion.

Both are free, but they work differently. Choose based on whether you want to restrict new-credit access or add identity checks while keeping the file available.

Unfreeze only the credit file and time window you need, then verify that protection is back in place.

Use dependency order: secure the accounts that reset other accounts before working through lower-impact logins.

Email is often the recovery channel for everything else. Lock it down before an attacker can use it to reset other accounts.

Use all three reports as a baseline, then look for accounts, inquiries, addresses, and debts that do not fit your history.

Investigate first, then move quickly if the account truly is not yours.

What the federal reporting process does, what to gather before you start, and how the resulting report fits into recovery.

A local police report can be useful or required in some recovery situations, but it is not the same document as an FTC Identity Theft Report.

Treat a duplicate filing as tax identity theft, follow the IRS notice or rejection path, and protect future returns with an IP PIN.

Medical identity theft can mix another person’s care or claims with your records. Review clinical records, insurance statements, and credit information separately.

A child may have no normal reason to possess a credit file, which makes an unexpected file or account especially important to investigate.

Credit freezes do not secure an existing bank account. Contact the bank directly and focus on transaction controls, login security, and account-number replacement when appropriate.

Card-number exposure is usually handled at the issuer level: replace credentials, review transactions, and secure the account that controls the card.

Free monitoring can be useful for alerts, but read the enrollment terms and understand what it cannot prevent.

A consumer-focused reading guide to California’s official breach-notice system and public notice database.

Use the Texas Attorney General’s official breach resources to understand notice timing, public reports, and the consumer complaint route.

Understand how New York defines covered breaches, where consumers can complain, and how to use the state’s official guidance without turning it into legal advice.

Identity-theft blocking is different from a normal accuracy dispute and requires specific documentation.

Credit reports do not show every misuse of a Social Security number. Review the SSA earnings record for wages that are not yours.

Use an extended fraud alert after confirmed identity theft when you want lenders to take extra steps to verify new-credit applications in your name.

An unfamiliar hard inquiry can signal a credit application in your name. Verify the source, document it, and use the identity-theft dispute path if unauthorized.

If a collector contacts you about identity-theft debt, verify the collector, preserve the validation notice, dispute in writing, and document the theft.

If USPS confirms a change of address you never requested, report the fraud, restore mail control, and secure accounts that rely on postal delivery.

An unexpected unemployment claim, debit card, or 1099-G can mean your identity was used for benefits fraud. Report it to the issuing state and preserve the tax record.

If your phone loses service or your number moves without permission, contact the carrier, recover the number, and secure accounts that use SMS verification.

A response plan for an exposed license or state ID number without assuming the physical card must be replaced.

What a leaked U.S. passport number means, when not to cancel a valid passport, and what to monitor after the breach.

How to respond when a breach exposes identity details that cannot simply be changed, without treating them like passwords.

A practical response for a leaked health-plan member or subscriber ID, with emphasis on claims, benefits, and medical records.

How to handle a breach that exposes your main contact channels and makes phishing, password resets, and impersonation more convincing.

A bank-account takeover response that prioritizes access control, transaction review, and verified contact with the financial institution.

A verification-first workflow for unexpected password-reset messages that arrive after a real company breach.

How to respond when identity thieves use your information to open a cellular account or device line you did not authorize.

A takeover-focused response for unauthorized changes to account recovery settings after a breach.

A bank-first response for electronic debits you did not authorize after account or routing information was exposed.
Steps for a fraudulent electric, water, cable, or similar service account that appears after your identity information is stolen.
How to investigate an unfamiliar address, distinguish a harmless reporting artifact from identity theft, and correct inaccurate credit-file data.
A documentation-first approach when a debt collector contacts you about an account created through identity theft.
A step-by-step response when a bank, lender, or creditor confirms a new account that you did not authorize.
How identity-theft victims can ask a business for documents tied to fraudulent accounts or transactions and keep the request organized.
A practical incident-file system for breach notices, calls, disputes, confirmations, and evidence without turning recovery into a pile of screenshots.
How to review an SSA earnings history, distinguish ordinary reporting delays from misuse, and request a correction when wages are wrong.
What parents and guardians should know about creating or freezing a minor’s credit file when identity data may have been exposed.
How to respond when a dependent’s SSN appears on another tax return or an IRS notice suggests employment or filing misuse.
How to respond when a vehicle loan or lease appears after identity theft, including lender records, credit reports, and downstream collection risks.
A consumer reading guide to Florida’s breach-notification rule, the 30-day timing language, and the data details that drive your response.
How to read an Illinois Personal Information Protection Act notice and connect its required consumer information to practical recovery steps.
What Massachusetts residents should know about breach letters, security-freeze information, police-report language, and SSN-related monitoring.
A plain-language guide to Washington’s 30-day breach-notification framework and the specific details a resident notice should contain.
How Colorado’s 30-day notification rule, consumer notice content, and 500-resident Attorney General threshold affect the letter you receive.
A reading guide to Virginia’s harm-based notification rule, required notice content, and the identity data covered by the statute.
What Georgia residents should know about the state breach-notification framework and why the law’s scope should be read carefully.
A consumer guide to Pennsylvania’s updated breach law, including health data, account credentials, state reporting, and monitoring provisions.
How to read Ohio’s material-risk breach rule, 45-day outer timing language, and the personal information categories in the statute.
A plain-language guide to North Carolina’s notice content, Attorney General reporting, and the account and credit details residents should verify.