Situation

A company that stored your fingerprint, face scan, or genetic data for identity verification tells you that data was exposed in a breach.

Why this is not the same as a password breach

Every other credential this site covers can eventually be replaced: a password can be reset, a credit card number can be reissued, even a Social Security number can, in rare documented-fraud cases, be changed by the Social Security Administration. A fingerprint, a facial geometry map, an iris scan, a voiceprint, or a DNA profile cannot. It is permanently and uniquely yours, which is exactly what made it useful as an authentication method — and exactly what makes its exposure harder to fully undo.

This doesn't mean nothing can be done. It means the response has to focus on what the biometric data was being used for, rather than on trying to reissue the data itself.

What kind of company typically holds biometric data

Biometric identifiers show up most often with a specific type of company: workplace time-clock systems that use a fingerprint scan for clock-in, phone and laptop manufacturers storing a face or fingerprint template for device unlock, building-access systems using fingerprint or facial recognition, some banking or fraud-prevention services using voiceprint verification for phone support, and consumer genetic-testing companies that analyze a DNA sample you submitted directly.

The breach notice should specify which category applies to you, because the practical response differs meaningfully between, say, a workplace fingerprint clock system and a consumer DNA-testing company.

Turn off or replace the specific biometric authentication

If the exposed biometric data was being used to unlock a device or authenticate into an account — a phone's fingerprint or face unlock tied to a cloud account, a bank's voiceprint verification for phone banking — check whether you can disable that specific biometric method and fall back to a PIN, password, or another authentication factor for that account going forward.

This does not undo the exposure of the biometric data itself, but it limits what a stolen biometric template can actually be used for going forward with that specific provider, since the template alone is generally useless without also compromising the matching system it was designed to work with.

Ask what was actually stored — a raw scan, or a mathematical template

Most modern biometric systems don't store your actual fingerprint image or a photograph of your face; they store a mathematical template derived from it, which is much harder to reverse into something usable by another system. Ask the company directly whether the breach exposed raw biometric images or template data, since that materially changes how much practical risk the exposure carries — and be skeptical of a vague answer, since this is a specific, answerable technical question a company handling biometric data should be able to address.

Illinois and other states with biometric-specific laws

Illinois' Biometric Information Privacy Act requires a private company to get your written consent before collecting a fingerprint, retina or iris scan, voiceprint, facial geometry scan, or DNA-derived identifier, and to disclose in writing how long the data will be kept and used. It also creates a private right to sue over violations, with statutory damages per violation. Texas and Washington have similar, though less litigation-heavy, biometric privacy laws.

If you're an Illinois resident and a company collected your biometric data without the consent and disclosure BIPA requires, that's a separate legal issue from the breach itself, and worth raising with a consumer-protection attorney if you believe the company never obtained proper consent in the first place.

Genetic data breaches carry a longer-term consideration

A breach at a consumer genetic-testing company is a distinct case, because the exposed data can include not just an identifier but health-related genetic predispositions and, depending on the service, information that indirectly reveals details about biological relatives who never submitted a sample themselves. There is no equivalent of freezing a credit file for genetic data — the practical steps are limited to reviewing the company's own account-security settings, deleting your data from their service if you no longer want it stored, and watching for how the exposed information could be used in phishing that references your specific ancestry or health results to seem more convincing.

Standard identity-theft steps still apply if other data was included

Biometric data is often exposed alongside more conventional identifiers — a name, email, or account number in the same breached record. If your notice mentions any of those alongside the biometric data, follow the standard steps for whichever conventional identifier was also involved; the biometric exposure adds a separate, longer-term consideration but doesn't replace the usual response.

Frequently asked questions about biometric data breaches

  • Can someone use my stolen fingerprint template to unlock my phone? Generally no on its own — unlocking typically requires the physical sensor and matching hardware/software on your specific device, not just the template data, though this depends heavily on the specific system involved.
  • Should I stop using fingerprint or face unlock altogether after this? Not necessarily for every device — the concern is specific to the breached provider's system; switching that one account or device to a PIN is the targeted response, not abandoning biometric authentication everywhere.
  • Can a company sell my biometric data to someone else? Laws like Illinois' BIPA specifically prohibit selling or profiting from biometric data without consent — if you suspect that happened, that's a separate legal question from the breach notification itself and worth raising with a consumer-protection attorney in a state with a biometric privacy law.
  • Is there a credit-freeze equivalent for biometric data? No — there's no bureau or registry that can “freeze” a fingerprint or face scan the way credit bureaus freeze a credit file, which is exactly why the response here focuses on the systems using the biometric data rather than the data itself.

A fingerprint time-clock system breach at work

Your employer's third-party time-and-attendance vendor discloses that its database, which stores fingerprint templates used for employee clock-in, was accessed without authorization. You ask HR directly whether the vendor stored raw fingerprint images or a converted template, and whether the same fingerprint data is linked to anything beyond the time-clock system, like a building access badge.

HR confirms the vendor stores only a mathematical template, not an image, and that the time-clock system is not connected to any other authentication. You still ask whether the company plans to switch away from fingerprint clock-in given the incident, since that decision affects whether the same vendor will keep collecting this data going forward — but there's no version of this response that involves trying to "change" your own fingerprint.

Primary sources used

Check the official source before you submit sensitive information.