A company confirms your full date of birth and mailing address were exposed, but it says no Social Security number, password, or payment card was involved.
Why durable identity facts need a different response
Start by treating an exposed date of birth and home address as a specific response problem rather than as proof that every part of your identity has been taken over. These are durable identity facts that can make social-engineering attempts more convincing even when they are not enough by themselves to open every kind of account. Read the notice carefully to see whether the exposure also included an SSN, account number, credential, security answer, or government ID because those additions change the response.
Do this first: keep the notice, log its arrival date, and write down which data point or account it flags. Do not treat a birth date or address as if it can be reset; the practical controls are stronger account authentication, reduced reliance on knowledge-based questions, and better verification of future contacts.
A birth date and home address are not credentials you can rotate. The practical goal is therefore to make them less useful as recovery clues. Review important accounts that still rely on knowledge-based questions, especially questions built from address history or other public facts. Replace weak recovery questions where the provider allows it and make sure stronger recovery methods are under your control.
Protect the accounts that use those facts as recovery clues
The first move should reduce the most immediate pathway to misuse. Secure your primary email and important financial accounts, then remove obsolete recovery questions or weak security answers where providers allow stronger options.
Resist the urge to tackle every downstream risk simultaneously. An account that can reset other accounts matters more than changing a public profile that happens to display the same address.
Treat unexpected mail as a signal, not junk. A new-account welcome letter, insurance notice, government letter, or collection notice addressed to you can reveal misuse before it becomes visible elsewhere. Save the envelope and document the sender before contacting the organization through a known channel; the mailing date and address used may help distinguish a clerical error from an identity-theft application.
Review which services still treat old facts as authentication
For each important account, review whether the provider uses address, date of birth, or similar facts as a recovery check and add stronger authentication where available.
Never upload identity documents without first confirming the request came from a genuine source. Make these changes from saved bookmarks or official apps so a fake breach-support message cannot collect the same information again.
The exposed address can also make phishing more convincing. A caller who knows your street and birth date has not proved who they are. Do not let those facts authenticate an inbound contact. If a bank, insurer, carrier, or government office appears to be calling, end the contact and use the institution's official number or app to verify whether a real case exists.
Use credit reports as a signal, not a prediction
Not every breach warrants a credit freeze — it matters when the data could enable new credit applications. A freeze is most compelling when stronger identity data was also exposed or when you find an unfamiliar inquiry or account; it is not automatically required because an address appeared in a leak.
For cases where credit monitoring matters, get a dated report from annualcreditreport.com as the starting reference point. Use your credit reports to look for new accounts, inquiries, and address changes that do not fit your actual activity.
Create an incident baseline without spreading the data again
Keeping a clear paper trail is part of fixing this, not something to handle once the dust settles. Save the breach notice and record which durable identity facts were involved, but do not copy a full dossier of your personal data into an unsecured incident note.
The moment misuse is verified, the task shifts from prevention to identity-theft recovery. If the exposed facts are later used to open an account or take over a service, document the actual misuse at IdentityTheft.gov rather than reporting exposure alone as completed theft.
Review credit reports for new accounts, inquiries, or address changes, but keep the response proportional. A freeze can be useful when the breach also exposed information that could support new-credit fraud; it does not make your birth date private again. The lasting control is stronger account recovery plus skepticism toward contacts that exploit durable personal facts.
Avoid unnecessary address or identity changes
One control rarely fixes every consequence of a case like this. Changing your mailing address solely to respond to a breach can create new problems and does not change the leaked historical address or birth date.
Also separate exposure from confirmed misuse. A suspicious address change on a credit report, unexplained mailed account, or recovery attempt is a concrete signal that deserves a targeted response.
Assume convincing follow-up scams will know something about you
Expect follow-up scams that make use of these facts. A caller who knows your birthday and address may sound credible, but breached data can give scammers exactly those details.
A legitimate recovery process should be verifiable through an established channel. Call back through a number on a statement, card, or official website instead of continuing an inbound call that asks you to confirm more personal data.
Keep monitoring proportional to the data that was exposed
The last step of the initial response should be calendar entries, not a mental note to check back later. Review high-value accounts after the breach and again when you receive unexpected account-recovery, credit, tax, carrier, or benefits messages.
The useful outcome is stronger authentication around durable facts and a clear plan for what new signal would count as actual misuse.
Document which organizations already know the exposed address and birth date so you can recognize plausible-looking future messages. You do not need to move homes or change every account simply because those facts leaked. Escalate when a concrete sign appears—an account, inquiry, changed recovery method, or official notice you cannot explain.



