Situation

A breach exposes your email address and mobile number but not your password, and scam texts begin mentioning the breached company by name.

Contact data is useful to scammers even without a password

Start by treating an exposed email address and phone number as a specific response problem rather than as proof that every part of your identity has been taken over. These details give scammers reliable delivery channels and context for impersonation even when the breach did not include a password. Check whether the same notice also lists password hashes, security answers, SIM information, account recovery data, or an SSN, because those details would increase urgency.

Your first move is documentation: save the notice, log the date it came in, and note precisely which data or account it identifies. The immediate problem is targeted phishing and account recovery abuse rather than an assumption that a new credit account has already been opened.

Contact data like this usually increases the quality of follow-up scams more than it creates direct account access on its own. Expect messages that mention the breached company, pretend to offer monitoring, or claim a refund is expiring. The fact that the sender knows your details is not proof the message came from the company.

Secure email before chasing every suspicious text

The first move should reduce the most immediate pathway to misuse. Strengthen the primary email account with a unique password and two-factor authentication, then review recent sessions and recovery contacts.

One risk at a time, in order of urgency, beats trying to cover everything on day one. Email deserves attention before low-value accounts, because password-reset links for many services arrive there.

Secure the primary email account first, since it is often the reset channel for other services. Check recent sessions, forwarding rules, filters, app passwords, recovery addresses, and recovery phone numbers. If any of those changed without your permission, treat the problem as an account takeover rather than merely a contact-information breach.

Review recovery settings and active sessions

Your email and mobile providers can show account-recovery settings, signed-in devices, forwarding rules, SIM or port security options, and recent changes — check all of them.

When an organization asks for identity documents while you're fixing this, verify the destination before uploading anything. Open the provider app directly instead of following a “secure your account” link from a text that arrived after the breach.

For the phone number, add the carrier's strongest available account protection, such as a separate account PIN or port-out control. A breach does not mean a SIM swap has occurred, but sudden loss of service, unexplained carrier messages, or a notice that the number moved to another device should be handled immediately through the carrier.

Decide whether the breach creates a credit risk

A freeze is worth doing when the leaked data could plausibly be used to open an account, not as a default step. It may not be necessary for contact data alone unless other identity information was exposed or you see evidence of new-account fraud.

In situations calling for credit monitoring, annualcreditreport.com is the place to pull a dated baseline first. Watch for password-reset messages you did not request, login alerts from unfamiliar devices, carrier notices, and new-account emails from services you never joined.

Save evidence of targeted reset or impersonation attempts

This isn't paperwork for its own sake — good records actively help resolve the situation. Save examples of suspicious messages with sender details and timestamps, especially when they show a progression from generic spam to account-specific reset attempts.

If you find actual misuse connected to the breach, shift from breach preparation to identity-theft recovery. If an account is taken over or your identity is used to open another service, document the actual misuse through IdentityTheft.gov and the affected provider.

Prefer an authenticator app or hardware-backed method over SMS for high-value accounts when the service supports it. That reduces the impact if the phone number is later hijacked. Do not disable two-factor authentication entirely just because the number leaked; replace a weaker recovery path with a stronger one instead.

Understand what changing a phone number would miss

One control rarely fixes every consequence of a breach like this. Changing a phone number or email address is disruptive and does not erase old contact data already in databases or stop scams aimed at the former address.

Also separate exposure from confirmed misuse. A single phishing message is different from a confirmed recovery-email change or SIM port; the second kind of event deserves immediate provider contact.

Use a separate channel to verify urgent messages

Expect follow-up scams that refer to the breach. Expect messages that cite the real incident and claim a deadline to “verify” your identity, cancel protection, or restore a payment.

A legitimate recovery process should be verifiable through an established channel. Use a known website or app to check whether the claimed problem exists before replying or entering a code.

Watch for escalation from contact data to account takeover

Wrap up this phase by scheduling actual follow-up dates rather than trusting yourself to remember them. Review recovery settings again after major password changes and after any carrier or email notice that you did not initiate.

The main channels are under your control when recovery contacts are correct, unknown sessions are removed, and unexpected reset traffic is treated as a signal instead of an instruction.

Credit controls are usually secondary when only contact details were exposed. Review the breach letter carefully for other data before freezing credit solely because of an email address or phone number. The best continuing defense is to secure the accounts those contact details can recover and to distrust inbound messages that use personal details to manufacture credibility.

Create a short list of high-value services that use the exposed email or phone as a recovery key. Banking, payroll, tax, cloud storage, password managers, and mobile-carrier accounts deserve more attention than low-value newsletters. For each one, check whether an attacker could reset access with only the exposed contact detail plus public information. Where possible, require an authenticator, security key, or separate PIN that was not part of the breach. This turns a broad contact-information incident into a finite account-hardening task and gives you a clear stopping point instead of changing settings on every service you have ever used.

Primary sources used

Check the official source before you submit sensitive information.