Situation

A travel company says your passport number was included in a breach, but you still possess the passport and there is no sign of a fraudulent passport application.

Separate a leaked number from a lost passport

Start by treating an exposed U.S. Passport number as a specific response problem rather than as proof that every part of your identity has been taken over. The State Department says a person cannot travel using only a U.S. Passport number; international travel requires the original physical passport. Confirm whether the breach involved only passport data or whether the physical passport itself was lost, stolen, or intercepted.

Save the notice, jot down the date it arrived, and note the exact data element or account it names before doing anything else. A leaked number can still be useful in broader identity fraud when combined with a name, date of birth, address, or other identifiers, so it should not be ignored.

A passport number is sensitive identity data, but it is not the same thing as losing the passport book or card. Keep the physical document secured and confirm that it has not gone missing. The State Department's lost-or-stolen process is designed for a document that is actually lost or stolen; reporting a valid passport that way cancels it, so a number-only breach should not trigger an unnecessary cancellation.

Do not cancel a document that is still safely with you

Lead with whichever step closes off the most immediate risk of misuse. Keep the passport secure, save the breach notice, and review other exposed data before deciding what controls are relevant.

Do not try to solve every possible consequence at once. If the physical passport is missing or stolen, use the State Department’s lost-or-stolen reporting process immediately because that fact changes the response.

If travel is coming soon, separate the security problem from the travel deadline. Verify the passport's physical location, expiration date, and condition first, then use Travel.State.Gov for any replacement or loss question. A third-party site advertising an emergency cancellation or a paid 'passport lock' after a breach is not a substitute for the State Department's own instructions.

Know when the State Department process actually applies

Here, the U.S. Department of State explains that reporting a valid passport lost or stolen cancels it and that the document remains invalid even if you later find it.

A request for ID documents is a signal to slow down and confirm who is actually asking. Use Travel.State.Gov directly for passport reporting or replacement instead of a search ad or message that promises expedited cancellation.

The more realistic follow-up concern is identity verification outside the border-control context. A stolen passport number may be combined with a name, birth date, address, or other data in an application. Watch the systems that would show that activity—credit reports, bank correspondence, carrier notices, and government mail—rather than assuming the likely misuse would involve someone traveling with only the number.

Look beyond travel misuse to identity verification

Freezing credit or pulling a report makes sense only when this exposure touches new-account or reporting risk. A credit freeze may be useful if the breach also exposed data suitable for new-credit fraud, but it does not cancel or alter a passport record.

If credit monitoring is the right call, pull a baseline report from annualcreditreport.com first, dated, so later reports have something to measure against. Watch for unfamiliar credit inquiries, financial accounts, or government correspondence rather than assuming the likely misuse would involve physical travel.

Document any fraudulent application or account

Documentation isn't busywork tacked onto the end; it's part of the resolution process itself. Record the passport expiration date and the breach details without storing a full unmasked passport number in an ordinary notes app.

Confirmed misuse changes everything: this becomes an identity-theft recovery case, not a preparedness one. If you discover an account or application created with your identity, use IdentityTheft.gov to document the misuse and follow the recovery plan for the affected organization.

When saving evidence, avoid creating another full copy of the passport number in ordinary notes. The breach notice, the affected company's case number, and a masked identifier are enough for an incident timeline. If an official process later needs a passport image, confirm the upload destination independently and keep a record of exactly what you submitted.

Understand what passport cancellation would and would not fix

One control rarely fixes everything here. Canceling a passport unnecessarily creates travel disruption and does not remove other stolen identifiers from a breach database.

Also separate exposure from confirmed misuse. The decision changes if the physical book or card is lost, mail delivery was intercepted, or the State Department tells you a fraudulent application was attempted.

Expect fake passport-replacement outreach

Expect follow-up scams that use this same pretext. Fraudsters may impersonate passport services and demand payment or copies of identification shortly after a widely publicized breach.

A legitimate recovery process should be verifiable through an established channel. A legitimate passport problem can be checked at Travel.State.Gov without trusting the contact details in an unsolicited message.

Recheck the situation if the physical document changes hands

Close things out with concrete dates on a calendar — memory is not a reliable tracking system here. Keep the notice until the passport expires and re-evaluate if you receive unexplained travel-document, credit, tax, or banking correspondence.

The response is on track when the physical passport is accounted for, you have not canceled it without reason, and any actual identity misuse has its own case record.

Revisit the issue if the facts change. A missing passport book, intercepted replacement mail, or notice of an application you did not make is materially different from passive exposure. At that point use the State Department's current document process for the passport itself and IdentityTheft.gov for any separate account or identity misuse.

One more practical check is to separate the passport record from every account that merely stores a passport copy. A hotel, airline, employer, or travel vendor may have kept an image or number for its own verification process, but that does not give the vendor authority to cancel or alter the passport itself. Ask the breached organization whether a full image, only the number, or additional identity fields were exposed. That distinction affects how useful the stolen data may be in later impersonation. If a company says it will delete or replace its stored copy, keep that confirmation with the breach notice, but continue to rely on the State Department for the status of the actual passport document.

Primary sources used

Check the official source before you submit sensitive information.