The first 48 hours after a breach names you
A breach notice isn't one task — it's a routing decision. The letter's own “sign up for free monitoring” button is almost always the least urgent line on the page. Here is the actual order: verify the letter is real, read exactly what field was exposed, and let that field — not the “X million affected” headline — decide everything that follows.
A breach letter is a routing decision, not a single task — and the order most people follow is backwards.
12% of Americans 16+ get at least one breach notification in a given year — the only true per-person, government-measured probability in this space.
BJS, Data Breach Notifications and Identity Theft, 2021 (pub. 2024)Health data alone on roughly 276 million Americans — about 82% of the population — was breached in 2024, with a single incident accounting for 192.7 million of that. Assume exposure is common; the real question is what to do about your specific letter, not whether breaches happen.
HHS OCR breach portal, tabulated by HIPAA Journal, 2025The typical identity-theft case costs the median victim nothing out of pocket and about an hour to resolve — 88% of victims lose no money at all. The catastrophic cases are real but concentrated in a minority, which is exactly why triaging by what was actually exposed beats one generic response.
BJS, Victims of Identity Theft, 2021 (pub. 2023)What's actually measured — and what isn't.
12% of Americans 16+ received at least one data-breach notification in a single year — the only true per-person government probability.
Health data on ~276 million Americans — about 82% of the population — was breached in 2024 alone; one attack (Change Healthcare) accounted for 192.7 million people.
The typical identity-theft case: median $0 out of pocket (88% of victims lose nothing), median 1 hour to resolve. The catastrophic cases concentrate in the elder tail.
11 steps, in this order.
Verify the notice is real before touching anything in it
A fake notice can be the actual attack. Don't click any link or call any number printed only in the letter itself — navigate to the company's known site directly, or call a number from a bill or card you already have. A real breach-response vendor (Kroll, IDX, Epiq, and ID Experts are the common ones) never needs your full Social Security number a second time to “activate” a code you were told you already have.
- A portal or caller asking for your full SSN again to “activate” something
- Off-brand logos, poor grammar, or artificial urgency (“respond within 24 hours or lose eligibility”)
- A URL that isn't the vendor's real, independently-checked domain
- Even a state AG's own public breach database has been gamed — Maine's was taken offline in June 2026 after two fabricated reports (fake breach claims impersonating real companies) were filed under a made-up employee name, so a listing alone doesn't prove a breach happened exactly as described
Read exactly what field was exposed
Most state-law-compliant notices are required to specify the exact data exposed — name plus SSN, name plus card number, email plus password hash — and that field, not the “X million affected” headline or the offered remedy, should set your entire response. Treating every letter the same regardless of what it actually says is the most common way people skip the steps that matter and go straight to the least urgent one.
Password or credential exposed → change it everywhere it was reused
Change the password at the breached site first, then check every other site where you reused that password or a close variant — the reused password, not the one breached account, is what actually causes downstream takeovers. Enable MFA while you're there, and run your email through Have I Been Pwned (haveibeenpwned.com) to check for other exposures tied to the same address.
Financial account or card number exposed → call for reissue now, don't wait
Call the number on the back of the card, or your bank's main line, and ask specifically for the account to be closed and reissued, not just flagged — set up transaction alerts before you hang up. Credit-card losses are capped at $50 by federal law, $0 if you report before any unauthorized charge posts; Visa and Mastercard's “zero liability” policies are separate, voluntary network commitments on top of that, not the statute itself.
- Report within 2 business days of learning of the loss → liability capped at the lesser of $50 or the unauthorized amount
- Report after 2 days, but the transactions appeared on a statement you got within 60 days → capped at $500
- Miss the 60-day window after that statement → unlimited liability for transfers after the window closes (Regulation E)
SSN exposed → freeze your credit
Full freeze mechanics — every bureau, the fallback ladder, and the secondary agencies most people forget — belong in the freeze guide, not re-derived here; just do them. The one breach-specific addition: an initial fraud alert (1 year, one bureau's request, businesses must verify your identity before opening new credit) is a lighter fallback if you want to keep normal credit access without the freeze/thaw cycle, but a freeze is the stronger, now-free default for an SSN a breach letter has actually named.
- If you also want new third-party monitoring, enroll in it before you freeze — a new enrollment can fail identity verification against an already-frozen file
- Full bureau-by-bureau mechanics: see this site's credit-freeze guide
SSN exposed near tax season → get an IRS Identity Protection PIN
Anyone with an SSN or ITIN who can verify their identity is eligible now, not just confirmed fraud victims. Do this independent of your freeze decision, but be aware of the calendar: losing an IP PIN before filing season causes an e-filed return to be rejected outright or a paper return delayed, so treat it as time-sensitive once you're enrolled, not a one-time task you can forget about.
Medical or insurance ID exposed → get a new member ID and start reading EOBs
Call the insurer for a new member ID, then watch every Explanation of Benefits for services you didn't receive. This is the one breach type where the letter's credit-monitoring offer does the least good — credit monitoring doesn't watch EOBs or medical claims at all, so the free tool the letter pushes doesn't cover the actual exposure.
- You have a federal right under HIPAA to inspect and get copies of your own medical records, with limited exceptions
- A separate, narrower HIPAA right lets you request who your records were disclosed to over the prior six years — but it excludes routine treatment, payment, and operations disclosures, which is most of what actually happens, so it's a narrow forensic tool, not a full access log
- Correcting a fraud-tainted medical record may require a police report as supporting documentation — one of the few places one is genuinely likely to be asked for
Driver's license number exposed → check your specific state's process
This is genuinely state-by-state, not uniform. Vermont, for example, requires a signed, dated letter to the DMV plus a confirmation document, which flags the file for extra ID checks rather than issuing a new license number. Check your own state DMV's page directly rather than assuming any single process — most states mark the record instead of reissuing a number, and a fresh physical card may carry its own fee.
Passport number alone exposed → don't rush to pay for a replacement
If only the number — not the physical document — was exposed, the number by itself doesn't directly enable meaningful fraud, and the State Department won't necessarily issue a free replacement for that reason alone. Paying out of pocket for a preemptive replacement the government doesn't consider necessary, and won't reimburse absent documented fraud, is a real and avoidable failure mode. If the physical passport itself is lost or stolen, that's a different, faster process — report it directly at travel.state.gov.
Decide on the free monitoring offer last, not first
It's free to accept, and there's little downside once you've verified the letter is real (step 1) — but read the enrollment terms once, specifically for auto-renewal into a paid tier. It detects fraud after the fact; it doesn't prevent anything or fix your exposure, which is why it belongs last, not first, no matter how prominently the letter features it.
- A bureau-bundled credit lock (not a statutory freeze) can silently revert when its free period ends — Equifax's post-2017 free TrustedID Premier lock auto-unlocked when the trial expired, without a clear renewed warning
- The one historical scare on this topic — a forced-arbitration clause buried in Equifax's 2017 enrollment terms — was reversed within about a day after public backlash; it's the reason “read the terms once” is permanently good advice, not evidence that today's offers hide the same trap
File an FTC Identity Theft Report only once you've found actual fraud
This is a tool for after fraud is confirmed — a fraudulent account, a wrong tax return, a fraudulent medical claim — not a required response to merely receiving a notification letter. It substitutes for a police report in many credit-related cases; specific institutions (some banks, DMVs, medical-record correction requests) may still ask for one, so ask the specific institution rather than assuming either way.
Where this actually goes wrong
- You sign up for the free monitoring first and consider the letter handled — it's the least urgent line on the page; it detects fraud after the fact and does nothing about the actual exposure named above it.
- You click the link or call the number printed only in the letter itself — verifying independently is the one step that protects you from the letter being the actual attack.
- You change the password at the breached site and stop there, leaving the same password live everywhere else you reused it — the reused password, not the one breached account, is what actually gets exploited.
- You wait for a fraudulent charge to show up before calling your card issuer — the point of calling after a breach notice is to reissue before the number gets used, not to dispute after.
- You request a new Social Security number as your first move after an SSN exposure — SSA issues one only in narrow circumstances (an identity-theft victim who's already tried to fix the resulting problems and remains disadvantaged), it requires an in-person appointment, and a new number creates its own complications rather than being a clean fix.
You already pay for an assistant that can do the drafting.
Paste one of these prompts in, fill in your details, and it will draft the checklist or the letter for you — the guardrails below each prompt are built from the failure modes AI assistants specifically hit on this topic.
We don't see your details and we're not in the loop. This is genuinely yours to run.
Help me figure out exactly what to do about a specific data-breach notification I received. MY LETTER - Company/organization that sent it: [NAME] - What the letter's “information involved” section says was exposed: [PASTE THE EXACT LANGUAGE, e.g. name + SSN, email + password, card number, medical ID] - State I live in: [STATE] WHAT I NEED 1. Based on exactly what was exposed (not the headline number of people affected), tell me the specific steps that actually apply to my situation, in the right order. 2. Tell me which of those steps are time-sensitive and which can wait. 3. Tell me plainly whether signing up for the letter's free monitoring offer should be my first step or a later one, and why. RULES - Do not tell me whether my specific data was or wasn't in this breach beyond what the letter itself states — you cannot verify that independently. - Do not produce a URL, phone number, or portal address for this company, a breach-response vendor, or my state's Attorney General office from memory — tell me to find it independently (the company's own known site, a bill I already have, or the state AG's official domain) and warn me not to use any link or number printed only in the letter without independent verification. - Do not tell me a police report is always or never required — tell me an FTC Identity Theft Report often substitutes for credit-related cases, but that specific institutions may still ask for one, and to check directly.
Check what it produces before sending — verify any statute, phone number, or URL it gives you.
The things people actually ask.
Usually yes — it costs nothing and there's no meaningful downside once you've verified the letter is legitimate. But read the enrollment terms once for auto-renewal into a paid tier, and understand it detects fraud after the fact; it does not prevent anything or fix your exposure. Treating enrollment as “handling” the breach is the most common mistake — it's the least urgent step in the sequence, not a substitute for the freeze, reissue, and password steps.
- No study measures what share of the millions of annual breach notices ever leads to confirmed fraud against the specific recipient — this response rests on mechanism and regulatory mandate, not a measured per-notice risk probability, and this guide won't invent one.
- The free monitoring offer detects fraud after it happens. It does not prevent identity theft, undo the breach, or replace a credit freeze.
- A credit freeze only blocks the new-credit-account pull. It does nothing for medical identity theft, tax fraud, or fraud on accounts you already have — each of those needs its own specific response, not a freeze.
- Requesting a new Social Security number is almost never the answer. SSA issues one only when you've already tried to fix the resulting problems and remain disadvantaged, and a new number creates its own complications rather than being a clean fix.
- A class-action settlement, if one ever arrives, is not meaningful compensation. Documented actual per-person payouts have run from a few dollars to about $25 against advertised ceilings in the hundreds or thousands.