What to Do When a Company You Trusted Loses Control of Your Information
By the end of this lesson, you'll understand:
A data breach happens to a company, not to you directly, but the consequences land on you regardless, since your information can then be used for phishing, credential stuffing, or direct identity theft. Knowing exactly what to do in the days after a breach notification meaningfully limits the damage.
A data breach occurs when an unauthorized party gains access to a company's stored data, which can include names, email addresses, passwords, Social Security numbers, or payment information, depending on what that company collected and how it was secured. Breaches happen to organizations of every size, including major, well-resourced companies.
What to check: You typically learn about a breach through a direct notification from the affected company, though not always immediately, sometimes months pass between the breach and public disclosure.
The specific data exposed varies by breach, some involve only email addresses and passwords, while others include Social Security numbers, financial account details, or medical information. The notification you receive should specify what type of information was involved, which determines how urgently and specifically you need to respond.
What to check: Read the breach notification carefully to understand exactly what was exposed, rather than assuming the worst or dismissing it as minor without checking.
Change the password for the affected account immediately, and change it everywhere else you reused that same password (a strong argument for the password manager habit from FPS108). If financial account numbers or a Social Security number were exposed, consider a credit freeze or fraud alert (covered in upcoming lessons) and monitor those accounts closely.
What to check: Take advantage of any free credit monitoring the breached company offers as part of its response, many are legally or voluntarily required to provide this for a period of time.
Beyond direct notifications, independent tools like Have I Been Pwned let you check whether your email address has appeared in a known breach, sometimes surfacing exposures the affected company never directly notified you about.
What to check: Periodically check your primary email addresses against a reputable breach-checking tool, rather than relying solely on direct notifications, which aren't always sent promptly or at all.
Grace receives an email notifying her that a retailer she'd shopped with was breached, exposing her name, email, and a hashed password. She immediately changes her password on that retailer's site and, realizing she'd used a similar password on her email account, updates that one too.
She also checks Have I Been Pwned and discovers her email appeared in two additional breaches she was never directly notified about, from services she'd forgotten she'd signed up for years earlier. She updates those passwords as well and begins migrating to a password manager, closing several gaps at once rather than addressing them one at a time as future notifications arrive.
If a company I trust is breached, it means I did something wrong or was careless.
A breach reflects a security failure on the company's end, not a personal mistake. Your responsibility is in how you respond afterward, changing passwords, monitoring accounts, not in preventing a breach you had no control over.
If I haven't received a breach notification, my information hasn't been exposed.
Notifications aren't always sent promptly, and some breaches go undetected or undisclosed for a long time. Independent breach-checking tools can reveal exposures a company never directly told you about.
The right level of response depends on what was exposed, an email-only breach warrants a password change, while a breach involving your Social Security number warrants the more significant steps (credit freeze, closer monitoring) covered in the lessons ahead.
Depending on the circumstances, class-action settlements sometimes follow major breaches, and affected individuals may be eligible for compensation or free monitoring services, watch for official settlement notifications rather than unsolicited claims offers, which can themselves be scams.
Reputable, well-established breach-checking tools only require an email address to check, not a password or other sensitive information, be cautious of any similar-sounding tool that asks for more than that.
Check your primary email addresses against a reputable breach-checking tool today, and update the password on any account flagged as compromised.
With data breaches understood, the next lesson, FPS112: Protecting Older and Vulnerable Adults, addresses a group especially and specifically targeted by fraud.
That's where Financial Confidence becomes your personal breach response guide.
Financial Confidence can help you check for known breaches involving your information, track which passwords need updating, flag accounts eligible for free post-breach monitoring, and organize your response to a new breach notification.
Explore More LessonsLet us know if this lesson was useful, it helps us know what to keep improving.
Thanks for letting us know!