What to do after a data breach

What to do after a data breach

Natalie Moore
April 5, 2026· Updated April 27, 2026· 4 min read

What to do after a data breach? Do not start by clicking every "check your leak" link you see. First confirm the source of the breach and what type of data was exposed. Then handle passwords, MFA, payments, email, and follow-up scams in risk order. The FTC's identity theft recovery guidance also recommends different steps depending on the type of exposed information and timely contact with the relevant organizations.[1]

Not every breach is equally serious. An exposed email address, password, card number, or identity document requires a different response order.

What to do after a data breach: confirm the exposure in the first 10 minutes

Do not stop at "your data was leaked." Confirm:

  • which company or platform was breached;
  • whether the exposed data includes email, phone number, password, address, payment card, or ID document;
  • whether passwords were plaintext, hashed, or unclear;
  • whether there is an official notice or reliable media report;
  • whether the notice asks you to click a login link.

If the notice came by email, open the official website or app manually instead of clicking the email button.

Within 1 hour: change the highest-risk accounts first

Use this order:

  1. Primary email;
  2. Accounts using the same or similar password;
  3. Banks, payment apps, and shopping platforms;
  4. Cloud storage and photo backup;
  5. Social media;
  6. Work accounts.

NIST recommends avoiding passwords that have already been exposed.[2]If you reused a password, change every account that used it.


Within 24 hours: enable MFA and revoke old sessions

After changing passwords, sign out of all devices, revoke suspicious sessions, and check recovery email, phone number, backup codes, and third-party app access.

Email deserves special attention. Some attackers do not change the password immediately after gaining access. Instead, they quietly set up forwarding rules and keep watching bills, codes, and reset emails.

What if a payment card or ID document was exposed?

For a payment card: contact the bank, freeze or replace the card, enable transaction alerts, and review recent statements.

For identity documents: keep the notice as evidence and watch for loan, payment, carrier, and real-name account activity. Identity theft procedures vary by region, but FTC IdentityTheft.gov gives step-by-step recovery guidance.[1]

For the next 7 days: watch for follow-up scams

After a breach, scammers may pretend to be "support," a "bank," or a "platform security team." They may quote your email, phone number, or order details accurately to sound legitimate.

Remember three rules:

  • Do not share verification codes.
  • Do not install remote-control software.
  • Do not sign in from SMS or email links.

For more warning signs, read Phishing attacks in 2026.

Summary

  • After a data breach, confirm the type of exposure before acting.
  • Primary email, reused passwords, financial accounts, and cloud storage are highest priority.
  • After changing passwords, turn on MFA, sign out old sessions, and check recovery methods and forwarding rules.
  • For the next week, watch closely for fake support and follow-up phishing.

FAQ

Is it serious if only my email address leaked?

Yes, but it is usually not the highest-risk breach. It can lead to spam, phishing, and credential stuffing attempts, so check for reused passwords.

Should I change a password if only the hash leaked?

Yes. You cannot know the hash strength, salting method, or attacker resources. Changing it is safer.

Can I remove my email from the dark web?

Usually not completely. What you can do is change passwords, turn on MFA, monitor accounts, and reduce future exposure.

Is every data breach notice real?

No. Confirm through the official website, app, official announcement, or reliable reporting before clicking any login link in a notice.

Should I handle a work account breach myself?

No. Notify your company's IT or security team immediately because attackers may use your account to target coworkers.


Disclaimer: This article is general security education and does not replace advice from your bank, platform, company security team, or legal professionals.

This guide comes from AethoVPN; VPN routing does not carry out the checks required for personal information exposed.

Sources

[1]FTC — IdentityTheft.gov: https://www.identitytheft.gov/ [2]NIST — Digital Identity Guidelines, SP 800-63B: https://pages.nist.gov/800-63-3/sp800-63b.html

Sources checked 8 May 2026.


Related Articles:

Start your 3-day free trial

Sign up to experience all premium features at no cost.

*Available only to new users. Each user is limited to one trial.

What to do after a data breach | AethoVPN