Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


What to do after a data breach? Do not start by clicking every "check your leak" link you see. First confirm the source of the breach and what type of data was exposed. Then handle passwords, MFA, payments, email, and follow-up scams in risk order. The FTC's identity theft recovery guidance also recommends different steps depending on the type of exposed information and timely contact with the relevant organizations.[1]
Not every breach is equally serious. An exposed email address, password, card number, or identity document requires a different response order.
Do not stop at "your data was leaked." Confirm:
If the notice came by email, open the official website or app manually instead of clicking the email button.
Use this order:
NIST recommends avoiding passwords that have already been exposed.[2]If you reused a password, change every account that used it.
After changing passwords, sign out of all devices, revoke suspicious sessions, and check recovery email, phone number, backup codes, and third-party app access.
Email deserves special attention. Some attackers do not change the password immediately after gaining access. Instead, they quietly set up forwarding rules and keep watching bills, codes, and reset emails.
For a payment card: contact the bank, freeze or replace the card, enable transaction alerts, and review recent statements.
For identity documents: keep the notice as evidence and watch for loan, payment, carrier, and real-name account activity. Identity theft procedures vary by region, but FTC IdentityTheft.gov gives step-by-step recovery guidance.[1]
After a breach, scammers may pretend to be "support," a "bank," or a "platform security team." They may quote your email, phone number, or order details accurately to sound legitimate.
Remember three rules:
For more warning signs, read Phishing attacks in 2026.
Yes, but it is usually not the highest-risk breach. It can lead to spam, phishing, and credential stuffing attempts, so check for reused passwords.
Yes. You cannot know the hash strength, salting method, or attacker resources. Changing it is safer.
Usually not completely. What you can do is change passwords, turn on MFA, monitor accounts, and reduce future exposure.
No. Confirm through the official website, app, official announcement, or reliable reporting before clicking any login link in a notice.
No. Notify your company's IT or security team immediately because attackers may use your account to target coworkers.
Disclaimer: This article is general security education and does not replace advice from your bank, platform, company security team, or legal professionals.
This guide comes from AethoVPN; VPN routing does not carry out the checks required for personal information exposed.
Sources
[1]FTC — IdentityTheft.gov: https://www.identitytheft.gov/ [2]NIST — Digital Identity Guidelines, SP 800-63B: https://pages.nist.gov/800-63-3/sp800-63b.html
Sources checked 8 May 2026.
Related Articles:
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.