The email usually starts the same way: a company you have an account with says your information "may have been involved" in a security incident. The vague wording is often a legal choice, not an evasive one — but it leaves you to figure out what to actually do. Here's a clear order of operations.
First, figure out what was actually exposed
Breach notices are legally required to say what category of data was involved, even when the rest of the email is vague. Look for specific terms: passwords, email addresses, physical addresses, phone numbers, partial or full payment card numbers, government ID numbers. What you do next depends heavily on which of these applies — a leaked email address alone calls for far less action than an exposed password or ID number.
In the next 24 hours
Watch for the follow-up scam
Breach notices are themselves a template scammers copy. In the days after a real, well-publicized breach, expect a wave of fake "your account was compromised, click here to secure it" emails impersonating the same company. Don't click links in any breach-related email — go to the company's site directly, the way you normally would, and check your account settings from there.
A simple decision guide
- Email address only: stay alert for phishing, no password change needed unless you reused that email as a password component elsewhere (some people do).
- Password exposed: change it on that site and everywhere you reused it, today.
- Payment card exposed: call your card issuer.
- Government ID number exposed: freeze your credit with all three major bureaus.
- Any of the above, repeatedly, across multiple breaches: that's a sign to get a password manager and stop reusing passwords, since it's very likely one of your old, reused passwords is already circulating.
The takeaway
A breach notice isn't an emergency that demands panic, but it is a deadline: the specific actions above are time-sensitive precisely because the same information reaching you has usually already reached people looking to use it. Match your response to what was actually exposed, and treat any "click here to secure your account" link in the notice itself as suspicious by default.