What to do after a data breach
Turn a breach notice into a short, prioritized response plan.

Confirm the event
Keep the notice and open the organization’s website independently. Match the incident and affected service before using any link or offer in a message. A public report is useful context; it is not a personal match.
List only the affected fields
Separate passwords, contact details, identity documents and financial data. Record which fields the notice attributes to you and which remain uncertain. This prevents a broad headline from turning into an inaccurate personal diagnosis.
Choose the first useful action
Prioritize a reused password or suspicious account access. For financial activity, contact the provider through a known channel. For U.S. identity or credit concerns, use the FTC’s guidance to choose the relevant protection or recovery step.
Keep a small response log
Save the source, date checked, action taken and next review date in a private place. Record a submitted request separately from a confirmed result. Do not paste passwords, full document numbers or sensitive notices into public forums.
