
What to do after a data breach: change the password on the breached account immediately, then check every other account for the same or a similar password, and turn on multi-factor authentication everywhere you can. If your Social Security number was exposed, place a credit freeze with all three credit bureaus. Over the following weeks, monitor your bank and credit card statements, your credit reports, and any insurance or tax accounts tied to the exposed information.
If you run a business, the sequence is different. Your first priority is containment, not notification. Isolate affected systems, preserve forensic evidence, and get your cyber insurer and breach counsel involved within the first 24 hours, because state and federal notification deadlines, some as short as 30 days, start running from the moment you discover the incident.
According to the Identity Theft Resource Center, U.S. organizations reported more than 3,200 data compromises in 2023, the highest annual total the organization has tracked. Stolen credentials often appear for sale on criminal marketplaces within hours of a breach, so the choices you make in the first day or two determine whether the incident stays contained or turns into months of identity theft and fraud cleanup.
Quick Answer
After a data breach, change the password on the affected account first, then any account reusing that password, and turn on multi-factor authentication. Check HaveIBeenPwned.com to confirm what was exposed, and place a credit freeze with Equifax, Experian, and TransUnion if your Social Security number was involved. Businesses should contain the incident, preserve forensic evidence, and notify cyber insurance and breach counsel within 24 hours, since notification deadlines, some as short as 30 days, start running immediately.
Data Breach Impact by the Numbers
Immediate Response for Individuals (First 24 to 48 Hours)
If you received a breach notification letter or found out your information was exposed some other way, treat the first day as the most important. The FBI's Internet Crime Complaint Center (IC3), the federal government's central hub for reporting cybercrime, notes that acting quickly narrows the window attackers have to use stolen credentials before you close it.
Start with the breached account: change its password, then check every other account where you used the same or a similar password. Password reuse is one of the most common ways a single breach turns into account takeovers across multiple services. A password manager generates and stores a unique, complex password for every account, which removes this risk going forward.
Next, check HaveIBeenPwned.com, a free tool that checks whether your email address or password has appeared in a known breach, so you know the scope of what was exposed. Then enable multi-factor authentication (MFA) on every account that offers it, starting with email, banking, and work accounts, since email is usually the account attackers use to reset everything else.
If financial account numbers or card numbers were exposed, call your bank or card issuer. Most institutions can issue new account numbers immediately once they confirm the breach. Sign up for any free credit monitoring the breached organization offers; companies are increasingly required to provide this at no cost to affected individuals.
Individual Breach Response Protocol
- Change the password on the breached account, then find and change every other account using the same or a similar password.
- Enable multi-factor authentication on affected accounts, starting with email, banking, and work accounts.
- Check HaveIBeenPwned.com with your email address to see which breaches have exposed your data.
- Call your bank and card issuer if any financial account numbers were exposed, and request new account numbers.
- Sign up for any free credit monitoring the breached organization offers.
- Place a fraud alert or credit freeze if your Social Security number was exposed.
- File a report at IdentityTheft.gov if fraud has already occurred.
Credit Freeze vs. Fraud Alert: Which Do You Need?
If the breach exposed a Social Security number or other identity data, password changes are not enough on their own. Identity thieves can use a stolen Social Security number to open credit accounts, file false tax returns, or get medical services in your name, sometimes months or years after the original breach.
A fraud alert is a free notice placed on your credit file that requires lenders to verify your identity before issuing new credit. You only need to contact one of the three credit bureaus; federal law requires that bureau to notify the other two. A fraud alert lasts one year and can be renewed.
A credit freeze, also called a security freeze, blocks anyone, including you, from opening new credit in your name until you lift it. Freezes are free under federal law and stay active until you remove them, but you have to contact all three bureaus separately: Equifax at 1-800-349-9960, Experian at 1-888-397-3742, and TransUnion at 1-888-909-8872.
A credit freeze is the stronger protection after a confirmed Social Security number exposure, since it blocks the main path to new-account fraud. Request your free credit report at AnnualCreditReport.com, the only source authorized under federal law to provide free reports from all three bureaus, to check for accounts you did not open.
Credit Freeze vs. Fraud Alert: Which Do You Need?
Cost
- Credit Freeze
- Free
Duration
- Credit Freeze
- One year, renewable indefinitely
Effect on Credit File
- Credit Freeze
- Creditors must verify your identity
Bureaus to Contact
- Credit Freeze
- One, it notifies the other two
Best Use Case
- Credit Freeze
- Suspected exposure, SSN not confirmed
| Feature | Credit Freeze |
|---|---|
| Cost | Free |
| Duration | One year, renewable indefinitely |
| Effect on Credit File | Creditors must verify your identity |
| Bureaus to Contact | One, it notifies the other two |
| Best Use Case | Suspected exposure, SSN not confirmed |
Financial Protection Checklist After a Data Breach
- Place a credit freeze with Equifax, Experian, and TransUnion separately if your Social Security number was exposed.
- Sign up for any free credit monitoring the breached organization offers.
- Set up real-time transaction alerts with your bank and credit card providers.
- Request a free credit report at AnnualCreditReport.com and review it for unauthorized accounts.
- Review Explanation of Benefits (EOB) statements from your health insurer if medical data was exposed.
- Check the IRS Get Transcript tool if your Social Security number was confirmed compromised.
- Report identity theft and start a recovery plan at IdentityTheft.gov.
Business Response: What to Do in the First 24 Hours
If your organization experienced a data breach, the first 24 hours decide whether you contain the damage or face compounding regulatory penalties, lawsuits, and reputational harm. Business response is different from individual response because legal obligations, regulatory deadlines, and a forensic investigation all have to be managed at the same time, not one after another.
Contain first: isolate affected systems, revoke compromised credentials, and block the attack vector you identified. Do not wipe or rebuild systems right away. Preserving forensic evidence matters for understanding what happened, meeting legal obligations, and supporting an insurance claim or litigation. The FBI recommends preserving evidence before cleaning infected systems, since it supports root cause analysis and possible law enforcement involvement through IC3.
Activate your incident response plan immediately. If you do not have a documented plan, this incident is the reason to build one, but respond with whatever structure you have right now. Engage breach counsel and a forensic cybersecurity firm in parallel, not sequentially: counsel protects you from regulatory missteps, and forensic investigators identify the root cause and scope.
Notify your cyber insurance provider as early as possible. Most policies have strict notification requirements, and your insurer may have preferred vendors that reduce your out-of-pocket cost. Waiting on this notification is one of the most common and expensive mistakes organizations make in the early hours of a breach.
Breach Notification Deadlines Are Legally Binding
Notification deadlines vary by industry and state, and missing one creates liability separate from the breach itself. Healthcare organizations covered by HIPAA's breach notification rule must notify affected individuals within 60 days. Non-bank financial firms covered by the FTC Safeguards Rule must notify the FTC within 30 days if 500 or more consumers are affected. Public companies must file an SEC Form 8-K within 4 business days of determining a breach is material, under the SEC's 2023 cybersecurity disclosure rule. Florida, Colorado, and several other states require notification within 30 days for all businesses, regardless of industry.
Business Breach Containment Protocol
- Isolate affected systems, revoke exposed credentials, and block the identified attack vector.
- Preserve forensic evidence, including disk images, memory captures, and firewall and endpoint logs, before remediation.
- Activate your incident response plan and document every action with timestamps.
- Engage breach counsel and a forensic cybersecurity firm at the same time, not sequentially.
- Notify your cyber insurance provider and document the date and time of notification.
- Work with breach counsel to determine which state and federal notification laws apply based on where affected individuals live.
- Notify affected individuals and regulators within the applicable deadlines.
Legal and Regulatory Notification Requirements
Every U.S. state has a data breach notification law, and requirements vary in timing, scope, and penalties. Your obligation is based on where affected individuals live, not where your business is located, so a breach touching customers in multiple states can trigger several different notification requirements at once. That is why experienced breach counsel matters from day one, not as an optional expense.
Federal Requirements by Industry
Healthcare (HIPAA): Covered entities and business associates under the Health Insurance Portability and Accountability Act must notify affected individuals within 60 days, report to the Department of Health and Human Services within 60 days for breaches affecting 500 or more people, and notify local media when 500 or more residents of a single state are affected. According to the IBM Cost of a Data Breach Report 2024, the average healthcare breach cost $9.77 million, well above the all-industry average. For more on covered entity obligations, see our guide to healthcare ransomware and breach protection.
Financial services (FTC Safeguards Rule): The FTC Safeguards Rule requires non-bank financial institutions, including many tax preparers, mortgage brokers, and accountants, to notify the Federal Trade Commission within 30 days if a breach affects 500 or more consumers. Our guide on the FTC Safeguards Rule's qualified individual requirement covers how the rule applies to tax and accounting firms. Noncompliance can expose a firm to FTC enforcement action, which can include fines and mandated security audits.
Public companies (SEC): Publicly traded companies must evaluate whether a breach is material under the SEC's 2023 cybersecurity disclosure rules. If it is material, the company must file a Form 8-K, a report disclosing significant events to investors, within 4 business days of that determination.
State Notification Laws
State breach laws vary widely. California requires disclosure 'in the most expedient time possible.' New York's SHIELD Act requires notification 'without unreasonable delay.' Florida and Colorado set fixed deadlines of 30 days or fewer. Because state laws can overlap and conflict in a multi-state incident, legal counsel is not optional for any business with customers across state lines.
What Your Breach Notification Must Include
Regulators, class action attorneys, and reporters read breach notification letters closely. At minimum, yours should explain what happened and when, which data types were exposed, what you have done in response, what recipients should do to protect themselves, and how to reach you with questions. Avoid minimizing language such as 'limited incident' or 'no evidence of misuse.' Stolen data can be used well after a breach, and affected individuals deserve straightforward guidance about that risk. For breaches involving Social Security numbers, financial account numbers, or medical records, plan to offer at least 12 to 24 months of credit monitoring and identity restoration at no cost to those affected.
Preventing Future Data Breaches
A data breach should push you to fix the gaps that allowed it, not just clean up the immediate damage. The same vulnerabilities that enabled one breach often enable a second one if you leave them unresolved.
For Individuals
Use a password manager to generate and store a unique password for every account. Turn on multi-factor authentication everywhere it is offered, starting with email, financial accounts, and work systems. Watch for phishing attempts that use details from the breach to look more convincing than a generic scam email, since attackers often follow a breach with targeted messages built from the stolen data. Keep your operating system, browser, and apps updated, since many breaches exploit known vulnerabilities that a security patch would have closed. Review which third-party apps have access to your accounts and remove permissions you no longer use.
For Organizations
After containing a breach, work with your forensic firm to identify the root cause and any related vulnerabilities still present in your environment. Put mandatory security awareness training in place for all employees, especially if the breach involved phishing or social engineering. Add network segmentation to limit how far an attacker can move during a future incident, and deploy Endpoint Detection and Response (EDR) to catch threats before they become full incidents.
Review your vendor relationships. A third-party vendor with access to your systems or data is a risk surface that is easy to overlook until a breach traces back to a supplier. A security risk assessment and annual vendor reviews are practical starting points if you do not have in-house security staff.
Data Breach Prevention Checklist
- Use a password manager and create a unique password for every account.
- Enable multi-factor authentication on all accounts, especially email and banking.
- Keep operating systems, browsers, and applications updated with current security patches.
- Verify the sender before clicking a link or opening an attachment in an unexpected email.
- Run annual phishing and security awareness training for all employees.
- Deploy Endpoint Detection and Response (EDR) on all workstations and servers.
- Maintain and test a documented incident response plan at least once a year.
- Review third-party vendor access and security posture at least once a year.
Managed EDR Built for Small Teams
Bellator Core combines managed endpoint detection and response, 24/7 monitoring, and Ransomware Rollback® to reduce the chance a compromised endpoint turns into a reportable breach.
Get Your Free Cybersecurity Evaluation
A Bellator security expert will review your current endpoint protection, access controls, and incident response readiness and show you the specific gaps to close before the next incident.
Frequently Asked Questions
Respond the same day. Stolen credentials are often traded on criminal forums within hours of a breach, so change the password on the affected account and any account reusing it, then turn on multi-factor authentication immediately. Contact your bank right away if financial data was exposed.
It depends on what was exposed. If your Social Security number was compromised, place a credit freeze with Equifax, Experian, and TransUnion separately, since it blocks anyone from opening new credit in your name. If only an email address or password was exposed, a fraud alert placed with one bureau, which then notifies the other two, is a reasonable precaution. Both are free under federal law.
Credit monitoring tracks your credit reports at the three major bureaus and alerts you to new accounts, inquiries, or score changes. Identity theft protection services usually go further, adding dark web scanning for your personal information and Social Security number monitoring, and sometimes recovery assistance if theft occurs. Many companies offer free credit monitoring after a breach; identity theft protection is typically a paid add-on worth considering if your Social Security number was confirmed compromised.
Plan on at least 12 to 24 months. Stolen data can sit on criminal forums for years before it is actively used, and identity thieves sometimes wait months before filing a fraudulent tax return or opening a new account with a stolen Social Security number. Set up transaction alerts with your bank and card providers, and check your credit reports regularly at AnnualCreditReport.com.
Contain the incident by isolating affected systems and revoking compromised credentials, but preserve forensic evidence before wiping or rebuilding anything. Engage breach counsel and a forensic cybersecurity firm at the same time, and notify your cyber insurance provider promptly. Do not manage the legal side of the response on your own; missing a regulatory notification deadline creates liability separate from the breach itself.
Yes. A healthcare breach triggers HIPAA notification requirements with a 60-day deadline for covered entities and business associates. A breach at a non-bank financial firm covered by the FTC Safeguards Rule requires notifying the FTC within 30 days if 500 or more consumers are affected. A breach at a public company may require an SEC Form 8-K filing within 4 business days if the breach is material. State laws add another layer, with requirements that vary by data type, the number of affected residents, and where those residents live.
From requirement to defensible practice
Turn the requirement into a security plan people can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Incident response & NIST
Build a response process that helps people detect, contain, recover, and improve when something goes wrong.
- Common question: incident response planBuild an incident response planStart with clear roles, escalation steps, evidence handling, and recovery priorities.
- Common question: NIST incident response frameworkUse the NIST incident response frameworkWalk through preparation, detection, containment, recovery, and lessons learned.
- Common question: NIST cybersecurity framework guideUnderstand NIST CSF 2.0Connect governance and risk decisions to identify, protect, detect, respond, and recover.
- Common question: cyber incident response plan templateUse an incident response templateTurn response concepts into a document your team can follow under pressure.
- Common question: tax data breach responsePrepare a tax-practice response planAdd IRS, client-data, and tax-season considerations to the general response process.



