What to Do After a Data Breach: A Five-Step Checklist

0
9
What to Do After a Data Breach: A Five-Step Checklist

Getting a letter or email saying a company you do business with had a data breach is unsettling. The good news is that a few steps, taken in order, greatly reduce your risk. Most people can finish them in under an hour.

Step 1: Confirm the notice is real

Scammers send fake breach notices to trick people. Do not click links in the message. Instead, go to the company’s official website by typing the address yourself, or call the number on your card or statement, and look for the same announcement.

Step 2: Find out what was exposed

A genuine notice should say what kinds of information were involved. The response depends on the answer:

  • Passwords: change that password now, and change it anywhere else you reused it.
  • Payment card details: contact your card issuer, who can replace the card and watch for fraud.
  • Social Security or other ID numbers: consider placing a fraud alert or credit freeze with the credit bureaus. In the United States, freezes are free.
  • Email address or phone number only: stay alert for phishing messages that mention the company.

Step 3: Strengthen your accounts

  • Use a unique password for every account, ideally with a password manager.
  • Turn on two-factor authentication wherever it is offered.

Step 4: Watch for follow-up scams

After a breach, criminals sometimes contact affected people pretending to offer help or refunds. A real company will not ask for your password or full card number by phone, text, or email.

Step 5: Keep an eye on your accounts

Review bank and card statements for a few months, and check your credit reports for free at AnnualCreditReport.com. Report anything unfamiliar right away.

The takeaway

A breach is not your fault, and it does not mean your identity will be stolen. Acting calmly and quickly keeps most of the risk under control.

LEAVE A REPLY

Please enter your comment!
Please enter your name here