What to do if your personal information is exposed in a security breach

Oct 8, 2019 | Updated Mar 21, 2024

by Jennifer Bridges @JenBridgesRD

Frustrated man sitting in front of his computer with his hand on his head
  1. Change your passwords>>Change all your passwords
  2. Use 2-factor authentication>>Enable two-factor authentication on all your accounts
  3. Monitor the web>>Monitor the Web for signs of someone using your information
  4. How to create strong passwords>>How to create strong passwords
  5. Other privacy tips>>Other ways to protect your online privacy
  6. Resources>>Resources

This post has been modified to reflect new information since its original publication.

Nobody wants to get this email: “Your information may have been exposed in a security breach.” If you have received a similar message, you are not alone. Since 2005, 9,106 data breaches have exposed more than 10 billion records, containing Americans’ Social Security numbers, financial data, and account passwords.

If your personal information has been compromised by a data breach, you need to do three things right away:

  1. Change all your passwords
  2. Enable two-factor authentication on all your accounts
  3. Monitor the Web for signs of someone using your information

In order to successfully complete these tasks, you’ll need to learn more about what happened in the breach. What items of personal information were exposed? When did the breach occur?

While all 50 states require companies to promptly notify individuals affected by a breach, there are circumstances that might delay this notification, sometimes for years. For example, a company might learn about a breach years after the fact or law enforcement agencies might request the company’s silence during an investigation.

Once you know what data has been exposed and how long it’s been out there, you can start doing damage control.

1. Change all your passwords

To secure all your private information, you’ll need to change both your email password and the passwords to all your other online accounts as quickly as possible after a breach.

Access to your email address is among the most valuable assets for hackers. This is because your email account is the key to finding and breaching many of your other online accounts, including your banking and credit accounts. Access to your email also allows the hacker to impersonate you in order to trick your contacts into revealing their sensitive information (a.k.a. “phishing”).

Has your personal information been exposed online?

Remove my information

If you can’t log in to your email account, then someone has probably already taken it over. You’ll need to contact your email provider for instructions on getting back into your account—or deleting it if this isn’t possible.

After you’ve changed your email password, you need to protect all your other online accounts. This is because hackers who gain access—however temporarily—to your email address and password can easily get into some or all your other accounts using the account’s “forgot password?” feature.

As such, you need to lock out any intruders by changing the password for every account you have.

While doing so, make sure you create a unique password for every site. This way, if someone breaches one account, then that person can’t reuse those login credentials to access your other accounts.

To make this task easier, you can use a password manager, like 1Password, Dashlane, or Keeper. These tools store all your passwords in an encrypted vault that only you know the password to. They can also generate robust passwords and automatically enter them for you on websites and apps.

2. Enable two-factor authentication on all your accounts

Ready to protect your identity & secure your private information?

Protect my identity

This extra security step, which involves entering a special code sent to your phone whenever you log into an account, is one of the most effective ways to keep your private information safe. Not only does two-factor authentication prevent others from logging in as you, but it also notifies you (via the message on your phone) whenever this occurs.

If your service lets you use a two-factor authentication app, like Google Authenticator, you should do so. Apps like this are even more secure than text-message authentication.

3. Monitor the Web for signs of someone using your information

If your email address and password were exposed in a data breach, there’s a good chance that other vital information has been compromised. Therefore, you need to be vigilant about looking for evidence of ID theft and fraud.

A good way to do this is to monitor your financial statements for any charges that you didn’t make. If you find anything suspicious, you should alert your bank as soon as possible.

You should also closely monitor your credit reports for any new or unusual activity. Make sure that no one has opened any new accounts, credit cards, or loans in your name.

An easy way to check your credit history is to request a free report from Experian, Equifax, and TransUnion via annualcreditreport.com. You can receive one free report per year (and asking for a report doesn’t hurt your credit score.)

How to create strong passwords

Picture of a padlock with strong arms

Of course, the easiest route to creating strong and unique passwords for all your accounts is to use a password management tool. These tools’ password-generator features can quickly produce random, hacker-proof passwords like “6′(T@?8JWxutD6ws6YNp.” However, if you prefer to create your own passwords, there are a few simple best practices you should follow to make sure they are as strong as possible:

Has your personal information been exposed online?

Remove my information

Other ways to protect your online privacy

Ready to protect your identity & secure your private information?

Protect my identity

Resources

Locking down your online privacy can seem like an overwhelming task at first. However, it becomes easier once you understand what you need to do. Luckily, there are resources you can turn to for help.

ReputationDefender offers free advice 24/7 on the best ways to protect your privacy. We also have several privacy-related articles in our Resource Center, including:

Need assistance? Talk to an expert.

All ReputationDefender consultations are free, confidential, and without obligation.

Call 877-492-5209 or Schedule a Consultation

<div class="trustpilot-widget" data-locale="en-US" data-template-id="539adbd6dec7e10e686debee" data-businessunit-id="5c645cb3dc82bd0001544269" data-style-height="500px" data-style-width="100%" data-theme="light" data-stars="4,5" data-review-languages="en"> <a href="https://www.trustpilot.com/review/reputationdefender.com" target="_blank" rel="noopener">Trustpilot</a></div>