What to Do After a Data Breach: Protect Your Identity in 2026

A "paste or "dump with your email does not equal identity theft - but it raises the probability. Attackers automate credential stuffing within hours. Act fast, in order.
1. Confirm Exposure
- Check Have I Been Pwned (Troy Hunt) - enter your email, not password.
- Review breach details: what fields leaked (email+password? SSN? phone?)? When? From which service?
- Scan your own dark web exposure via your password manager's breach watch or enterprise monitoring - see dark web monitoring for businesses.
2. First 24 Hours - Contain
- Change passwords for the breached service and any other site where you reused that password. Use a password manager; generate 18+ character random passwords.
- Enable 2FA everywhere - prefer authenticator app or hardware key over SMS.
- Revoke sessions - log out all devices on the breached service and on email (Google/Microsoft account -> active sessions).
- Watch financials - if card or SSN leaked, contact your bank; in the US consider a credit freeze with all three bureaus (Equifax, Experian, TransUnion).
3. Next 7 Days - Recover
- File breach notice with the affected company; request what they will do (forced reset, free monitoring).
- If ID documents leaked, consider an FTC identity-theft report (identitytheft.gov in US) or police report in EU.
- Replace exposed security questions - they are not secret.
- Audit OAuth grants: Google -> third-party app access; revoke unknown apps.
For EU residents (GDPR)
You can request erasure (Art. 17) and information (Art. 15) from the controller. They must respond within one month. If they suffered the breach, they should have notified their supervisory authority within 72 hours - ask for the reference. See GDPR vs CCPA comparison.
For US residents (CCPA/CPRA)
California residents can request to know, delete, and opt out of sale/sharing of personal information. Even outside California, similar state laws now apply in 10+ states with comparable rights.
4. Long-Term - Harden
- One password per site, managed by a vault; never reuse.
- Hardware key for email and financial accounts.
- Freeze credit by default; thaw only when applying.
- Monitor with HIBP alerts or OSINT alerting for your domain.
| Action | When | Why |
|---|---|---|
| Rotate breached password + reuse | Hour 0-"4 | Stops credential stuffing |
| Enable 2FA | Hour 0-"12 | Blocks takeover even with password |
| Revoke sessions & tokens | Day 1 | Kills stolen cookies |
| Freeze credit / notify bank | Day 1-"2 | Prevents new account fraud |
| Request deletion / info | Week 1 | Exercises legal rights |
5. Rights You Can Exercise Now
Under both EU and many US state laws you can: know what data a company holds, correct it, delete it, and limit automated decisions. Templates for requests are linked from Wikipedia: GDPR and your state attorney general. We provide a template in the Contact packet.
Not legal advice. For credit freezes see Equifax, Experian, TransUnion sites; for EU, consult your DPA. Sources: FTC, ICO UK, ENISA, Have I Been Pwned.