Pinzen
GuidesUse casesFAQSupportOpen Pinzen
  1. Home
  2. Guides
  3. What to Do After a Data Breach: A Step-by-Step Family Checklist

Breaches and Hacked Accounts

What to Do After a Data Breach: A Step-by-Step Family Checklist

What to do after a data breach, step by step: confirm the notice, change the right passwords, protect cards and credit, and help your whole family stay safe.

Last updated October 4, 2026 · 8 min read
On this page
  1. First, make sure the breach notice is real
  2. What to do after a data breach, based on what leaked
  3. Your data breach checklist: the first hour and first week
  4. Protecting the rest of your family
  5. Finding reused and exposed passwords quickly
  6. Frequently asked questions

Here's what to do after a data breach: confirm the notice is real by going to the company's website yourself, then find out exactly what leaked. Change the passwords that matter most, and protect your cards and credit if financial or ID details were exposed. The urgent steps take about an hour; the rest can wait for the week ahead.

Plenty of breach advice is written for companies. This guide covers what to do after a personal data breach, for you, your kids, and your parents.

Being in a breach doesn't mean your identity has been stolen. A few calm steps now make your leaked data far less useful to thieves.

First, make sure the breach notice is real

Scammers send fake breach alerts because they know people are worried, so check before you click anything.

A data breach notification letter is how a company tells you your information was exposed. Real ones usually arrive by mail or email and explain what was taken. To check one:

  1. Don't use the links or phone numbers in the message. Type the company's web address yourself, or call a number you trust, like the one on your card.
  2. Look for the same announcement on the company's official website. Big breaches also make the news, and some U.S. state attorney general websites publish breach notices.
  3. Watch for pressure. Real notices don't ask for payment, gift cards, or your password, and they don't give you 10 minutes to act.
  4. Double-check free credit monitoring offers. Many real letters include one, but confirm it on the company's official site first.

Already typed a password into a page you now doubt? Start with what to do in the next hour if you gave a scammer your password.

What to do after a data breach, based on what leaked

Not every breach needs the same response. Find what was exposed in the notice:

  • Email address only: Expect more spam and phishing (scam messages built to steal your logins), but there's nothing urgent to change. Here's what it means when your email is in a data breach.
  • Phone number: Expect scam texts and calls. Ask your carrier for an account PIN or number lock to help block a SIM swap, where a thief moves your number to their phone to get your sign-in codes.
  • Passwords or security questions: Change them now, on that site and everywhere you reused them.
  • Card or bank details: Call your bank or card issuer.
  • Social Security number or ID documents: Freeze your credit.

Passwords and security questions

If a password leaked, treat it as public. Criminals automatically try leaked passwords on other sites, so change it on the breached site and everywhere else you used it.

When changing passwords after a data breach, work in this order:

  1. Your email accounts. Whoever controls your email can reset almost everything else.
  2. Banking, payment apps, and shopping sites that store your card.
  3. Your phone carrier and your Apple or Google account.
  4. Everything else, as time allows.

Make each new password unique. A password generator or four random words beats a small twist on the old one: if Sunshine1 leaked, attackers will try Sunshine2.

If answers to security questions (like your first pet's name) leaked, choose new questions where you can and give made-up answers. Save them somewhere safe, like a password manager.

While you're in each account, turn on two-step sign-in, which asks for a code after your password. Codes from an authenticator app on your phone are safer than texted codes. Where a site offers a passkey, use it: you sign in with your face, fingerprint, or screen lock, so there's no password to leak.

You don't need to change every password you own. Change one when there's a reason, and a breach is a reason. Here's how often you should change your password and what experts recommend now.

Card and bank details

If your full card number was exposed, call the number on the back of the card and ask for a new one, which makes the leaked number useless. If only the last four digits leaked, you usually don't need a replacement. For a leaked bank account number, ask your bank whether to open a new account.

Either way:

  • Read the last few months of statements. Thieves often test a card with a tiny purchase first, so look for small charges you don't recognize.
  • Turn on transaction alerts in your bank's app so you hear about charges right away.
  • Update autopay and subscriptions if you get a new card number.
  • Change your PIN if it leaked, plus anywhere you reuse those digits, like your phone or a door keypad. Pinzen, a family password manager, can store these PINs with reminders to rotate them.

Report fraud fast. In the U.S., debit cards generally have weaker fraud protections than credit cards, and delays can cost you more.

Social Security numbers and ID documents

This is the most serious category, because a Social Security number is nearly impossible to change. These U.S. steps help stop anyone from opening accounts in your name; other countries have similar tools.

  1. Freeze your credit at Equifax, Experian, and TransUnion. A freeze blocks new lenders from seeing your credit report, so thieves have a much harder time opening accounts as you. It's free, doesn't hurt your score, and can be lifted when you need credit. Contact each bureau separately.
  2. Add a fraud alert if you don't want a freeze. It tells lenders to take extra steps to verify it's you. Contact one bureau and it tells the others.
  3. Check your credit reports for free at AnnualCreditReport.com, the official site, and look for accounts you didn't open.
  4. Report identity theft if it has already happened. The FTC's IdentityTheft.gov builds a personal recovery plan and an FTC identity theft report.
  5. Ask the IRS for an Identity Protection PIN. This six-digit number helps stop anyone else from filing a tax return with your Social Security number.
  6. Ask about a leaked driver's license number. Your state's motor vehicle office can say whether to flag it or get a new license.

A freeze is a smart default after a Social Security number leaks, and lifting it before you apply for credit is the main hassle. Free credit monitoring is fine to accept, but it only warns you after something happens; a freeze helps prevent it.

Your data breach checklist: the first hour and first week

Breach cleanup is easier in two short windows.

The first hour

  1. Confirm the notice is real.
  2. Change any leaked password and your main email password.
  3. Call your bank if card details were exposed.
  4. Turn on two-step sign-in for email and banking.
  5. Start credit freezes if your Social Security number leaked.

The first week

  1. Change passwords on your other important accounts, in the order above.
  2. Replace every reused password. A health check, covered below, finds them fast.
  3. Review statements and turn on transaction alerts.
  4. Lock down your phone carrier account if your number leaked.
  5. Save the notice and note what you changed and when, in case you need to dispute fraud.
  6. Set a reminder to recheck your credit reports in a few months.

After that, stay alert: stolen data can surface long after the headlines fade, so be wary of unexpected calls, texts, and emails about the breached company.

Protecting the rest of your family

A breach rarely affects just one person in a family, especially if it hit a shared login, a school, or a doctor's office. Tell everyone what happened, and ask them to check with you before clicking anything odd.

Kids. Children are attractive targets because nobody checks their credit for years. If a breach exposed your child's Social Security number, freeze their credit: in the U.S., it's free for children under 16, though each bureau asks for documents like a birth certificate. Also help older kids replace reused passwords, especially on gaming accounts.

Older parents. After a breach, scammers often pose as the company, the bank, or a "fraud department," and older adults are frequent targets. Remind them that no real company will ask for a password or verification code over the phone, and offer to check any worrying message together. Our guide to protecting elderly parents from phone scams goes further.

Your partner. Agree on who changes which shared accounts so nothing gets missed, and don't text new passwords; a shared vault in a password manager is safer.

Finding reused and exposed passwords quickly

The hardest part of changing passwords after a breach is knowing which ones to change.

A password health check scans your saved logins and flags passwords that are:

  • Weak: short or easy to guess.
  • Reused: the same on more than one site.
  • Exposed: found in known breaches.

If your iPhone or Google account has already flagged a password, here's what a compromised password warning means.

Many password managers include a health check, and Pinzen does too. Its exposure check uses Have I Been Pwned (a free service that tracks known breaches) with a privacy method called k-anonymity: only five characters of a hash, a scrambled code made from your password, ever leave your browser. You can also check your email address there.

Pinzen's free plan includes health checks and CSV import (a simple spreadsheet-style file) from another password manager. It works on one trusted device at a time; syncing across devices is part of the paid plan. To see your own weak spots, create a free vault and add or import your passwords.

Still, no tool replaces the basics: unique passwords, two-step sign-in, and a credit freeze when your Social Security number is at risk.

Frequently asked questions

What should I do first after a data breach?

First, confirm the notice is real by going to the company's website yourself, not through links in the message. Then change the password for the breached account and your main email. If card details or your Social Security number were exposed, call your bank or start credit freezes right away.

Do I need to freeze my credit after a data breach?

Yes, if your Social Security number or another government ID number was exposed. In the U.S., freezes are free at all three credit bureaus, don't affect your score, and can be lifted when you apply for credit. If only an email or password leaked, a freeze isn't urgent, though many people keep one anyway.

How do I know if a data breach notice is real?

Don't use the links or phone numbers in the message. Go to the company's official website yourself and look for the same announcement, or call a number you already trust. Be wary of any message that asks for payment, gift cards, or your password, or that pushes you to act within minutes.

Should I change all my passwords after a data breach?

No. Start with the breached account, your email, and any account that used the same password, then move on to banking and other important accounts. A password health check shows which passwords are reused, weak, or exposed, so you can focus on the ones that matter instead of changing everything.

Keep your family's passwords in one safe place

Pinzen is free to start. Sign up with Face ID, save your Recovery Kit, and share only what you choose.

Create a free vault

Keep reading

Breaches and Hacked AccountsIs Have I Been Pwned Safe? How Password Checks Stay Private7 min readBreaches and Hacked AccountsHow Often Should You Change Your Password? What Experts Say Now7 min readBreaches and Hacked AccountsI Gave a Scammer My Password: What to Do in the Next Hour8 min read
Pinzen

A private place for the passwords your household depends on.

ProductFeaturesFamily use casesGuidesPlatformsPricing
ResourcesFAQSecurityHelp & supportShare your story
LegalPrivacy policyTerms of use© 2026 Pinzen