Byte Technology
Byte Privacy 10 min read

You Got a Data Breach Notice. The First 72 Hours, Sorted by What Leaked

A breach notice lists what was exposed for a reason. Your response depends on whether it was a password, a card number, or your Social Security number.

Byte Editorial

A data breach notice lands in your inbox, and it is written to be survivable. It apologizes, it says the incident has been contained, and it offers you a year of free credit monitoring. Somewhere in the middle is a list of what was actually exposed — and that list is the only part that matters.

Your response is not determined by the size of the breach or the prominence of the company. It is determined by which type of data leaked. A leaked password and a leaked Social Security number are different problems with different fixes, and conflating them is how people end up freezing credit they did not need to freeze while leaving a reused password untouched.

The first question is not “what leaked” — it is “has anyone used it”

Before you do anything, answer one question honestly: has someone actually used your information?

That is not a rhetorical filter. It is the first branch on the FTC’s breach response guide at IdentityTheft.gov, and it exists because the two paths are genuinely different. If someone has used your information, you are an identity theft victim and you should go to IdentityTheft.gov and file a report. If nobody has used it — or you do not know yet — you do not file a report. You take protective steps instead.

This distinction matters more than it looks. An identity theft report is a statement, under penalty of law, that a crime occurred against you. Filing one when nothing has happened is not a harmless precaution. The Social Security Administration states the point directly for its own domain: if your number was exposed or stolen but not misused, you do not need to file an FTC identity theft report.

If you are in the second category — exposed, not yet used — here is the sequence, ordered by how much the clock actually matters.

The first hour: freeze, then look

Place a security freeze with all three credit bureaus. Equifax, Experian, and TransUnion. Individually, because a freeze is applied per bureau. It is free, it is a statutory right under 15 U.S.C. § 1681c-1, and the bureaus must place it within one business day of an online or phone request.

A freeze blocks a bureau from releasing your file to a new creditor, which is the single most effective way to stop someone from opening an account in your name. Unlike a fraud alert, it does not require the person pulling your file to take any extra step — the file simply is not available.

Then pull your reports. All three, free, from AnnualCreditReport.com. This is the only federally authorized source, and you can now check each bureau’s report weekly at no cost. Read them for accounts you do not recognize, and for hard inquiries you did not authorise. What you find here determines whether you stay on the protection path or move to the recovery path.

One clarification the notice will not give you: a freeze and a fraud alert are not the same thing, and the differences — duration, who qualifies, which bureaus you must contact — are laid out in Credit Freeze, Fraud Alert, or Credit Lock. Short version: freeze first, and only add an alert if you have reason to believe someone is actively trying.

Now sort by what leaked

This is where most breach responses go wrong, because people apply a credit-based fix to a non-credit problem. Work down the notice’s list and treat each item separately.

What was exposedWhat it enablesWhat actually helps
Password or login credentialsAccount takeover, especially where you reused the passwordChange the password everywhere it was reused, then turn on multi-factor authentication. A credit freeze does nothing here.
Debit or credit card numberUnauthorized chargesDispute promptly — the deadline is the whole ballgame on a debit card. See the note below the table.
Bank or investment account numberUnauthorized transfersContact the institution directly. Ask what monitoring and transfer limits apply. Do not rely on a credit freeze to secure an account.
Social Security numberNew credit, tax refund fraud, employment fraudFreeze all three bureaus, get an IRS Identity Protection PIN, consider E-Verify Self Lock, and check your earnings record at SSA. This is the branch that needs the most work.
Driver’s license or state ID numberFraudulent identity documentsContact your state DMV or licensing agency. Credit tools generally do not help.
Passport numberLimited on its own — travel requires the physical passportReport only if the physical passport is lost or stolen. A leaked number by itself does not let anyone travel.
Medicare or Medicaid informationBilling fraud against your benefitsContact 1-800-MEDICARE (1-800-633-4227) or, for Medicaid, your state Medicaid office.
Children’s informationCredit files opened in a minor’s name, which often sit undiscovered for yearsFreeze the child’s credit file with each bureau. Parents and guardians may do this for anyone under 16.
Health or medical recordsMedical identity theft — care billed and recorded under your nameRequest your medical records and review them for treatment you did not receive. This is a records problem, not a credit problem.

The pattern in that table is the thing to take away: credit tools protect your credit file, and only your credit file. They are the right answer for a Social Security number and the wrong answer for a password, an account number, or a medical record. If your notice lists a password and no financial identifiers, freezing your credit is not a partial response — it is a non-response.

One row in that table is more reassuring than the others, and it is worth stating plainly. A leaked passport number, on its own, is not a travel risk. The State Department’s position is that no one can travel on a passport number alone — international travel requires the physical passport, and passport books and cards carry anti-forgery features. The document to report is the physical one, and only if it is lost or stolen: once reported, it is canceled and cannot be used for travel even if it turns up again. If your breach notice lists a passport number but your passport is in your desk drawer, you do not need to report anything to the State Department over the number alone.

One row deserves a longer answer. A leaked card number is the one case where how fast you move changes what you legally owe, and the difference between credit and debit is larger than most people realize.

On a credit card, your liability for unauthorized charges is capped at $50 under 15 U.S.C. § 1643, and that cap does not grow if you report late — most issuers waive even the $50. On a debit card the money is already gone from your account, and the cap escalates with delay under 15 U.S.C. § 1693g: $50 if you report within two business days of learning the card was lost or stolen, $500 if you report later than that but within 60 days of the statement being sent, and no federal cap at all after 60 days. That last tier is the one worth avoiding. If a breached debit card number concerns you and you have not reported it, report it today rather than at the end of the month.

If your Social Security number is on the list

This is the branch worth going slow on, because a Social Security number does not change. Three things are worth considering, in rough order of effort.

An IRS Identity Protection PIN. This is a six-digit number that must be included on your federal tax return for the IRS to accept it. Without it, someone who has your Social Security number can file a return in your name and claim a refund before you file. The PIN is available to any taxpayer with a Social Security number or ITIN who can verify their identity — you do not need to have been a victim already. It is valid for one calendar year and regenerates each year, and if you obtain it online you must retrieve the new one yourself each January rather than waiting for a letter. Applicants under 18 cannot use the online tool and must apply through an alternative process.

The IRS is blunt about one thing: the IRS will never ask you for your IP PIN. Any call, email, or text requesting it is a scam, and it is a scam that only targets people who have done the sensible thing and obtained one.

E-Verify Self Lock. Run by the Department of Homeland Security and the Social Security Administration, this lets you place a lock on your Social Security number within the E-Verify system, so that an employer attempting to verify employment authorisation with your number gets a mismatch instead. It is aimed at a specific fraud pattern: someone else working under your identity, with their wages reported to the IRS and SSA in your name. The operational catch is that the lock applies to you as well as to any impostor. If you are about to start a job with an E-Verify employer, you must sign in and unlock the number first, or you will trigger the same mismatch for yourself. You will also need to re-answer three challenge questions to resolve it.

Check your earnings record. If someone is working under your number, the evidence shows up as wages you never earned on your Social Security statement at ssa.gov. Review it, and if you find earnings that are not yours, contact the Social Security Administration. This is the cheapest early-warning system available for that particular fraud, and almost nobody uses it.

A new Social Security number is almost certainly not available to you. This is the option people ask about first and it is the one the SSA is most restrictive about: in most cases of a lost or stolen number you cannot get a new one without evidence that someone else is misusing it. Even then, a new number is a partial fix — agencies and institutions retain records linking you to the old one, so the problem follows you rather than disappearing.

Two things the notice will not tell you

Free credit monitoring is a notification service, not a lock. It watches your file and tells you when it changes. It does not prevent a new account from being opened, and it watches only the credit bureaus — so it will not flag a fraudulent tax return or an impostor at an E-Verify employer. Accept it, because it is free and it may catch something, but do not let it stand in place of a freeze.

Someone else’s notification timeline is not your deadline. Breach notification deadlines in the law run against the organization that lost the data, and they vary by state — there is no single federal notification statute covering all personal data. California, as one example, now requires that affected residents be notified within 30 calendar days of discovery, and the Attorney General within 15 calendar days when more than 500 residents are involved, under Civil Code § 1798.82 as amended by Senate Bill 446, effective January 1, 2026. That is California’s rule. Your state’s deadline may be longer, shorter, or phrased as a reasonableness standard rather than a number of days. None of it creates an obligation on your side, and none of your own remedies expire if you take a month to work through them.

A 72-hour plan you can actually finish

  1. Answer the branch question. Has anyone used your information? If yes, file at IdentityTheft.gov. If no, continue.
  2. Freeze all three credit bureaus — individually, free, minutes each.
  3. Pull all three reports at AnnualCreditReport.com and read them for unfamiliar accounts and inquiries.
  4. Work the table. Change reused passwords and enable multi-factor authentication. If a debit card number was exposed, report it today — the liability cap rises at day two. If a Social Security number is on the list, request an IRS Identity Protection PIN, consider E-Verify Self Lock, and check your earnings record.
  5. Decline any paid recovery service. Everything here is free by law or directly from the agency that administers it.
  6. Write down what you did and when. Dates, names, confirmation numbers. If fraud surfaces later, this record is what lets you establish that you acted promptly.
  7. Re-check your reports in a few months. A single look today catches what has already happened; a second look later catches what is attempted afterward.

The bottom line

The notice is not the event. The list of what leaked is the event. Read that list, sort yourself into one row of the table, and act on that row rather than on the breach in general. If a Social Security number is involved, the priority order is freeze, then PIN, then earnings record. If it is a debit card number, report it today, because your liability cap rises from $50 to $500 after two business days. If it is a password, the priority order is change the password everywhere it was reused and turn on multi-factor authentication — and your credit file is not part of the problem.

Byte is the technology site of the Omni Mundi Compendium network. The difference between the three credit protection tools is covered in Credit Freeze, Fraud Alert, or Credit Lock, and the question of what federal websites are required to publish about their own systems is in Why Federal Websites Now Say “SI”.

This article is general information about federal consumer-protection law, not legal advice. Breach notification duties, credit file rules for minors, and identity theft remedies vary by state. It is AI-written and independently AI-reviewed before publication; the review standard and this article’s findings are recorded in the network’s editorial review log.

Frequently asked questions

Should I file an identity theft report if my Social Security number was breached but nobody has used it yet?
No. The Social Security Administration is explicit on this point: if your number was exposed but not misused, you do not need to file an FTC identity theft report. An identity theft report is a statement that fraud occurred. Use IdentityTheft.gov's lost-or-stolen-information path instead, which gives you a protection checklist without asserting a crime. Filing a false report is itself an offense.
The notice offers free credit monitoring for a year. Is that enough?
Credit monitoring is a notification service, not a lock. It watches your credit file and tells you when something changes; it does not stop a new account from being opened, and it covers only the credit bureaus, so it will not flag someone filing a tax return or taking a job under your number. It is worth accepting because it is free, but treat it as an addition to a freeze, not a substitute for one.
How long do I have to act?
There is no deadline on your side. Breach notification deadlines in the law run against the company that lost the data, not against you, and they vary by state. What changes with time is your exposure, not your rights: the sooner you freeze, the smaller the window in which an account can be opened. Nothing about your remedies expires if you wait a month.
Do I need to pay anyone to help me respond to a breach notice?
No. Every tool described here is free by law or free to request directly from the agency that runs it: credit freezes and fraud alerts under 15 U.S.C. § 1681c-1, reports at AnnualCreditReport.com, the IRS Identity Protection PIN, and E-Verify Self Lock. Services that charge a monthly fee for breach recovery are selling convenience, not access.

Sources

  1. Federal Trade Commission, IdentityTheft.gov — "Data Breach" response guide, including the initial question "Did someone use your information?", the check-freeze-monitor first step, and the data-type-specific branches for Social Security numbers, passwords, card numbers, bank accounts, driver's licenses, passports, Medicare and Medicaid, and children's information
  2. Social Security Administration — "Identity Theft and Social Security Numbers" and the SSA Office of the Inspector General fraud reporting guidance: the position that an exposed-but-unused Social Security number does not require an FTC identity theft report, the eServices block and Direct Deposit Fraud Prevention block, and the SSA OIG fraud hotline 1-800-269-0271
  3. Internal Revenue Service — "Get an Identity Protection PIN (IP PIN)": the six-digit PIN, eligibility for any taxpayer with a Social Security number or ITIN who can verify identity, the one-calendar-year validity and annual regeneration, the forms it applies to, the rule that applicants under 18 cannot use the online tool, and the warning that the IRS never asks for your IP PIN
  4. Internal Revenue Service — "Data Breach Information for Taxpayers": the guidance to identify which type of personal information was exposed, the judgment that a tax account is most at risk when both a Social Security number and financial data such as wage records are involved, and the instruction to file Form 14039 only once
  5. U.S. Department of Homeland Security and Social Security Administration, E-Verify — "Self Lock": the myE-Verify feature that locks a Social Security number against use in E-Verify cases, the resulting Tentative Nonconfirmation for anyone who tries to use it, and the requirement that the account holder unlock it before starting a job with an E-Verify employer
  6. U.S. Department of State, Bureau of Consular Affairs — "Report a Lost or Stolen Passport": the requirement to report immediately to guard against identity theft, the rule that a reported passport is canceled and unusable for travel even if recovered, the three reporting methods including Form DS-64 and the online form filler, the 1-877-487-2778 number and 1-888-874-7793 TTY for the National Passport Information Center, and the statement that a passport number alone cannot be used for travel because the physical document is required
  7. 15 U.S.C. § 1643 (Truth in Lending Act) — liability of a credit card holder for unauthorized use, capped at $50, with no liability for charges made after the issuer is notified
  8. 15 U.S.C. § 1693g (Electronic Fund Transfer Act) — consumer liability for unauthorized electronic fund transfers, including the $50 tier for reporting within two business days, the $500 tier for later reporting within 60 days of the statement, and the absence of a federal cap beyond that
  9. 15 U.S.C. § 1681c-1 (Fair Credit Reporting Act) — identity theft prevention; fraud alerts and active duty alerts, including the one-year initial fraud alert, the seven-year extended fraud alert requiring an identity theft report, and the security freeze definitions and placement deadlines
  10. 15 U.S.C. § 1681j (Fair Credit Reporting Act, as amended by the Fair and Accurate Credit Transactions Act of 2003) — the free annual file disclosure, and the centralised source at AnnualCreditReport.com through which requests must be made
  11. California Civil Code § 1798.82, as amended by Senate Bill 446 (2025), effective January 1, 2026 — an example of a state notification deadline: 30 calendar days to notify affected residents and 15 calendar days to notify the Attorney General when more than 500 residents are affected. Breach notification duties vary by state and this is one state's rule, not a national standard
#data breach#identity theft#credit freeze#IP PIN#Social Security number#breach notification#E-Verify Self Lock