After a breach: the first week, in order

By MercPrivacy · Published 2026-07-02 · Updated 2026-08-05

A breach notice means a copy of your data is loose. The first week, in order: read what leaked, freeze credit free at all three bureaus, rotate reused passwords, and log the noise that follows.

The letter is always calm. We are writing to inform you of a security incident that may have involved some of your information. Somewhere between the apology and the offer of complimentary monitoring sits the actual news: a copy of your data is loose, and the company that lost it cannot get it back.

What you do in the first week matters more than anything the company offers you. Not because panic is warranted — it is not — but because a few free, unglamorous moves close the doors that matter before anyone tries them.

Here is the week, in order.

## Day one: read what was actually taken

Breach notices name categories of data, and the categories decide your week:

- **Card or bank numbers** — the risk is fraud on that account. Fast to fix, and mostly the bank's job. - **Social Security number and date of birth** — the risk is new accounts opened in your name. This is the pairing that justifies the full checklist below. - **Passwords** — the risk is every other site where you reused the same one. - **Email, phone, address** — the quiet one. Contact data feeds list vendors, dialers, and phishing crews. Expect noise more than fraud.

Match the response to the exposure and the week stays short. Read the notice itself rather than the news coverage of it: the letter about your account is usually more specific than any headline about the incident, and the difference decides your checklist.

## Days one and two: money first

1. **Check card and bank activity.** Scan recent transactions, dispute anything unfamiliar with the issuer, and turn on transaction alerts while you are in the app. 2. **Freeze your credit.** Credit freezes are free at all three bureaus, they block new credit accounts from being opened in your name, and they can be lifted when you actually need to open credit. The catch people miss: you place the freeze at each bureau separately — one freeze is a locked front door with two side doors standing open. If your Social Security number was in the breach, this is the highest-value move of the week. 3. **Pull your reports.** Everyone gets free weekly credit reports at [annualcreditreport.com](https://www.annualcreditreport.com). Look for accounts or inquiries you do not recognize; a clean report today is your baseline for the months ahead. 4. **Or set a fraud alert.** If a freeze feels heavier than you want, a fraud alert asks creditors to take extra steps to verify identity before extending credit. Free, lighter-touch, and better than nothing — though the freeze is the stronger lock.

> The breach was not your fault. The next account opened in your name is preventable anyway.

A word on the complimentary credit monitoring the letter offered: take it if you like — it costs nothing extra and another alarm hurts nobody. Just be clear about what it is. Monitoring tells you something happened after it happened. The freeze prevents the main something from happening at all. One is a smoke detector, the other is a lock, and the letters tend to offer the detector.

## Days three and four: passwords and logins

If a password was involved, assume the leaked copy is already being tried elsewhere, because that is what leaked passwords are for:

- **Change it at the breached site** — obvious, done in a minute. - **Change it everywhere you reused it** — the actual risk. Attackers try known email-and-password pairs against banks, email providers, and stores at scale. - **Move to a password manager** — unique passwords per site turn the next breach into a one-site problem instead of a chain reaction. - **Turn on two-factor login** — email and financial accounts first; your inbox is the master key to everything else. - **Consider aliases going forward** — a unique email address per company tells you exactly who leaked when the spam starts arriving somewhere new.

## The rest of the week: expect the noise, and log it

Breached contact lists circulate, and the weeks after a breach commonly bring more calls, more texts, and more phishing dressed in the breached company's branding. The scripts get more convincing precisely because the caller now knows something true about you. Expect the classics: a text about a package that needs a small fee, a call from your bank's fraud department that is not your bank, an email inviting you to claim breach compensation through a link. Real institutions survive you hanging up and calling back on the number printed on your card; imposters do not, which makes that one habit worth more than any filter.

Two habits carry you through it:

- **Treat inbound as hostile.** The company will not call to verify your Social Security number. Anyone who does is not the company. - **Log the surge.** Numbers, dates, what was said, whether you said stop. Unwanted calls and texts carry statutory teeth of their own — $500 per violating call or text under the TCPA, up to $1,500 where the violation is willful or knowing — and a contemporaneous log is what makes any of that usable. The method is in [the evidence file](https://mercprivacy.com/knowledge/the-evidence-file-what-to-keep), and the week after a breach is exactly when to start one. More on the call side at [spam call defense](https://mercprivacy.com/spam/calls).

## If identity misuse actually appears

If a new account, a tax problem, or a collection notice surfaces that is not yours, go to [identitytheft.gov](https://www.identitytheft.gov). The FTC's site generates a personal recovery plan and the paperwork most institutions expect to see, tailored to what actually happened. Keep the breach notice itself in the same folder — it anchors your timeline, and a documented breach preceding the misuse is a fact you will be glad to have on paper. From there, recovery is mostly paperwork, and paperwork rewards the organized.

## If the phone will not stop

The after-breach surge is our lane: suppressing the broker-and-list layer that feeds it, and documenting the callers who ignore the rules. [Stephanie](https://mercprivacy.com/stephanie) answers instantly and free, or call (830) 587-5011. We are not a law firm; when a matter requires legal representation, a licensed attorney is engaged.