Homeβ€ΊBlogβ€ΊArticle
Action Checklist

What to Do After Receiving a Data Breach Letter: Your First 48 Hours

By David S. Harris, Esq.Β·Β·9 min read

A data breach letter tells you something specific: your personal information was involved in a confirmed security incident. What you do in the next two days matters more than what you do over the next two months, because the most damaging forms of fraud tend to happen quickly, before victims have taken basic precautions. This checklist walks through the first 48 hours in a practical order.

Hour 0–2: Confirm the Letter Is Genuine Before Acting On It

Fake breach notices exist, and they are designed to make you click a link or call a number that leads to a scammer. Before you do anything else:

  • Read the letter for specifics. A genuine notice names the company, describes the incident, lists the categories of data involved, and usually references a filing with a state Attorney General.
  • Don't use the contact details in the letter to verify the letter. If you want to confirm it, find the company's website or customer service number yourself, independently.
  • Cross-check the breach. You can look the company up in a registry of official state Attorney General filings, such as our free breach registry.
  • Never provide your Social Security number, account numbers, or passwords in response to any notice that asks you to "verify" your identity. Legitimate notices do not require this.

Hour 2–12: Secure What the Breach Actually Touched

Your protective steps should match the data involved. Re-read the letter and note which categories were exposed, then act accordingly:

  • Login credentials exposed: change those passwords immediately, and change the same password anywhere else you reused it. Turn on multi-factor authentication for every account that offers it.
  • Social Security number exposed: this is the highest-risk category. Go straight to the credit freeze step below.
  • Financial account or payment card numbers exposed: contact your bank or card issuer, ask about a replacement card, and review recent transactions with them.
  • Medical or health insurance data exposed: watch for explanation-of-benefits statements for care you never received, which is the signature of medical identity theft.

Hour 12–24: Freeze Your Credit or Place a Fraud Alert

A credit freeze is the single strongest protection available to most consumers, and under federal law it is free at all three major credit bureaus β€” Equifax, Experian, and TransUnion. A freeze stops new credit accounts from being opened in your name at all, which prevents the most common SSN-driven fraud.

Here is how the two main options compare:

  • Credit freeze: strongest protection; new creditors cannot see your file at all. You must place it separately with each bureau, and you temporarily lift it when you legitimately apply for credit. Free by law.
  • Fraud alert: lighter-touch; creditors are asked to verify your identity before extending credit. One call to any single bureau places it, and it is shared with the other two automatically. Lasts one year, renewable.

A freeze and an alert are not mutually exclusive, but most people choose one or the other. If you plan to apply for a mortgage, car loan, or credit card in the near future, a fraud alert may be the more practical choice because it does not require lifting anything.

Hour 24–48: Document Everything

This step is where future options are preserved or lost. If a class action settlement or another legal remedy later becomes available, your documentation is what supports your position.

  1. Keep the original letter and envelope. The postmark can matter.
  2. Take photos or scans of the letter and store them somewhere durable, not just in your email.
  3. Start a simple log: the date you received the notice, what the letter said was exposed, and every protective action you took, with dates β€” password changes, freeze placements, calls to your bank.
  4. Save receipts for any out-of-pocket costs related to the breach: credit monitoring you paid for, notarization, postage, fees to lift or place protections in some situations, and hours of documented time.
  5. If you see actual fraud, report it at IdentityTheft.gov to create an official FTC record, and file a police report if your bank or a creditor asks for one.

What Not to Do in the First 48 Hours

  • Don't ignore the letter. Notices are legally required disclosure, not marketing mail.
  • Don't panic and pay for expensive "identity protection" services pushed by cold calls claiming to be about the breach.
  • Don't sign up for anything through links in the letter until you have independently verified the notice is genuine.
  • Don't assume enrolling in the offered credit monitoring is enough on its own. Monitoring alerts you to problems; a freeze prevents the most common one.

After the First 48 Hours

Once the immediate protections are in place, shift to monitoring: review your credit reports at AnnualCreditReport.com, watch your bank and card statements for unfamiliar charges, and renew your fraud alert when it expires if you chose that route. If the company offered free credit monitoring, it is usually worth enrolling β€” our companion article walks through what that coverage does and does not include.

Finally, consider whether you want a legal evaluation. Depending on the breach, affected individuals are sometimes able to participate in settlements or other remedies. Deadlines in this area are strict, so if you are going to explore that route, doing it early is meaningfully better than doing it late.

Do I need to contact the police after receiving a breach letter?

Not for the letter itself. A police report becomes relevant only if actual fraud occurs and a creditor, bank, or the FTC asks for one. The letter alone documents exposure, not a crime against you specifically.

Does a credit freeze hurt my credit score?

No. A freeze does not affect your score at all, and it does not interfere with your existing accounts. It only blocks new credit inquiries, which is precisely the fraud pathway it is designed to shut down.

What's the difference between a fraud alert and a credit freeze?

A fraud alert asks creditors to take reasonable steps to verify your identity before extending credit, and placing it with one bureau covers all three. A freeze goes further: it makes your credit file invisible to new creditors entirely, but must be placed separately with each bureau and temporarily lifted when you apply for credit.

Should I enroll in the free credit monitoring the letter offers?

Generally yes β€” it costs you nothing and adds an early-warning layer. Just treat it as one layer, not a substitute for a freeze when sensitive data like your Social Security number was exposed.

How long do I need to stay vigilant after a breach?

Exposed data can circulate and be misused long after the incident. At minimum, keep your protections in place and review statements carefully for at least a year, and keep the letter and your log indefinitely in case a settlement or claim process appears later.

Want a Second Opinion on Your Letter?

If you're unsure what your notice means for your situation, the Law Office of David S. Harris offers free, no-obligation case reviews β€” on a no-win, no-fee basis.

Get Your Free Case Review β†’
Made with AI in Macaly