A message saying a company has lost your data can be worrying, and criminals also send fake breach notices to trick people. The right response depends on exactly what was exposed. This guide helps you confirm the notice is real, match your actions to the risk and keep watch afterwards.
Step by step
Confirm the notice is genuine
Do not click links or call numbers in the message. Go to the organisation's website or app directly, or check reputable news coverage, to confirm a breach has happened. Genuine notices usually explain what happened without asking you to pay or hand over full passwords or card numbers.
Identify exactly what was exposed
Note which types of data are listed: email address, password, phone number, address, date of birth, bank or card details, or identity documents. Each carries different risks, so write the list down and use it to decide your next steps.
Deal with passwords and sign-ins
If a password was involved, even in scrambled form, change it for that account and anywhere you used the same or a similar password. Turn on 2-step verification where available and sign out of other sessions.
Protect money and payment details
If card or bank details were exposed, contact your bank using the number on your card and ask about your options, which may include a replacement card. Check statements closely for unfamiliar payments, including small test amounts.
Guard against identity misuse
If your date of birth, address or identity documents were exposed, check your credit files with the main credit reference agencies for applications you did not make. Some people choose a paid protective registration service from Cifas, the fraud prevention organisation, which adds extra checks when credit is applied for in your name. For stolen passport or driving licence details, follow the guidance on GOV.UK.
Keep records and know where to complain
Save the notice and write a dated note of the actions you took. If you are unhappy with how the organisation handled your data or your questions, complain to them first, then to the Information Commissioner's Office if needed. If you lose money, report it to Report Fraud, or Police Scotland on 101 in Scotland.
Ready-to-use checklist
- Notice checked through an independent route
- Exposed data types listed
- Affected and reused passwords changed
- 2-step verification switched on
- Bank contacted if payment details exposed
- Statements checked for unusual payments
- Credit files checked if identity data exposed
- Notice and actions saved in a dated record
Practical tips
- Expect targeted scams that quote the breach and your real details, and never share one-time codes.
- Set a calendar reminder to recheck statements and credit files over the following months.
- If several family members use the same service, check whether each of them was affected.
Common problems
The company will not tell me what data was involved.
You have a right to ask what personal data an organisation holds about you through a subject access request. Put your question in writing and keep a copy. If you do not get a proper response, the Information Commissioner's Office explains how to raise a concern.
I found an application for credit I did not make.
Contact the lender and the credit reference agency straight away to dispute it, and report it as fraud to Report Fraud or Police Scotland. Keep the crime or reference number you are given for later correspondence.
Should I pay for a credit monitoring service?
It is a personal choice, and some breached organisations offer monitoring free of charge. You can check your credit files yourself through the credit reference agencies' free options. Be wary of unsolicited offers of paid protection that arrive after a breach.