Technology guide

Respond to a data breach notification

Work out what a data breach letter or email means for you, reduce the risk of fraud and keep a record in case you need to complain or report.

Time needed: 45–90 minutesUpdated: 28 September 2026

A message saying a company has lost your data can be worrying, and criminals also send fake breach notices to trick people. The right response depends on exactly what was exposed. This guide helps you confirm the notice is real, match your actions to the risk and keep watch afterwards.

Step by step

  1. Confirm the notice is genuine

    Do not click links or call numbers in the message. Go to the organisation's website or app directly, or check reputable news coverage, to confirm a breach has happened. Genuine notices usually explain what happened without asking you to pay or hand over full passwords or card numbers.

  2. Identify exactly what was exposed

    Note which types of data are listed: email address, password, phone number, address, date of birth, bank or card details, or identity documents. Each carries different risks, so write the list down and use it to decide your next steps.

  3. Deal with passwords and sign-ins

    If a password was involved, even in scrambled form, change it for that account and anywhere you used the same or a similar password. Turn on 2-step verification where available and sign out of other sessions.

  4. Protect money and payment details

    If card or bank details were exposed, contact your bank using the number on your card and ask about your options, which may include a replacement card. Check statements closely for unfamiliar payments, including small test amounts.

  5. Guard against identity misuse

    If your date of birth, address or identity documents were exposed, check your credit files with the main credit reference agencies for applications you did not make. Some people choose a paid protective registration service from Cifas, the fraud prevention organisation, which adds extra checks when credit is applied for in your name. For stolen passport or driving licence details, follow the guidance on GOV.UK.

  6. Keep records and know where to complain

    Save the notice and write a dated note of the actions you took. If you are unhappy with how the organisation handled your data or your questions, complain to them first, then to the Information Commissioner's Office if needed. If you lose money, report it to Report Fraud, or Police Scotland on 101 in Scotland.

Ready-to-use checklist

  • Notice checked through an independent route
  • Exposed data types listed
  • Affected and reused passwords changed
  • 2-step verification switched on
  • Bank contacted if payment details exposed
  • Statements checked for unusual payments
  • Credit files checked if identity data exposed
  • Notice and actions saved in a dated record

Practical tips

  • Expect targeted scams that quote the breach and your real details, and never share one-time codes.
  • Set a calendar reminder to recheck statements and credit files over the following months.
  • If several family members use the same service, check whether each of them was affected.

Common problems

The company will not tell me what data was involved.

You have a right to ask what personal data an organisation holds about you through a subject access request. Put your question in writing and keep a copy. If you do not get a proper response, the Information Commissioner's Office explains how to raise a concern.

I found an application for credit I did not make.

Contact the lender and the credit reference agency straight away to dispute it, and report it as fraud to Report Fraud or Police Scotland. Keep the crime or reference number you are given for later correspondence.

Should I pay for a credit monitoring service?

It is a personal choice, and some breached organisations offer monitoring free of charge. You can check your credit files yourself through the credit reference agencies' free options. Be wary of unsolicited offers of paid protection that arrive after a breach.